Published on: July 21, 2026
On March 1, 2026, Iranian drones struck Amazon Web Services (AWS) facilities in Bahrain and the United Arab Emirates. Days earlier, a separate strike had already hit AWS infrastructure in Bahrain. It was the first time in history that a military attack had directly disrupted the cloud operations of a major American technology company. Banking apps, payment systems and enterprise software across the region went dark as Amazon scrambled to reroute its workloads elsewhere.
Weeks later, at a Future Investment Initiative summit in Miami, US presidential envoy Steve Witkoff put the moment into plain words: the Gulf now carries a “risk premium” from the threat of its data centers “being blown up.”
Why this matters
Artificial intelligence has become the twenty-first century’s version of a strategic resource, much like oil was in the twentieth. Whoever builds and controls the physical backbone of AI, the chips, the servers, the electricity and the cables that connect them, gains real economic and political power. Today, that backbone is dominated by two countries. The United States leads through companies like Nvidia, which designs the most advanced AI chips, and through Microsoft, Google, Amazon and Oracle, which run most of the world’s large data centers. China is the main challenger, building its own chips through Huawei and its own AI models, such as DeepSeek’s latest releases. Almost every other country, for now, is simply a customer of one system or the other.
The Gulf states want to change that. The United Arab Emirates, Saudi Arabia and Qatar are trying to become more than customers. They want to be hosts, and eventually owners, of a meaningful share of the world’s technology infrastructure. The Israel-Iran war of 2026 has turned that ambition into an unplanned, live experiment. It is testing the physical strength of Gulf technology infrastructure, the cyber and information defenses built around it, and a harder question underneath both: how much genuine independence, or sovereignty, the Gulf actually has in a system still built mostly on American and Chinese foundations.
The scale of the ambition
The numbers involved are hard to overstate. The UAE alone has invested $148 billion in artificial intelligence, at home and abroad, since the start of 2024. Its flagship Stargate UAE project is planned to reach 5 gigawatts of capacity, enough to power a small country. Saudi Arabia’s Data and AI Authority, known as SDAIA, is building a parallel national push through its HUMAIN initiative. Together, the UAE, Saudi Arabia and Qatar are planning an estimated 8 to 10 gigawatts of AI-related infrastructure capacity, according to the Middle East Institute. Geography helps this plan along: the Gulf sits at what MEI analyst Mohammed Soliman calls “the latency sweet spot” between Europe, South Asia and East Africa, a location that matters more each year as AI systems shift from slow, offline training toward instant, real-time use.
Gulf sovereign wealth funds, which together manage close to $6 trillion, deployed an estimated $66 billion into AI and digital projects last year alone, more than any other group of investors in the world. The Public Investment Fund’s $10 billion partnership with Google Cloud and the Qatar Investment Authority’s $20 billion infrastructure deal with Brookfield are not simple financial bets. They are, in the words of Nvidia chief executive Jensen Huang, layers of a “five-layer cake” that spans energy, technology infrastructure, cloud platforms, AI models and applications. Gulf states are trying to build the whole cake themselves, not just one slice of it.
Abu Dhabi shows this logic most clearly. Instead of treating energy, AI and shipping as separate industries, the Emirate is fusing them into one connected system. State oil company ADNOC’s revenue helps finance the abundant, reliable electricity that AI data centers need. Abu Dhabi Ports and the technology firm G42 extend that same platform into smart logistics and government-run cloud services. The goal is a new kind of economy: one that earns money not from oil beneath the ground, but from the electricity and computing power built above it. The UAE’s National Strategy for Artificial Intelligence 2031 puts a number on this ambition, targeting AED 335 billion (about $91 billion) in AI-driven economic growth, while Saudi Arabia pursues similar goals under its Vision 2030 plan.
A war tests the plan
The war did not wait for this infrastructure to finish growing before testing it. Three separate weaknesses showed up almost at once.
The first was physical. Of the 233 data centers operating across the Gulf, only three were affected by the March strikes. Workloads were rerouted, and Amazon’s teams worked around the clock to keep services running. Still, the strikes set a troubling precedent. Microsoft’s president has since called for new international rules to protect civilian data centers, similar to the legal protections already given to hospitals and other civilian sites during wartime. Sam Winter-Levy, a fellow at the Carnegie Endowment for International Peace, warned that such attacks “are only going to become more common moving forward as AI becomes more and more significant.”
