Guide › Part 11
Part 11
Security
12 chapters
11.111.211.311.411.511.611.711.811.911.1011.1111.12
Threat Model, Assets & Security Levels for AI Infrastructure
An AI campus concentrates frontier weights, allocation-constrained silicon, and strategically targeted infrastructure; name the adversary tier it must survive before buying controls; that target level derives the whole stack and its cost.
Physical Security: Siting, Zones & Kinetic/Drone Threats
Physical security is fixed by siting years before the first attack — standoff, overhead airspace, and the exposed utility tie set in concrete — and since 2026 the drone threat is real.
Supply-Chain Security & Hardware Provenance
An AI data center's security boundary runs from the fab to the shredder, and any link in that supply chain you cannot cryptographically re-verify is one an adversary can substitute.
Hardware Root of Trust, Firmware & BMC Security
The root of trust anchored in silicon lets a node prove what firmware it runs; cede that anchor to the BMC and one rooted controller owns the rack beneath every defense.
GPU Confidential Computing & Trusted Execution
A GPU TEE removes the operator from the trust boundary for data-in-use; the price is attestation plumbing, residual side-channels, and a performance tax severe on PCIe-bound paths, near-zero on Blackwell.
Multi-Tenant & Workload Isolation Security
Sharing a GPU means inheriting a neighbor's blast radius; before renting fractions of an accelerator, decide which boundary you trust to hold against the adversary your data class faces.
Network Segmentation, Microsegmentation & Zero Trust
Training fabrics are built flat for collective bandwidth, so segmentation decides where a compromised node's blast radius ends; a perimeter firewall alone guards a network with no interior walls.
Model & Weight Protection (At-Rest, In-Transit, In-Use)
Frontier weights are a few terabytes an adversary can copy silently and permanently; protecting them means controlling every path out of a machine built to emit terabytes per day.
Insider Threat & Human-Layer Security
Insider access runs through most attack vectors, and it is the gap holding frontier programs at RAND Security Level 2; the climb to SL4-5 is bought with human-layer controls and friction.
Cyber-Physical & Destructive Attacks on OT/Facility Systems
A compromised BMS, EPMS, cooling controller, or power-cap firmware layer can physically destroy an AI factory in seconds, so its last-line trips must live on hardware the control software cannot override.
Compliance, Certification & Governance
Compliance frameworks are an upstream scoping decision — they fix where data may sit, which workloads you can host, and who may touch the silicon; the wrong portfolio makes a campus legally unsellable.
Security Operations, Detection & Incident Response
Security operations tests Part 11's controls against a live adversary; on an AI campus the SOC must span a converged estate where one intrusion becomes a kinetic, life-safety, and grid event.