Introduction: The Small Component Inside the Giant AI Factory

In early August 2026, the next chapter of the U.S.–China artificial-intelligence conflict appeared in an unlikely place. It was not another Nvidia GPU, another semiconductor fabrication plant, another frontier model, or another billion-dollar AI investment. It was an optical transceiver: a comparatively small piece of equipment, often no larger than a thumb drive, that turns electrical signals into light and allows enormous quantities of data to move between servers, switches, and computing racks at nearly the speed of light.

On August 4, 2026, Reuters reported that the Trump administration was preparing restrictions on imports of new Chinese datacenter components, with optical transceivers at the center of the proposed action.[1] The effort was being developed through the Federal Communications Commission and reflected concerns that Chinese equipment embedded inside rapidly expanding American AI infrastructure could create espionage, malware, remote-disruption, or supply-chain risks. The most exposed company was Zhongji Innolight, which industry analysts at Counterpoint Research estimate holds approximately 27 percent of the global datacenter optical-transceiver market, with fellow Chinese supplier Eoptolink joining it to control roughly 60 percent of the high-bandwidth 800-gigabit segment on which modern AI clusters depend.[2] Innolight is a company that, by most estimates, earns about 90 percent of its revenue outside China, much of it from the very American hyperscalers and AI-chip designers now debating whether its products constitute a national-security risk.[4] Financial markets grasped the significance immediately: on the day of the Reuters report, shares of American optical suppliers Lumentum and Coherent surged, Applied Optoelectronics jumped 18 percent, and Innolight fell as much as 14 percent in Shenzhen trading before paring losses.[3]

That small component exposes a much larger problem.

For much of the past several years, policymakers have discussed artificial-intelligence infrastructure as though the geopolitical contest could be reduced to one question: Who controls the GPUs?

The United States restricted exports of advanced accelerators. Nvidia and AMD redesigned products around regulatory thresholds. Chinese companies searched for alternative supplies and domestic accelerators. Washington tightened semiconductor-manufacturing restrictions. Beijing accelerated Huawei and domestic chip programs. Smuggling networks, intermediary jurisdictions, licensing systems, HBM supplies, semiconductor equipment, advanced packaging, and foundry access became part of the contest. Economic historian Chris Miller of the Fletcher School at Tufts University captured the intellectual spirit of that era in a single sentence:

“You can’t understand the modern world without putting chips at the center of the story.”

— Chris Miller, Professor, The Fletcher School, Tufts University [31]

All of those issues remain important. The chip is still the beating heart of the intelligence economy.

But the AI factory has changed.

A modern AI system is no longer adequately described as a collection of GPUs installed inside an ordinary datacenter. Nvidia’s Vera Rubin architecture illustrates the transition. Vera Rubin is designed as a collection of purpose-built rack-scale systems containing CPUs, GPUs, networking, DPUs, storage infrastructure, optical connectivity, power systems, cooling systems, security technologies, and software that must function together. At its GTC Taipei announcement in May 2026, Nvidia said its Vera Rubin ecosystem involves hundreds of supply-chain partners, more than 350 factories across approximately 30 countries, and 150 supply-chain partners in Taiwan alone, delivering what the company describes as its most extensive POD-scale platform: five purpose-built racks operating as one massive AI supercomputer for agentic workloads.[10] Jensen Huang, Nvidia’s founder and chief executive, framed the platform in explicitly systemic terms at GTC 2026:

“Vera Rubin is a generational leap — seven breakthrough chips, five racks, one giant supercomputer — built to power every phase of AI.”

— Jensen Huang, Founder and CEO, NVIDIA [11]

The strategic unit is therefore changing.

The chip remains essential, but the rack is becoming the smallest useful industrial unit for understanding modern AI power.

I chose the title “Rack Sovereignty” for precisely this reason.

“Sovereignty” has become common language in artificial intelligence. Governments speak about sovereign AI, sovereign cloud infrastructure, sovereign models, national compute capacity, domestic semiconductor manufacturing, data localization, and technological independence. Yet many of those discussions remain strangely abstract. A government may describe an AI model as sovereign because it is trained domestically or operated on national territory, while the physical machinery underneath that model remains dependent on components, firmware, materials, manufacturing capacity, and suppliers distributed across potentially adversarial jurisdictions.

Rack Sovereignty asks a harder question.

A country may own the land underneath a datacenter. It may own the electricity contracts. It may operate Nvidia GPUs. It may train a domestic model. It may possess the model weights. But can it authenticate the optical modules connecting those GPUs? Can it replace the power electronics? Does it know who wrote the firmware controlling the equipment? Can it obtain spare cooling pumps during a geopolitical crisis? Who owns the manufacturer of the network device? Where are its components fabricated? Does the equipment contain remotely updateable software? Where does its telemetry travel? Can the system be repaired without components originating in a strategic competitor?

If the answers are uncertain, sovereignty is incomplete.

