The Paranoidist | Issue #6 By Paul Morin | March 14, 2026

Everyone is debating what AI will do to the world. Nobody is asking what the world can do to AI.

On March 2, Iranian drones struck three Amazon Web Services data centers in Bahrain and the United Arab Emirates. Iran's Fars News Agency cited Amazon's support for "U.S. military and intelligence activities" as the rationale. All three facilities went offline. As of this writing, they remain offline, two weeks later. The strikes were not sophisticated. They were not expensive. They did not require advanced military technology. And they demonstrated, in a few minutes, that the physical infrastructure underpinning the most consequential technological transformation since the internet is targetable, fragile, and concentrated in ways that nobody has stress-tested.

Those three data centers are a microcosm of a much larger structural vulnerability. The AI revolution is the most capital-intensive infrastructure buildout since the railroad era. Hundreds of billions of dollars are flowing into facilities that require enormous amounts of electricity, millions of gallons of water, specialized semiconductors from a single manufacturer on a geopolitically contested island, financing from sovereign wealth funds whose revenue base just got disrupted, and the implicit cooperation of local communities who are increasingly saying no. Each of these dependencies is, individually, manageable. Together, they form a portfolio of correlated risks that, as readers of this publication know, is the most dangerous kind: the kind where the failure of any single component cascades through the others.

Last week, in Issue #5, I argued that the most dangerous analytical failures occur when embedded assumptions are mistaken for facts. The AI infrastructure buildout is saturated with such assumptions. The grid will expand fast enough. The water will be available. The capital will keep flowing. The communities will accept the facilities. The geopolitical environment will remain stable enough that building critical infrastructure in contested regions is rational. The semiconductors will keep shipping from Taiwan.

None of these assumptions are facts. All of them are under simultaneous pressure. And the organizations betting their futures on AI transformation have not, in most cases, asked what happens when several of them fail at once.

The Nine-Vector Vulnerability

What follows is not a prediction that AI infrastructure will fail. It is an audit of the attack surface, using the same portfolio-of-risks framework that The Paranoidist applied to the Iran escalation in Flash Issue #1. Each vector is examined individually. The systemic risk emerges from their correlation.

Vector 1: Power

A single AI-related task can consume up to 1,000 times more electricity than a traditional web search. A hyperscale AI data center campus can draw 100 megawatts or more, equivalent to a small city. Some planned facilities are requesting five gigawatts, which exceeds the peak load for the entire city of Austin, Texas. The Lawrence Berkeley National Laboratory projects that data center electricity demand will grow from 176 terawatt-hours in 2023 (4.4% of total U.S. consumption) to between 325 and 580 terawatt-hours by 2028 (6.7% to 12.0%). BloombergNEF's latest forecast projects data center power demand hitting 106 gigawatts by 2035, a 36% jump from their projection just seven months earlier.

The grid cannot keep up. Approximately 70% of the U.S. power grid was built between the 1950s and 1970s and is approaching the end of its life cycle. PJM Interconnection, the largest U.S. grid operator serving over 65 million people across 13 states, projects it will be six gigawatts short of its reliability requirements by 2027. The president of PJM's independent market monitor told CNBC he has never seen the grid under such projected strain. Gartner predicts that power shortages will restrict 40% of AI data centers by 2027.

The market is already pricing the strain. PJM's capacity market clearing prices for the 2026-2027 delivery year increased to $329.17 per megawatt, more than ten times the $28.92 price in the 2024-2025 delivery year, with data center growth identified as a major contributing factor. In Virginia, the world capital of data centers, Dominion Energy proposed its first base-rate increase since 1992, adding roughly $8.51 per month for a typical household in 2026. The cost of AI infrastructure is being socialized to ordinary ratepayers, a dynamic that is generating political backlash from both sides of the aisle.

