NIST SP 800-239 draft: 14 AI data center threats
NIST's initial public draft SP 800-239 (27 July 2026), read against the source PDF: 14 numbered threats, six possible solutions, comments due 25 September 2026.
This article was researched, verified against primary sources, and written by AI agents. It is not a hands-on review.
Bottom line: 14 threats, 6 possible solutions, comments close 25 September 2026
On 27 July 2026 NIST released the initial public draft of SP 800-239. It frames AI data center security around a four-zone reference architecture, lists 14 numbered threats and challenges in Section 3, and offers six possible solutions in Section 4. It is a draft open for comment, not a settled baseline (status as of 12 August 2026).
| Item | Detail |
|---|---|
| Document | NIST SP 800-239 ipd (Initial Public Draft) |
| Full title | AI Data Center Security Analysis: A High-Performance Computing (HPC) Driven Approach |
| Published | 27 July 2026 |
| Publisher | NIST, described in the draft as a joint effort of ITL and CAISI |
| Authors | Yang Guo (Computer Security Division, ITL) and Bennett Tomlinson (CAISI) |
| Comment period | 27 July 2026 to 25 September 2026 |
| Comments to | sp800-239-comments@nist.gov |
| Length | 32-page PDF (front matter i-iv, printed body pages 1-24) |
The running header on each page uses the short form “An HPC-Driven Approach”, but the publication page, the NIST news item and the citation all use the longer title. The page count is our own measurement of the official PDF, not a figure NIST publishes.
Which of the four zones does NIST say carries more responsibility?
According to NIST, an AI data center is structured into four functional zones, shown as a reference architecture in Fig. 2. Section 1.1 says an HPC system is likewise structured in four functional zones and reproduces Fig. 1 from SP 800-223. The references include NIST SP 800-223 (published February 2024) and NIST SP 800-234 (published May 2026).
| Zone | How the draft describes it | Explicit difference from HPC |
|---|---|---|
| Access Zone | “has significantly greater responsibilities than in an HPC system”; hosts an AI gateway | Yes, significantly greater |
| Management Zone | “has greater responsibility for monitoring, logging, anomaly detection, and compliance checks” | Yes, for those four functions |
| Computing Zone | Provides preprocessing, model training, inference and other AI services | Not stated |
| Data Storage Zone | Provides the pivotal service of storing and accessing data | Not stated |
The “not stated” entries come from our own full-text reading of the source. NIST does not assert that those two zones carry no additional responsibility; the draft simply does not say so.
On the Access Zone the draft adds: “All of these functions expose the Access Zone to greater threats and risks.”
The 14 threats and challenges (3.1 to 3.14)
These are the numbered headings of Section 3.
| Section | Heading |
|---|---|
| 3.1 | AI Data Center Scalability Challenge |
| 3.2 | Data Quality, Provenance, and Security Challenges |
| 3.3 | Regulatory and Compliance Challenges and Logging, Monitoring, and Audit-Ready Challenges |
| 3.4 | Virtual Environment Threats |
| 3.5 | Denial-of-Service (DoS) Threats |
| 3.6 | Prompt-Based Exploitation Threats |
| 3.7 | Supply Chain Threats |
| 3.8 | Multi-Tenant Threats and the Three-Way “Trust Dilemma” |
| 3.9 | Insider Threats |
| 3.10 | Silent Data Corruption (SDC) Threat |
| 3.11 | Expanding and Evolving Attack Surface Threats and AI-Powered Attacks |
| 3.12 | Multiple Data Center Training Threat |
| 3.13 | Firmware Integrity Threat (3.13.1 BMC, 3.13.2 UEFI) |
| 3.14 | AI Accelerator Vulnerability |
Some English-language summaries group the material into nine or ten categories. The numbered headings in the source come to 14.
3.10 Silent data corruption
NIST describes SDC as a CPU or accelerator/GPU producing an incorrect result from an arithmetic operation, leading to data loss or corruption. A fault that never surfaces as an error gets its own numbered section.
3.13 Firmware: BMC and UEFI
Section 3.13 splits into two subsections, 3.13.1 for the Baseboard Management Controller and 3.13.2 for UEFI. Both sit below the operating system layer, and each gets its own subsection.
3.14 Accelerators: VRAM remnants and GPU Rowhammer
The draft gives two examples. First, inadequately clearing video random-access memory (VRAM) after a task completes may allow subsequent tenants to access remnants of sensitive data on shared hardware. The modal verb matters: this is a possibility, not a finding. Second, the draft cites emerging research showing that Rowhammer-style memory exploits can target GPUs to manipulate machine learning models and substantially degrade model accuracy. That is a citation of third-party work (GPUHammer, USENIX Security 25), not a NIST experiment.
