Follow us on Facebook → fresh APAC stories, daily

Tech & AI

Missile strikes force UAE to scatter its 5GW AI campus across emirates

After March drone attacks damaged AWS facilities in the Gulf, Abu Dhabi is redesigning its flagship Stargate project as a network of hardened, dispersed sites with air defences and underground construction.

The United Arab Emirates is quietly revising plans for its flagship 5‑gigawatt AI data centre project after March 2-3, 2026 drone and missile strikes damaged cloud infrastructure in the Gulf. Originally designed as a single 10‑square‑mile campus in Abu Dhabi, the project is now likely to become a network of hardened, dispersed sites with air defences and some underground construction, according to people familiar with the matter.

The first 1GW Stargate cluster, backed by OpenAI, Oracle, Nvidia, Cisco and SoftBank, will proceed with modifications. But the remaining 4GW are expected to be split across multiple emirates — a design shift that embeds military‑grade resilience into what was once a utility‑scale commercial campus.

The drone and missile strikes that hit Amazon Web Services facilities in the UAE and Bahrain on March 2-3, 2026 did more than knock cloud services offline. They showed that concentrating 5 gigawatts of AI compute in a single Abu Dhabi campus creates a single point of failure the region’s security environment will not tolerate. The UAE is now rethinking that concentration.

Instead of one 10‑square‑mile site, the project is being recast as a distributed network of smaller, physically hardened data centres. Officials are looking at underground construction, blast‑resistant materials, and co‑located air‑defence systems for the most sensitive workloads, according to sources familiar with the review. G42, the Abu Dhabi‑based firm leading the development, says construction is ongoing and that design specifics remain under continuous review for security and resilience. The shape emerging looks less like a cloud region and more like a forward operating base.

Get the latest APAC news as it happens — follow Indoneo on Facebook

The drone strike that rewrote a campus blueprint

Two AWS sites in the UAE were directly struck by drones, and a strike near a Bahrain facility triggered structural damage, power disruption, and water damage from fire‑suppression systems, according to a March incident report. Those kinetic hits provided the first proof that commercial cloud sites could be collateral in a regional escalation.

An AWS Health Dashboard update from April 2, 2026 confirms the effect: two of the three Availability Zones in the UAE’s ME‑CENTRAL‑1 region remained significantly impaired. Core services such as EC2, S3, DynamoDB, Lambda, and RDS suffered elevated error rates. AWS advised customers on April 30 to migrate accessible resources to other regions and restore inaccessible ones from remote backups; full recovery was expected to take months, and the region remained disrupted as of September 11, 2026.

According to Reuters reporting, Emirati officials began reviewing their AI infrastructure plans soon after Tehran launched missiles and drones at Gulf neighbours hosting US forces. The revision now encompasses a dispersed network of data centres, with options that include mountain siting and the integration of drone and missile interceptors, electronic jamming equipment, and blast‑resistant concrete.

The first phase, a Stargate UAE cluster originally planned as a 1‑gigawatt deployment, will be built with modifications to protect against aerial attacks, according to people familiar with the matter. According to G42, the first 200‑megawatt tranche is expected online in 2026. Oracle has described the cluster as a $30‑billion, 1‑gigawatt compute deployment meant to connect UAE government agencies and commercial institutions to advanced AI models. The hardening programme now runs in parallel.

What that hardening looks like in practice is assembled in the breakdown below.

The original US‑UAE agreement, announced in May 2025, included Know Your Customer procedures to screen organisations accessing campus compute and prevent technology diversion. The PDPL separately regulates cross‑border data flows, requiring contractual safeguards for personal data sent abroad. Together they create a dual gate that Western firms must clear: identity vetting and data‑governance compliance.

Policy layers shaping the hardened AI campus
Entity Current rule Impact on hardened AI
UAE PDPL Regulates cross‑border data transfers; requires contractual safeguards for foreign processing Western firms must align data governance with UAE law when using onshore compute
KYC under US‑UAE AI Campus Screens tenant organisations to prevent technology diversion and control access Western AI providers need to pass identity checks and align with US export‑control conditions
NIST SP 800‑53 Physical and environmental protection controls; guides site selection factoring hazards Hardened campus may follow these controls, providing a standards‑based defence framework
US Export Controls (bilateral) Ties access to advanced AI chips to security commitments Compute access contingent on UAE maintaining physical security standards and KYC
Source: UAE Personal Data Protection Law; U.S. Department of Commerce; NIST SP 800-53

Commerce campus, defence posture

The UAE redesign reflects a broader reclassification: sovereign AI compute moves from commercial infrastructure to a strategic asset shaped by battlefield experience. Daniel Benaim, a former US Deputy Assistant Secretary of State for Arabian Peninsula Affairs, has characterized the Iran‑linked war and its strikes on Gulf infrastructure as an economic shock for states that had marketed themselves as safe havens. For AI data centres, that means site selection must now weigh military threats alongside power prices and fibre routes.