The power dependency compounds with the geopolitical environment. Many new data centers are turning to natural gas for on-site generation to bridge the gap between demand and grid capacity. Meta is sourcing power from a new 200-megawatt gas-fired plant in Ohio. CloudBurst signed a long-term agreement for up to 450,000 MMBtu per day of natural gas for its Texas campus. Natural gas prices are sensitive to the same geopolitical disruptions that affect global energy markets. The Iran war has pushed U.S. gas prices higher. A sustained energy crisis does not just threaten the grid; it threatens the backup power strategies that data centers are deploying to compensate for the grid's inadequacy.

Vector 2: Water

Large data centers can consume up to 5 million gallons of water per day, equivalent to the water use of a town of 10,000 to 50,000 people. Northern Virginia's data centers consumed nearly 2 billion gallons in 2023, a 63% increase from 2019. A January 2026 report from the Houston Advanced Research Center found that Texas data centers consume around 25 billion gallons annually, with an upper-end estimate of 161 billion gallons per year by 2030. Projections suggest total data center water consumption could rise 170% by 2030 compared to 2023 levels.

The water dependency is compounded by geography. Two-thirds of all data centers built or in development since 2022 are located in water-stressed areas: southern Arizona, the Colorado River Basin, Texas, and Nevada. More than half of Nevada's groundwater basins are already over-appropriated. Throughout Central Texas, at least 14 counties are experiencing moderate to extreme drought, with aquifers reaching historic lows. The irony is structural: the dry climates where evaporative cooling is most efficient are also the climates where water is scarcest.

The indirect water footprint is even larger. Fossil fuel power plants that supply electricity to data centers consumed roughly 211 billion gallons of water in 2023 for steam generation. As data centers build out gas-fired on-site power to compensate for grid shortfalls, they add water consumption at the power generation layer on top of water consumption at the cooling layer. The dependencies compound.

Vector 3: Community and Political Resistance

Community pushback in the last quarter of 2025 alone halted $98 billion in planned data center development. In San Marcos, Texas, the city council voted 5-2 to block a proposed data center after hundreds of residents appeared with concerns ranging from water access for generational ranches to the ability to swim in local rivers. Hays County's judge proposed a moratorium on water-intensive building permits, citing aquifer levels at historic lows. In Ohio, a proposal to rezone 300 acres of farmland for data centers generated such opposition that the landowners withdrew their application. Similar resistance has emerged in Georgia, Ireland, and the Netherlands.

The political dynamics are intensifying. Data center opposition is coming from both left and right: Senator Bernie Sanders on environmental and ratepayer grounds, Governor Ron DeSantis on community impact grounds. A Food and Water Watch report published in March 2026 warned that the national push for AI data centers threatens clean energy and water supplies. Every politician, as one analyst noted, will be running on affordability in 2026 elections, and data centers that raise electricity rates make easy targets. A single well-organized campaign that establishes legal precedent for blocking data centers on environmental or water grounds could cascade across jurisdictions.

The structural vulnerability is that much of the planned AI infrastructure expansion assumes permitting environments will remain favorable. Many hyperscale facilities are being sited on unincorporated land specifically to avoid municipal oversight. But the political winds are shifting. Local governments are increasingly using discretionary land-use authority, utility service conditions, and drought contingency requirements to delay or condition approvals. What was a permitting nuisance is becoming a material constraint.

Vector 4: Kinetic Attack

The AWS data center strikes in Bahrain and the UAE were the first deliberate state-level kinetic attacks on major cloud infrastructure. Iran's stated rationale (Amazon supports "U.S. military and intelligence activities") sets a precedent for any adversary to characterize commercial cloud infrastructure as a legitimate military target. The strikes used inexpensive drones, not advanced missiles. The facilities went offline and have remained offline for two weeks.

This vector was previously theoretical. It is now demonstrated. The implications extend beyond war zones. Data centers are large, stationary, energy-intensive facilities that are difficult to conceal and easy to locate. They are typically hardened against natural disasters and power outages, not against kinetic attack. The security perimeter of a typical commercial data center is designed to prevent unauthorized physical access, not to intercept incoming projectiles. In a world where drone technology is proliferating rapidly and cheaply, the assumption that data centers in "safe" geographies are immune from kinetic threat deserves scrutiny.

