4 min read

AI’s data-center boom risks a physical-security gap

AI data centers are expanding fast as a US physical-security standard nears expiration, leaving new private facilities exposed to weaker oversight.

Image: TechRadar

AI’s data-center boom is creating a physical-security gap at the same time governments are treating these facilities as critical infrastructure. The immediate trigger is a US regulatory deadline: the Federal Data Center Enhancement Act is due to expire on September 30, with no replacement currently waiting.

The act established minimum standards for federal data centers, including protection against physical intrusion. Broader frameworks such as FISMA and the NIST control catalogue would remain in place, but they set principles rather than the detailed operational assessment that the Enhancement Act required.

Acre Security’s CEO argues that the distinction matters. Without a specific enforcement mechanism, security requirements can be interpreted generously—especially while developers and hyperscalers race to bring AI capacity online faster than power grids, planning departments, and supply chains can comfortably support.

Recommended reading

Texas pauses data-center approvals for grid audits

Why new AI data centers are exposed

The current construction race is directing attention toward metrics that appear prominently in project plans: megawatts, cooling, chips, networking, and cybersecurity. Physical protection is easier to defer, particularly when a facility must be designed and built under intense time and budget pressure.

The risks are practical rather than theoretical. They include:

  • Contractors with unescorted access to server halls
  • Unmonitored loading bays
  • Maintenance doors left open for convenience
  • Former employees whose credentials still open restricted areas

Those access routes can enable data theft, sabotage, or an outage at a facility that may occupy an entire warehouse-sized building.

The greatest exposure is not necessarily in established data centers. Existing operators generally maintain security spending through active contracts and their own risk assessments. The bigger concern is the wave of new, mostly private facilities being specified and procured at extraordinary speed—many of them built without a mandate that requires a data-center-specific physical-security assessment.

If the assessment framework disappears, physical protection can be reduced during procurement to meet a budget or schedule without generating a compliance warning. That creates a gap precisely where the industry is adding capacity fastest.

The US baseline could disappear

This is not the first time the requirement has faced uncertainty. The act’s predecessor lapsed in 2022 and survived only after being folded into the following year’s defense bill. That history suggests the standard can disappear without a single dramatic policy decision: it may simply fail to be renewed.

Security baselines often erode through omission. When a government’s own minimum standard vanishes, private operators may also lose the benchmark against which they quietly measure their facilities—even if their existing security programs remain unchanged.

The policy contradiction is straightforward. Governments are increasingly designating data centers as critical national infrastructure; the UK now does so. Allowing their physical-security baseline to weaken at the same time points in the opposite direction. Infrastructure cannot consistently be classified as critical while its protection is treated as optional.

Physical security must be designed with the facility

Renewing the act would help, but regulation alone is not the proposed answer. The stronger approach is to treat physical security as a core design requirement, specified alongside power and cooling rather than added after the building shell is complete.

Large critical facilities are most vulnerable when security is assembled from disconnected components: a camera in one area, an access reader in another, and alarms added at the end of construction. A more effective system links access control, video, identity, and alarms so that an anomaly in one system can trigger a coordinated response.

That integration also connects physical and digital security. A propped door, cloned badge, or rogue contractor can become the starting point for a cyber incident. If operators cannot correlate a door event with an access log and camera feed, they are likely to respond after an intrusion rather than stop it in progress.

Retrofitting those controls into a live, fully loaded data center is harder and more expensive than designing them in from the beginning. For operators, the practical decision is therefore clear: physical protection needs to be specified during the same planning process as the facility’s compute, power, cooling, and network systems.

The AI infrastructure buildout is solving difficult engineering problems at remarkable speed. But if a federal statute lapses and that alone determines whether new data centers receive an adequate physical-security assessment, the industry’s priorities are misaligned. For infrastructure already considered critical, protecting the building should be a baseline requirement—not the first item cut when a deadline tightens.

Marcus Vance

Enterprise Editor

Marcus follows the money. He covers enterprise software, cloud architecture, and the tectonic shifts in Big Tech strategy. He translates dense earnings calls and complex M&A activity into actionable insights about where the industry is actually heading. If a tech giant makes a silent pivot, Marcus is usually the first to notice.

via TechRadar

/ Keep reading