That is why Rack Sovereignty fits this paper better than semiconductor sovereignty, compute sovereignty, infrastructure sovereignty, or another variation of technological nationalism. The rack sits at the physical intersection of the first three layers of what I have described as the Five-Layer AI Economy: Energy, Chips, Datacenters, Models, and Applications/Agents. Electricity arrives from Layer 1. Semiconductor intelligence arrives from Layer 2. The rack transforms them into the operational computing infrastructure of Layer 3. Models in Layer 4 and agents in Layer 5 cannot function at scale without that physical machine.

The rack is where electrons become compute and compute becomes intelligence.

This paper therefore makes a larger argument: the U.S.–China technology conflict is entering a stage in which governments will increasingly care not merely about the most advanced semiconductor inside an AI factory but about the provenance, security, replaceability, interoperability, ownership, firmware, and geopolitical reliability of the entire physical system surrounding it.

The evidence is already accumulating, and its sequencing across 2025 and 2026 is remarkable.

In December 2025, the FCC updated its Covered List to include foreign unmanned aircraft systems and their critical components. In March 2026, the FCC added foreign-produced consumer-grade routers to its Covered List following a National Security Determination by a White House-convened interagency body, which concluded that such routers “pose unacceptable risks to the national security of the United States or the safety and security of United States persons.”[5] The restriction applies to new models, with a conditional-approval process available through the Department of War or the Department of Homeland Security, and the determination cited both cybersecurity and supply-chain concerns; notably, the entry covers routers produced in any foreign country, with a production test under which manufacturing, assembly, design, or development in a foreign country can trigger coverage.[6][37]

By June 2026, the administration was developing restrictions targeting foreign-made connected energy inverters, particularly Chinese equipment, because inverters connecting solar generation and batteries to electricity systems were increasingly being treated as potential critical-infrastructure vulnerabilities. On July 28, 2026, the FCC formally updated its Covered List to include two new categories — “advanced robotic devices,” defined as mobile robots such as humanoids and quadrupeds, and, separately, connected power inverters produced in foreign countries — following national security determinations by executive-branch agencies.[7] The policy brought physical AI and electricity-control devices into the same national-security perimeter previously associated more closely with telecommunications equipment.[9] FCC Chairman Brendan Carr framed the action in supply-chain terms:

“Following President Trump’s leadership, the FCC will continue to do our part to secure America’s critical supply chains and, with today’s action, the FCC is acting in lock step with our national security agencies to do just that.”

— Brendan Carr, Chairman, Federal Communications Commission [8]

Then came optical transceivers.

Seen separately, these actions can look like unrelated trade restrictions.

Seen together, they reveal something more significant:

Drone → router → inverter → robot → optical transceiver → datacenter.

The security perimeter is moving inward, toward the machinery that produces artificial intelligence.


DateActionInstrumentCoverage
December 2025Foreign UAS (drones) and critical components added to Covered ListFCC Covered List / National Security DeterminationNew foreign-made drone models
March 23, 2026Foreign-produced consumer-grade routers added to Covered ListFCC Covered List / NSD of March 20, 2026All new consumer router models produced abroad, subject to DoW/DHS Conditional Approval
June 2026Restrictions in development on foreign connected energy invertersInteragency review (reported)Chinese-made grid-connected inverters
July 28, 2026Advanced robotic devices and connected power inverters added to Covered ListFCC Covered List / dual NSDsNew foreign humanoid, quadruped, and mobile robots over 4.4 lbs with ≥200 kbps connectivity; connected inverters
July 30, 2026Presidential Determination on recoverable critical minerals and materialsDefense Production Act §101Black mass, end-of-life rare-earth magnets, swarf, critical-mineral scrap
August 4, 2026Draft restriction on new Chinese optical transceivers revealedFCC (draft rule, reported by Reuters)New Chinese-made transceiver models for datacenters

Table 1. The expanding U.S. import-security perimeter, December 2025 – August 2026. Sources: FCC public notices and fact sheets; White House presidential actions; Reuters reporting.[1][5][7][20]


At almost the same moment, Nvidia is pushing in the opposite direction technologically: integrating more components into a unified rack-scale architecture. Its Vera Rubin platform connects specialized computing, storage, networking, photonics, and infrastructure into what Nvidia describes as an AI factory platform. Spectrum-X Ethernet Photonics — now in production — combines co-packaged optics with Spectrum-X switching and is intended to support networks stretching eventually toward million-GPU systems.[10]

Government security policy is broadening just as AI hardware architecture is integrating.

That convergence is the foundation of Rack Sovereignty.

A useful starting formulation is:

Rack Sovereignty = Provenance × Integrity × Replaceability × Connectivity Control × Energy Control × Lifecycle Control

The multiplication matters. These are not independent advantages that can simply be added together. Extreme weakness in one component can undermine the value of the others.

