Andy Blumenthal
Leadership With Heart

The AI Race Is Also a Race for Survivability

AI generated image

Building more powerful AI is only half the challenge. Israel must ensure essential capabilities keep working under attack—and recover when defenses fail.

The cloud is not in the sky. It has an address.

Behind every AI service is physical equipment that needs power, cooling, communications, and people able to keep it running. We talk constantly about what the model can do. We talk less about what happens when the systems behind it fail.

That is becoming a strategic question for Israel—not simply an engineering one.

We tend to forget infrastructure until something breaks. Then we remember it all at once.

Israel has already seen what interruption means

In June 2025, an Iranian attack significantly damaged the power station supplying steam and electricity to Bazan’s Haifa Bay refinery complex. Refinery operations shut down. Damage to a supporting system interrupted a much larger operation.

An Iranian missile also struck the Weizmann Institute of Science, damaging laboratories and destroying research materials.

These were not attacks on AI. They were reminders that sophisticated capability depends on physical assets—and that some losses cannot be reversed simply by restarting a computer.

Attacks on Amazon facilities in the Gulf brought the concern directly into cloud infrastructure. Facilities in the UAE were struck, while a facility in Bahrain suffered damage under less clear circumstances. Civilian cloud services were disrupted. Public information did not establish whether the affected facilities supported military operations.

The lesson does not require speculation about what was inside those buildings. An adversary may not need to defeat a model or destroy its processors. Disrupting the infrastructure that makes it accessible can be enough.

A powerful AI model running in a demonstration is a technological achievement. A capability that remains useful under attack is a strategic advantage.

Israel should pursue both.

Advancement and defense belong together

AI is entering services people depend on when time matters most. Sheba Medical Center is pursuing an “AI-powered hospital,” with tools assisting emergency-department documentation and clinical summaries. Magen David Adom has introduced AI supporting triage and ambulance dispatch.

This is promising. It does not establish that either institution lacks safeguards. But it makes a question immediate: when a helpful assistant becomes an essential capability, what happens when the system is unavailable—or cannot be trusted?

The answer is not to slow advancement. It is to build the capability and its defenses together.

The race for more powerful AI should not become a race toward dependence without defenses.

The financial commitment makes that argument harder to ignore. Brookings projects $10.3 trillion in American AI-related infrastructure investment between 2025 and 2032. That is a forecast, not money already spent, and it is not an estimate of Israeli investment.

Still, it frames a question both countries should answer: what good is a multitrillion-dollar investment in intelligence if we fail to protect the infrastructure that makes it usable?

The investment remains valuable. Its strategic value depends on whether essential capabilities can be sustained and restored.

Israel does not need to match America’s spending for that question to apply. The consequences of losing a capability matter more than the price of the hardware behind it.

What survives when defenses fail?

Three concepts should guide the buildout.

Defensibility reduces the chance of losing a capability. Survivability limits what is lost when defenses fail. Recovery determines how quickly it returns.

All three belong in the design—not added after the ribbon-cutting.

Start with relevant threats, honestly assessed. Data-center industry analysis identifies relatively inexpensive drones as a potential danger to supporting infrastructure. Coordinated attacks, including potential swarms, belong in risk assessments without being presumed unstoppable.

Other risks require different safeguards. The US Cybersecurity and Infrastructure Security Agency describes extreme electromagnetic incidents as low-probability, high-consequence events—not a guaranteed national off switch. The US National Institute of Standards and Technology recognizes model-backdoor attacks that cause incorrect behavior when a particular trigger appears. Neither establishes a vulnerability in any named Israeli deployment. Both reinforce the need to plan for loss of infrastructure and loss of trust.

The objective is not to predict one spectacular attack. It is to identify failures that could interrupt an essential function and demonstrate how that function continues.

Geographic dispersal can help, but distance is not proof of independence. The test is not whether the backup is far away. It is whether it remains usable under the conditions that disabled the first site.

Shared power, communications, providers, and access to data all need examination. More addresses do not automatically mean more resilience.

Dependence is not only physical. Boycott, Divestment and Sanctions—BDS—and related campaigns seek to pressure technology companies to end relationships with Israel, including cloud-service agreements. Political pressure is not a missile strike, and a campaign is not proof of a service cutoff. But it belongs in an assessment of provider dependence. Whether access is lost through political pressure, legal restrictions, or a contractual dispute, the continuity question remains: what essential function can Israel preserve without that provider?

Contractual protections matter. So do the ability to move data and workloads, access to alternative providers, and the time needed to make the switch. A building can remain standing while the capability becomes unavailable.

Nor does a written fallback establish capability. During the 2021 ransomware attack on Hillel Yaffe Medical Center, staff used alternative systems and pen-and-paper admissions. Urgent services continued, but delays and postponed procedures showed the cost of disruption.

A manual procedure nobody has practiced is a document, not a capability.

The question is not, “Do you have a backup?”

It is, “What capability have you demonstrated that you can preserve?”

A strategic standard for Israel

Israel already has foundations on which to build. Public-sector AI guidance addresses risk management, accountability, monitoring, and incident response. The Institute for National Security Studies has recommended mapping dependence on foreign AI models, developing alternatives, and establishing continuity mechanisms across government, the economy, and defense.

The next step is to establish what existing requirements demand and how compliance is demonstrated—not assume that safeguards are absent.

A time-bound assessment, conducted through the appropriate civilian and defense channels, should identify critical dependencies, applicable continuity standards, and any gaps requiring funded corrective action.

Where existing arrangements meet the standard, validate them. Where they do not, assign an accountable owner, fund the correction, and require a successful retest.

For critical systems, procurement and deployment decisions should answer three questions:

  • What must continue? Define the minimum acceptable capability, tolerable interruption, and recovery priority.
  • How does it continue? Demonstrate performance under specified failures, including infrastructure loss, unavailable providers, and unreliable output.
  • Who is accountable? Name an operator with the authority, personnel, equipment, training, and budget to make the plan work.

Hospitals and emergency dispatch can begin with controlled exercises that protect patients. Military systems require defense-led testing against relevant operational scenarios, with sensitive results protected.

Protection costs money. Testing takes time. Those burdens should match the stakes, not become blanket obstacles to innovation. Nor should reducing dependence mean trying to build everything alone. The goal is to keep partnerships from becoming irreplaceable points of failure.

A fallback need not reproduce normal performance. It must preserve the minimum that keeps people alive and essential operations functioning.

We should not lower our ambitions for AI. We should broaden what we mean by strength.

The race is not only to build more capable machines. It is to build capabilities that remain dependable under pressure—and can be restored when defenses fail.

For Israel and America alike, survivability is not an accessory to AI strategy. It is part of what capability means.

About the Author
Andy Blumenthal is a dynamic, award-winning leader who writes frequently about Jewish life, culture, and security. All opinions are his own.
Related Topics
Related Posts
Sign in or Register
Please use the following structure: example@domain.com
Or Continue with
By registering you agree to the terms and conditions
Register to continue
Or Continue with
Log in to continue
Sign in or Register
Or Continue with
check your email
Check your email
We sent an email to you at .
It has a link that will sign you in.