UAE AI Data Center Redesign Turns a 5GW Campus Into a Security Test
The UAE AI data center redesign follows a direct conflict signal: Iranian strikes damaged three regional cloud facilities, while Stargate UAE received an explicit threat.
The original vision centered on a 5-gigawatt campus covering 26 square kilometers near Abu Dhabi. That concentration promised enormous computing capacity, low-latency connections, and simpler operations. It also created one visible target containing servers, power systems, cooling equipment, and network links.
The United Arab Emirates is now reconsidering that architecture, according to six people who spoke with Reuters. Proposed changes include distributing capacity across several locations, moving sensitive systems underground, and installing defenses against drones and missiles.
The redesign is not yet a finalized public plan. G42 says campus work remains on schedule, while acknowledging continuous reviews involving security, resilience, and operational standards.
That tension matters. The UAE wants to operate one of the largest AI infrastructure projects outside the United States. The Iran conflict has made physical survival part of the project’s basic design.
What Changed in the UAE AI Data Center Redesign
The reported shift replaces concentration as the default architecture with geographic separation, hardened construction, and operational redundancy.
The UAE and its American partners announced the original campus during President Donald Trump’s May 2025 visit. G42 would lead development of a 5GW AI campus spanning about 10 square miles outside Abu Dhabi.
Inside it, Stargate UAE would provide a 1GW computing cluster operated by OpenAI and Oracle. Nvidia, Cisco, and SoftBank also joined the project.
The first 200MW portion was expected to become operational during 2026. OpenAI described it as the first international deployment of its Stargate infrastructure platform.
That initial phase remains under construction. However, the rest of the campus will likely become a network of smaller facilities spread across the Emirates, according to the reported redesign.
Officials are reportedly studying several protective measures. These include blast-resistant concrete, backup power, additional cooling systems, electronic jamming equipment, and interceptors for drones and missiles.
Some sensitive computing systems might be placed underground. Facilities handling military or government data might also be built inside mountains in Ras Al Khaimah or Fujairah.
These measures remain under consideration. Reuters could not determine whether Emirati authorities had finalized a new master plan or calculated its effect on schedules and costs.
G42 offered a carefully balanced response. The company said construction was progressing as planned, but project details receive continuous review under critical-infrastructure standards.
OpenAI also said it was making progress with the UAE on infrastructure and adoption priorities. Nvidia, Oracle, Cisco, and the relevant Emirati ministry did not provide detailed public responses to Reuters.
The important change is therefore architectural, not a confirmed cancellation. The first phase appears set to continue, with defenses added around it. Later phases face a more fundamental redistribution.
That distinction prevents the story from becoming more definitive than the available evidence supports. The UAE has not publicly released revised maps, engineering specifications, or completion dates.
Still, the direction is clear. A single campus can maximize scale, but it also concentrates exposure. A distributed network reduces the chance that one strike disables the entire system.
The original 5GW campus plan combined nuclear, solar, and natural-gas power. It also included a science park and regional computing services.
That combination represented more than a collection of server buildings. It was a national platform for delivering advanced AI models across government, healthcare, education, transportation, energy, and private industry.
Redesigning that platform means revisiting power delivery, fiber routes, cooling capacity, security perimeters, and workload placement. Those choices will determine whether distribution creates genuine resilience or simply more sites requiring protection.
Iranian Strikes Turned Cloud Risk Into Physical Risk
The conflict exposed a weakness that conventional cloud planning often treats as remote: several supposedly redundant facilities can suffer physical damage together.
In March 2026, Iranian drone strikes damaged two Amazon Web Services facilities in the UAE. A third AWS facility in Bahrain also sustained physical effects from a nearby strike.
AWS said the attacks caused structural damage, interrupted electricity, and triggered fire suppression that produced additional water damage. Two of the company’s three UAE availability zones remained significantly impaired during the incident.
An availability zone is an isolated group of data centers within a cloud region. Providers use several zones so applications can continue when one location fails.
The strikes tested that principle under conditions more severe than a routine equipment failure. Multiple facilities and supporting systems were affected within the same regional conflict.
AWS advised some customers to move workloads to other regions and redirect traffic away from the UAE and Bahrain. Services including computing, storage, databases, monitoring, and identity tools experienced degraded availability.