A country with secure GPUs but compromised networking does not possess complete sovereignty. A country with secure networking but irreplaceable foreign power electronics does not possess complete sovereignty. A country with domestically assembled servers but opaque firmware does not possess complete sovereignty. A country with trusted hardware but no replacement inventory during a geopolitical rupture does not possess complete sovereignty. And a country that controls its models while depending upon an adversarial industrial ecosystem to power, connect, cool, and repair those models possesses something closer to conditional sovereignty.

The central question of the AI infrastructure contest is therefore evolving.

The old question was: Who has the chips?

The emerging question is: Who can keep the rack operating when the supply chain, the power system, the network, or the geopolitical relationship breaks?

That is Rack Sovereignty. The remainder of this paper develops the concept in six movements. Section 1 traces the transition from chip war to rack war. Section 2 dissects the physical anatomy of the sovereign rack — compute, memory, networking, optics, power, cooling, and firmware. Section 3 proposes the Sovereign Rack Bill of Materials as a practical analytical instrument. Section 4 examines how corporate procurement is becoming national AI policy, from the FCC and NIST to hyperscaler boardrooms and state capitols. Section 5 analyzes the emergence of two competing physical AI systems and the alliance architecture of Pax Silica. Section 6 distills the lessons into six pillars, before the conclusion returns to the question that animates the entire inquiry: who controls everything that makes the GPU work?


Section 1: From Chip War to Rack War


1.1 The GPU Was the First Chokepoint, Not the Last

The extraordinary rise of generative AI made the advanced accelerator one of the world’s most strategically important manufactured products. Nvidia GPUs became simultaneously commercial products, industrial inputs, geopolitical bargaining instruments, objects of export regulation, and measures of national AI capacity. The financial numbers alone justify the obsession. Nvidia closed its fiscal year 2026 in January with $215.9 billion in revenue, up 65 percent from the prior year, including a record fourth quarter of $68.1 billion in which data-center revenue reached $62.3 billion.[26] One quarter later, in results reported in late May 2026, the company posted $81.6 billion in quarterly revenue — the largest single quarter any technology company has ever recorded — with data-center revenue of $75.2 billion, up 92 percent year over year, and a market capitalization hovering near $5 trillion.[27] The demand side is equally staggering: following second-quarter 2026 earnings, the four largest hyperscalers — Microsoft, Alphabet, Amazon, and Meta — were collectively guiding toward roughly $725 to $760 billion in 2026 capital expenditure, up more than 75 percent from approximately $410 billion in 2025, with Goldman Sachs projecting a baseline of $7.6 trillion in aggregate capex between 2026 and 2031 across compute, datacenters, and power.[28][29]

That emphasis on the accelerator was understandable.

Without accelerators, the largest contemporary models cannot be trained economically. Without large quantities of accelerators, inference capacity cannot grow with billions of queries, increasingly complicated reasoning chains, multimodal workloads, autonomous agents, and physical AI.

Yet successful technological systems are rarely determined by one component alone.

A commercial airliner cannot operate because a country owns jet engines but lacks avionics, replacement parts, navigation systems, maintenance certification, or fuel infrastructure. A nuclear plant is not sovereign merely because its reactor vessel sits domestically if fuel-cycle services, control equipment, pumps, replacement components, or technical expertise depend upon an adversary.

An AI factory follows the same logic.

The GPU was simply the first component important enough for governments to notice.

The transition toward rack-scale architecture now exposes dependencies that previously hid behind the accelerator. Nvidia’s Vera Rubin platform brings Vera CPUs, Rubin GPUs, NVLink 6 switching, ConnectX-9 SuperNICs, BlueField-4 DPUs, Spectrum-6 Ethernet, integrated Groq 3 LPUs, storage infrastructure, security features, and other systems into a tightly coordinated architecture — seven new chips in full production, designed to operate together across five purpose-built rack classes as one AI supercomputer rather than independent servers performing isolated tasks.[11] The Vera Rubin NVL72 rack alone integrates 72 Rubin GPUs and 36 Vera CPUs in a liquid-cooled system connected over NVLink 6, and Nvidia claims the platform delivers roughly ten times the agent throughput at scale of the previous Grace Blackwell generation.[10]

This changes the economics of strategic dependence.

When AI computing consisted of relatively independent servers, failure or unavailability of one peripheral component might have produced inconvenience. At rack and pod scale, high-performance computing increasingly depends upon system synchronization. Networking performance affects GPU utilization. Power architecture affects rack density. Cooling determines available computational output. Optics determine how quickly information travels across the cluster. Firmware determines whether equipment can be trusted and maintained. Software defines how components are orchestrated.

The intelligence factory becomes a chain of interdependent industrial systems.

The weakest component may therefore establish the effective ceiling on the strongest one. This is the first structural insight of the rack war: in a synchronized machine, strategic risk migrates from the most sophisticated component to the least replaceable one.