The second weakness was cyber, and it moved at a speed shaped by AI itself. According to Help AG, the cybersecurity arm of UAE telecom operator e&, daily cyberattack attempts against the UAE jumped from around 200,000 to as many as 700,000 as tensions rose. AI-enabled attackers cut the average time needed to complete an attack by 65% in early 2026, with some causing damage within 40 hours of first breaking in. The UAE’s financial sector absorbed a wave of sophisticated attacks in early July that were successfully stopped, but the country’s Cyber Security Council admitted that criminals are using AI to invent new techniques faster than defenders can track them. The costs are real: a data breach in the Middle East now costs $7.29 million on average, well above the global figure of $4.44 million, according to IBM.
The third weakness was cognitive: the manipulation of what people believe. Fake AI-generated video appeared to show a burning building in Bahrain. A deepfake showed the USS Abraham Lincoln sinking after an Iranian strike, which never happened. Another falsely showed Chinese military trucks resupplying Iran. All circulated widely during the war, helped along by cheap, fast AI video tools and by patchy content moderation for Arabic-language material on major platforms. This kind of interference is not new to the region. A decade earlier, the Stuxnet cyberattack on Iran’s nuclear program (2010) and Iran’s 2020 cyberattack on Israeli water systems already showed that conflicts between rivals spill over onto neighboring states, whether those states want it or not. What is new in 2026 is the speed: AI has made this kind of manipulation dramatically cheaper and faster to produce.
Deep pockets, real gaps
Gulf capital treated the war as a pricing problem, not a reason to retreat. One week after the AWS strikes, Brookfield confirmed its $20 billion partnership with the Qatar Investment Authority would go ahead as planned. The UAE government said there was “no change” to its investment priorities. PIF governor Yasir al-Rumayyan summed up the thinking at the Miami summit: “We measure our returns not in quarters, but in decades.” Gulf sovereign funds are built to hold onto long-term projects through short-term shocks in a way that ordinary private investors usually are not, and Gulf air-defense systems, which intercepted roughly three times the missile and drone volume aimed at Israel over the same period, gave data centers the same protection as energy sites.
That response is not wrong, but it leaves two real gaps unaddressed.
The first is insurance. As researcher Elizabeth Heyes of the Observer Research Foundation Middle East has written, cyber-insurance coverage in the Gulf remains far below levels seen in the US and UK, and many existing policies exclude or limit coverage for acts of war or state-sponsored attacks, exactly the categories this war has produced. Cybersecurity spending across the Gulf Cooperation Council (GCC) is projected to more than triple by 2032, but insurance has not kept pace. Sovereign wealth funds can absorb a shock on their own balance sheets. It is a separate question whether smaller companies and everyday investors can do the same.
The second gap is dependency. Despite talk of “sovereign AI,” Gulf technology infrastructure still relies heavily on outside suppliers, according to the International Institute for Strategic Studies. Chip export approvals, cloud platforms built by Microsoft, Google and Oracle, and increasingly Chinese alternatives from firms like Huawei all sit outside full Gulf control. This creates a form of leverage that scholars call weaponized interdependence: whoever controls a resource that everyone else needs, in this case advanced chips and cloud platforms, can grant or withhold access as a tool of pressure. Soliman’s research at MEI names this dynamic directly from the American side, describing a “technology-for-alignment” bargain in which Washington welcomes Gulf AI growth partly because it keeps Gulf states anchored to American systems rather than Chinese ones. This is also where a live geopolitical debate sits. Some analysts see deepening US influence over the Gulf through this arrangement. Others argue the Gulf is gaining real leverage of its own, positioning itself as a swing player that Washington and Beijing must both compete to keep close. Gulf sovereignty, in other words, is genuine at the level of money and land, but only partial at the level of the underlying technology.
