A Chinese company doesn’t need to hack Silicon Valley; it can simply rent the server next door.
In 2024, U.S. officials shut down a Chinese-owned data facility near a nuclear missile base in Wyoming, fearing Beijing’s surveillance. But as commercial data centers expand rapidly across the globe, a similar threat has gone virtually unnoticed—American and Chinese companies leasing space under the same roof. In a shared data center, an attacker doesn’t need to execute a complex hack to steal sensitive data. They can simply walk in, plant a spying device nearby, or alter physical hardware.
The national security debate around China’s artificial intelligence (AI) ambitions often centers on chips. Chips matter, but so does where those chips run. Data centers are the backbone of the digital age, housing racks of servers powering everything from cloud storage to financial transactions. Increasingly, they also hold the most important assets of the AI era: the model weights that define what a large AI system can do. And foreign adversaries want them.
Many of the world’s data centers operate through a model called “colocation,” where multiple companies lease racks of servers in the same facility, sharing electricity, cooling, and network connections. Colocation accounts for more than 90 percent of public data centers worldwide and roughly a fifth of global computing capacity. It’s an efficient model for both data center owners and companies looking to house their data. But it also means an American company could be training its most advanced models just one rack away—that is, inches—from a Chinese tenant bound by Beijing’s intelligence laws.
Colocation assumes that neighbors can’t reach into each other’s racks. In reality, servers are swapped constantly, often by short-term, local contractors performing routine maintenance. A tenant or technician with consistent access could easily bypass basic safeguards such as keycard doors, cameras, and access logs to plant surveillance gear nearby or replace basic components with parts that have been altered to send information elsewhere. It turns out that good old fashioned spycraft takes far less energy than a complicated hack, even for a sophisticated adversary. And while tampering is possible anywhere in the world, it is much easier overseas, away from stronger oversight and American regulatory guardrails.
Colocation also carries digital risks. Flaws in virtualization software, GPUs, and even management and cooling systems routinely surface, sometimes letting one tenant peer into another’s environment or disrupt operations. Patching them quickly doesn’t alter the fact that shared infrastructure means vulnerabilities are easier to exploit.
The scale of the build-out makes the problem more difficult to ignore. Fueled by demand for compute, data centers are multiplying at a historic pace—especially outside of the United States. Chinese tech giants Alibaba, ByteDance, and Tencent are pouring billions of dollars into new facilities across Southeast Asia. American firms are scrambling for infrastructure in those same markets. But space is scarce, as demand far outstrips supply and vacancies hover near zero for the third year in a row. With various U.S. states pushing policies to stop or limit data center construction, tenants take whatever space they can get. Data center landlords, meanwhile, rarely advertise who else is on the floor.
Washington started to catch on toward the end of the Biden administration, but then lost interest. In 2024 the Commerce Department proposed “know-your-customer” rules for U.S. cloud providers, requiring them to verify who accesses their servers to train AI models just as banks must verify who their customers are. A separate rule in January 2025 restricted where companies could store model weights and what safeguards data centers must use to store them, including hosting weights on separate servers from other companies’ data. Both Biden-era efforts are now effectively dead, and the Trump administration has been somewhat inconsistent on tech policy involving restricting foreign adversaries—particularly around China.
To address the colocation issue, the United States has tools, such as the Committee on Foreign Investment in the United States or the Commerce Department’s Information and Communications Technology and Services authorities, that could be used to block foreign ownership of data centers or prohibit adversary-produced equipment inside of them. Commerce drafted precisely such a measure, restricting the sale of Chinese equipment for U.S. data centers. It was never implemented, as the Trump administration shelved it in early 2026 along with other China tech restrictions to avoid antagonizing Beijing after the rare earths showdown a few months before. Regulators could also set baseline security standards for data centers housing sensitive AI projects, including standards for facility access, personnel screening, and vetting of hardware that enters the building. While these steps wouldn’t eliminate the risks associated with colocation, they would make entering a data center and compromising its equipment more difficult for an adversary.
Overseas, where most of the data center build-out is happening and U.S. regulators don’t have jurisdiction, America has fewer tools to rely on. At a minimum, companies handling frontier AI systems should know who their neighbors are. Choosing a data center in Singapore or Kuala Lumpur based purely on price could end up costing far more in stolen intellectual property or disrupted operations.
In the global AI competition, the question isn’t only who makes the chips, but who has access to where they run. If the United States acts now, it could support the growth of secure data center hubs abroad, giving domestic firms safe harbors, allies alternatives to Chinese providers, and America continued leverage over critical digital infrastructure.
The United States once learned not to let adversaries camp outside its missile silos. It should also be wary about who is renting the servers next door.