Guide › Part 11
Part 11
Security
12 chapters
11.111.211.311.411.511.611.711.811.911.1011.1111.12
Threat Model, Assets & Security Levels for AI Infrastructure
Frontier weights, concentrated accelerator inventory and plant controls are different valuable assets; name which adversary can steal, disable or manipulate each before selecting controls.
Physical Security: Siting, Zones & Kinetic/Drone Threats
Physical security is fixed by siting years before the first attack: standoff, aerial approach paths (drone incursions became a live threat in 2026) and exposed utility ties can bypass a ground-intrusion perimeter, so assess their actual reach and outage consequence before treating detection as protection.
Supply-Chain Security & Hardware Provenance
Carry supplier, custody, identity and measured-state evidence from the fab through receiving, repair and media destruction; cryptography cannot replace physical custody evidence.
Hardware Root of Trust, Firmware & BMC Security
An immutable silicon root can authenticate measured firmware evidence; on platforms where the BMC holds host and device power, cede that anchor to the BMC and one rooted controller owns the rack beneath every defense. Test those powers and recovery paths.
GPU Confidential Computing & Trusted Execution
A supported GPU/CPU TEE can exclude specified operators from plaintext access; the price is attestation plumbing, key-broker availability, residual side-channels and a performance tax that is severe on PCIe-bound paths and about 1–3% on a tuned Blackwell serving stack — price all four on the named workload.
Multi-Tenant & Workload Isolation Security
Choose the sharing mode by the boundary it actually enforces, then qualify tenant handoff, privileged control paths and failure propagation before selling hostile tenants the same resource.
Network Segmentation, Microsegmentation & Zero Trust
Where a collective training fabric admits broad east-west reach, a perimeter firewall leaves compromised-node paths inside the boundary; place and test enforcement without assuming all fabrics are flat.
Model & Weight Protection (At-Rest, In-Transit, In-Use)
An exfiltrated copy of frontier weights cannot be recalled by revoking a key. Size the actual artifact and all export channels, then bind key and export policy to the model release.
Insider Threat & Human-Layer Security
Insider access runs through most attack vectors, and it is the human-layer gap between RAND Security Level 2 and Security Level 3, where insiders first enter the threat model: limit what one privileged person can authorize, bind exceptional access to a specific action, prove revocation across every credential and active session, and measure the operating friction that SL4–5 human-layer controls add alongside the exposure they remove.
Cyber-Physical & Destructive Attacks on OT/Facility Systems
A compromised control plane can create destructive states, so allocate each protection function from the project hazard and risk analysis, then engineer the required independence, integrity, bypass control, diagnostics, proof testing, and defense in depth.
Compliance, Certification & Governance
The applicable compliance portfolio constrains workload eligibility, data location and staff access; a mismatch can make an otherwise working campus uncontractable.
Security Operations, Detection & Incident Response
Security operations tests the controls against an adversary; a cyber intrusion can become an OT, life-safety or grid event, requiring escalation through 14.11's incident command.