Vector 5: Capital Dependency on Gulf Sovereign Wealth

A substantial portion of the capital funding AI data center expansion comes from sovereign wealth funds tied to Gulf oil states. Saudi Arabia's Public Investment Fund, Abu Dhabi's Mubadala and ADIA, and the Qatar Investment Authority are among the deep-pocketed investors backing both direct data center builds in the Gulf and the Western technology companies building AI infrastructure globally.

The Iran war just demonstrated that these investors' revenue base (oil exports through the Strait of Hormuz) can be disrupted, that their domestic infrastructure is targetable, and that their political stability is less certain than capital markets assumed. Qatar halted LNG production at its two main facilities. Saudi Arabia is intercepting Iranian ballistic missiles at its military bases. If Gulf sovereign wealth funds redirect capital toward domestic security, reconstruction, and economic stabilization, the funding pipeline for global AI infrastructure development thins.

There is a deeper irony. Some AI data centers are being built in the Gulf precisely because of cheap energy from hydrocarbons. The optimization for cheap power created a geographic vulnerability to the geopolitical risks that hydrocarbon-rich regions inherently carry. The same conflict that disrupted the energy also disrupted the data centers that were located there because of the energy. This is what tight coupling looks like in practice.

Vector 6: Cyber Attack

Data centers have always been cyber targets. What has changed is the convergence of IT and operational technology (OT) within these facilities. Building management systems (HVAC, power distribution, fire suppression) are increasingly networked and often running on legacy protocols with known vulnerabilities. A cyber attack that disables cooling in a facility running at capacity can cause physical damage to server hardware within minutes. This is the same attack vector that Stuxnet exploited against Iran's nuclear centrifuges: attacking a physical process through the digital control system.

The escalation ladder now includes both kinetic and cyber attack on the same class of targets. A nation-state that has demonstrated willingness to drone a data center (Iran) also has cyber capabilities that can target data center operational systems. The attack surface is not either/or; it is both simultaneously. The defensive challenge is that physical security teams and cybersecurity teams within data center operators often operate in separate organizational silos with different reporting structures, different threat models, and different response protocols. The convergence of kinetic and cyber threat requires a convergence of defensive capability that most operators have not achieved.

Vector 7: Semiconductor Supply Chain

The hardware that goes into AI data centers has its own concentration vulnerabilities. Advanced AI chips are fabricated overwhelmingly by TSMC in Taiwan. Taiwan faces a March 15, 2026 deadline to sign three U.S. arms packages or lose the deals. Its legislature is gridlocked between the ruling DPP and the KMT/TPP opposition. China conducted its most extensive military exercise around Taiwan to date in December 2025, simulating a total blockade. The International Crisis Group describes the Taiwan Strait status quo as "precarious."

A Taiwan Strait disruption does not just affect consumer electronics. It halts the ability to build and maintain the data centers that AI runs on. The lead times for critical data center components are already measured in years. Networking equipment, specialized cooling systems, backup power generators, and fiber optic cable each have their own supply chain chokepoints. The planned semiconductor fabrication facilities outside Taiwan (TSMC's Arizona plant, Samsung's Texas expansion, Intel's Ohio facilities) are years from full production capacity and cannot substitute for Taiwan's output in the near term.

Vector 8: Regulatory Fragmentation

The EU's data sovereignty rules require certain data to be stored and processed within EU borders. China has its own data localization requirements. India is developing similar frameworks. The result is that the "global cloud" is fragmenting into regional clouds, each with different rules, different infrastructure, and different vulnerability profiles. This fragmentation reduces the efficiency gains that centralized cloud infrastructure was supposed to provide, increases costs, and creates compliance risks that compound the physical and cyber risks.

For organizations running AI workloads, regulatory fragmentation means that the disaster recovery strategy of "fail over to another region" may not be legally permissible if that region is in a different regulatory jurisdiction. Data that cannot move across borders during a crisis is data that cannot be recovered from a regional failure. The assumption that cloud infrastructure is globally fungible, that a compute job can run anywhere, is an assumption dressed up as architecture.