1.2 Optical Transceivers Reveal the Hidden Supply Chain

Optics provide perhaps the clearest example of why the GPU-centered narrative is becoming inadequate.

Modern AI training and inference require accelerators to exchange enormous quantities of information. As models grow and workloads become increasingly distributed, networking becomes a computational problem rather than a peripheral communications problem. Thousands of GPUs that cannot communicate rapidly with one another are not equivalent to thousands of GPUs functioning as a coordinated system. Industry analysts describe superclusters of tens of thousands of GPUs hitting a physical “copper wall,” forcing an accelerated migration to high-speed optical interconnects for rack-to-rack communication, with 800-gigabit modules dominant today and 1.6-terabit modules already entering production.[2]

This makes optical connectivity part of the intelligence-production process. The numbers inside Nvidia’s own income statement confirm it: networking revenue reached a record $11.0 billion in the fourth quarter of fiscal 2026, up 263 percent from a year earlier, driven by NVLink compute fabric, Ethernet, and InfiniBand platforms.[26] The network is no longer plumbing. It is product.

Nvidia itself demonstrated the strategic importance of the sector on March 2, 2026, when it announced separate $2 billion investments in Lumentum and Coherent. The agreements included multibillion-dollar purchase commitments, future capacity access rights for advanced laser components and optical networking products, R&D cooperation, and support for expanding U.S.-based manufacturing of advanced optical technologies — including an entirely new Lumentum fabrication facility.[12][13] Lumentum shares closed nearly 12 percent higher and Coherent jumped 15 percent on the announcement.[14] Huang described the ambition directly:

“Together with Lumentum, NVIDIA is advancing the world’s most sophisticated silicon photonics to build the next generation of gigawatt-scale AI factories.”

— Jensen Huang, Founder and CEO, NVIDIA [14]

The investment is revealing.

A company synonymous with GPUs was deploying $4 billion not simply to design another accelerator but to strengthen the ecosystem that connects accelerators. Analysts at Futurum Group interpreted the move as a signal that Nvidia now views optics as a strategic bottleneck requiring the same level of supply-chain engineering it previously applied to high-bandwidth memory, CoWoS advanced packaging, and networking silicon.

That is Rack Sovereignty operating through corporate capital allocation.

The U.S. government’s August examination of Chinese optical transceivers points toward the same conclusion from the policy direction. Counterpoint Research estimates that Zhongji Innolight leads the global datacenter transceiver market with roughly a 27 percent revenue share, Coherent holds approximately 17 percent, and Chinese manufacturers collectively supply around two-thirds of global units, with Innolight and Eoptolink together supplying the majority of Nvidia’s 800G module demand.[2] Innolight posted approximately RMB 19.5 billion — roughly $2.9 billion — in revenue in the first quarter of 2026 alone, and analyses cited by Reuters indicate the company earns about 90 percent of its revenue outside China.[3][4]

This creates a remarkable geopolitical paradox.

American companies lead the frontier of AI computing. American hyperscalers are spending three-quarters of a trillion dollars a year constructing AI factories. American chip designers dominate advanced accelerators. Yet some physical components required to connect these systems have developed substantial Chinese supply-chain exposure — and, in a further twist, the Western alternatives designated as replacements depend on indium phosphide substrates that Beijing placed under export licensing in 2025, a move that drove prices up roughly 250 percent, while Chinese module makers in turn rely on American digital signal processors from Broadcom and Marvell and on lasers from Lumentum, Coherent, and Mitsubishi Electric.[2][3] The proposed ban would disrupt a genuinely interdependent system rather than cleanly separating two independent ones.

The paradox does not mean that every Chinese-produced optical module is compromised, nor does it prove that every foreign component presents a security risk. Such conclusions would require product-specific evidence, and, as careful observers noted, the Reuters reporting did not identify a product-specific vulnerability or a public technical assessment supporting the concerns.[4]

The more important point is structural.

If Washington determines that a category of component is strategically sensitive after that component has become deeply embedded in AI infrastructure, replacing it can be slow, expensive, disruptive, and technically complicated. Counterpoint estimates Western suppliers would face a 12-to-24-month ramp gap before they could replace Chinese volume at current AI cluster build-out rates.[2][3]

The Huawei telecommunications experience taught policymakers how costly late-stage removal can become — the “rip and replace” program for rural American networks consumed years and billions of dollars. The emerging policy preference is therefore shifting toward controlling exposure before dependency becomes irreversible. The proposed transceiver rule, like the router and robot actions before it, targets new model imports while leaving the millions of already-deployed Chinese transceivers in U.S. datacenters untouched — a forward-looking perimeter rather than a retroactive purge.[1][3]

That changes technology policy from remediation to preemption.


1.3 Routers, Inverters, and Robots Expand the Security Perimeter

The move beyond chips is not limited to optics.