The company’s service update showed why physical damage behaves differently from a software outage. Engineers needed both infrastructure repairs and software workarounds.
Software can reroute requests within seconds when healthy capacity remains available. It cannot instantly replace damaged electrical systems, flooded hardware, destroyed network links, or inaccessible buildings.
AWS designed its regions around separated availability zones with redundant power, water, telecommunications, and internet connections. Yet regional separation has practical boundaries.
Facilities must remain close enough for low-latency communication. That proximity can expose several sites to one military campaign, even when a single explosion cannot reach them all.
Mike Chapple, an information technology professor at the University of Notre Dame, told the Associated Press that one lost data center is normally manageable. Losing several facilities within one zone can create capacity shortages.
He also noted that cloud computing still depends on physical structures exposed to disasters. The regional strikes made that dependence unusually visible.
The threat soon moved from regional cloud infrastructure to Stargate UAE itself. In April, Iranian military media published imagery identifying the construction site near Al Dhafra Air Base.
The accompanying message said information and communications technology companies in the region would be treated as targets. It asserted that the site had not escaped Iranian surveillance.
The video reportedly misidentified several technology executives. That error weakens its informational reliability, but it does not erase the strategic signal.
Two people familiar with the project confirmed to Reuters that the identified location was near Al Dhafra. The air base hosts American forces and had already faced attacks during the conflict.
That proximity links a commercial AI project with a military geography it does not control. Servers need not perform military work to become exposed when they sit near a strategic installation.
The UAE’s earlier security model focused heavily on cyberattacks, unauthorized entry, equipment failures, and service continuity. Missile and drone defense now belongs in the same planning conversation.
A 5GW AI Campus Creates Both Scale and Concentration
The primary contest is no longer the UAE against another AI hub. It is hyperscale efficiency against national resilience.
A centralized campus offers clear engineering advantages. Operators can share electrical substations, water systems, network connections, security staff, and maintenance resources.
Large clusters also reduce communication delays between accelerators. That matters when thousands of specialized AI chips cooperate on model training or high-volume inference.
Inference is the process of using a trained model to generate an answer or prediction. Low latency becomes important when governments and businesses depend on those responses continuously.
Stargate UAE was designed around these scale benefits. The announced 1GW cluster included a 200MW opening phase and access to Nvidia’s advanced computing systems.
OpenAI said the project could serve users within a 2,000-mile radius. The company also presented it as infrastructure for nationwide adoption across major public and commercial sectors.
Its Stargate UAE launch connected domestic infrastructure with investments in American Stargate facilities. The arrangement embedded the project inside a broader political partnership.
The UAE gained a pathway to advanced American chips and AI services. In return, it accepted security conditions and tighter alignment with the United States technology stack.
A single campus made that partnership visible. It created a flagship destination for investment, talent, power generation, and technical operations.
The same visibility became a liability once conflict reached nearby cloud facilities. A campus holding several gigawatts of capacity offers an adversary a concentrated target with strategic and symbolic value.
Dispersal changes that equation. An attacker would need to identify and disable multiple sites, supporting networks, and power sources to achieve the same systemwide effect.
It also complicates construction. Every location needs secure energy, cooling, fiber, spare equipment, trained staff, and physical protection.
Duplicating those systems increases capital requirements even before underground excavation or defensive equipment enters the calculation. Reuters could not establish the expected cost increase.
Distance creates another tradeoff. Separate facilities improve survival, but longer network paths can reduce performance for tightly coupled computing tasks.
The UAE can address part of that problem by assigning different workloads to different sites. Large training jobs might remain within closely connected clusters, while inference and backup systems spread more widely.
Sensitive government applications could receive the most protected locations. Less critical commercial services might operate from standard facilities with regional failover arrangements.
That approach resembles cloud architecture at a national scale. Operators divide systems into failure domains so one local incident does not become a complete outage.
However, national infrastructure has dependencies that software cannot abstract away. Several data centers might still rely on the same power grid, fiber corridor, port, desalination system, or imported replacement parts.
Physical separation therefore offers protection only when supporting infrastructure is also diversified. Moving servers without separating electricity and network routes would preserve hidden concentration.
