U.S. Sailors conduct final checks on an F/A-18F Super Hornet, attached to Strike Fighter Squadron (VFA) 41, as it prepares to launch from the flight deck of Nimitz-class aircraft carrier USS Abraham Lincoln (CVN 72), Operation Epic Fury, March 23, 2026
US Sailors conduct final checks on an F/A-18F Super Hornet, attached to Strike Fighter Squadron (VFA) 41, as it prepares to launch from the flight deck of Nimitz-class aircraft carrier USS Abraham Lincoln (CVN 72) during Operation Epic Fury, March 23, 2026. – US DVIDS

On March 1, 2026, Iranian Revolutionary Guard drones struck Amazon Web Services facilities in the UAE and Bahrain. The stated justification: AWS was hosting US military simulations. Online systems went offline, facilities burned, and the data center industry, which has spent years describing itself as neutral commercial infrastructure, had to quietly absorb that this description no longer covers them.

This matters to the data center industry for a specific reason: once military significance is attached to a workload, neutrality is no longer determined by branding, customer mix, or logical separation. It is determined by physical infrastructure, and physical infrastructure can be hit.

The pattern, not the incident

Iran’s AWS strikes were retaliation. On February 28, 2026, US and Israeli forces launched Operation Epic Fury, striking sites across Iran, including at least two data centers in Tehran, one of which was actively used by the Islamic Revolutionary Guard Corps. The drone strikes on AWS the following day were Iran’s direct response. Iran’s Islamic Revolutionary Guard Corps (IRGC) claimed responsibility and stated the justification explicitly: the facilities were legitimate targets because they hosted US military AI systems and intelligence simulations.

Iran war
President Donald Trump presiding over Operation Epic Fury – The White House

The escalation continued. On March 11, a missile struck a Bank Sepah data center in Tehran, a facility processing salary payments for Iran’s military and the IRGC. Iran formally declared that the attack gave the IRGC the right to expand its legitimate targets to include US and Israeli economic centers and banks across the region. Iranian state-linked media published a list of companies now designated as legitimate targets: Google, Microsoft, Palantir, IBM, Nvidia, and Oracle. The stated justification was that these sites supply foundational cloud or AI capabilities to the military, therefore stripping a technology corporation of its civilian neutrality.

The kinetic strikes were accompanied by simultaneous cyber operations. Within 72 hours, a coordinated hacktivist coalition launched 149 DDoS attacks against 110 organizations across 16 nations. Iranian actors exploited IP cameras across the Gulf to conduct real-time battle damage assessments for missile targeting. Physical attack and digital exploitation were co-dependent operations.

Ukraine and Israel had already established the underlying pattern. When Russia invaded in 2022, AWS absorbed over 10 petabytes of Ukrainian governmental data. Microsoft integrated digital operations across sixteen Ukrainian ministries. Google Cloud provided 50,000 Workspace licenses to sustain governmental communication. Ukraine’s Digital Transformation Minister said AWS “literally saved our digital infrastructure.” The intervention preserved state functionality under kinetic attack and embedded core sovereign functions within privately governed digital systems that the Ukrainian state does not own or fully control.

Taiwan has preemptively migrated eighteen governmental and military systems, including citizen databases, border control, and defense communications, to offshore hyperscaler platforms, anticipating a local Strait crisis. Microsoft, Google, and AWS have committed to building local data centers there, alongside satellite-linked backup connectivity. The architecture of military readiness now runs through commercial cloud contracts.

Israel’s experience makes the trajectory explicit. Since 2021, Project Nimbus (a $1.2 billion initiative) has been migrating governmental and defense operations onto AWS and Google Cloud. The contracts forbid providers from suspending services to any Israeli governmental or military entity for political or ideological reasons.

On October 7, 2023, when Israel was attacked by Hamas and other militant groups, the IDF’s internal data centers collapsed under a 30-fold surge in concurrent users. These users were desperately attempting to process an unprecedented avalanche of incoming intelligence, which included surveillance footage, intercepted communications, and geospatial analytics.

The military transitioned critical intelligence workloads onto AWS, Google Cloud, and Microsoft Azure. Microsoft employees were reportedly directly embedded within IDF units. Israeli military personnel described AWS’s analytics capabilities as placing an “order from Amazon” for battlefield intelligence.

