The most dangerous idea in the AI rivalry is not a new algorithm; it is the emerging belief that data centers are fair game in a preemptive campaign to shape who reaches the next plateau of capability first.
At a Glance
- Think-tank analysis linked to a former White House official urged Washington to plan for extreme options—espionage, cyber operations, even kinetic strikes—against Chinese AI infrastructure in scenarios where Beijing appears poised to win an AGI breakthrough.
- Critics warn such strikes on data centers would be reckless escalation between nuclear-armed states and blur the line between civilian and military targets.
- The debate sits inside a broader shift: compute and cloud infrastructure have become strategic choke points, with export controls, model diffusion, and site security shaping advantage more than any single “AGI finish line”.
- Real conflicts have already targeted commercial data centers, proving the vulnerability—and the escalatory ambiguity—of the cloud as battlespace.
How a think-tank recommendation put data centers in the crosshairs
The spark was not a classified leak but a public argument. Reporting attributed to the South China Morning Post describes Jacob Stokes, a deputy director at the Center for a New American Security and a former White House official, pressing U.S. agencies to prepare for scenarios that justify “diplomatic, espionage, cyber and kinetic measures” to prevent China from getting to artificial general intelligence first. That is not operational tasking, but it is a consequential shift in the Overton window: it normalizes contingency planning that treats compute hubs as legitimate targets in a technology race framed as existential. The suggestion derives its force from a simple proposition—if strategic AI advantage hinges on concentrated, fragile infrastructure, then disabling that infrastructure can shape outcomes.
This logic is not theoretical to strategists steeped in dual‑use technology competition. In every domain where breakthrough capability appears decisive and surprise confers advantage, policy discourse drifts toward preemption, denial, and sabotage prevention. AI is following that arc because modern training runs and high‑end inference depend on clustered accelerators, vast power and cooling, and high‑bandwidth networking—the physical substrate of “the cloud.” If that substrate is chokepoint and vulnerability in one, military planners will analyze it the way they analyze runways, radars, and satellite ground stations.
Why compute hubs look like strategic targets to hard‑power thinkers
At the heart of the argument is concentration. Frontier AI performance is bottlenecked by access to advanced accelerators, reliable power, and secure interconnects; the United States currently commands a dominant share of frontier compute, a fact that underwrites its edge as much as algorithmic ingenuity does. If Beijing narrows that gap through domestic build‑out or foreign procurement, the delta can swing quickly—not because models alone change, but because the compute to train and deploy them does. In that world, a handful of hyperscale sites become the practical “centers of gravity” for capability. A strategist who believes AGI confers outsize military or economic leverage will naturally explore options to hold those centers at risk, just as an air planner studies fuel farms and C2 nodes.
China’s own doctrinal and media discourse increasingly frames AI as a war‑shaping capability; that bilateral mirroring fuels worst‑case planning cycles. Meanwhile, U.S. export controls seek to deny Beijing the most advanced chips, reinforcing the perception that compute is the decisive terrain. When the battlefield is racks and substations instead of runways and shipyards, the temptation grows to recast data centers from “civilian utility” to “dual‑use target.”
The strongest counterargument: escalation, law, and civilian risk
The case for preemptive strikes collides with three hard realities. First, escalation dynamics: William Hartung and others argue that attacking Chinese data centers would risk triggering a shooting war between nuclear‑armed powers—an exchange whose risks dwarf any advantage gained by delaying an AI milestone. Second, the law of armed conflict strains under these scenarios. Commercial facilities that host mixed civilian and military or state workloads often retain protected status unless and while they make an effective contribution to military action; disentangling that in real time is perilous. Even sympathetic commentators concede that the question of whether military AI use makes data centers lawful targets “outruns the law”. Third, socialized risk: as more governments run sensitive workloads on civilian clouds, they effectively extend the battlespace into neighborhoods and industrial parks, exposing populations—and a global commercial backbone—to hazards originating in secret policy choices.
These are not abstract cautions. A United Nations Institute for Disarmament Research assessment identified the first documented instance of deliberate strikes on commercial data centers during a recent Middle East escalation, a watershed that transformed a hypothetical into precedent. Once a class of targets is normalized in one theater, it becomes easier to justify elsewhere; norms rarely stay compartmentalized.
What “AGI first” obscures: the real contours of advantage
Framing the contest as a sprint to a single finish line distorts both the risk calculus and the policy menu. Analysts across the spectrum increasingly describe advantage as a function of four interlocking elements: compute access, model quality and diffusion, adoption into real workflows, and infrastructure resilience. On each dimension, levers exist that do not involve high‑explosive risk. Tightened export controls and end‑use verification can slow adversary access to advanced chips; multilateral regimes can make transshipment harder. Domestic investments can widen the lead in training efficiency, data curation, and safety tooling. Above all, the United States can harden its own AI infrastructure—fully air‑gapped training clusters where warranted, cleared‑personnel regimes, onsite response teams, and robust physical fortification—so that the nation’s crown‑jewel compute is less of a tempting single point of failure.
The adoption frontier matters too. Countries win less by declaring AGI than by deploying capable systems safely and at scale across logistics, manufacturing, intelligence analysis, and command support. If the operational dividend accumulates through thousands of integrations rather than a singular “AGI moment,” then strategic patience and industrial policy can outperform coercive gambits that court escalation.
Policy triage: build denial without crossing the kinetic Rubicon
How should Washington proceed in a world where data centers are simultaneously critical infrastructure, dual‑use assets, and potential targets? Start with the measures that bend risk curves decisively without loosening nuclear thresholds. Four priorities stand out. First, expand the compute denial architecture—licensing, compliance auditing, and sanctions that target illicit procurement networks—while coordinating with allies to limit backfill. Second, accelerate domestic build‑out of secure, resilient compute with diversified siting and grid upgrades; the best deterrent is a posture that can absorb blows without systemic collapse. Third, codify red‑line diplomacy around civilian cloud infrastructure: articulate conditions under which mixed‑use facilities could forfeit protection and, more importantly, the reciprocal commitments not to target purely civilian sites—credibility reinforced by verifiable segmentation of military workloads. Fourth, invest in attribution, inspection, and incident‑response capacity so policymakers can distinguish espionage, sabotage, and overt attack quickly, reducing the fog that drives escalation ladders.
There is still a place for intelligence collection and cyber operations; states will not abandon those tools. But the burden of persuasion for kinetic action against mainland facilities should be set extraordinarily high, not because AI is trivial but because the stability costs are enormous and the alternatives are many. Even those who believe AGI confers decisive advantage must weigh whether a month’s delay achieved by force is worth decades of strategic blowback.
America has officially lost the plot.
A former White House official is openly calling for Washington to prepare espionage, cyberattacks and even military strikes against Chinese data centres if China gets too close to achieving AGI first.
Read that again.
The country that… pic.twitter.com/VLho2YapYC
— Barrett (@BarrettYouTube) September 4, 2026
The strategic bottom line
Treating data centers as preemptive strike targets is a door the United States should keep closed except in the direst, law‑grounded circumstances. The cloud has moved from bystander to battlespace, but that shift makes restraint—not adventurism—the mark of strategy. Build and defend the capacity that compounds advantage. Starve adversaries of the inputs they cannot replace quickly. And resist the seductive clarity of the “AGI first” frame; it is a poor guide to power in a competition that will be won by resilience, scale, and steady integration rather than by a single audacious blow.
Sources:
feedpress.me, finance.sina.com.cn, dwarkesh.com, situational-awareness.ai, newtalk.tw, futurism.com, au.finance.yahoo.com, sohu.com, economy.ac, convergenceanalysis.org



