Two Missiles Took Out Two-Thirds of a Cloud Region. The UAE Just Answered With a Mountain.

The UAE is breaking up its 5-gigawatt AI campus after drones hit two AWS data centres in March — and six months on, that cloud region is still degraded. A hosting founder on the new price of survivability.

Sep 11, 2026 - 17:04
0 8
Two Missiles Took Out Two-Thirds of a Cloud Region. The UAE Just Answered With a Mountain.

Two Missiles Took Out Two-Thirds of a Cloud Region. The UAE Just Answered With a Mountain.

I have been running servers for over a decade, and for basically all of it the disaster I planned for was a fire, a flood, a failed drive, or somebody leaning on a breaker. Never once did I plan for a drone.

That changed on March 1, 2026. And this week the invoice came due — a redesign that throws out the most sacred assumption in this business: that bigger is better, and that redundancy means two data centres a few miles apart.

The Emirates Just Quietly Broke Up the Biggest AI Campus Outside America

Reuters reported on Thursday that the United Arab Emirates is revising its 5-gigawatt UAE-US AI Campus — the 10-square-mile (26 square kilometre) megaproject in Abu Dhabi announced by both governments in May 2025, led by G42 with OpenAI, Oracle, Nvidia, Cisco and SoftBank attached to it.

It is no longer going to be one campus. According to six people briefed on the deliberations, it will likely become a network of data centres spread across the Emirates instead.

And here is the part that tells you how seriously they are taking this. Officials are weighing underground construction. They are weighing hardened air defences. And for the most sensitive workloads — including military data — they are considering putting servers inside mountains.

Read that again. One of the wealthiest, most technically ambitious countries on earth has decided the correct shape for a frontier AI cluster is not a campus. It is a scattered archipelago with a bunker aesthetic.

The first phase, Stargate UAE — a 1-gigawatt cluster with an initial 200 megawatts targeted this year — is still going ahead, just with modifications to protect it from the sky. Nobody cancels a 5-gigawatt plan. They spread it out and pray the warhead only picks one.

The Outage That Never Ended

Now here is why they did it.

On March 1, Iranian drones struck two Amazon Web Services data centres in the UAE and damaged a third facility in Bahrain. AWS confirmed structural damage, disrupted power delivery, and water damage from fire suppression activity. Two of the three availability zones in the UAE region went offline. Bahrain's facility was hit again on March 24, and again on April 1.

Iran's Islamic Revolutionary Guard Corps said the Bahrain facility was targeted because AWS hosted U.S. military workloads there. Whatever you make of that claim, the reporting around it established something this entire industry now has to live with: commercial cloud infrastructure is a legitimate military target.

Here is the detail that should be printed and taped up in every network operations centre on the planet. Six months later — as of this week — AWS's own status updates say cloud services in the region are still disrupted.

Six months. On top of that, AWS waived all usage-related charges for the UAE region for the whole of March, an unprecedented move. That tells you exactly what an availability guarantee is worth when something real happens: a service credit measured in single-digit percentages, against half a year of disruption.

Multi-availability-zone architecture — sold for a decade as high availability — was designed for a disk failure, a botched firmware push, or a substation fault. It was not designed for a drone. All three zones sit inside one metropolitan area, sharing one threat envelope. Hit two of three in a single attack and your redundant deployment is two dead halves of a whole. As the cloud architect Harshwardhan Choudhary put it: multi-AZ is not disaster recovery. It protects you from hardware failures, not missiles.

There are roughly 326 data centres across the Middle East, run by Google, Amazon, Microsoft and Oracle. The Center for Strategic and International Studies said the quiet part out loud: past adversaries in this region went after pipelines, refineries and oil fields. In the compute era, they go after data centres, the power feeding them, and fibre chokepoints.

Second Force: The Pentagon Just Became a Data Centre Lender

On the same day the Emirates were busy breaking their campus into pieces, the Wall Street Journal reported that the Pentagon is in talks to lend roughly $5 billion to Fluidstack, an AI cloud startup that manages more than 100,000 GPUs.

The money would come from the Pentagon's Office of Strategic Capital, which finances companies working on things Washington considers critical to national security. It would be, by far, the largest loan that office has ever made. And look at what the money is actually for: not a new AI facility. It is to shore up domestic supply chains and manufacturing capacity for data centre components.

That is the signal. The United States government has concluded that the risk of its AI buildout breaking is now a federal problem, so it is lending against the supply chain that keeps it standing. Fluidstack — backed by Google and Anthropic demand and valued near $18 billion — is being advised on the loan by Erebor Bank, and last month the President declared a national emergency over foreign-made electrical equipment sitting in the grid that feeds these facilities.

When the military starts underwriting the parts that keep your racks powered, resilience has stopped being a marketing word. It is a budget line now. And it is being paid out of somebody's taxes.

The Bottleneck Nobody Wants to Say Out Loud: Nobody Will Insure This

Here is where it gets genuinely ugly for anybody who sells capacity.