The UAE AI data center redesign succeeds only if it distributes failure, not merely buildings.
Stargate UAE Now Pressures Every Partner
G42 carries the construction burden, but OpenAI, Oracle, Nvidia, Cisco, and government agencies all depend on the redesign working.
G42 leads the UAE side of the project and controls much of its infrastructure strategy. Its data center subsidiary, Khazna, has developed hyperscale facilities across the region.
The company must now reconcile three commitments. It needs to deliver capacity, meet American security requirements, and protect infrastructure from a demonstrated military threat.
Those goals can conflict. Faster deployment favors standardized construction at one prepared site. Greater protection favors custom engineering, dispersed locations, and duplicated systems.
OpenAI faces a different form of pressure. Stargate UAE was presented as the first international example of a model that could expand to other countries.
A major delay would challenge that template. A secure redesign, however, could create a more credible model for politically exposed regions.
Oracle is expected to help operate the cluster, while Nvidia supplies its central computing equipment. Cisco provides connectivity and security technology across the planned infrastructure.
Each partner depends on physical continuity. Advanced chips have limited value when power, cooling, or fiber connections fail.
The project also carries diplomatic obligations. The United States approved closer technology cooperation while demanding safeguards against the diversion of advanced hardware.
The UAE committed to invest in American data centers at least as large and capable as facilities built domestically. That arrangement ties infrastructure delivery to bilateral trust.
Dispersing the campus might improve security while complicating oversight. Authorities must track hardware, operators, workloads, and network access across more locations.
Underground facilities introduce further operational questions. Servers create intense heat, and removing it requires substantial cooling infrastructure and reliable power.
Subterranean construction can shield equipment from blast effects. It can also complicate ventilation, water management, emergency access, and hardware replacement.
Mountain locations offer natural protection but fewer established utility connections. Moving large computing clusters into them requires roads, substations, fiber links, cooling systems, and secure logistics.
These challenges do not make the concept impractical. Data centers already operate in former mines, caves, and military bunkers in several countries.
The question is whether those precedents translate to AI clusters at the UAE project’s planned scale. High-density accelerators impose power and heat requirements beyond conventional storage facilities.
Partner pressure will also increase if the redesign delays the promised 200MW opening phase. That milestone provides the first measurable test of construction progress.
For enterprise customers, the consequences extend beyond one campus. Organizations place data, applications, and AI workflows in a region based partly on assumptions about availability.
The AWS strikes showed that geographic labels do not guarantee independence from a shared conflict. Buyers must examine actual failure domains, recovery locations, and cross-region dependencies.
Teams also need records that remain usable during service interruptions. A searchable AI knowledge base can support continuity, but it does not replace tested backups and infrastructure planning.
For developers, the lesson is equally concrete. A region-level endpoint can conceal several physical dependencies whose failure appears as an ordinary API error.
Resilient applications need retry logic, alternate regions, portable data, and clear rules for operating with reduced model capacity. Those design choices become costly when postponed.
Underground Facilities Cannot Remove Every Weak Point
Hardening buildings reduces direct strike risk, but it cannot make the broader AI supply chain invisible or self-sufficient.
The reported redesign can lower the damage caused by a successful attack. Blast-resistant structures protect equipment, while underground placement adds material between weapons and critical systems.
Air defenses and electronic jamming can intercept or disrupt some incoming threats. Backup generators and cooling systems can preserve operations after utility failures.
None of these controls offers certainty. Air defense inventories are finite, and repeated attacks can overwhelm even well-protected locations.
Large AI sites also produce observable signatures. They consume immense electricity, require substantial cooling, connect to high-capacity fiber, and receive specialized equipment.
Those characteristics make concealment difficult. Burying servers does not hide substations, transmission lines, network routes, construction activity, or logistics.
Distribution can create more potential entry points. Each site needs staff, vendors, physical access controls, cyber defenses, and maintenance procedures.
A network of smaller facilities might survive attacks better while becoming harder to govern consistently. Security gaps at one location can threaten connected workloads elsewhere.
The UAE also remains dependent on imported AI accelerators and replacement components. Damage that destroys scarce hardware could produce recovery delays even when buildings remain usable.