Routers matter because they determine where data travels. In August 2025, CISA, the NSA, the FBI, and international partners from a dozen allied countries released a joint advisory warning that PRC state-sponsored advanced persistent threat actors — activity overlapping with groups tracked as Salt Typhoon, OPERATOR PANDA, RedMike, UNC5807, and GhostEmperor — had been exploiting vulnerabilities in the large backbone routers of telecommunications providers, specifically provider-edge and customer-edge routers that often lack visibility and are difficult to monitor, across telecommunications, government, transportation, lodging, and military infrastructure networks.[22] The advisory’s core warning was stark:

“These actors often modify routers to maintain persistent, long-term access to networks.”

— CISA / NSA / FBI Joint Cybersecurity Advisory AA25-239A [22]

That threat environment helps explain why network infrastructure is becoming inseparable from national-security policy.

It is important to distinguish categories carefully. The FCC’s March 2026 Covered List action concerned foreign-produced consumer-grade routers, not a blanket prohibition on all foreign datacenter networking equipment.[5] But as a policy precedent it is significant for two reasons. First, regulators treated country-of-production and supply-chain exposure — not merely company identity — as relevant to equipment authorization; the entry covers all consumer routers produced abroad, regardless of the manufacturer’s nationality, and applies whenever any major stage of production, including design or development, occurs in a foreign country.[37] Second, the March action marked the moment the Covered List evolved from a list of named untrusted companies (Huawei, ZTE, Hikvision) into a mechanism for restricting entire product categories by geography of production. That is a fundamentally more expansive instrument.

Power electronics introduce another dimension.

An inverter may not look like an AI component. It is associated primarily with converting direct-current power from solar installations and batteries into usable alternating-current electricity and connecting those resources to the grid. But AI factories increasingly depend upon complex combinations of grid electricity, renewable generation, batteries, backup generation, substations, power-conditioning equipment, and microgrids. Grid-connected inverters routinely communicate with manufacturer servers for monitoring, over-the-air firmware updates, and remote control of power output. If connected power electronics contain remotely controllable software, security concerns move directly into the energy layer of the AI economy. The July 28 Covered List action rested on precisely this logic: a national security determination that foreign-produced connected power inverters pose supply-chain and cybersecurity risks to an electric grid increasingly dependent on inverter-based resources.[7][9]

Robots push the boundary further.

Datacenter robotics remains relatively early compared with industrial automation in manufacturing, but the direction is important. Physical AI systems can inspect equipment, detect thermal anomalies, patrol facilities, transport components, perform routine maintenance, manage warehouse operations, or operate around electrical and mechanical infrastructure. The FCC’s definition of a covered “advanced robotic device” is instructive in its breadth: a mechanical mobile device — including autonomous mobile robots, humanoids, and quadrupeds — capable of locomotion or navigation, operating at a distance from a human operator based on commands or sensor data, weighing over 4.4 pounds, and containing network connectivity of at least 200 kilobits per second.[9] The commercial impact falls overwhelmingly on China, which shipped approximately 80 percent of the world’s humanoid robots in 2025, led by Unitree and AgiBot, each of which delivered more than 5,000 units in a year when leading U.S. developers produced a few hundred machines or fewer.[8] The security logic was reinforced by disclosed vulnerabilities in widely deployed Chinese robots, including a wormable Bluetooth exploit yielding root-level access to Unitree quadrupeds and humanoids already operating in American university laboratories. Industry reaction was telling. Brendan Schulman, vice president of policy at Boston Dynamics, publicly welcomed the restriction:

“Communications and national security policy are crucial aspects of the national robotics strategy that Boston Dynamics and others have been advocating for. I sense that this is just the first round in a series of policies that will define the success and growth of the industry for decades to come.”

— Brendan Schulman, Vice President of Policy and Government Relations, Boston Dynamics [8]

A robot inside a sensitive facility can possess cameras, microphones, wireless connectivity, mapping capabilities, onboard AI, cloud communications, remote updates, and physical mobility. That makes it more than another piece of machinery. It becomes a mobile sensor, computer, network node, and physical actuator.

This is why restrictions involving robotics belong inside Rack Sovereignty even if robots are not literally bolted into every server rack. The security perimeter of the AI factory increasingly includes everything that can observe, influence, connect to, power, cool, maintain, or physically interact with the system.


1.4 From Export Control to Import Security

The first era of the U.S.–China AI conflict concentrated largely on outbound technology.

Washington asked which GPUs China should be permitted to buy. Which semiconductor-manufacturing machines should be exported? Which performance thresholds should trigger licenses? Which memory technologies should be restricted? Which foundries could manufacture advanced Chinese designs? Which intermediary countries might become diversion points?

Rack Sovereignty introduces the reverse question:

Which foreign technologies should be allowed inside American intelligence infrastructure?

That is a profound shift.

Export controls attempt to slow the technological capabilities of another country. Import security attempts to reduce vulnerabilities inside one’s own country. The first asks: What are we willing to sell them? The second asks: What are we willing to depend upon?