Data centre insurance is a business measured in the low billions, priced for fire, flood and power failure. The OVHcloud fire in Strasbourg in 2021 took 3.6 million websites offline, and the industry priced that in. It never priced in a military strike.

Business interruption policies typically carry war and military-action exclusions, and the U.S. terrorism backstop is built around certified acts on American soil. If your facility sits in Bahrain and something with a warhead arrives, you are on the exclusions page — and the burden of proving coverage lands on you.

The contracts are no friendlier. Regulatory filings reported by CNBC show that SpaceX faces a September 30 deadline to deliver committed GPU capacity to Google under a compute agreement worth roughly $920 million a month for about 110,000 Nvidia GPUs. Miss it, and Google can terminate after a one-month grace period — or accept less and pay a reduced, prorated fee. That is a hyperscaler writing an exit ramp into a compute contract and putting a date on it.

SpaceX is also dealing with reliability failures at sites in Tennessee and Mississippi, a leadership reshuffle on its AI data centre build, and a Mississippi fight where regulators counted 69 temporary gas turbines at the plant feeding Colossus 2 — roughly twice what the company had disclosed — while the Justice Department argued that cutting its power would threaten national security.

Look at the shape of that. On one side, cancel-or-reduce clauses with deadlines. On the other side, the government saying the power cannot be turned off. Nobody in that chain has a clean way to price the risk, so it sits there in the middle — until it lands on whoever signed the paper.

What This Actually Means for Independent Hosting Providers

Now the part you came for, because there is real opportunity hiding inside all this bad news.

First — audit your own redundancy claim before a customer does it for you. If your two sites share a substation, a fibre route, a regional grid operator or a twenty-mile radius, you do not have geo-redundancy. You have two rooms. Draw your power topology on one page. If both sites trace back to the same switchyard, you are selling a promise you cannot keep, and 2026 is not the year to find that out in public.

Second — sell dispersion as a product instead of apologising for it. The independent operator's structural advantage is that we were never going to build a ten-square-mile campus anyway. We have racks in three cities, on three grids, under three legal jurisdictions, because that is what we could afford. Turns out that is exactly what the market just discovered it wants. Price it. Name it. Put a number on it.

Third — read your own force majeure and war-exclusion language this week, in both directions. If your upstream provider's SLA excludes acts of war or civil unrest — and most do — you cannot pass that promise through to your customer. Know precisely what you can and cannot survive, and get it in writing before they ask you.

Fourth — document your physical facts for insurers and lenders. Power conditioning, generator hours, fuel contracts, cooling redundancy, fire suppression, real distance between sites. Underwriting this stuff is about to get harder and more expensive, and the operators who can produce clean documentation will pay less and get capacity the sloppy ones will not.

Fifth — stop benchmarking yourself against the hyperscaler campus. Scale is now a liability that has to be defended with air defences, mountains and a redesign. Your job is not to match it. It is to be the operator who can say, honestly: if one of my sites goes dark, my customer's workload is already running somewhere else, on a different grid, in a different country.

The Counter-Argument — "Dispersion Costs Money and Latency"

Fair point. Every extra site costs you cross-connects, replication bandwidth, duplicated staffing and a second set of compliance headaches. Latency between sites is real, and you cannot replicate everything synchronously.

But do the arithmetic honestly. The customer who needs dispersion most is not the one chasing a two-millisecond shave for a video game. It is the bank, the payment processor, the hospital group, the university and the government contractor who just watched two-thirds of a cloud region get destroyed, then waited six months for the lights. AWS told them to back up critical data and move workloads to unaffected regions. That is the whole product — and it works, if somebody built the other region and priced it honestly.

The Bottom Line

For twenty years this industry sold availability by pointing at a number of nines on a slide. The nines were always fiction. They described a world without war, without a twenty-year drought, without an operator on the other side of a border deciding that your rack is a target.

In 2026 the fiction got expensive. A 5-gigawatt campus became a network. Two availability zones became one dead region. A compute contract got a deadline and an exit clause. And the insurance market quietly looked the other way.

Ent? The survivors in this business will not be the ones with the biggest buildings. They will be the ones who can hand a customer a single page that says exactly what happens when the power goes out, the fibre gets cut, or the drones come — and can prove the workload keeps running somewhere else.

Resilience used to be a brochure. Now it is a bill. Get in front of yours before your customer reads theirs.

— Allan Ali, Founder

This article was produced with AI-assisted research and editorial support. Sources: Reuters ("Exclusive: UAE revises AI data center plan after Iranian attacks," September 11, 2026), The Wall Street Journal ("Pentagon in Talks to Get Into AI Infrastructure Funding With a $5 Billion Loan," September 10, 2026), CNBC, The Register, InfoQ, AWS Health Dashboard, Center for Strategic and International Studies, Network World, Arab News, The Information via CNBC regulatory filings.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Allan Ali

Publisher of Global1.News. Automation architect, systems builder, and the guy making sure the truth gets published.

Comments (0)

User