When Compute Becomes a Target: The Gulf Data Center Strikes and the Sovereignty Question Africa Cannot Ignore
- Oludare Ogunlana
- 1 day ago
- 4 min read

At least five data centers in the Gulf have been attacked during the ongoing war between Iran and the United States, including two Iranian strikes on the Amazon Web Services facility in Bahrain, first on April 30 and again on July 21. For the first time in modern conflict, hyperscale cloud and AI infrastructure has been treated as a legitimate military target. The lesson for African governments is direct: any state that hosts foreign-linked compute infrastructure without negotiating sovereignty protections, consultation rights, and dual-use transparency is importing strategic risk it does not control. Nigeria and its peers should treat this as a governance problem first and an investment opportunity second.
What Happened
The escalation followed a clear sequence. In early March, Iranian drones struck three AWS data centers, two in the United Arab Emirates and one in Bahrain. The strikes disrupted banking, payments, and enterprise software across the region, and AWS advised clients to migrate workloads out of the Middle East region entirely.
On March 31, the Islamic Revolutionary Guard Corps declared 18 American technology companies operating in the Gulf to be legitimate targets, naming Microsoft, Google, Apple, Meta, and Oracle among them, on the grounds that their infrastructure supports American intelligence, communications, and artificial intelligence operations. Iranian statements later characterized the Bahrain facility hosting the AWS me-south-1 cloud region as a digital eye for United States Central Command.
The April 30 strike on the Bahrain facility produced a sustained regional service disruption that satellite imagery confirms involved extensive physical damage. The July 21 follow-on strike on the same facility demonstrated that this is a deliberate campaign, not an isolated escalation. American strikes on Iranian-linked facilities have added to the count, bringing the total to at least five data centers attacked during the war.
Why the Targets Were Chosen
The Gulf states spent the past decade positioning themselves as the world's post-oil compute hub. The buildout exceeded 300 billion dollars, anchored by Microsoft's 15.2 billion-dollar commitment in the UAE, more than 5.3 billion dollars from AWS in Saudi Arabia, Oracle's 1.5 billion-dollar cloud expansion, and the first international deployment of the Stargate project in Abu Dhabi. Washington encouraged this concentration through what analysts call compute diplomacy, formalized in the January 2026 Pax Silica framework that brought the UAE and Qatar into a United States-led effort to keep advanced semiconductors away from China.
That architecture created the vulnerability. The facilities host civilian banking, government services, and enterprise workloads, as well as those Iran asserts serve American military and intelligence functions. Dual use made them targetable in Tehran's calculus. And because Gulf states aligned exclusively with American providers and excluded Chinese alternatives under Washington's conditions, they eliminated the diversification that might have hedged their exposure. Iran did not strike Chinese facilities in the region. It struck the American ones.
Most consequentially, reporting indicates the Gulf hosts were not consulted before the American military operation that triggered the war began. Their territory became an active war zone, and their flagship economic diversification assets became targets, through decisions made in other capitals.
The Lesson for Africa
African governments are now negotiating their own data center and AI infrastructure deals with the same hyperscalers, often from a weaker bargaining position than the Gulf states held. Nigeria, Kenya, South Africa, and Egypt are all courting hyperscale investment. The Gulf experience should reshape how those negotiations are conducted.
First, sovereignty must be contractual, not assumed. Host governments should require disclosure of whether facilities on their soil will carry defense or intelligence workloads for any foreign power, and should retain the right to refuse such workloads. A data center that quietly serves a foreign military converts the host nation into a belligerent without its consent.
Second, consultation rights matter. Hosting agreements should include binding commitments that the host state will be consulted before its territory is implicated in military operations connected to the infrastructure it hosts. The Gulf states learned the cost of omitting this provision.
Third, diversification is a security strategy, not merely a procurement preference. Exclusive alignment with a single foreign technology ecosystem concentrates risk. African states should preserve multi-vendor and multi-national options in their compute architecture, including sovereign and regional capacity, so that no single geopolitical rupture can take national payment systems, government services, and financial infrastructure offline.
Fourth, critical national workloads need domestic redundancy. When the Bahrain facility went down, banking and payments across the region failed. Any African state migrating government and financial services to foreign-operated regional cloud infrastructure should mandate in-country failover for essential services as a condition of licensing.
The Governance Question
The deeper issue is that AI infrastructure has now crossed the threshold from economic asset to military objective, and international law has not caught up. There is no settled framework governing when a civilian cloud facility becomes a lawful target, what transparency hosts are owed about dual-use workloads, or how neutral states protect themselves from wars fought partly on their servers.
African states have an opportunity the Gulf states no longer have: to build these protections in before the concrete is poured. The African Union, national assemblies, and regulators such as Nigeria's NITDA should move now to establish hosting standards that address dual-use disclosure, consultation rights, redundancy mandates, and neutrality protections. Sovereignty in the AI era will not be defended at the border. It will be defended in the hosting agreement.
Dr. Sunday Oludare Ogunlana is Founder and CEO of OGUN Security Research and Strategic Consulting LLC, a Texas licensed intelligence and security firm. He writes on homeland security policy, AI governance, and African security architecture.
