Secure Inference Data Centers

A Vertically Integrated Strategy for Security Engineering

Steven F. Comer, Hunter Pavela, Varun Gandhi, Kyle Siler-Evans, Erich Devendorf, Ben Kelley, James Gimbi, Jair Aguirre, Gabriel Kulp, Mark Stalczynski, et al.

ResearchPublished Aug 4, 2026

As artificial intelligence (AI) systems become increasingly critical to national security and other high-stakes domains, the risk of model theft, manipulation, and misuse by sophisticated adversaries grows. In this report, the authors present a vertically integrated security strategy for secure inference data centers (SIDCs): purpose-built, Security Level 5 facilities designed to protect trained AI models against the most-advanced nation-state adversaries.

The authors’ proposed SIDC architecture employs rigorous system partitioning, unidirectional data diodes, and formally verified cross-realm protocols to ensure the confidentiality and integrity of model weights, algorithms, and inference data.

The report details a concept-to-circuit methodology, emphasizing minimal, purpose-built features and the use of formal methods for high-assurance components. While operational constraints—such as limited connectivity, fixed software, and restricted physical access—limit general applicability, SIDCs are recommended for national security, emergency response, and pilot deployments.

SIDCs can be implemented today using proven technologies. The authors recommend that stakeholders initiate detailed design and prototyping to accelerate deployment.

Key Takeaways

The SIDC strategy is designed to defend against highly capable nation-state adversaries

  • An SIDC built in accordance with the proposed security strategy can preserve the confidentiality and integrity of model weights, algorithms, and inference data over a five-year operational period.
  • The SIDC security strategy follows a concept-to-circuit approach: Security-critical design choices are derived from the strategic outcomes the system must prevent, rather than being added later as controls around general-purpose infrastructure.
  • This approach favors minimal, purpose-built features because excess capacity introduces unnecessary risk. For the most security-critical elements, the SIDC strategy requires high trustworthiness, including formal methods and other rigorous assurance techniques, to demonstrate that components satisfy their required security properties.

An SIDC can be implemented today using proven, off-the-shelf compute hardware

  • No fundamental research breakthroughs are required.
  • Estimated costs are $37 million to $50 million for a proof-of-concept facility and $277 million to $345 million for a larger, enterprise-scale version.
  • Construction and deployment activities can be completed rapidly, in as few as 14 months, under emergency or national priority conditions.

Recommendations

  • Identify an implementing entity and begin detailed engineering. An AI laboratory, cloud provider, U.S. government agency, or public-interest organization should step forward, engage a system integrator, and initiate detailed design.
  • Select a site early. Because major construction phases are largely sequential, early site selection is critical to minimizing the total project duration. For rapid deployment, housing the SIDC within an existing government facility can bypass or significantly shorten key development steps.
  • Prototype key security features and integration now. Critical security components, including formally verified protocols and unidirectional dataflows, can be tested on short timescales, independent of facility construction. Doing so is a low-cost opportunity to reduce technical risk and prevent downstream delays.

Topics

Document Details

Citation

Chicago Manual of Style

Comer, Steven F., Hunter Pavela, Varun Gandhi, Kyle Siler-Evans, Erich Devendorf, Ben Kelley, James Gimbi, Jair Aguirre, Gabriel Kulp, Mark Stalczynski, and Matthew J. Malone, Secure Inference Data Centers: A Vertically Integrated Strategy for Security Engineering. Santa Monica, CA: RAND Corporation, 2026. https://www.rand.org/pubs/research_reports/RRA4827-1.html.
BibTeX RIS

Research conducted by

This publication is part of the RAND research report series. Research reports present research findings and objective analysis that address the challenges facing the public and private sectors. All RAND research reports undergo rigorous peer review to ensure high standards for research quality and objectivity.

This document and trademark(s) contained herein are protected by law. This representation of RAND intellectual property is provided for noncommercial use only. Unauthorized posting of this publication online is prohibited; linking directly to this product page is encouraged. Permission is required from RAND to reproduce, or reuse in another form, any of its research documents for commercial purposes. For information on reprint and reuse permissions, please visit www.rand.org/pubs/permissions.

RAND is a nonprofit institution that helps improve policy and decisionmaking through research and analysis. RAND's publications do not necessarily reflect the opinions of its research clients and sponsors.