Those questions overlap, but they are not identical.

A country might decide that a foreign product presents little value as a military export while still presenting unacceptable risk if deployed by the millions across domestic infrastructure. Conversely, a component may be technically unsophisticated yet strategically important because failure or remote disruption could disable expensive systems built around it. Chris Miller made a version of this observation at Carnegie Mellon in March 2026: global powers, he noted, are increasingly wary of foreign-made technologies capable of autonomous processing or independent communication, and this skepticism raises critical questions about who has access to these systems, how they operate, who writes the software, and who provides the over-the-air updates — questions for which there are currently no clear answers. While the primary concern regarding semiconductors today is access, Miller argued, the defining question of tomorrow will be trust.[30]

Rack Sovereignty therefore broadens the meaning of a chokepoint.

The chokepoint is not necessarily the component with the highest transistor count.

It can be the component whose absence stops the system.


1.5 The Five-Layer AI Economy Becomes Physically Coupled

The Five-Layer AI Economy provides a useful framework for understanding why this shift matters.

LayerFunctionRepresentative AssetsRack Sovereignty Exposure
Layer 1 — EnergyProvides the electricityGrids, generation, transformers, inverters, batteries, substationsConnected inverters; transformer lead times; grid cyber risk
Layer 2 — ChipsTransforms electricity into computationGPUs, CPUs, HBM, DPUs, power semiconductors, packagingExport controls; foundry concentration; HBM supply
Layer 3 — DatacentersIntegrates physical infrastructure for continuous computationRacks, optics, switches, cooling, firmware, robots, storageOptical transceivers; routers; cooling controllers; firmware provenance
Layer 4 — ModelsTransforms computation into intelligenceFrontier models, weights, training pipelinesDependent on Layers 1–3 uptime
Layer 5 — Applications & AgentsConverts intelligence into economic activityAgents, copilots, robotics software, industrial AIDependent on all layers below

Table 2. The Five-Layer AI Economy and its Rack Sovereignty exposure. The rack sits at the hinge between Layers 1–3 and everything above.


The earlier AI economy often allowed these layers to be discussed separately.

Rack-scale infrastructure increasingly compresses them. Power architecture now influences chip architecture. Networking influences model performance. Cooling constrains token production. Agentic inference increases network traffic. Model architecture changes memory requirements. GPU density changes transformer and switchgear requirements. Datacenter location changes electricity procurement. Grid reliability affects inference availability.

The stack therefore behaves increasingly like an industrial organism.

That is why the geopolitical contest is moving from the individual semiconductor toward the full machinery of intelligence production.

The chip war is not ending.

It is expanding into the rack war.


Section 2: The Physical Anatomy of Rack Sovereignty


2.1 The Compute Core: Sovereignty Begins with Silicon but Cannot End There

At the center of every modern AI factory remains the accelerator.

Nvidia, AMD, Google, Amazon, Microsoft, Meta, and other companies increasingly design or deploy specialized chips optimized for different AI workloads. Nvidia retains extraordinary importance because its accelerators, networking technologies, software ecosystem, and rack architectures increasingly operate as an integrated platform — a position reflected in an AI-accelerator market share still estimated near 80 percent in mid-2026.

With Vera Rubin, the company is moving even further from selling a discrete processor toward delivering an architectural blueprint for the AI factory. Nvidia says the platform provides approximately ten times the agent throughput at scale of its previous Grace Blackwell platform, brings five purpose-built rack classes together as one system, and can train large mixture-of-experts models using roughly one-fourth the number of GPUs that Blackwell-generation chips would require.[10] At GTC 2026, Huang went further, raising Nvidia’s multi-year sales projection to $1 trillion in cumulative revenue through 2027 on the strength of the Blackwell and Rubin generations, and describing a trajectory in which a one-gigawatt AI factory’s token generation rises from roughly 2 million tokens per second in the Hopper era to about 700 million tokens per second on Vera Rubin systems — a 350-fold increase that collapses the cost per token while multiplying throughput.

This matters because the meaning of hardware sovereignty changes when systems become integrated.

Imagine that a government successfully secures a domestic allocation of advanced Rubin accelerators. That is Layer 2 capacity. But the accelerators still need host CPUs, HBM, network adapters, switches, storage, optical connectivity, power conversion, cooling, rack management, firmware, and replacement parts. If a geopolitical event disrupts any critical component, the theoretical computational capacity of those GPUs may exceed the usable computational capacity of the facility.

This creates a distinction between Installed Compute and Sovereign Compute.

Installed Compute measures how many accelerators are physically present. Sovereign Compute measures how much of that capacity can continue operating under stressed geopolitical, cyber, industrial, or energy conditions.

