You Can Bomb the Data Centre. You Cannot Uncopy the Model.
Attacking AI infrastructure can achieve a great deal. It can terminate a training run, destroy accelerators worth hundreds of millions, deny a rival the use of its models for months, and delay the next generation by however long it takes to rebuild. The serious proposals are not naive about any of this. Eliezer Yudkowsky’s 2023 regime aims at training runs in progress under a moratorium. Superintelligence Strategy separates stealing or corrupting weights from sabotaging the machinery that produces them. Both already distinguish the artefact from the factory.
What the literature has not worked through is what happens after the artefact exists.
Nuclear material is conserved physical stock, and making another copy means producing more of it. A trained checkpoint is non-rival information, and copying it creates a second complete instance at almost no marginal cost. Once independent copies exist outside the target, destroying the originating infrastructure cannot recall them.
That is a narrower claim than “bombing does not work,” and it is the one that survives scrutiny.
Weights are the object, and this is not a new observation
RAND set this out in 2024, in a report the kinetic-strategy writing has largely not engaged with.
Securing AI Model Weights, published in May 2024 by Sella Nevo, Dan Lahav, Ajay Karpur, Yogev Bar-On, Henry Alexander Bradley and Jeff Alstott, identifies 38 distinct attack vectors against model weights and maps them against five categories of attacker operational capacity, from opportunistic criminals up to top-priority nation-state operations. It defines five security levels, SL1 to SL5, with benchmark controls for each.
The framing argument is the one that matters here. Weights are the output of everything expensive about building a frontier model: the compute, the data collection, the years of research. An attacker who obtains them bypasses most of those sunk prerequisites and can operate the model outside the owner’s access controls, provided they can reconstruct the architecture and supply enough inference compute. RAND’s own description of frontier weights is that they reach terabytes of storage, which is the relevant property. Llama 3.1 405B in 16-bit precision is roughly 810 gigabytes; larger mixture-of-experts checkpoints run past a terabyte. Sharded across files, encrypted or quantised, it remains something a network can move.
That ladder has moved into the labs’ own safety documents. Google DeepMind’s Frontier Safety Framework aligns its model-weight security levels with RAND’s. Anthropic’s June 2025 work with Pattern Labs on confidential inference is written against SL4 and SL5 directly, which is less a case of adoption than of continuity: Dan Lahav of Pattern Labs, later Irregular, co-wrote the RAND report. And Sella Nevo has proposed a national security sprint aimed explicitly at reaching SL5. AI model weight security is now a named discipline with benchmarks attached. The strategic writing about strikes is still targeting the factory.
This site has covered model extraction as an attack for years. What changes at national scale is only the adversary’s budget.
What a strike actually removes
Three things happen inside a data centre, and they have completely different destruction properties.
Accelerator capacity and active training state are genuinely destroyed. Kill the cluster mid-run and the run stops. The compute is gone, and recovery depends entirely on where the checkpoints were written. Against active training state, a strike does what its advocates claim. It works only inside a narrow window, after a run has started and before its output has been replicated. It also works only if enough of the necessary capacity is physically concentrated to make the strike decisive. That last condition is weakening: in April 2026 Google DeepMind reported training a 12-billion-parameter model across four US regions with the system continuing after entire compute units were lost and reintegrating them when they returned.
Serving capacity is destroyed locally and restored elsewhere, more easily than training but not for free. Independent user requests route among regional replicas, which is why inference disperses geographically far better than training does. A single large request may still depend on tensor or pipeline parallelism across tightly coupled nodes, and cross-region serving carries latency, capacity, state and data-residency costs. Easier to move, not coordination-free.
An existing set of weights is not destroyed at all, once independent copies exist elsewhere, whether as backups, regional deployment artefacts, partner holdings or deliberate public release. That is not automatic. A high-security design can deliberately minimise copies, hold replicas encrypted and materialise plaintext only inside attested hardware. But the default posture at most organisations produces copies, and the whole point of the open-weight case is that it produces them everywhere.
Collapsing those three into “the model” is what makes the strike argument sound stronger than it is. Destroying a serving site or a training cluster leaves replicated weights and finished models untouched.
It does, though, destroy what comes next, and this is where I would resist the glib version of my own argument. Training capacity is what you need to continue an interrupted run, and to do post-training and reinforcement learning. You need it again to retrain after a defect, to distil, to adapt, and to build the successor model. Destroying the infrastructure that trained a model does not destroy a model whose weights have been replicated. It destroys the capacity to produce the next one. Whether that is decisive depends entirely on whether the thing you fear already exists.
Organising this by objective rather than by target is what makes it tractable. Compute denial works before and during training and keeps working afterwards against serving and successor capacity. Model erasure gets harder with every copy made, and becomes impossible once independent copies exist outside the target. The narrow window belongs only to erasure: after a run starts, before the checkpoint propagates. That is also the window hardest to observe from outside, which is the same intelligence problem the authors of these proposals cannot solve. You would need to know a run had started, know it mattered, and act before completion, using dual-use accelerators that are commercially deployed everywhere and constantly in use.
