هذا التقرير متاح أيضًا بـ العربية
Before dawn on 1 March 2026, Iranian Shahed drones targeted critical infrastructure in Abu Dhabi, exposing vulnerabilities with implications for regional security.
The drones hit two Amazon Web Services data centres; a third, in Bahrain, was also damaged. As fires broke out, civil defence crews cut the main power supply and emergency generators, taking down two of the three availability zones in the UAE cloud region. Within hours, banking apps had stopped working, payment services were disrupted and business platforms had gone dark across six countries.
It was almost certainly the first time commercial data centres had been deliberately targeted as military objectives during an active armed conflict. A few weeks later, Iran’s Revolutionary Guard declared 18 American technology companies “legitimate military targets”. Media outlets close to the Guard then published a list of more than 29 sites across Bahrain, Qatar, the UAE and “Israel”. They included Google’s regional office in Dubai, Palantir’s collaboration centre in Abu Dhabi, Oracle offices and other Amazon facilities. The accompanying message was explicit: as the regional war expanded to critical infrastructure, so did the range of sites Tehran considered legitimate targets.
The shift turned the Gulf’s AI relationship with the US from a series of major commercial deals into a shared security effort, giving policymakers assurances of continued cooperation and stability.
The war also raised a sharper question. If Washington alone controls access to the chips that power these facilities, as well as the security umbrella protecting them from missile attacks, how much say do Abu Dhabi and Riyadh retain over facilities built with their own money, on their own soil?
The answer lay less in partnership announcements than in licensing agreements, security arrangements and ownership structures. Over the following six months, all three were rewritten.
Investment on a vast scale
In Abu Dhabi, the region’s largest project is taking shape: the UAE-US AI campus, an infrastructure complex designed for a capacity of five gigawatts and covering about 10 square miles. Within it, G42 is building “Stargate UAE”, a one-gigawatt computing cluster for OpenAI, in partnership with Oracle, Cisco, Nvidia and SoftBank. The project reflects the Gulf’s commitment to developing its technology sector and has bolstered expectations of regional growth.
Its first phase, with a capacity of 200 megawatts, was designed to include about 100,000 GB300 chips across roughly 1,400 NVL72-class servers. G42 group chief executive Peng Xiao has said the plan is then to add between 200 and 500 megawatts each quarter, reaching the full five gigawatts within years.
How did the chip battle turn into an intelligence issue between the UAE and the US?
In Saudi Arabia, the Humain project, owned by the Public Investment Fund, plays a similar role. Its first phase comprised 18,000 GB300 systems, part of a wider plan to build “AI factories” with a capacity of 500 megawatts over five years, powered by hundreds of thousands of Nvidia processors. The target then rises to 1.9 gigawatts by 2030, with a longer-term goal approaching 6.6 gigawatts.
Alongside Nvidia, Humain signed a $10bn agreement with AMD, a $2bn agreement with Groq and a partnership with Qualcomm to fill a 200-megawatt data centre. It also invested $3bn in xAI. Beyond those deals sits a Saudi investment framework for technology and artificial intelligence estimated at hundreds of billions of dollars, with some estimates putting its upper limit at around $600bn over the decade.
When the war broke out in late February 2026, the Gulf was preparing to invest more than $300bn in data centres, chips and AI infrastructure, with the backing of OpenAI, xAI, Microsoft, Amazon, Oracle and Google. Investments on that scale cannot simply be abandoned. The money already committed makes withdrawal economically impossible and leaves hedging as the only available option. That gives the party controlling access to the chips enormous bargaining power.
The change in the relationship is clear. Before the war, the governing principle was “compliance in exchange for licences”. Afterwards, it became “military alignment in exchange for computing flows”. These are different kinds of arrangement. One is a regulatory relationship open to negotiation on technical grounds; the other is an alliance tested in every regional crisis.
