DataAI & Technology

The AI Race Runs on Data Centers. A Strengthening El Niño Will Test How Exposed They Are.

By Andrea Little Limbago, SVP, Research and Analysis at interos.ai

AI Physical Infrastructure and its Exposure to Force Majeure Events 

In early March 2026, Iranian drones targeted two AWS data centers in the United Arab Emirates and one in Bahrain, leaving millions of people unable to access bank accounts, order taxis, or schedule food deliveries. An Oracle data center in Dubai was bombed a month later. Data centers are now targets in warfare, highlighting the growing exposure of the physical infrastructure powering the AI revolution.  

In an era defined by polycrisis, with multiple and distinct crises interacting simultaneously, warfare is not the only growing threat to the AI physical infrastructure. On June 11, NOAA’s National Weather Service declared that El Niño has formed in the tropical Pacific, and issued an El Niño Advisory. El Niño’s impact is likely to strengthen throughout the fall, causing a whiplash in some areas just emerging from record wet periods into drought, and vice versa.  

While AI risk is largely viewed through a digital lens, it is now strongly correlated with geography due to the physical infrastructure powering it. Whether due to political instability or natural hazards, force majeure scenarios that historically have been viewed as outside the scope of AI risk are now front and center and direct targets in the AI race.  

Toward a Holistic View of AI Risk 

As organizations have rushed toward AI adoption, the potential security vulnerabilities across the AI supply chain has monopolized the AI risk discourse. AI introduces a new form of third-party risk, with a supply chain consisting of the data inputs, outputs, and the model itself, each of which requires security assessments and considerations. For instance, researchers discovered over 100 malicious AI models on the popular, open-source AI platform, Hugging Face. There also are privacy and IP risks if sensitive data is disclosed through AI-assisted chat services, making it accessible to the company producing the technology, or to hackers who have found side channels into the data. Researchers have also demonstrated the ability to spread data-stealing prompt injection worms through large language model (LLM)-powered email assistants. And of course this doesn’t even touch on the security shock earlier this year from Anthropic’s Mythos, which was deemed too dangerous for public release due to its unprecedented ability to discover zero-days and autonomously exploit vulnerabilities. 

While there is rightfully a growing emphasis on securing the digital AI supply chain, there has been less emphasis on securing the physical AI supply chain. “Data center warfare” defines the need to defend and protect AI infrastructure. In the first weeks of the war, Iran published a list of U.S. tech companies deemed viable targets, and a caption declaring, “Enemy’s technological infrastructure: Iran’s new goals in the region.” 

Iran is not the first to target AI infrastructure for geopolitical aims. Just prior to invading Ukraine, Russian hackers targeted Viasat satellites, leading to a significant loss of communication capabilities upon the invasion and effectively destroying the modems and routers with wiper malware that permanently erased data and disabled the systems. More recently, reports highlight collaboration between China and Russia aimed at countering Starlink through a variety of means, including physical destruction. 

Just as the land and space AI infrastructure are at risk, so too are the underseas cables through which almost all global data flows. For example, Gulf countries like Saudi Arabia and the UAE have spent billions of dollars on AI infrastructure, with the infrastructure carrying the data now a geopolitical liability. In May, reports claimed Iran was considering taking control of all seven of the underseas cables in the Strait of Hormuz. These cables have already been targeted from the Red Sea to the South China Sea to the Baltic. Underseas cables not only are essential for the internet and data access, but are critical to the AI business models of these regions.  

The AI Supply Chain and El Niño 

Geopolitical instability is not the only geographically-focused risk for AI infrastructure, but so too is climate instability. A Super El Niño has developed, with a 96% chance that it persists into 2027. El Niño occurs when trade winds weaken and lead to warmer ocean water in the Pacific. The impact will be unequal and variable, with data centers in high-risk areas especially vulnerable. Globally, almost 80% of data center capacity faces heightened risk of natural hazards, including flooding, fire, and drought.  18% of global data centers are in extreme risk zones, heavily concentrated in the U.S., Brazil, Australia, and China. Looking forward, 107 data centers globally are projected to reach maximum climate risk within 15 years, primarily in Brazil, the U.S., Thailand, and the Philippines. El Niño will only exacerbate these risks. 

Data center cooling demands require vast quantities of water, turning drought into a rapidly escalating threat to data center reliability. This year’s El Niño is expected to amplify drought risk in Indonesia and the Philippines, Australia, and South Africa, weaken monsoon season in India, while amplifying flood risk in other parts of South Asia and Eastern Africa. 

Data centers in the UK have already reported outages following the heatwave in early July. UK data centers have been knocked offline in the past, including in 2023 when a heatwave-induced outage hit the NHS, costing $1.9M and making patients’ records inaccessible. In 2022, extreme heat in California knocked an X (Twitter) data center offline, and did the same for Google and Oracle data centers in the UK. 

El Niño is just in the beginning stages and is expected to be the second strongest since 1991. NOAA’s updated outlook in June nearly doubled the odds that El Niño will grow into a very strong event later this year, while the U.S. Climate Prediction Center forecast a 97% chance that El Niño will persist into 2027 as one of the largest El Niño events since 1950. 

What Decision Makers Should Do 

With peak El Niño expected later this year, the questions worth asking now, while a window remains, are concrete. Leaders should know precisely where their AI compute physically runs, down to the campus and the utility, and how correlated those locations are with the rising geopolitical risks and El Niño forecasts. They should know which of their hardware and component suppliers sit in the regions these force majeure events are most likely to disrupt, and whether they understand those suppliers’ sub-tier dependencies. They should know what happens to their most important workloads if a U.S. cluster faces flood disruption at the same moment an Asian supplier faces drought or fire. Most organizations cannot answer that last question, and that gap is the problem.  

The AI boom is often described as a race for intelligence. It is also a buildout of physical infrastructure in some of the most politically unstable and climate-exposed regions in the world. War in the Middle East and a strengthening El Niño will not be the last events to test that footprint. Organizations must reimagine their AI supply not only as a digital supply chain, but as a physical supply chain as well. Securing both the physical and digital AI supply chain is key to resilience in an era defined by force majeure events and uncertainty. 

Related Articles

Back to top button