Vector 9: Insurance Repricing

Just as war risk insurance withdrawal effectively closed the Strait of Hormuz, insurance is becoming a constraint on data center operations and construction. The Gulf data center attacks will trigger a repricing of war risk coverage for technology infrastructure in geopolitically exposed regions. Higher insurance costs undermine the cost advantage that attracted data centers to those regions. The insurance mechanism that closed Hormuz could, in a less dramatic but structurally similar way, reshape the geography of AI infrastructure.

Beyond war risk, the insurance industry is reassessing coverage for data center operational risks including water supply interruption, power grid failure, and community-driven regulatory changes that strand invested capital. When insurers reprice risk, they are, in effect, doing the stress test that the infrastructure builders did not do. The question is whether the repricing arrives before or after a material loss event.

The Portfolio Effect

Each of these nine vectors is, individually, a known risk that the data center industry discusses (some more openly than others). The analytical failure is the same one that The Paranoidist identified in Flash Issue #1 regarding the Iran escalation: treating correlated risks as independent events.

The vectors are not independent. Power constraints drive data centers to water-stressed regions with cheap natural gas (compounding water and geopolitical risk). Gulf capital funds infrastructure in regions with cheap energy (compounding capital dependency and kinetic risk). Semiconductor constraints lengthen construction timelines (compounding community resistance as projects remain in planning longer). Regulatory fragmentation forces geographic distribution (potentially into less secure regions). Insurance repricing shifts economics (potentially pushing operators toward regions with lower costs but higher risk profiles).

When you model each vector independently, you get a manageable set of risks with mitigation strategies for each. When you model the portfolio, you get a system with compounding fragilities and feedback loops where the mitigation for one vector can exacerbate another. This is normal accidents theory applied to AI infrastructure: in a tightly coupled, complex system, the question is not whether a cascading failure occurs, but when.

But the portfolio effect has a second dimension that is, if anything, more dangerous than the first: the same vectors that threaten AI infrastructure simultaneously constrain the ability to repair AI infrastructure after a disruption. The Gulf data center destruction creates urgent demand to rebuild or migrate workloads. But semiconductor constraints limit available hardware for that rebuild. Rising energy costs increase the expense of spinning up replacement capacity in alternative regions. Regulatory requirements restrict where data can be moved during an emergency (GDPR-compliant data in the Gulf cannot simply be failed over to U.S. infrastructure without regulatory assessment). Community opposition slows the permitting of new facilities that displaced workloads need. Insurance repricing makes the replacement infrastructure more expensive to insure. The nine vectors do not just create the crisis. They create the conditions under which recovery from the crisis is slower, more expensive, and more constrained than anyone's disaster recovery plan assumed.

There is a third dimension that normal accidents theory makes visible: the events that destroy or degrade AI infrastructure simultaneously increase demand for AI infrastructure outputs. A war that takes data centers offline also creates market volatility that makes portfolio analytics, risk modeling, and real-time data processing more critical than at any other moment. A cyberattack that degrades cloud services simultaneously creates the cybersecurity analysis workload that requires cloud services. An energy crisis that strains the grid powering data centers also generates the energy market data processing that data centers perform. Infrastructure failures occur at peak demand because the same events drive both the failure and the demand. This is the textbook definition of tight coupling: the system's failure mode and its peak performance requirement are triggered by the same input.

A financial services firm whose AI-driven portfolio analytics go offline during the most volatile market conditions in years is not experiencing an inconvenience. It is experiencing a fiduciary crisis. A healthcare system whose AI diagnostic tools go dark during a mass casualty event is not experiencing a technology issue. It is experiencing a patient safety emergency. The organizations most dependent on AI are, by definition, the organizations most harmed when AI infrastructure fails, and the failures arrive precisely when the dependency is most acute.

