AI data centers are critical infrastructure now. The U.S. investment in AI is nearing a trillion dollars, and new agreements between global superpowers and hyperscaler companies are turning AI into what recent congressional testimony from the Center for Strategic and International Studies described as “the defining competition of the 21st century.” Experts from CSIS further testified that “AI companies must be treated not just as technology providers, but as pillars of national resilience” NVIDIA cofounder Jensen Huang echoed this message in a May, 2025 keynote address, stating: “NVIDIA is not a technology company, only, anymore. In fact, we are an essential infrastructure company.” The stakes are international leadership and the attackers are sophisticated nation-state adversaries. This is not child’s play. It’s an international arms race.

While AI may not yet be officially included in CISA’s framework of critical infrastructure sectors, it is time to start treating AI data centers with the same cybersecurity rigor as we treat other critical infrastructure sectors such as energy, telecommunications, manufacturing, and defense.
Other governments have already made that call. In 2024, the United Kingdom designated data centres as Critical National Infrastructure, placing them alongside energy and water for national resilience purposes. The European Union’s NIS2 Directive goes further, explicitly naming cloud computing and data center service providers among the entities subject to its cybersecurity and resilience requirements.
Meanwhile, a new crop of global AI infrastructure companies are building fast. Neocloud companies like CoreWeave are delivering AI training and inference services at scale. NVIDIA, OpenAI, AMD, and other AI heavyweights have committed hundreds of billions of dollars to build AI infrastructure worldwide, with heavy presence in the U.S. and Saudi Arabia.
And while many news cycles have been spent on the AI challenges of intellectual property theft, protection of proprietary models, abuse of AI to write phishing emails and more. The security of the underlying infrastructure and foundational hardware of AI data centers has been largely kept out of the spotlight.
There is an urgent need for focus on securing the very foundational hardware and supply chain that enables the operation of AI data centers.
Cyber Risk To AI Data Center Infrastructure and Supply Chains
From GPUs and GPU servers to network infrastructure like routers, switches, and firewalls, the technology that underpins and connects AI data centers is profoundly vulnerable. Numerous GPU vulnerabilities were disclosed in 2025 alone. And the network and security appliances that are also present in data centers have seen a radical increase in being targeted for exploitation by cyberattackers.
In July 2025, Wiz Research disclosed NVIDIAScape (CVE-2025-23266), a critical, CVSS 9.0 flaw in the NVIDIA Container Toolkit that let a malicious container escape its boundaries and gain full root access to the host machine, using nothing more than a three-line Dockerfile. Because the toolkit underpins managed AI services across every major cloud provider, the vulnerability put shared GPU infrastructure at risk across the industry, not just at NVIDIA.
What Is AI Infrastructure Supply Chain Security?
AI infrastructure supply chain security means verifying and monitoring every hardware, firmware, and software component that goes into building and running an AI data center, from the GPUs and servers themselves to the network devices connecting them, both before deployment and throughout their use.
An IT supply chain is the full chain of suppliers, manufacturers, and integrators that touch a piece of infrastructure before it reaches an organization. A single AI server can carry components from dozens of vendors, each running its own firmware, each representing a point where something could be altered, misconfigured, or compromised before it’s ever powered on.
For AI data centers, that scrutiny extends past the applications and models running on top of the infrastructure and down to the physical layer underneath them, the GPUs training and running models, the servers housing them, and the network devices connecting it all together.
NVIDIA has described its own supply chain this way: “NVIDIA operates one of the largest and most complex supply chains in the world. The supercomputers we build connect tens of thousands of NVIDIA GPUs with hundreds of miles of high-speed optical cables.” That’s before counting everything else moving through server, network, and facility supply chains to bring a single AI data center online.
The 2025 Verizon Data Breach Investigation Report found a stunning nearly eight-fold increase in exploitation of vulnerabilities against network edge devices, particularly VPNs, compared to the year before, with vulnerability exploitation as an initial access tactic nearly catching up to credential abuse, long the leading cause. Nation-state groups such as Silk Typhoon have already used IT infrastructure supply chains to compromise high-value targets, and as AI data centers become more central to critical infrastructure worldwide, that same supply chain represents a potent attack surface.
Filling the Security Gap in AI Data Center Infrastructure
Beyond GPUs, data center and network infrastructure is frequently less monitored and less secured than user endpoints in the enterprise.
A recent Mandiant investigation into compromised enterprise network routers deployed globally in major organizations and governments noted that the attacker was targeting defense and communications infrastructure in the U.S. and Asia, and highlighted the China-Nexus attacker’s “focus on malware and capabilities that enable them to operate on network and edge devices, which typically lack security monitoring and detection solutions.”