For Western cloud users, the closest analogue is how hyperscalers structure regions into multiple Availability Zones — separate buildings with independent power, but no anti‑missile defences. The UAE model layers military hardening onto a sovereign campus, so compute there carries resilience assumptions closer to defence infrastructure than to standard cloud. The governance that emerges is hybrid: NIST SP 800‑53 physical‑security guidelines sit beside UAE privacy law and bilateral export controls that tie chip access to physical security commitments.

If similar attacks had occurred two years later, much of the 5GW build might already have been structurally committed, making retrofitted hardening far costlier and slower. The UAE’s revision, forced by timing, now sets a pattern for sovereign AI builds in volatile regions: engineering that starts with the threat, not the floor plan.

Beyond the headline

The Bigger Picture

The redesign illustrates that sovereign AI compute is being reclassified from commercial infrastructure to strategic assets shaped by battlefield experience. Instead of treating data centres as utility‑like back‑office facilities, planners are importing concepts from hardened command posts and energy installations. Future negotiations over where large model training runs occur will hinge as much on defence posture and threat intelligence as on electricity prices or fibre routes, tying AI geography to military risk in ways Western cloud buyers have not yet priced into their strategies.

The Reach

One underappreciated actor is the US export‑control system, which effectively decides where cutting‑edge AI chips can operate at scale. The mechanism is the bilateral AI campus framework: the UAE commits to security conditions and KYC, and in return gains access to Nvidia‑class hardware that would otherwise be constrained. For Western businesses, that means some of the most attractive compute pools will exist in jurisdictions whose physical security posture is calibrated to US strategic needs — an alignment that is a resilience advantage but also embeds geopolitical dependencies into everyday cloud procurement.

The Timing

The redesign did not occur in a vacuum. March’s strikes demonstrated that commercial cloud sites can be collateral in regional escalation. In April 2026, Iran’s armed forces released a public video naming Stargate UAE as a potential target, which transformed hypothetical risk into a personalised threat. Those shocks arrived just as sovereign AI projects worldwide were moving from memorandum‑stage to concrete pours, forcing the UAE to integrate war‑time lessons before construction locks in. If similar attacks had happened two years later, much of the 5GW build would already have been structurally committed, making retrofitted hardening far costlier and slower.

The decisions on your desk

With the UAE’s AI campus redesign still taking shape and AWS services not yet fully restored, companies with Gulf‑based cloud or AI investments face immediate decisions.

  • Western Cloud-Dependent Business Operating in MENA Check the latest AWS Health Dashboard for ME‑CENTRAL‑1 and ME‑SOUTH‑1 — as of September 11, 2026, service disruptions persist. Identify where your workloads rely on the impaired Availability Zones and build a failover runbook that assumes multi‑AZ disruption, not just single‑facility loss. For new deployments, factor in the risk that future Gulf‑based regions may not meet the resilience assumptions of standard commercial cloud.
  • US-Based AI/Hyperscale Investor with Gulf Exposure Re‑run the numbers on your Gulf data‑centre or AI infrastructure plays with a hardening premium. Site‑by‑site cost estimates have not been published, but adding blast‑resistant construction, dual‑fed utilities, and air‑defence coordination will raise capex materially. Delays are possible as the UAE finalises the distributed blueprint; watch official statements from G42 and the Abu Dhabi government media office for confirmation of site locations and revised capacity timelines before committing.
  • Western Technology Company Seeking AI Compute in UAE Monitor the UAE‑US AI Campus portal and G42’s project updates for any official shift from single‑site to distributed topology. The redesign will affect latency profiles between sites, inter‑site fibre costs, and potentially the availability of low‑latency inference clusters. If your AI workloads depend on tight co‑location of training and inference, map how a multi‑emirate footprint changes your architecture and update your due diligence checklist to include physical security parameters — from blast ratings to power redundancy — for each site.
  • Western Supply Chain Manager for Critical IT Hardware Expect installation windows to tighten as physical security perimeters expand. Delivering AI chips and servers to multiple, possibly unannounced sites across the UAE will require vetting of logistics partners for defence‑grade security protocols. Work with your procurement teams to pre‑qualify freight carriers and last‑mile handlers who can meet the access controls and environmental standards that hardened sites will demand, and build contingency stock abroad to offset any delays from site‑by‑site commissioning.