The difference could become strategically important, and it is measurable in principle. A facility’s Sovereign Compute ratio — the fraction of installed FLOPS that survives a defined disruption scenario, such as a twelve-month interruption of Chinese component exports or a Taiwan Strait logistics crisis — could become a standard reporting metric for national AI capacity, in the same way that reserve margins are standard metrics for electricity systems. A country can possess a warehouse of GPUs while lacking the infrastructure required to keep them functioning at scale. In that scenario, the warehouse is inventory, not capability.


2.2 Memory and Networking: The Accelerator Is Part of a Collective Machine

AI systems increasingly depend upon parallelism.

A large model is divided across accelerators. Parameters must move. Activations must be exchanged. Gradients must be synchronized. Storage systems must continuously deliver information. Inference workloads — particularly the long reasoning chains of agentic AI — may require many processors to collaborate on one reasoning process, with prefill and decode phases disaggregated across heterogeneous hardware.

This makes network latency and bandwidth part of computational performance.

Nvidia’s architecture recognizes this explicitly. Vera Rubin incorporates NVLink 6, ConnectX-9 SuperNICs, BlueField-4 DPUs, and Spectrum-6 Ethernet switching, while Spectrum-X Ethernet Photonics — combining co-packaged optics with Spectrum-X switching — is intended to improve the efficiency and reliability of very large AI fabrics on the path toward million-GPU factories.[10][11]

The datacenter network is therefore not merely an internal version of the internet. It increasingly behaves like the nervous system of the AI factory.

A slow or unreliable network wastes accelerators because processors spend time waiting for information. At extreme scale, small networking inefficiencies become enormous financial losses because the stranded resource is no longer a cheap server. It is an extraordinarily expensive accelerator fleet consuming equally expensive electricity and cooling capacity. When a single NVL72 rack represents millions of dollars of silicon, a one-percent improvement in network utilization across a hyperscale fleet is worth more than the entire annual revenue of many component suppliers. That asymmetry explains why Nvidia’s networking revenue grew 263 percent year over year in its most recent fiscal fourth quarter, reaching $11.0 billion in a single quarter — a figure that, on its own, would rank Nvidia’s networking business among the largest networking companies in the world.[26]

Rack Sovereignty must therefore include networking sovereignty.

But networking sovereignty does not require that every component be manufactured inside the United States. That would be economically unrealistic and potentially counterproductive. The better standard is trusted availability. A sovereign rack should have suppliers whose ownership is understood, whose security can be assessed, whose firmware can be controlled, whose components can be replaced, and whose manufacturing geography is sufficiently diversified that one geopolitical event cannot incapacitate the system.

Sovereignty thus differs from autarky.

Autarky means producing everything yourself. Rack Sovereignty means preventing unacceptable dependence on components you cannot trust or replace.


2.3 Optical Sovereignty: When Light Becomes Strategic Infrastructure

As AI clusters grow, copper connections increasingly face physical limits involving distance, bandwidth, heat, signal integrity, and electricity consumption. Optics becomes more important — and with co-packaged optics, light is moving from the edge of the switch into the package of the switch silicon itself.

Nvidia’s March 2026 investments in Lumentum and Coherent are particularly instructive because the company did more than make financial investments. The agreements included multibillion-dollar purchase commitments, future capacity access rights, and support for new U.S. fabrication capacity; SEC filings show Nvidia paid $2 billion in cash for nearly 2.9 million Lumentum shares.[12][13] Nvidia was effectively using capital to reinforce a strategic upstream infrastructure category before scarcity could constrain its own product roadmap.

This can be interpreted as a form of private industrial policy.

Nvidia has an enormous economic interest in selling more compute. But selling more GPUs requires customers to connect those GPUs. Therefore Nvidia has an incentive to ensure that optical supply grows alongside semiconductor supply. The logic resembles a railway company investing in steel, a car manufacturer investing in batteries, or a utility investing in transformers. Control of the primary product creates incentives to stabilize complementary infrastructure.

At the same time, the U.S. government is examining the security implications of dependence on Chinese transceiver manufacturers — manufacturers who supply the majority of the 800G modules feeding Nvidia’s own platforms, at prices running 20 to 25 percent below Western incumbents.[2][3]

That produces a fascinating convergence: corporate demand security and national security begin pointing toward the same component.

The strategic importance of optical modules will probably increase as systems transition toward higher-bandwidth technologies and co-packaged optics. This could eventually produce what might be called Photonics Industrial Policy: governments and hyperscalers deliberately supporting domestic or allied laser, transceiver, packaging, and optical-component manufacturing because AI scaling becomes impossible without it. The early ingredients are already visible: Nvidia’s $4 billion, Lumentum’s new fab, Coherent’s expanded U.S. footprint, the Pentagon’s June 2026 addition of Innolight to its Section 1260H list of Chinese military companies, and the FCC’s draft import restriction.[3][4][12][13]

Yet the material layer complicates the story. Every Western alternative transceiver depends on indium phosphide, a substrate over which China imposed export licensing in 2025, sending prices up roughly 250 percent; China also holds a dominant position in the silicon lenses used in optical modules.[3] An optical decoupling that ignores the mineral and substrate layer risks merely relocating the chokepoint downward.

