Compute Was Already a Target
On 1 March 2026, Iranian drones directly struck two Amazon Web Services facilities in the United Arab Emirates, and a strike in close proximity damaged a third AWS facility in Bahrain. The strikes cut power and caused structural damage. Fire suppression added water.
Regional services survived the first zone loss and failed only after the second. AWS reported that at around 4:30 AM PST availability zone mec1-az2 had been struck, and said at the time that the region’s other zones were operating normally and that customers running redundantly across zones were unaffected. That is the architecture doing its job. Later the same day a second zone, mec1-az3, became impaired as well. Only then did regional services fail: S3 is built to tolerate the loss of one availability zone rather than two, and with two impaired the failure rates propagated into financial, payment, delivery and enterprise services across the Gulf.
On 31 March, the Islamic Revolutionary Guard Corps named eighteen companies as prospective targets, sixteen American and two Emirati, among them Microsoft, Nvidia, Google, Apple, Meta, Oracle, IBM, Palantir, JPMorgan, Tesla and Boeing. Amazon was not on that list; its facilities had been struck thirty days earlier.
I mention this because in the last week a report from the Center for a New American Security produced a round of coverage announcing that a former Obama administration official wants to bomb Chinese data centres. Iran crossed that threshold six months ago, against commercial cloud rather than frontier training. Stokes notes this in the report.
This site has argued for years that AI systems fail in ways traditional controls do not catch. The strike debate is that failure at national scale: a threat model built on the wrong object.
Striking compute is no longer hypothetical. Acting on it requires an intelligence judgement about when a rival crosses a capability threshold. Nobody can make that judgement today. That is the argument I want to make, and the strange thing is that the report being attacked for warmongering makes it better than its critics do.
Where the argument came from
The idea predates the August 2026 report along two separate lines. The strategic logic of destroying a rival’s technology rather than defeating the rival is five years old. The explicit argument for bombing AI compute is three and a half.
The first half starts with semiconductors. In late 2021, Jared McKinney and Peter Harris published Broken Nest: Deterring China from Invading Taiwan in Parameters, the US Army War College quarterly. Their proposal was that Taiwan and Washington should plan to destroy TSMC’s fabrication plants in the event of an invasion, making the island expensive to hold rather than valuable to take. It has been among the War College’s most downloaded papers since. McKinney and Harris proposed holding the technology asset at risk instead of the state that owns it, and every later version does the same.
On 29 March 2023, Eliezer Yudkowsky moved the same logic from fabs onto compute in TIME. Arguing that the six-month training pause proposed that week asked for too little, he set out an enforcement regime: shut down large GPU clusters, cap training compute and ratchet the cap downward, track all GPUs sold, and if a country outside the agreement builds a cluster, “be willing to destroy a rogue datacenter by airstrike.” Worth noting what his version is not. Yudkowsky framed it as multinational treaty enforcement against anyone, explicitly including governments and militaries, and dismissed arms-race framing entirely. Everyone loses together or nobody does.
The competitive version arrived two years later. In March 2025, Dan Hendrycks, Eric Schmidt and Alexandr Wang published Superintelligence Strategy, introducing Mutual Assured AI Malfunction. Where Yudkowsky proposed enforcement among cooperating states, MAIM describes deterrence between rivals: a state making an aggressive bid for unilateral AI dominance is met with preventive sabotage. The paper sets out a ladder. Espionage first, then covert sabotage by insiders tampering with weights, training data or chip fabrication, then hackers quietly degrading a training run so the finished model underperforms, with Stuxnet as the stated analogy, and kinetic strikes on data centres at the top. Its stronger claim is that MAIM already describes the situation the AI powers are in rather than proposing a new one.
RAND-affiliated authors answered within weeks, arguing MAIM is not a feasible deterrent in practice. The Machine Intelligence Research Institute followed in April 2025 with a longer analysis of unmonitorable red lines, questionable threat credibility and a volatile deterrence calculus. Hendrycks replied with Adam Khoja in September 2025. Three rounds of serious argument, eighteen months before the report that made the news.