There is also a dimension that the nine vectors individually miss: the financial health of the cloud providers themselves. The analysis above has examined capital flows into new infrastructure construction. But what about the corporate entities operating existing infrastructure? A cloud provider that suffers significant losses from Gulf facility destruction, faces insurance claim disputes, confronts rising energy costs across all its regions, and simultaneously sees customers demanding emergency migration support is under financial stress. A credit downgrade or capital crisis at a major cloud provider would cascade to every organization running workloads on that provider's infrastructure. This is not a physical infrastructure risk. It is a counterparty risk, and most organizations have not assessed their cloud provider as a counterparty whose financial health affects their operational continuity.

What to Do About It

If you are a board director: At your next meeting, ask management a simple question: "How many of our critical AI workloads run on a single cloud provider, and what is our recovery plan if that provider goes offline for two weeks, not two hours?" If the answer references a disaster recovery plan designed for natural disasters or cyber incidents, press further: the Gulf data center attacks demonstrated that the threat model now includes state-level kinetic attack, which most DR plans do not contemplate. Then ask the harder question: "Do we know where our cloud provider's data centers are physically located, what their power and water sources are, and whether those sources are under stress?" Most boards will discover that their organization has made a multi-million-dollar bet on AI transformation without understanding the physical infrastructure that transformation depends on.

Five specific questions for the Risk Committee agenda:

First, has management assessed our cloud provider as a counterparty, not just a vendor? If the provider faces financial stress from Gulf losses, insurance disputes, and rising energy costs simultaneously, what is our exposure?

Second, does our disaster recovery plan work across regulatory boundaries? If our primary region goes down and the backup is in a different jurisdiction, do data sovereignty rules permit the failover?

Third, what is the recovery timeline if multiple organizations are competing for the same limited rebuild resources (hardware, alternative cloud capacity, engineering talent) simultaneously? Our DR plan assumes we are the only entity recovering. In a correlated disruption, everyone is recovering at once.

Fourth, has anyone assessed whether the same events that would take our AI infrastructure offline would simultaneously increase demand for AI infrastructure outputs? In financial services, that is almost certainly the case. What is our manual fallback for the period when AI-driven analytics are unavailable and market conditions are most volatile?

Fifth, does our D&O insurance cover losses arising from AI infrastructure disruption, and has the policy been reviewed since the Gulf data center attacks? The policies written two years ago were not drafted with drone strikes on data centers in mind.

If your management team cannot answer these questions, that gap is itself a finding.

If you are a CRO or risk leader: Audit your risk framework for embedded assumptions about AI infrastructure availability. If your business continuity plan assumes cloud services will be restored within hours (the typical SLA commitment), stress-test that assumption against a scenario where restoration takes weeks. The AWS Gulf facilities have been offline for two weeks with no public timeline for restoration. Then conduct a dependency mapping exercise across the nine vectors for your primary and secondary cloud providers. Specifically: What is the grid capacity outlook in the regions where your data resides? Are those regions water-stressed? Has your provider disclosed its water sourcing agreements? What percentage of your provider's capital comes from investors whose own operating environment is under geopolitical pressure? Are the building management systems in your provider's facilities on a segmented network, or could a cyber attack on the HVAC system cause physical damage to the servers holding your data? Where are the critical hardware components manufactured, and what is the lead time for replacement? Can your disaster recovery plan operate across regulatory boundaries if your primary region goes down and the backup is in a different jurisdiction? These are not theoretical questions. They are risk register items that most organizations have not yet added because the threat was, until three weeks ago, theoretical. It is no longer theoretical.

The most important framework change: AI infrastructure should be reclassified from "technology risk" to "compound infrastructure risk" with explicit multi-domain assessment spanning technology, geopolitical, energy, water, regulatory, insurance, and supply chain dimensions. As long as AI infrastructure lives in the technology risk silo, the correlated, cross-domain vulnerabilities this article describes will remain invisible to the risk framework that is supposed to surface them.

If you are a CEO or founder: The strategic question is not whether to pursue AI transformation. It is whether your AI transformation strategy has been stress-tested against the infrastructure risks that could derail it. Most AI strategies are built around capability (what can we do with AI?) and economics (what will it cost and what will it return?). Almost none are built around resilience (what happens to our AI capability when the infrastructure it runs on is disrupted?).