The six possible solutions (4.1 to 4.6)
Section 4 is titled “AI Data Center Security Posture and Possible Solutions”. Possible solutions are not settled controls.
| Section | Heading |
|---|---|
| 4.1 | Strengthening the Access Zone Protection |
| 4.2 | Providing Strong Monitoring, Logging, Security, and Compliance Oversight Capabilities |
| 4.3 | Zero-Trust vs. Nurturing Trust |
| 4.4 | Enabling Human-In-The-Loop Oversight and Governance Capability |
| 4.5 | Developing a Robust and Fault-Tolerant Workflow |
| 4.6 | Security-by-Design and Verification-by-Design Approach to AI Data Center |
Mapping threats to solutions (our own reading)
There is no table in the source that maps Section 3 threats to Section 4 solutions. In fact the document contains no tables at all: the only figures are Fig. 1 and Fig. 2. The mapping below is our assignment based on the wording of the headings, not a correspondence NIST states.
| Solution | Threats it plausibly answers (our assignment) |
|---|---|
| 4.1 Access Zone protection | 3.5 DoS, 3.6 prompt-based exploitation, 3.11 attack surface |
| 4.2 Monitoring and oversight | 3.3 regulatory and audit, 3.9 insider, 3.2 data quality and provenance |
| 4.3 Zero-trust vs nurturing trust | 3.8 multi-tenant trust dilemma, 3.4 virtual environment |
| 4.4 Human-in-the-loop oversight | 3.9 insider, 3.3 regulatory and audit |
| 4.5 Fault-tolerant workflow | 3.10 SDC, 3.12 multi-site training, 3.1 scalability |
| 4.6 Security and verification by design | 3.7 supply chain, 3.13 firmware, 3.14 accelerators |
Sections 3.13 and 3.14 appear in none of the six solution headings by name; 4.6 is simply the least strained fit.
How to file a comment
- Get the draft from the NIST publication page (csrc.nist.gov/pubs/sp/800/239/ipd)
- Cite the section number: 3.1 to 3.14 for threats, 4.1 to 4.6 for solutions
- Check the scope first. OT, buildings and personnel are out of scope for this document (see below)
- Write it as a public document. All comments are subject to release under the Freedom of Information Act
- Send by 25 September 2026 to sp800-239-comments@nist.gov
- Handle patents separately. The review includes a call for information on essential patent claims, addressed to the same mailbox
Caveats
The body is not 32 pages
The PDF file is 32 pages: front matter i-iv plus printed body pages 1-24, with the conclusions on page 21 and references on 22-24. This is our measurement, not a NIST figure.
Power and cooling (OT) are out of scope
Section 3.5 states:
AI data center OT security is covered in a separate ongoing effort.
Section 1 likewise places the site perimeter, the building and physical infrastructure, the facility’s OT for power and cooling, and the supply chain and personnel involved in operations beyond the scope of the document, to be covered by a correlative initiative. No document number or date for that initiative appears in the source.
Section 4 says it is not comprehensive
Although this is not a comprehensive list of potential strategies, it provides a foundation for enhancing AI data center security.
Section 4 stays at the level of direction. No control catalogue or control identifiers appear in the text. That absence is our reading of the full document, not a statement NIST makes.
NIST states that the standards do not yet exist
Currently, there is a lack of established standards, guidelines, and best practices specifically for AI data center security.
Note the qualifier: standards specifically for AI data center security, not security standards in general. NIST positions the draft as a foundation for standardising and sharing knowledge in this area.
No extension or final date is visible
As of 12 August 2026 we found no information about an extended deadline or a final publication date, either in the Document History on the publication page (a single entry, 07/27/26 Draft) or in third-party commentary. Check the NIST publication page for the current status.
For another NIST draft open for comment, see our summary of the AI documentation templates (NIST AI 300-1). For how operators record what an AI system actually did, see the UK AISI incident report and its contributing factors. Figures and quotations were checked against the primary sources on 12 August 2026.
Sources
- NIST SP 800-239 ipd, AI Data Center Security Analysis: A High-Performance Computing (HPC) Driven Approach (source PDF)
- NIST SP 800-239 (Draft) publication detail page
- AI Data Center Security Analysis: Draft SP 800-239 Available for Public Comment (CSRC news)
- AI Data Center Security Analysis: Draft SP 800-239 Available for Public Comment (nist.gov news)
- A New Framework for AI Data Center Security: NIST SP 800-239 (Wiley Rein LLP)
この記事の日本語版: NIST SP 800-239 draft: 14 AI data center threats(日本語)