← Back to Analysis
Defend, Disperse, Recover: A New Resilience Model for AI Continuity
Iranian strikes on AI infrastructure expose a new wartime vulnerability. Gulf states need a resilience model that protects facilities, distributes workloads, and accelerates recovery.
Jesse Marks
August 2, 2026
Iranian strikes on AI infrastructure should change how governments think about the security of strategic compute. For years, data center protection has focused on cyber intrusion, physical access, power redundancy, and disaster recovery. Those measures remain necessary, but they are no longer sufficient. As artificial intelligence becomes increasingly important to military operations, intelligence analysis, financial systems, public administration, and critical industries, the infrastructure supporting it is becoming a plausible target in conflict.
See our new data product: Data Center Strikes in the 2026 Iran War, for further context for this paper.
Data centers can no longer be treated solely as commercial facilities designed around cost, latency, and uptime. In high-risk environments, they must also be understood as strategic infrastructure whose disruption could degrade military effectiveness, economic activity, and administrative capacity. The central policy challenge is broader than protecting individual facilities. It is ensuring that essential computational capabilities remain available even when domestic infrastructure is damaged or destroyed.
A useful framework for approaching this challenge is the conflict resilience triangle model built around three principles: defend, disperse, and recover.
Defend
The first requirement is to improve the physical protection of critical AI infrastructure. High-value data centers in conflict-prone regions should be incorporated into national critical-infrastructure and defense planning rather than left primarily to private security arrangements. This may require hardened construction, redundant energy supplies, protected telecommunications, layered perimeter security, and integration with national air and missile defense networks. In some cases, governments may need dedicated point-defense systems capable of intercepting drones, cruise missiles, or other precision weapons approaching particularly important facilities.
This does not imply that every commercial data center should receive military protection. Governments will need to distinguish ordinary computing facilities from infrastructure supporting essential state functions, military applications, financial systems, or nationally significant AI capabilities. Priority sites may warrant protection comparable to power plants, command centers, ports, or airfields.
Physical defense, however, cannot guarantee continuity. Fixed infrastructure remains vulnerable to saturation attacks, sabotage, power disruption, and repeated strikes. Even a well-defended facility can be disabled. Resilience therefore depends on ensuring that the loss of a site does not produce the loss of the capability it supports.
Disperse
The second requirement is the ability to distribute workloads across multiple facilities during periods of heightened risk. This may involve building additional domestic sites or purchasing backup services from commercial cloud providers. More importantly, states should develop prearranged mechanisms for transferring eligible critical workloads to trusted infrastructure abroad during emergencies.
Under a framework such as the U.S.-led Pax Silica, participating states could negotiate reciprocal continuity agreements for strategically important data processing. If data centers in the United Arab Emirates were degraded during a regional conflict, designated government or commercial workloads could shift temporarily to certified facilities in the United States, Germany, Australia, Japan, or another trusted partner. Similar arrangements could operate in reverse when other members faced disruption.
The immediate objective would be tactical and strategic continuity. A government might lose part of its domestic compute infrastructure without losing the ability to process timely intelligence, manage public services, keep financial transactions online, or operate critical AI workloads.
This system would require extensive preparation. Workloads cannot be moved reliably across borders during a crisis unless legal, technical, and operational arrangements are already in place. Participating countries would need common standards for encryption, identity management, network security, hardware certification, data handling, access controls, and incident response. They would also need to determine which workloads were eligible for relocation, who could authorize an emergency transfer, how foreign-hosted systems would be supervised, and when processing would return to domestic infrastructure.
A credible arrangement would also require preallocated reserve capacity. Commercial providers often operate close to capacity during periods of high demand; a state cannot assume that sufficient compute will become available once a conflict has begun.
The model resembles military logistics. Defense partnerships do not assume that every base, port, or supply route will remain operational during conflict. They preserve capability through redundancy, access agreements, prepositioning, and rerouting. Strategic compute should increasingly follow the same logic: a network of trusted continuity partners providing access to precertified infrastructure, reserved capacity, and rapid workload migration when domestic facilities become unavailable.
Dispersal would also reduce the strategic value of attacking AI infrastructure. If critical workloads can move rapidly to predetermined facilities in trusted partner countries, destroying any single site is less likely to produce a sustained loss of national capability. Attacks may still impose economic costs and temporary disruption, but their ability to alter the broader balance of power diminishes. The relevant security objective is the survivability of function.
Recover
The third pillar is recovery. Moving workloads abroad may sustain operations during a crisis, but it is not an indefinite substitute for domestic capacity. States must also be able to repair, replace, or rebuild damaged infrastructure quickly.
Recovery planning should include assured access to servers, networking hardware, cooling systems, power components, and the specialized personnel needed to restore operations. Governments may need strategic reserves of critical hardware, priority-access agreements with suppliers, and alternate sites that can be activated when damaged facilities require extensive reconstruction. Telecommunications and energy infrastructure belong in the same framework: restored compute has little operational value without reliable power and secure connectivity.
This is particularly important because advanced AI hardware can be difficult to replace on short notice. Export controls, supply-chain bottlenecks, long procurement cycles, and limited access to high-end chips could leave damaged facilities offline for months. Resilience planning must therefore cover the entire supporting ecosystem.
A New Role for U.S. Technology Partnerships
The resilience triangle creates an opportunity for the United States to broaden its international AI partnerships. Current policy debates focus heavily on access to semiconductors, frontier models, cloud services, and export controls. These policies shape which countries can build advanced AI capabilities, but provide fewer answers about how those capabilities would be sustained during conflict.
Washington could distinguish its partnerships by offering trusted continuity arrangements alongside access to hardware and software. For countries investing heavily in AI infrastructure—especially those in exposed regions—guaranteed emergency compute capacity could become a major strategic benefit.
A continuity network would also reinforce U.S. technology standards. Participating states would have incentives to adopt compatible cybersecurity practices, trusted hardware, common cloud architectures, and interoperable operating procedures. Over time, this could create a more integrated ecosystem in which technological alignment rests partly on a shared interest in infrastructure resilience.
Such agreements would require careful limits. Military systems, classified files, personally identifiable information, and other sensitive datasets may require separate treatment. States would need to decide in advance which functions could move abroad, which could operate only within specially secured facilities, and which must remain on national territory. Less sensitive applications could move through conventional trusted-cloud environments; more sensitive workloads could be processed in isolated facilities governed by stricter legal and technical controls.
Protecting Capability, Not Only Infrastructure
The growing strategic importance of compute makes it a new category of wartime vulnerability. As governments concentrate economic and administrative functions in a small number of highly visible facilities dependent on complex energy, telecommunications, and hardware supply chains, contingency planning for AI continuity is becoming urgent.
No state can assume that every critical facility will remain protected during conflict. Countries such as the UAE and Saudi Arabia therefore need systems capable of absorbing disruption without losing essential functions. Defense lowers the probability that an attack succeeds. Dispersal prevents the loss of one facility from disabling national capability. Recovery limits the duration and strategic consequences of disruption.
Together, these measures provide a more credible model for AI infrastructure security than physical protection alone. They also suggest that future technology partnerships will involve not only the acquisition of advanced capabilities, but the interstate arrangements needed to sustain those capabilities when they come under attack.