And the non-kinetic version of the same policy has been running since 7 October 2022, when the United States imposed comprehensive controls on advanced semiconductor exports to China. That instrument has been in flux since. BIS stopped enforcing the AI Diffusion Rule in May 2025 and announced it would rescind it, though the formal rescission remained incomplete, and on 13 January 2026 the Bureau of Industry and Security moved H200-class and equivalent chips from presumption of denial to case-by-case review. Headline restrictions loosened while major enforcement actions continued. Applied Materials agreed on 11 February 2026 to pay $252 million to settle allegations of earlier unlawful exports of ion implantation equipment to China. Stokes recommends Washington keep these controls and tighten them where it can. He also recommends restoring them where they have lapsed, which concedes the loosening of the last eighteen months.
The report argues close to the opposite of what was reported
I read Superpowers and AGI rather than the coverage of it, and the two do not describe the same document.
The sentence most widely quoted is: “Data centers can be bombed with conventional munitions.” It appears in a section arguing that AGI-enabled weapons would not be superweapons. Stokes’ point there is that AGI weapons remain subject to the same forces as everything else, including the fact that any military capability can be attacked physically by older and simpler means. It is a deflationary claim about the limits of AGI military power. It was reported as a proposal.
Three further inversions. The most alarmed coverage says the report assumes AGI is inevitable; the report states that it does not prejudge the prospects for such a system or presume AGI will emerge at all, cites the arguments that AGI is a fever dream and a conspiracy theory as compelling, and stipulates for analysis a system delivering only 60 to 70 percent of what boosters claim. The coverage frames the United States as the prospective attacker; the report says that given the current US lead in frontier models, China is the more likely one. And bombing is not among the nine recommendations. The relevant recommendation is to run a scenario exercise testing when and how the United States might intervene, which is a tabletop, not a target list.
Not every outlet made the same errors. In fairness to those that did, the report does say a surprise Chinese breakthrough could force Washington to consider preventive action. The kinetic passage is genuinely there. The inversion is one of emphasis and framing rather than invention. But if you formed your view of this debate from what was written about it in the last fortnight, you have it backwards. The coverage supplies the wrong reason for rejecting the strike option.
The intelligence problem
Stokes spends more of the kinetic passage on why you could not do it than on how.
The comparison he draws is nuclear, and it is instructive in the way he intends. Monitoring a nuclear programme means watching a short list of necessary inputs: fissile material production, specialised centrifuges, delivery systems. Warhead and delivery tests are close to impossible to conceal from modern surveillance and cannot easily be passed off as civilian. States built an entire analytic apparatus on that, including the concept of breakout time, meaning how long a rival needs to go from where it is to a weapon.
AI monitoring has none of those properties. AI inputs are ubiquitous and in constant operation. They have more civilian than military use. There is no established breakout-time framework for AGI, and there cannot yet be a good one, because nobody knows which inputs and thresholds matter. Stokes’ analogy for the position is precise: it is like hypothesising that nuclear weapons need fissile material set off by an explosive, without knowing the enrichment level or the device design.
A state with high confidence in its assessment can afford to wait and strike preemptively, just before a rival crosses. A state with low confidence is pushed toward a preventive strike, meaning earlier, while the threat is still gathering. Since nobody can have high confidence, a state weighing this decision has an incentive to strike sooner on worse information. That is not a stable arrangement. It is the same dynamic that made the 2003 Iraq intelligence failure possible, except that the object being assessed is less observable than centrifuges.
The historical record is more mixed than either side of this argument usually allows. Stokes notes that the United States considered bombing both Soviet and Chinese nuclear facilities and concluded in both cases that the risk of escalation to general war outweighed the benefit, and that it later invaded Iraq and struck Iran over their programmes. I have not independently verified the first pair and am reporting his account rather than asserting it myself. Those cases are less alike than one pattern would suggest and I would not draw a rule from them. What they establish, on his account, is that the United States has faced this decision repeatedly. Escalation risk outweighed the benefit against the Soviet Union and China. Washington invaded Iraq and struck Iran anyway. China is not Iraq, and the AGI case is a peer case.
