Guide › Part 11
Part 11
Security
12 chapters
11.111.211.311.411.511.611.711.811.911.1011.1111.12
Threat Model, Assets & Security Levels for AI Infrastructure
An AI campus concentrates frontier weights, allocation-constrained silicon, and strategically targeted infrastructure; name the adversary tier it must survive before buying controls; that target level derives the whole stack and its cost.
Physical Security: Siting, Zones & Kinetic/Drone Threats
Physical security is fixed by siting years before the first attack — standoff, overhead airspace, and the exposed utility tie set in concrete — and since 2026 the drone threat is real.
Supply-Chain Security & Hardware Provenance
An AI data center's security boundary runs from the fab to the shredder, and any link in that supply chain you cannot cryptographically re-verify is one an adversary can substitute.
Hardware Root of Trust, Firmware & BMC Security
The root of trust anchored in silicon lets a node prove what firmware it runs; cede that anchor to the BMC and one rooted controller owns the rack beneath every defense.
GPU Confidential Computing & Trusted Execution
A GPU TEE removes the operator from the trust boundary for data-in-use; the price is attestation plumbing, residual side-channels, and a performance tax severe on PCIe-bound paths, near-zero on Blackwell.
Multi-Tenant & Workload Isolation Security
Sharing a GPU means inheriting a neighbor's blast radius; before renting fractions of an accelerator, decide which boundary you trust to hold against the adversary your data class faces.
Network Segmentation, Microsegmentation & Zero Trust
Training fabrics are built flat for collective bandwidth, so segmentation decides where a compromised node's blast radius ends; a perimeter firewall alone guards a network with no interior walls.
Model & Weight Protection (At-Rest, In-Transit, In-Use)
Frontier weights are a few terabytes an adversary can copy silently and permanently; protecting them means controlling every path out of a machine built to emit terabytes per day.
Insider Threat & Human-Layer Security
Insider access runs through most attack vectors, and it is the gap holding frontier programs at RAND Security Level 2; the climb to SL4-5 is bought with human-layer controls and friction.
Cyber-Physical & Destructive Attacks on OT/Facility Systems
A compromised control plane can create destructive states, so allocate each protection function from the project hazard and risk analysis, then engineer the required independence, integrity, bypass control, diagnostics, proof testing, and defense in depth.
Compliance, Certification & Governance
Compliance frameworks are an upstream scoping decision — they fix where data may sit, which workloads you can host, and who may touch the silicon; the wrong portfolio makes a campus legally unsellable.
Security Operations, Detection & Incident Response
Security operations tests Part 11's controls against a live adversary; on an AI campus the SOC must span a converged estate where one intrusion becomes a kinetic, life-safety, and grid event.