There has never been a construction race like the one now under way in the data center industry.
AI’s demand for compute is driving the largest and fastest infrastructure buildout the sector has ever seen, with hyperscalers and developers racing to bring capacity online faster than power grids, planning departments or supply chains can comfortably keep up.
In that scramble, enormous attention goes to the things visible on a spreadsheet: megawatts, cooling, chips, network and, rightly, cybersecurity.
The dimension that gets quietly deprioritized is the physical protection of the buildings themselves. It is the easiest thing to defer under deadline pressure, and the hardest to retrofit once the concrete is poured.
A regulatory change in the United States is about to make that blind spot worse, and it is worth understanding even if you never operate a US federal facility, because of what it signals.
On 30 September, the Federal Data Center Enhancement Act is due to expire, with no replacement waiting. It set minimum standards for federal data centers, including, unusually, protection against physical intrusion, and it was the operational mandate that forced data-center-specific assessment.
Broader frameworks such as FISMA and the NIST control catalogue still apply, but they provide the principle; the Enhancement Act provided the practice. Principles without a mechanism to enforce them tend to be interpreted generously.
And when the government’s own floor is allowed to disappear, the benchmark private operators quietly measure themselves against tends to go with it.
Security baselines
This is not a hypothetical worry about whether the requirement comes back. The Act’s predecessor lapsed in 2022 and only survived by being folded into the following year’s defense bill. A rule that needs a legislative vehicle to return is one that can quietly fail to, and security baselines rarely erode through a single dramatic decision. They erode through the absence of one: a mandate that simply never gets renewed because nothing forces the issue.
It helps to be concrete about what is at stake, because physical security is not an abstraction. It is the contractor with unescorted access to a hall of servers; the unmonitored loading bay; the maintenance door propped open for convenience; the departed employee whose credential still opens the cage. These are the routes by which data is stolen, infrastructure is sabotaged, and a facility the size of a warehouse is taken offline.
The real exposure is not in the data centers we already have. Established operators keep that spending in place through existing contracts and their own risk appetite. It is in the new builds, the AI-era expansions specced and procured at extraordinary speed, most of them private, built by developers no mandate ever bound. Remove the assessment framework and physical security becomes something that can be scoped down in procurement to hit a budget or a timeline, with no compliance flag and no one formally alerted. The gap opens in the facilities we are racing to build.
There is a contradiction at the center of this. Governments increasingly classify data centers as critical national infrastructure, the UK now does, and rightly so. Reducing their security baseline at the same moment runs in two directions at once. You cannot call something critical and simultaneously make its protection optional.
A sensible fix
The fix is not simply more regulation, though a sensible renewal would help. It is to stop treating physical security as a compliance obligation that rises and falls with the statute book, and start treating it as core design.
The consistent lesson from securing large-scale critical facilities is that physical security fails when it is a collection of disconnected tools, a camera here, an access reader there, bolted on at the end of a project.
It works when it is designed from the start as one integrated system, where access control, video, identity and alarms inform each other and an anomaly anywhere triggers a coordinated response.
Treating the physical and the digital as separate problems is part of how the gap forms in the first place. In a modern data center they are the same problem: a propped door, a cloned badge or a rogue contractor is a cyber incident waiting to happen, and a facility that cannot correlate a door event with an access log or a camera feed will always be reacting after the fact rather than stopping an intrusion in progress.
For operators, the practical implication is simple: the physical security of an AI data center should be specified at the same moment as its power and cooling, not bolted on once the shell is up. Retrofitting protection into a live, fully-loaded facility is far harder, and far costlier, than designing it in.
The AI buildout is a genuine engineering achievement, and the energy and compute challenges are real. But the industry is optimizing hard for the risks it can measure and deferring the one it finds inconvenient. A statute lapsing in Washington should not be what decides whether the buildings holding the world’s most critical compute are properly protected.
For IT infrastructure we have all agreed is critical, getting its physical protection right should be a given, not something we quietly leave to whoever is under the most deadline pressure.
We’ve listed the best Linux distros for servers.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