Timing is what defeats the strike option. I find it more persuasive than the alternative on offer, which is that bombing is unthinkable. It plainly is not. Someone did it in March.
What March 2026 actually showed
The Iranian strikes are weaker precedent than they first appear.
Iran hit commercial cloud inside a war it was already fighting, not a training run inside a rival’s territory in peacetime. The escalation threshold Stokes describes for a US-China kinetic exchange was not the threshold Iran crossed. Analysts writing afterwards made the point that commercial hyperscale facilities are comparatively soft targets by military standards, neither hardened nor given dedicated air defence, which suggests these may have been targets of opportunity as much as considered strategic choices. The Islamic Revolutionary Guard Corps claimed the facilities supported the enemy’s military and intelligence work, and Amazon has not commented on the claim.
Nor were they the first data centre struck in a war. Russia hit a Ukrainian government data centre with a cruise missile on 1 March 2022, four years earlier to the day, which Microsoft documented that June and which drove Ukraine’s decision to move government data into cloud facilities outside the country. The defensible novelty here is narrower: this appears to be the first military strike on the infrastructure of a major American hyperscale cloud provider.
Destruction has also arrived without munitions. Ukrainian operators claimed in 2024 to have wiped roughly 300 terabytes held by OwenCloud, a Russian provider serving military-industrial customers, a claim the Kyiv Independent could not verify and the provider disputed. Munitions are the most expensive rung of that ladder.
What the strikes did establish is narrower and more useful. Commercial hyperscale data centres are soft targets by military standards. They burn. Their loss propagates immediately into banking, payments and logistics for everyone sharing the region, which makes them a dual-use targeting problem of the purest kind. Michael Schmitt published a legal analysis in Just Security on 12 March working through the customary targeting rules reflected in Additional Protocol I, and the questions are not comfortably settled.
And, most relevant for anyone reading this from inside a security function: the architecture absorbed the first strike exactly as intended, then failed when a second physical event arrived in the same region hours later. Zone redundancy hedges against one thing going wrong. A conflict is a source of repeated, correlated physical events in a single geography, which is a different failure mode from the one the design was built against.
The part that is actually in your control
Nothing above changes what a defender does on Monday, and none of it was meant to. State targeting decisions are outside an enterprise security team’s control, and a piece that pretends otherwise is selling something.
Two things follow that are in scope. The first is that availability-zone separation is a hedge against uncorrelated failure and was never a hedge against an adversary selecting aim points, which is a distinction worth writing into your own resilience documentation before someone else writes it for you. The second is that a strike can stop a training run and deny a rival its models for months without removing a capability from the world, because a replicated checkpoint outlives the building it was made in. The proposals mostly know this. The coverage of them does not.
A third assumption underpins both: that a frontier training run has to be physically concentrated. That has always been an engineering constraint rather than a property of frontier AI, critics of MAIM identified the targeting implication almost immediately, and the constraint is eroding fast. In April 2026 Google DeepMind reported training a 12-billion-parameter model across four US regions over ordinary wide-area links. A targeting strategy built on today’s concentration has to assume its own success would accelerate dispersal of the target. For now the useful correction is smaller. The argument about attacking compute is five years old and has already left the page. The reason to be against it is that nobody can tell you when to act or whether it worked.
Sources checked 5 September 2026. Export control status verified against the Federal Register and BIS guidance current to that date; this area has changed repeatedly and should be rechecked before citing.
In the early 2000s, running emerging-technology risk labs at CyberAgency, a defence client asked my team to break the AI systems they planned to put into weapons. We did. That is where my work on AI security started, two decades before the current wave of attention. I kept at it through risk labs at IBM, Accenture, PwC and KPMG. In 2016 I co-wrote a book on AI and leadership. My commercial work today is quantum, at Applied Quantum, which is why this site sells nothing.