Its temporary nature makes the new arrangement more consequential. Abu Dhabi’s open corridor is due to expire in April 2027, making it a renewable window rather than a permanent entitlement. No operator can build a multi-gigawatt system on an authorisation that must be renewed every nine months. That helps explain reports that G42 is considering reincorporating as an American company majority-owned by American investors.
The engineering assumption that failed
The damage caused by the Iranian strike on Amazon’s data centres in early March was serious. What it revealed about an assumption underlying the cloud computing industry may prove more consequential.
Availability zones within a cloud region are designed as physically separate facilities, each with its own power, cooling and network connections. A failure in one is supposed to remain isolated from the others. Engineers around the world build systems spanning multiple zones on that assumption.
On 1 March, two of the three zones went down at once. Their physical separation had been designed to withstand fires, floods and power cuts, rather than a swarm of drones striking two nearby targets in the same minute. The damage extended beyond the direct hits: the fires cut both primary and backup power, while the activation of fire suppression systems caused further water damage. Thirty-eight services went down in the UAE and 46 in Bahrain, with effects reaching even the main US region.
The strike was part of a wider campaign. Between late February and mid-May, Iran launched more than 6,700 drones and missiles at Gulf Cooperation Council states. The UAE bore the largest share. By 9 March alone, it had faced about 1,440 drones, eight cruise missiles and 253 ballistic missiles. Most were intercepted, at a rate approaching 90 percent, according to a Congressional Research Service report. The four drones that got through and reached the data centres were the exception. That is what makes the lesson so troubling: an air defence system that is 90 percent effective may be enough to protect a military base, but it cannot guarantee protection for a facility unable to tolerate even an hour of downtime.
As Gulf researchers following the issue have put it, the vulnerability lay in the underlying approach to security, rather than in military engineering. The security frameworks supporting the US-UAE AI partnership concentrated on supply-chain controls and geopolitical alignment, not physical defence during a high-intensity conflict. More precisely, Pax Silica was designed to keep Chinese chips out, not Iranian missiles.
Connectivity poses another risk. Seventeen submarine cables pass through the Red Sea, carrying the bulk of data traffic between Europe, Asia and Africa, while others pass through the Strait of Hormuz. An undamaged data centre cut off from the rest of the world cannot serve its purpose. The Gulf’s digital infrastructure is vulnerable through its connections as well as its facilities, echoing a problem that has shaped the region’s oil trade for a century.
When a data centre becomes a target
The US military has publicly acknowledged using commercial artificial intelligence tools in its operations against Iran. They include Anthropic’s Claude system, which runs on Amazon infrastructure, and Palantir’s Maven system. The tools were used to assess intelligence, identify targets and simulate battle scenarios. Iranian media cited that use specifically to justify attacks on the facilities. When commercial cloud infrastructure supports military operations, an adversary may treat it as military infrastructure regardless of the company name on the gate.
Whether the strikes were lawful remains contested. International law researchers have noted that Iran’s own description of their purpose — “to determine the role of these centres in supporting the enemy’s military and intelligence activity” — may indicate an unlawful approach. The law of armed conflict requires that determination to be made before an attack, rather than through the attack itself. That legal distinction, however sound, offers little comfort to a company whose servers are burning.
The strikes challenged another assumption: that civilian and military workloads can safely share a facility. Classified military work may run in the same data centre as a local bank’s apps, a food delivery company’s services and a government platform. Mixing civilian and military data in this way can effectively deprive a facility of civilian protection under the laws of war and expose its civilian customers to harm from an attack.
The financial consequences began to emerge before the legal ones. Insurance market reports described roughly 30 percent growth in the Gulf’s war-risk insurance sector in a single year, alongside the explicit addition of “war risk” clauses to cloud service contracts and extra premiums for recovery across multiple regions and reinforced infrastructure.
Operators began to respond. Amazon moved to accelerate existing plans for government infrastructure in the Middle East that is physically separate from commercial workloads. The reasoning was the same: placing military workloads alongside banking payment systems puts civilian systems at risk of attack.