Mandiant further noted that “the investigation was “hampered by the challenges inherent in analyzing proprietary network devices, which required novel methods for artifact acquisition and analysis.”
While the OWASP Top 10 GenAI and LLM Risks features a Supply Chain section, it focuses heavily on software packages, models, and AI application security, with only cursory coverage of hardware infrastructure. Similarly, the CISA’s AI Data Security: Best Practices for Securing Data Used to Train & Operate AI Systemsrecently released Best Practices Guide for Securing AI Data guide (released by CISA, NSA, and the FBI) focuses heavily on software and data related policies and procedures, with only a few mentions of secure hardware and infrastructure.
There’s a gap in the foundations of AI data center security, and Eclypsium can fill that gap with robust monitoring and protection for hardware, firmware, GPUs, and components in AI infrastructure.

Best Practices for Securing Your AI Infrastructure Supply Chain
- Verify hardware and firmware integrity before deployment. Confirm that a new GPU, server, or network device matches its expected configuration and hasn’t been altered somewhere between the manufacturer and your data center.
- Continuously monitor network edge devices. Firewalls, VPN gateways, and routers sit at the perimeter and often carry less security tooling than a typical server, which makes them a common entry point.
- Track firmware versions across every device class, not just servers. GPUs, network gear, and management controllers each run their own firmware, and each needs its own patch record.
- Vet supplier and component provenance. Know which vendors and sub-suppliers built the hardware running in your data center, and reassess that list as your infrastructure grows.
- Verify device integrity at every lifecycle stage. Check hardware when it’s onboarded, periodically while it’s in production, and again before it’s decommissioned or resold.
- Combine patch management with compromise detection. A device running the latest firmware version isn’t automatically a device that’s been confirmed clean; verify both.
How Eclypsium Proactively Protects AI Data Centers From Attack
Eclypsium fills the blind spot in AI infrastructure and supply chain security. Major AI data centers and their suppliers are already using the Eclypsium Infrastructure Assurance Platform to proactively protect their data centers and components from vulnerability and attack.
Eclypsium secures enterprise AI deployments against threats by proactively detecting vulnerabilities, integrity failures, and threat exposure in GPUs, AI servers, and network infrastructure. With Eclypsium, you can:
- Protect customer intellectual property from theft or leakage
- Verify and trust the AI hardware used to create model weights trained in-house or in the neocloud. Eclypsium verifies asset integrity before deployment, during use, between cloud customer training runs, and when assets are decommissioned and disposed of.
- Prevent cyberattacks against network and security edge devices from compromising AI infrastructure
As the global market for AI data centers sees hundreds of billions of dollars of investment while nation state cyberattack tactics shift to target infrastructure, now is the time to invest in proactively securing the foundation of AI data centers. Eclypsium is here to help.
Visit our AI Data Center Security solution page or watch a quick demo to see how Eclypsium verifies GPU, server, and network integrity across your AI stack.
Frequently Asked Questions
Supply chain security is the practice of verifying that every component, vendor, and supplier involved in building and delivering a product, hardware or software, can be trusted, rather than assuming it’s safe by default. It covers everything from source code and third-party libraries to physical components and firmware.
An IT supply chain is the full network of manufacturers, suppliers, and integrators that touch a piece of technology before it reaches an organization. A single server or network device can pass through dozens of suppliers, each contributing hardware, firmware, or software that could introduce risk before the device is ever deployed.
AI infrastructure supply chain security extends that same verification to the hardware running AI workloads specifically: GPUs, AI servers, and the network devices connecting them. It means confirming that infrastructure hasn’t been altered or compromised before deployment, and continuing to monitor it throughout its use.
Not officially in the United States yet; AI isn’t currently included in CISA’s list of critical infrastructure sectors. Other governments have moved faster. The UK designated data centres as Critical National Infrastructure in 2024, and the EU’s NIS2 Directive explicitly names cloud and data center providers among the entities subject to its cybersecurity requirements.
Best practices include verifying hardware and firmware integrity before deployment, continuously monitoring network edge devices, tracking firmware versions across every device class, vetting supplier and component provenance, and confirming device integrity at every lifecycle stage, not just at the point of purchase.
A patched device isn’t automatically an uncompromised one. Patching closes a known vulnerability, but it doesn’t confirm whether an attacker already gained access, altered a configuration, or established persistence before the patch was applied. Securing AI infrastructure requires verifying device integrity in addition to keeping software and firmware current.