Energy represents another exposed layer. A protected data hall cannot function without stable electricity, and dedicated generation assets can become targets themselves.
Cooling has similar limits. Desert facilities often depend on carefully engineered systems whose pumps, pipes, and electrical controls extend beyond the server room.
Fiber routes create a third vulnerability. Several hardened sites can become isolated if their connections pass through one corridor or landing station.
The International Institute for Strategic Studies argues that Gulf AI infrastructure depends on power grids, fiber networks, and cooling resources exposed to regional conflict. Its sovereignty analysis also highlights upstream risks involving energy and semiconductor supply chains.
The report points to Saudi Arabia’s Abqaiq oil facilities as a useful precedent. Attacks in 2019 temporarily removed 5.7 million barrels of daily production.
Saudi operators restored full output within weeks through spare capacity, redundant systems, and rapid replacement. The precedent supports redundancy, but it does not prove that underground construction alone ensures continuity.
Data centers differ from oil facilities in another important way. Digital workloads can move, provided another region has enough compatible capacity and current data.
That mobility favors a mixed strategy. The UAE can harden essential local systems while maintaining recovery capacity outside the immediate conflict zone.
However, cross-border recovery creates questions about data residency, legal control, and government access. Sovereign AI policies often demand that sensitive information remain under national authority.
The project therefore faces a deeper tradeoff. Local concentration supports sovereignty and performance, while international distribution can improve survival during a regional war.
No public statement has explained how the revised plan will balance those goals. Nor has the UAE disclosed which workloads would receive underground protection.
The proposed defenses should therefore be treated as an evolving risk response, not proof of an invulnerable AI network.
Three Signals Will Show Whether the Redesign Works
Construction milestones, confirmed geographic separation, and tested workload recovery will reveal whether the UAE has changed its architecture or only its messaging.
The first signal is the initial 200MW Stargate UAE phase. OpenAI and G42 originally expected it to become operational during 2026.
An on-time launch with added physical defenses would show that hardening can coexist with delivery. A substantial delay would reveal the construction cost of adapting an active project during conflict.
The second signal is a revised master plan. The UAE has not published one, and the reported changes rely mainly on anonymous officials, diplomats, and industry executives.
A credible plan should identify multiple operating locations, independent power sources, separated fiber routes, and clear workload roles. It need not disclose coordinates or sensitive defensive details.
Without that confirmation, claims about underground facilities and mountain sites remain proposals. G42’s statement about continuous review leaves considerable room between discussion and implementation.
The third signal is evidence of operational failover. Construction alone cannot establish resilience.
Operators must show that applications, data, and model services can move between facilities without unacceptable loss. That requires capacity tests, recovery exercises, and customer guidance.
The AWS incident provides a demanding reference point. Multiple availability zones suffered impairment, while customers were advised to redirect traffic outside affected regions.
A redesigned UAE network should demonstrate that losing several nodes does not eliminate essential computing services. It should also define which systems receive priority when capacity becomes constrained.
These signals matter beyond the Emirates. Saudi Arabia, Qatar, and other regional governments are also investing in domestic computing capacity.
Their projects compete for advanced chips, technical partners, capital, and international customers. They now compete on physical resilience as well.
The UAE AI data center redesign changes the sales argument for every regional provider. Cheap energy and strategic geography no longer tell the entire story.
Enterprise buyers will ask where backup capacity lives, how quickly workloads move, and whether several sites share one physical dependency. Governments will ask who controls recovery locations and operational data.
Developers should ask similar questions before treating any AI region as permanently available. Which workloads can tolerate delay, and which require a second provider or geography?
The answer will vary by application. A research assistant can wait, while a hospital, power operator, or government service needs stricter continuity.
Stargate UAE remains an ambitious infrastructure project with major American partners and strong state support. Those advantages improve its ability to absorb a redesign.
They do not settle the central question. Can the UAE preserve hyperscale AI performance while removing the single-campus risk that made Stargate an obvious target?
Watch the 200MW milestone, the geographic blueprint, and real recovery testing. Together, they will show whether dispersed sovereign AI becomes a working system or an expensive architectural promise.



