
OWASP framework cataloging the top 10 security risks in neocloud and AI data center infrastructure, covering hardware, networking, isolation, management planes, and supply chain.

FORGE - Harden the metal beneath the model.
🌐 Website: https://forge-framework.io
Neoclouds and AI data centers are being built faster than they are being secured.
The rapid expansion of neoclouds (GPU cloud providers), AI data centers, and specialized compute environments has introduced security risks across hardware, networking, storage, orchestration, identity, management planes, and physical operations. Many of these risks resemble traditional data center or cloud security issues, but neoclouds and AI data centers change their severity: systems originally designed for trusted operators are now supporting high-value, multi-tenant workloads from unrelated customers.
The Top 10 Neocloud and AI Data Center Security Risks provides a practical framework for identifying, prioritizing, and reducing the most important security risks in the infrastructure layer that powers AI. The framework defines the most critical failure modes in AI infrastructure and helps translate them into concrete security requirements.
This framework focuses on the security of AI infrastructure and the data centers that house it: the physical hardware, networking fabrics, management planes, orchestration systems, storage systems, and operational environments on which AI workloads run.
It does not focus on AI models themselves or application-layer risks such as prompt injection, insecure agent behavior, model abuse, or model-level evaluation. Those risks are addressed by frameworks focused on other parts of the AI stack, including the OWASP Top 10 for LLM Applications, MITRE ATLAS, the NIST AI Risk Management Framework, and ISO/IEC 42001. Together, these resources give practitioners a more complete picture of AI security, from governance and application-layer risks down to the underlying compute infrastructure.
Some risks in this document also exist in traditional data center and cloud environments. They are included here because AI infrastructure makes them materially more severe: shared high-value compute, complex accelerator clusters, dense management layers, and multi-tenant operations can turn ordinary infrastructure weaknesses into more severe security risks because the likelihood and impact of any incident are much higher than in traditional enterprise-level software and service deployments.
Neocloud providers and data center operators can benefit from the framework as a practical guide to the AI infrastructure threat landscape, attack surface review, environment hardening, security prioritization, and maturity demonstration.
Neocloud customers can benefit from the framework as a practical guide for procurement, security reviews, contractual requirements, provider comparison, and assessing resilience against realistic tenant-to-infrastructure compromise.
Hybrid Cloud security teams can benefit from this framework as a practical guide for configuring, maintaining, and securing their on-premise footprint against modern attacks, which can quickly pivot between environments.
Built to evolve with the field, and kept open so the whole AI and security community can use it, challenge it, and improve it.
We would like to thank and acknowledge all experts which took part in reviewing and validating this document.
Have feedback or want to contribute? [email protected]
FORGE domains define the evaluation lens: the infrastructure areas where AI security risk lives. The Risk Matrix below maps individual risks into these domains.
| Domain | Name | Description |
|---|---|---|
| F | Fleet integrity | Trust in the hardware, firmware, software artifacts, images, dependencies, and supply paths that make up the AI infrastructure fleet. |
| O | Operations & management planes | Privileged systems used to control, automate, and administer AI infrastructure, including BMCs, schedulers, orchestration, automation, and admin tooling. |
| R | Resource isolation | The boundaries that separate tenants, workloads, execution environments, and reused infrastructure across shared AI systems. |
| G | Grid | The networking fabrics and facility systems that connect AI clusters and keep them powered, cooled, and operational. |
| E | Evidence & exposure management | The evidence customers need to understand provider security maturity, architectural scope, exposed services, and patch velocity. |
FORGE IDs are ordered by severity, from highest to lowest. The matrix groups each risk by domain and shows its likelihood, impact, and detection difficulty.