Policy circles also began discussing whether data centres should be classified as “critical national infrastructure”, protected by national air defences like power plants and desalination stations, with counter-drone technology built into their design. Another proposal was the “data embassy”: a facility in a foreign country that stores another country’s data under that country’s sovereignty and laws. It was raised as a possible answer to the dilemma of keeping data within national borders, which had suddenly become a security burden rather than an advantage for sovereignty.
From commercial partnership to military doctrine
On 28 July 2026, US Central Command announced the creation of “Task Force Talon Synapse”, the world’s first bilateral military task force dedicated to speeding up the development of military AI applications in Abu Dhabi. It brings together about 20 American and Emirati experts in artificial intelligence, data science and cybersecurity. Its three stated missions are to incorporate AI into intelligence support, protect critical infrastructure and monitor the regional security environment. CENTCOM commander Adm. Brad Cooper called it a “historic milestone” and described the UAE as one of the most capable regional partners. Sheikh Tahnoon bin Zayed had proposed the task force in earlier talks with Cooper.
The initial figures are modest: 20 people, an undisclosed budget and no list of suppliers. But Cooper has a precedent. Task Force 59, which he established in 2021 with similarly modest beginnings, went on to set operational standards for unmanned maritime systems across the region. Talon Synapse is likely to serve a comparable purpose in its field: a model that can be replicated to bring the American military approach to AI into partner states.
Our assessment is that the task force supplies two elements the Abu Dhabi computing campus lacked: physical protection and integration into military operations. The war pushed both sides to develop those elements together. The Gulf gains a security umbrella and the operational knowledge to protect its digital assets. Washington, in turn, gains a permanent place in the digital defence systems of a partner spending hundreds of billions. Once a country builds its defence AI system to an ally’s standards and staffs it with a permanent team of that ally’s officers, replacing the ally becomes far more complicated than making a political decision.
Decoupling from China
The war accelerated both the Gulf’s integration into American systems and its technological separation from Beijing, although the latter has proved less complete than Washington would like.
G42 had already distanced itself from Chinese companies, above all the US-sanctioned Huawei, to improve its prospects of obtaining advanced chips. Concerns about the group persisted, however. They included years of scrutiny by US intelligence agencies, a classified file on its chief executive, Peng Xiao — who studied in the United States and gave up his American citizenship for Emirati citizenship — and calls in Congress since 2024 to put G42 on the entity list.
In June 2026, Senate Democrats went further. They said intelligence officials had detected American chip technology being diverted towards programmes that strengthened Chinese missile systems, despite G42’s earlier pledges to sever its ties. Administration officials disputed those conclusions, insisting that the Chinese links had been cut after comprehensive vetting.
Even assuming good faith, the financial interests involved make a complete separation difficult. G42 is backed by Mubadala, Abu Dhabi’s sovereign wealth fund, which manages a China portfolio worth more than $200bn and participates in a joint Emirati-Chinese investment fund that channels capital into infrastructure and engineering technologies. Researchers specialising in the political economy of technology point to a basic gap between what Washington can compel states to do and what those states can realistically achieve. The result is hedging rather than full alignment, much as other US allies in Asia have done.
The war itself opened other supply routes. The UAE bought and used the South Korean Cheongung system for medium-range missile defence because it costs far less than its American counterparts. Iran-backed forces, meanwhile, widely use Chinese-made DJI drones. Wartime pressure therefore encouraged a broader range of suppliers for defensive hardware even as it increased dependence on the US for computing hardware.
The latest American decision carries a further irony. Replacing a review of each shipment with a general exception means the Bureau of Industry and Security no longer examines individual deliveries in advance; it investigates afterwards if evidence of a leak emerges. American officials had already warned that Chinese companies could exploit a loophole to buy Blackwell-class servers through overseas subsidiaries — precisely the kind of leakage the controls were intended to stop. The measure meant to contain China weakened as the UAE was rewarded for its stance against Iran.