This gap creates both risk and opportunity. The risk: your competitors who have built resilient AI infrastructure will continue operating during a disruption while you are scrambling to recover. The opportunity: if you build infrastructure resilience into your AI strategy now, before a major disruption forces the market to reprice, you gain a competitive advantage that is difficult to replicate under crisis conditions. "Built to survive what the market learned the hard way" is a legitimate market position, and the companies that emerge from this period with genuinely resilient AI architecture will have a story that resonates with clients, investors, and regulators for years.

Specific actions: evaluate multi-cloud and hybrid (cloud plus on-premises) architectures for your most critical AI workloads. Assess whether smaller, distilled AI models that can run on local hardware could serve as fallback capability during cloud outages. Diversify your AI infrastructure across geographic regions with different risk profiles (not three data centers in the same region, which protects against a localized event but not against the grid-level or water-level constraints that affect entire regions). And include AI infrastructure resilience in your board-level strategic discussions, not as a technology item buried in the CTO's report, but as a strategic risk item that affects the viability of your most important transformation initiative.

A note of honesty: the hardest part of this conversation is that it requires questioning decisions you have already made and invested in. If you have spent 18 months building an AI transformation strategy on a specific cloud architecture, the psychological pull to defend that decision is powerful. Sunk cost bias, commitment escalation, and organizational inertia are predictable barriers to the kind of architectural rethinking this moment demands. Recognizing those barriers is the first step to overcoming them. The alternative, continuing to build on a foundation you now know is fragile because changing course feels like admitting a mistake, is the more expensive choice in every scenario except the one where nothing goes wrong. And the argument that nothing will go wrong is, as of February 28, 2026, no longer available.

If you are a citizen and a thinker: The AI infrastructure buildout is happening in your community, whether you know it or not. If you live in Virginia, Texas, Arizona, Nevada, Ohio, or the rural areas where hyperscale facilities are being sited, the data centers going up near you will affect your electricity rates, your water supply, your local traffic, and your property values. Community pushback has already halted $98 billion in planned development in a single quarter. That number is not a sign of irrational NIMBYism. It is a signal that the externalities of AI infrastructure (power consumption that raises rates for everyone, water consumption that depletes aquifers, noise and visual impact, tax incentives that benefit tech companies but not local services) are not being adequately priced or distributed. You have more leverage than you think. Local land-use authority, utility service conditions, and water rights are the mechanisms through which communities are shaping where and how AI infrastructure gets built. Engage with those mechanisms. And on a broader level, recognize that the digital services you use every day, the AI assistants, the cloud storage, the streaming services, are not ethereal. They run on physical infrastructure that consumes real resources, occupies real land, and exists in a real geopolitical environment. The assumption that these services will always be available, instantly and cheaply, is an assumption. It is not a fact.

A Framework for Assessing AI Infrastructure Resilience

Beyond the audience-specific actions above, any organization can apply the following framework to evaluate its AI infrastructure exposure across the nine vectors:

Vector

Key Question

Red Flag

Power

What is the grid capacity outlook where your data centers operate?

Provider relying on grid expansion that hasn't been permitted; on-site generation dependent on natural gas with geopolitical price exposure

Water

Is the facility in a water-stressed region? What cooling technology is used?

Evaporative cooling in a drought-prone area; no drought contingency in water supply agreement

Community

What is the local political environment for data centers?

Active moratoriums, recent permit denials, or organized opposition in the jurisdiction

Physical

Is the facility in a region with active or potential conflict?

Gulf region, areas within range of hostile state actors, facilities without kinetic threat assessment

Capital

Who financed the infrastructure? Is that capital source under pressure?

Heavy dependence on Gulf sovereign wealth; refinancing events during geopolitical instability

Cyber

Are building management systems segmented from the IT network?

Converged IT/OT networks; legacy protocols on cooling and fire suppression systems

Supply chain

Where are critical hardware components manufactured?