Where the nuclear analogy breaks
Counterproliferation runs through every version of this argument, and the comparison is good for most of its length. Both kinds of programme depend on expensive production infrastructure that can be attacked physically. Enrichment and training diverge after production.
Enrichment produces conserved physical stock. Doubling a stockpile requires enriching twice as much material. Training produces information. A second complete instance costs a network transfer, which no munition can undo.
I resist two claims that usually travel with this analogy. Highly enriched uranium is not conveniently bulky or conspicuous: the IAEA’s significant quantity is 25 kilograms, and its weak radiation signature is precisely why passive detection is difficult. And the strategic record of striking production is more contested than it is usually presented, with a real scholarly argument that Osirak drove Iraq’s programme underground rather than ending it. The digital-versus-physical distinction stands without either claim.
Verification is the separate problem, and inspectors face a harder version of it here. At declared safeguarded sites, inspectors can account for material and equipment against established physical signatures, though clandestine facilities remain a hard intelligence problem there too. Frontier AI is harder to separate by purpose. The same accelerator classes train models, serve them, render films and run scientific computing. The decisive variable is which software is executing.
The objection that has to be answered
There is a glib version of this argument, and March 2026 disproves it.
Drones in Iran’s retaliatory strikes on Gulf infrastructure hit two AWS facilities in the United Arab Emirates on 1 March, with a third damaged by a strike nearby in Bahrain. Banking, payments, delivery and enterprise software across the region stopped working, because a second availability zone failed hours after the first and took the region’s redundancy model with it. AWS said in April that the UAE region still could not reliably support customer applications and that full restoration would take months.
No public reporting establishes what model artefacts were in those buildings or whether every copy survived, and I am not going to assert that none was lost. What the incident demonstrates is narrower and sufficient: destroying cloud infrastructure produces prolonged denial of service, which is a real military effect and a different one from removing a capability from the world.
If someone takes out the facilities serving a model, the model still exists and nobody can use it for as long as the outage lasts. For a wartime adversary that may be entirely sufficient. Denying a rival the use of its AI for a week during a crisis is a real military objective, achievable with conventional munitions, and it does not require any of the verification the strategic literature struggles with.
What it does not achieve is permanent removal of a capability that already exists, and people collapse those two objectives constantly. Against training infrastructure before a capability is complete, a strike can still work as counterproliferation by delay, which is what counterproliferation usually means in practice. Against an already-replicated checkpoint, striking the infrastructure that serves it looks much more like wartime denial than like disarmament.
Denial of use belongs in the same category as attacking power stations or communications: temporarily degrade what an adversary can do inside a conflict you are already in. Iran did exactly that in March, without trying to prevent anyone from possessing anything.
Presenting a wartime denial capability as a nonproliferation instrument is how you arrive at a preventive strike doctrine aimed partly at an objective it cannot reach, justified by an intelligence judgement outsiders may be unable to make with sufficient confidence.
What follows for anyone protecting a model
The strategic argument resolves into a security recommendation, which is unusual and worth taking seriously.
If the objective is preventing another actor from coming to possess a closed model, the decisive control is weight security before replication rather than physical protection of the building it was trained in. That means the RAND ladder taken seriously: insider threat programmes, hardware-backed access controls, confidential computing at the higher levels, egress monitoring sized to notice terabytes leaving, and an honest assessment of which operational capacity of attacker you are defending against. It answers that one objective. It does nothing about serving sites or clusters that have been destroyed, or about a model already published. My own impression, which I have not measured, is that most organisations running near-frontier models operate two levels below what their security documentation implies.
The corollary is usually stated as a straight trade-off between dispersing weights for resilience and concentrating them for security, and that framing is too crude. RAND is right that an attacker who reaches a weaker copy has bypassed the primary site, and can use most of the 38 vectors regardless of how good your best facility is. But the security variable is how many paths can produce usable plaintext weights, and how well each one is controlled. Encrypted replication across independent failure domains, with materialisation confined to attested hardware and tightly held keys, buys resilience without multiplying the trust domains an attacker can work on. That is harder to build than either extreme, and it is the only version that gets you both.
Which still leaves a decision most organisations have not made explicitly: whether theft or unavailability is the failure they cannot accept. A model whose exfiltration would be a national security event and whose week-long outage would be an inconvenience is a different engineering problem from one people depend on daily where theft is a commercial loss. Skip that decision and you end up in the middle, which is the one position that is weak against both.
And for an already-published open-weight model, the erasure objective is void by construction. Once the checkpoint is broadly mirrored, no facility on earth is a unique point of destruction. Compute for successor models, serving infrastructure and fine-tuning capacity all remain attackable. The mirrored checkpoint stays where it is.
The argument about hitting the buildings is three years old and still mostly about the buildings. The buildings are worth hitting if what you want is delay. A finished model exists wherever its weights were copied.
Sources checked 5 September 2026.
In the early 2000s, running emerging-technology risk labs at CyberAgency, a defence client asked my team to break the AI systems they planned to put into weapons. We did. That is where my work on AI security started, two decades before the current wave of attention. I kept at it through risk labs at IBM, Accenture, PwC and KPMG. In 2016 I co-wrote a book on AI and leadership. My commercial work today is quantum, at Applied Quantum, which is why this site sells nothing.