For most of the cloud computing era, a data center was a commercial asset like any other — sited for power and tax incentives, financed like a warehouse. That premise no longer holds. Over the past eighteen months, the US government has moved across six distinct channels to treat AI compute infrastructure as a strategic resource it intends to actively manage, not leave to market forces. This analysis maps all six and verifies the numbers behind each.
The Six Channels
Export controls have become the fastest-moving lever in the entire policy landscape — reversing direction roughly eight times in seventeen months, from the Biden-era AI Diffusion Rule’s rescission through H20’s ban-then-approval cycle to H200’s conditional China waiver. Critically, licenses approved on paper haven’t translated into meaningful trade: as of mid-2026, actual H200 shipments to China remain what one Commerce official called “trivial,” after Beijing froze purchases pending its own security review.
Federal infrastructure policy shifted decisively with July 2025’s AI Action Plan and Executive Order 14318, which opened federal land — including military installations — to data center development above 100 MW, backed by new DOE, DOD, and Commerce financing tools.
Sovereign AI deals with the UAE (a 5 GW Abu Dhabi campus anchored by the 1 GW Stargate UAE cluster) and Saudi Arabia (Humain’s 6.6 GW target) now carry explicit security conditions — Chinese-partner divestment, mirrored US-based capacity — establishing a template likely to recur as more nations seek sovereign compute.
CFIUS has correspondingly tightened around foreign capital flowing into US data centers, sorting investors by nationality: Gulf capital fast-tracked with conditions, Chinese-linked capital facing a rising, increasingly automatic bar.
China’s parallel build-out — Huawei’s Ascend chip ramp, SMIC’s constrained advanced-node capacity, a reported $295B state computing-grid mandate — remains structurally behind US chips by an estimated 5x today, a gap analysts project could widen to 17x by 2027, though state-directed demand guarantees complicate that picture.
Critical-infrastructure classification remains undecided but is trending toward formalization: Congress held its first dedicated hearing on a standalone data center security sector in April 2026, while CISA’s “CI Fortify” guidance already assumes adversary access to grid systems during a crisis.
The Pentagon Factor
Threaded through all six is the Department of Defense’s emergence as a top-tier compute buyer in its own right — over $32 billion in AI, cloud, and cybersecurity commitments in just the first half of fiscal 2026, Scale AI’s CDAO contract growing fivefold in nine months, and a bipartisan bill now pushing back against vendor concentration risk.
The Takeaway for Decision-Makers
Five recommendations anchor the piece: treat power and policy positioning as board-level decisions on par with capital allocation; underwrite foreign capital against the bifurcated CFIUS regime before terms are set, not after; model chip-export volatility as a live scenario variable rather than a fixed assumption; separate confirmed capacity from announced targets in every diligence memo; and get ahead of critical-infrastructure compliance voluntarily rather than waiting for a mandate.