Single-source dependency on TSMC; multi-year lead times for replacement components

Regulatory

Can your DR plan operate across regulatory boundaries?

Data sovereignty rules preventing failover to backup regions in different jurisdictions

Insurance

Does your coverage include acts of war and government-ordered interruption?

Policies written before the Gulf data center attacks; no war risk coverage for tech infrastructure

The organizations that can work through this framework today have a decision advantage. The organizations that have never considered these questions are carrying risk they have not measured.

Who Benefits from Disorder

The antifragility question from Issue #5's framework applies here: who gains when AI infrastructure is disrupted?

Distributed computing advocates and on-premises AI providers benefit when centralized cloud concentration proves fragile. Companies building AI capabilities that can run on smaller, local hardware (edge computing, on-premises inference, model distillation) become more attractive to risk-conscious buyers. European sovereign cloud initiatives, which have struggled for market traction against the hyperscalers, gain a new selling proposition: not just data sovereignty, but physical security.

Open-source AI models that can be downloaded and run locally are a form of antifragility against cloud disruption. A company running Llama or Mistral on its own hardware is not affected by a data center attack in Bahrain. The trade-off is capability: the largest frontier models require infrastructure that only the hyperscalers can provide. But the gap is narrowing with each generation, and the risk calculus shifts as the vulnerability of centralized infrastructure becomes more visible.

Defense and intelligence communities, which have been moving toward commercial cloud (the CIA's contract with AWS is well-documented), face a particularly acute version of this dilemma. The same commercial infrastructure that provides cost efficiency and rapid capability deployment is now a demonstrated military target. The distinction between commercial and military infrastructure, which was always somewhat artificial, has been erased by an Iranian drone.

And there is an opportunity that applies to every organization, not just technology providers: the companies that experience this disruption and rebuild with genuine resilience can convert the crisis into competitive advantage. A financial services firm that emerges from the Iran war period with a multi-cloud, geographically diversified, regulatory-compliant AI architecture has a story that resonates with clients, regulators, and investors for years. "Built to survive what the market learned the hard way" is a market position that cannot be fabricated after the fact. The window to build it is now, while the market is still learning.

The Assumption Audit

Every major infrastructure buildout in history has carried embedded assumptions that seemed obvious at the time and proved catastrophic in retrospect. The railroad era assumed land grants would continue. The nuclear power era assumed waste disposal would be solved. The suburban development era assumed cheap gasoline would persist. The globalization era assumed supply chain stability.

The AI infrastructure era assumes: the grid will expand. The water will be available. The capital will flow. The communities will accept. The geopolitics will be manageable. The semiconductors will ship. The regulations will converge. The insurance will cover it. The physical security will hold.

These are not unreasonable assumptions individually. They are, collectively, a bet that nine things will go right simultaneously, during a period when the geopolitical, environmental, and political environment is demonstrating that correlated failures are the rule, not the exception.

Productive paranoia does not mean predicting that AI infrastructure will collapse. It means identifying the assumptions that the entire buildout depends on and asking, rigorously and honestly: what if three of them are wrong at the same time?

The organizations that ask that question now will be better positioned than the ones who ask it after the answer arrives uninvited.

The Paranoidist publishes weekly, with flash issues when events warrant. If this changed how you think about one thing, consider subscribing. If it didn't, tell me what I'm missing.

Paul Morin is the founder of DeepStrategy.ai and publisher of The Paranoidist, BoardroomRadar and ScenarioWatch. He has spent more than three decades in entrepreneurship, finance, risk management, and insurance, which is why he worries about the things that keep other people awake at night.

Researched, written, and edited in collaboration with Claude by Anthropic.

Disclosure: This issue analyzes structural vulnerabilities in AI infrastructure, including cloud platforms operated by Amazon Web Services, Microsoft Azure, and Google Cloud. Anthropic, the maker of Claude (the AI used in researching and editing this publication), operates on AWS and Google Cloud infrastructure. This relationship is disclosed in the interest of transparency. The analysis applies a structural vulnerability framework; it does not constitute investment advice or an endorsement or criticism of any specific provider.