In September 2025, Microsoft suspended certain Azure services for IDF Unit 8200 after determining its technology was being used for large-scale surveillance of civilians in Gaza, in breach of the company’s terms of service. A private corporation’s terms of service had become a constraint on a sovereign military’s operational capacity.

The US government’s involvement with Anthropic sharpens this further. When the company argued its models shouldn’t power fully autonomous weapons, the Department of War designated it a supply-chain risk. Court filings warn that Anthropic staff might “sabotage or subvert national security systems” if its corporate red lines were crossed. The industry has spent years arguing it provides infrastructure, not positions. The Pentagon has now told a court that this distinction is not one it recognizes.

Strait of Hormuz
The Strait of Hormuz, an area of conflict in the Iran war – Getty Images

Why the silence is structural

The data center sector’s failure to name what it has become is far from a communications problem. It reflects a structural condition that makes naming it difficult. The industry has been captured by its own entanglement.

Infrastructural entanglement, the condition in which sovereign military and civilian operations become inseparably dependent on privately governed digital systems, operates through three mechanisms that explain both how the dependence formed and why it persists.

The first is lock-in. Proprietary software, data formats, and licensing arrangements generate switching costs so high that once governmental or military systems have migrated to hyperscaler environments, reversal becomes economically and operationally prohibitive. Ukraine cannot simply migrate back to domestic servers. Israel cannot rebuild overnight what Project Nimbus has integrated over four years. The contracts that created this dependence are also, in some cases, the contracts that prevent exit. Project Nimbus, for example, explicitly forbids AWS and Google from suspending services for political reasons, locking the hyperscalers into supporting state operations regardless of the conflict environment.

The second is software-defined operational imperatives. Strategic functions are no longer tied to dedicated facilities. They are instantiated as mobile, scalable, and opaque workloads. This removes the visibility that once underpinned legal and political distinctions between types of infrastructure. Ukraine’s DELTA battlefield management system, identifying around 1,500 Russian targets daily at peak, required compute capacity surpassing the entire government IT infrastructure of several smaller European states. That demand cannot be met by current sovereign infrastructure, and the dependency it creates is not reversible on short notice.

The third is coalition-level geopolitical leverage. Because hyperscalers control global cloud architectures and interoperability standards, alliance coordination itself now depends on alignment with a small group of providers, most headquartered in the US. NATO’s multi-cloud strategy and the US Department of War’s $9 billion Joint Warfighting Cloud Capability contract reflect the same recognition: hyperscalers are no longer vendors to the military. They are structural components of it.

These three mechanisms explain why the silence persists. The industry is structurally implicated in them. Stating what it has become would require confronting what it has built. That is a harder conversation now, due to the recent Iranian strikes.

The legal exposure the industry hasn’t priced

Under Article 52(2) of Additional Protocol I to the Geneva Conventions, an object qualifies as a legitimate military target when it makes an effective contribution to military action and its neutralization offers a definite military advantage.

The threshold is functional, not volumetric. There is no rule requiring a certain percentage of military workloads. A single significant military function on shared physical infrastructure can render the entire facility a military objective. Legal analysis of the March 2026 strikes confirms what was already established in theory: physical colocation is the determinative factor. Logical separation, such as different virtual machines, different availability zones, and encrypted partitions, does not solve the physical targeting problem. If the military workload provides the legal justification for targeting, the entire building is destroyed.

The industry has no institutional framework for reasoning about this exposure. It has risk models for cyber incidents, operational failures, and natural disasters. It does not have risk models for legal reclassification as a military objective. The March 2026 strikes produced the first confirmed military attacks on hyperscale cloud providers. The jurisprudence that follows will be written around those facilities and the workloads they hosted.

What the silence costs

The data center sector is already operating inside a geopolitical reality it has declined to name. There has been no coherent public reckoning with what the infrastructure has become in aggregate or what obligations follow from that.

Those obligations are not abstract. If the industry wants to continue claiming civilian status, it will need to make decisions that are currently being deferred: physical segregation of military and civilian workloads, not logical separation; public disclosure frameworks for when infrastructure participates in strategic systems; contracts that do not lock providers into supporting state operations regardless of conflict environment; and risk models that price geopolitical targeting alongside cyber and operational failure.

The question now is whether the industry will define what comes after it or wait for the next set of court filings, target lists, and burning facilities to define it instead.