The gap nobody photographs
A quieter, less visible issue than missiles or malware is workforce readiness: whether the people and institutions needed to run this infrastructure are actually in place. Academic research applying workforce-readiness measures to national AI strategies across the GCC found real but uneven progress. Saudi Arabia scored highest on institutional readiness, the UAE close behind, with Oman and Kuwait trailing. The same research compared two competing training models in the region: the UAE’s Mohamed bin Zayed University of Artificial Intelligence, which trains a small, highly specialized group of AI researchers, against Saudi Arabia’s SDAIA Academy, which trains large numbers of workers in practical AI skills. Neither approach alone closes the gap. Researchers argue the GCC needs new bridges between the two, such as a shared “AI skills passport” and small grants to help smaller businesses adopt AI safely.
This matters directly for the lessons of the war. A data center that survives a drone strike still needs a cybersecurity team able to work at the same speed as AI-powered attackers. It also needs a public and a civil service able to recognize AI-generated disinformation before it shapes real decisions during the next crisis. Surviving a physical attack and being institutionally ready are two different tests, and the Gulf has so far passed the first one far more convincingly than the second.
What the Gulf could learn from Europe
There are useful examples elsewhere. The European Union’s Action Plan on Cable Security, adopted in February 2025 after a string of incidents in the Baltic Sea, lays out a clear cycle for protecting critical infrastructure: prevention, detection, response and deterrence. That model applies directly to the Gulf, where the Strait of Hormuz, the Bab el-Mandeb and the Red Sea already function as chokepoints for data as much as for oil. Submarine cables carry 99% of the world’s intercontinental internet traffic, and a single 2024 incident in the Red Sea disrupted roughly a quarter of all data traffic between Europe and Asia. The EU-GCC Strategic Partnership, agreed at the two blocs’ first summit in October 2024, already lists digital cooperation as a shared priority. That gives both sides an existing forum to build on, rather than starting from scratch.
The bigger picture
None of this means the Gulf’s AI strategy was a mistake. If anything, the war has proven the underlying financial logic: patient, state-backed money was willing to hold firm through direct military strikes in a way ordinary private investors likely would not have been. But the war has also exposed a real gap between two kinds of strength the region has built at very different speeds. The physical and financial side, protected capital, backup sites, strong air defense, is maturing quickly, helped along by the same oil wealth that AI is eventually meant to replace. The human and institutional side, honest war-risk insurance, a cybersecurity workforce that can outpace AI-driven attackers, information systems resistant to deepfakes, and less dependence on any single foreign supplier, is moving more slowly. Al-Rumayyan’s decade-long outlook may prove exactly right for the concrete and the chips. Whether Gulf institutions can build the human and regulatory side to match, on that same timeline, is the quieter test that is still underway, and it may ultimately matter more than the one already passed.
This article was edited using data and reporting from the following sources: Reuters, Data Centre Magazine, Semafor, Middle East Institute, OilPrice.com, UAE National Strategy for Artificial Intelligence 2031, Saudi Data and AI Authority (SDAIA), Fortune, Middle East Council on Global Affairs, International Institute for Strategic Studies, Observer Research Foundation Middle East, European Commission, and the academic studies Albous, Stephens & Al-Jayyousi (2025, Humanities and Social Sciences Communications), Haroon (2024, Journal of Politics and International Studies), and Azar & Haddad, eds. (2021, Palgrave Macmillan).
Disclaimer. The views and opinions expressed in this analysis are those of the author and do not necessarily reflect the official policy or position of MEPEI. Any content provided by our author is of her opinion and is not intended to malign any religion, ethnic group, club, organization, company, individual, or anyone or anything.
About the author:

Mr. Rafael MARCOU is a Research Intern at the Middle East Political and Economic Institute (MEPEI). He holds a Bachelor’s degree in European Studies from the University of Amsterdam, where he majored in European Politics and wrote his thesis on U.S. partnerships with Kurdish armed groups in the Syrian and Iranian cases. He also studied Political Science and International Relations at Boğaziçi University in Istanbul. He is currently pursuing a Master’s degree in International Relations, Security and Development at the Universitat Autònoma de Barcelona. His research interests include Middle Eastern geopolitics, EU–Middle East relations, security, and Kurdish affairs.