A smaller episode shows how far these controls can reach. In June 2026, a US export-control directive forced Anthropic to suspend global access to two newly launched advanced models until the issue was resolved in early July. When export controls apply to models as well as chips, the Gulf’s purchases amount to more than hardware. They also depend on access that Washington can revoke.
Tahnoon and cryptocurrency
According to The Wall Street Journal, citing undisclosed corporate documents, an Abu Dhabi entity called Aryam Investment 1, backed by Sheikh Tahnoon bin Zayed, signed an agreement to buy a 49 percent stake in the cryptocurrency company World Liberty Financial for $500m.
Eric Trump signed the agreement on 16 January 2025, four days before Donald Trump’s inauguration. About $263m of the sum was directed to entities affiliated with the Trump family. The deal was not announced and made the Emirati entity the company’s largest foreign shareholder. G42 executives managed the entity and obtained seats on the American company’s board. In August 2026, the same arrangement was extended to the holding company of a bank that World Liberty intends to establish; the bank received conditional preliminary approval for a federal banking licence.
Sheikh Tahnoon is the UAE’s national security adviser, deputy ruler of Abu Dhabi, brother of the president and chairman of G42. He also oversees the country’s largest sovereign wealth funds.
Months after the deal, Washington approved a route for the UAE to obtain up to 500,000 of the most advanced American chips each year. The sequence prompted a fierce reaction in Washington. Sen. Elizabeth Warren introduced a resolution calling for the deal to be condemned and reversed. At the same time, Rep. Ro Khanna opened an investigation into whether conflicts of interest were influencing US policy in its competition with China and requested detailed information from the company.
Can the Gulf remain a global hub?
The hardest question is whether the Gulf’s prospects as a digital hub have survived the war. They have, but at a cost.
The figures favour continued investment. Too much money has already been committed to abandon the projects, while American technology giants are planning capital spending of about $630bn in 2026 alone. Against that total, the loss of a single $1bn facility is financially bearable. So far, a strike on a data centre has also proved far less disruptive than a strike on an oil facility. Amazon showed that moving workloads to other regions can keep disruption temporary and localised; there is no equivalent reserve to draw on if Gulf energy exports are blockaded. That is why observers generally expect companies to hedge rather than leave.
The hedging matters in its own right. Industry officials have spoken of accelerating projects in Northern Europe, India and Southeast Asia, where energy supplies, regulations and security conditions are more predictable. Some companies have announced temporary pauses in Middle East investment decisions. More broadly, the industry is moving away from concentrating facilities in one place and towards a global network, spreading data across locations and maintaining capacity in multiple regions. Diversification within the Gulf has limits, too: the 2026 war showed that Iran can coordinate strikes in several Gulf states at once. Distributing workloads among the UAE, Bahrain, Saudi Arabia and Qatar would therefore provide only partial protection in a wider escalation.
Costs are rising on several fronts: higher war-risk insurance premiums, more expensive reinforced facilities, counter-drone technology, recovery systems spanning multiple regions and delays while new security frameworks are built. The risks extend beyond regulation. Iran explicitly threatened the Stargate site in Abu Dhabi, estimated to cost $30bn. Whoever owns these computing clusters will face physical threats as well as compliance obligations.
The Gulf still has two considerable advantages: sovereign wealth and plentiful cheap energy. Both matter when electricity is becoming the main constraint on AI expansion, including in Europe and the United States. Yet the combination that drove the past decade’s growth — money, electricity and quick permits — is no longer sufficient. Gulf capitals also need protection that they cannot currently provide on their own.
That is the irony the war has exposed. Some Gulf states entered the AI race seeking technological sovereignty, a way to prepare for declining hydrocarbons and reduce their dependence on a rentier economy. They have emerged from a war that is still under way with the chips they sought, on better terms than they had hoped for a year earlier. But those chips come with an American security umbrella, a joint military task force, an authorisation that must be renewed and the possibility that a national champion such as G42 may have to reincorporate as an American company to keep supplies flowing. Iran’s war did not end the deals. It changed the terms on which they depend — including the possibility that access granted over nine months could be withdrawn in nine days.