FAQ

What is the current status of AWS cloud services in the UAE and Bahrain?

As of September 11, 2026, two AWS Availability Zones in the UAE remained impaired, causing degraded availability for EC2, S3, DynamoDB, and other core services. AWS advised customers on April 30 to migrate accessible resources to other regions and restore from remote backups. Full restoration is expected to take several months; the Health Dashboard should be monitored for updates.

How does the UAE’s PDPL affect Western businesses using cloud AI in the Gulf?

PDPL treats sending personal data from the UAE to AI services hosted abroad as a regulated cross‑border transfer, requiring adequate safeguards. Running AI inference on sovereign UAE‑based infrastructure avoids such transfers but still requires compliance with local data‑protection obligations. Western firms must map which datasets stay onshore and which cross borders, and align cloud contracts with PDPL’s standards especially when combining UAE‑hosted and US‑ or EU‑hosted components.

How does the hardened campus design differ from standard Availability Zone design?

Standard Availability Zones are separate buildings with independent power and cooling, designed for isolated failures such as grid outages or local fires. The UAE’s hardened design adds missile and drone defence, underground siting, mountain locations for military workloads, and integrated air‑defence systems. Users of such a campus must plan for deliberate, conflict‑driven multi‑AZ attacks rather than assuming standard multi‑AZ architectures inherently cover such correlated failures.

Explainer

G42
G42 is an Abu Dhabi‑based technology company leading the development of the UAE‑US AI Campus. Founded in 2018, it operates across artificial intelligence, cloud computing, and digital transformation, and is the primary Emirati partner in the Stargate UAE cluster. G42’s role includes managing the campus construction and working with US hyperscalers under the bilateral security framework.
Stargate UAE
Stargate UAE is a planned 1‑gigawatt AI compute cluster within the larger UAE‑US AI Campus. It involves OpenAI, Oracle, Nvidia, Cisco, and SoftBank, with the first 200‑megawatt tranche slated for 2026. The cluster will provide advanced AI inference and training capacity for UAE government entities and commercial institutions, serving as the first operational phase of the campus.
PDPL
The UAE’s Personal Data Protection Law (Federal Decree‑Law No. 45 of 2021) is the country’s primary data‑protection framework, in force since January 2022. It regulates the processing and cross‑border transfer of personal data, requiring adequacy assessments or contractual safeguards for transfers outside the UAE. For AI compute users, PDPL means that running workloads on sovereign UAE infrastructure can avoid cross‑border compliance burdens, but data handling must still meet local standards.
NIST SP 800-53
NIST Special Publication 800‑53 provides security and privacy controls for US federal information systems. Revision 5 includes Physical and Environmental Protection controls such as PE‑3 (Physical Access Control), PE‑14 (Environmental Controls), and PE‑23 (Facility Location). These guidelines, used in the AI campus redesign, require organisations to consider physical and environmental hazards — including hostile attacks — when selecting and constructing data centres.
KYC
Know Your Customer (KYC) procedures in the context of the UAE‑US AI Campus involve screening organisations that seek to access compute resources. Under the bilateral agreement, the US Department of Commerce requires identity and use‑case vetting to prevent diversion of high‑end AI capabilities to sanctioned or high‑risk entities. This screening layer sits on top of UAE data‑protection law, adding a security gate to campus access.

Covered in this article: Middle East Bahrain Iran UAE

Indoneo APAC Desk

The editorial operation behind Indoneo's breaking news and developing story coverage. The APAC Desk monitors primary sources across 75 countries and territories — governments, regulators, research institutions — and answers the question regional coverage rarely asks: what does this mean for a Western reader's money, travel, safety, or decisions. Indoneo's reporting is produced using AI-assisted drafting within an editorial pipeline built for source verification and originality.