The lesson is broader.

When intelligence factories become sufficiently large, even light itself becomes an industrial-policy problem.


2.4 Power Sovereignty: The Rack Is Becoming an Electrical Machine

A contemporary AI rack consumes extraordinary electricity relative to conventional computing infrastructure. The trajectory is vertiginous: in the Hopper era, a rack drew roughly 40 kilowatts; the Grace Blackwell GB200 generation leapt to approximately 120 kilowatts; Schneider Electric’s validated reference design for Vera Rubin NVL72 racks supports operation at 188 to 227 kilowatts per rack;[33] and Nvidia’s Rubin Ultra “Kyber” rack, which will house 576 GPUs in vertically oriented compute blades beginning in 2027, is expected to reach 600 kilowatts to a full megawatt per rack.[16] Rack power density has grown roughly twenty-five-fold in three years.

Nvidia’s 800-volt direct current architecture is designed around the expectation that traditional power-distribution techniques will become insufficient for these densities. The physics are unforgiving: delivering one megawatt at the legacy 54-volt rack standard would require up to 200 kilograms of copper busbar per rack — and the busbars alone in a single gigawatt-scale datacenter could demand up to 200,000 kilograms of copper.[15] Moving to 800 VDC transmits over 150 percent more power through the same copper, eliminates repeated AC/DC conversion stages, improves end-to-end efficiency by roughly five percent, reduces copper use by an estimated 45 percent, and frees rack space for compute rather than power shelves.[15][16][36] Nvidia is coordinating the transition with Microsoft and Google through the Open Compute Project, with more than 80 ecosystem companies — spanning silicon providers such as Infineon, Navitas, onsemi, ROHM, STMicroelectronics, and Texas Instruments; power-system specialists such as Delta, Flex, and LiteOn; and infrastructure giants Eaton, Schneider Electric, and Vertiv — developing products against the specification, with the first 800 VDC platforms shipping in the second half of 2026 and full-scale 800 VDC datacenters coinciding with Kyber in 2027.[15][16]

This changes how we should think about the physical AI stack.

Power is not simply delivered to the datacenter. Power architecture becomes part of the computer.

That creates an enormous ecosystem of strategic components: transformers, rectifiers, solid-state converters, busways, switchgear, battery and supercapacitor systems buffering AI load volatility, power shelves, control electronics, protection devices, monitoring systems, gallium-nitride and silicon-carbide power semiconductors, and cooling equipment.

The transition therefore expands the semiconductor story in an unexpected direction. An AI factory does not merely contain digital semiconductors calculating matrix operations. It increasingly depends upon power semiconductors regulating the enormous flow of electricity into those digital semiconductors. The Five-Layer AI Economy folds back onto itself: Layer 1 and Layer 2 become physically intertwined.

The current debate over connected inverters demonstrates why this matters. The United States is already restricting foreign power-control equipment because connected electricity infrastructure can create cyber and operational vulnerabilities.[7] As AI racks move toward higher electrical densities and datacenters integrate on-site generation, batteries, and microgrids tied directly into DC buses, analogous questions will apply throughout the datacenter power chain.

Who manufactures the power electronics? Who wrote the controller firmware? Can software updates be disabled? Can components be operated offline? Can telemetry leave the facility? Can a supplier remotely alter operating parameters? Are replacement modules available domestically? How quickly can a compromised component be substituted?

These are not conventional IT procurement questions. They are questions of infrastructure sovereignty.


2.5 Thermal Sovereignty: The Chokepoint Nobody Sees

Every unit of computation creates heat.

As rack power rises toward the megawatt, thermal engineering becomes increasingly central to AI economics. Traditional datacenters relied extensively on air cooling. The newest high-density AI systems — every Vera Rubin NVL72 among them — require liquid cooling: cold plates, manifolds, cooling distribution units, pumps, heat exchangers, sophisticated controls, and facility-level heat-rejection equipment.[10][33]

Cooling is therefore another example of an apparently mundane industrial system becoming strategically significant. A one-megawatt rack without adequate cooling is not a one-megawatt computing asset. It is an expensive collection of electronics that cannot operate safely.

This creates the concept of the thermal chokepoint.

A thermal chokepoint is a component, material, control system, or supply-chain dependency whose failure constrains usable computing capacity by preventing heat from being removed. At ordinary computing densities, cooling equipment could be treated largely as building infrastructure. At AI densities, it becomes part of computational performance — Schneider Electric explicitly optimizes its Vera Rubin reference designs for “tokens per watt,” an efficiency metric that fuses thermal engineering with revenue generation.[33]

This is why Nvidia and its infrastructure partners increasingly discuss power and cooling jointly, and why partners at GTC 2026 emphasized that existing electrical rooms and cooling systems often cannot support new AI loads: power and thermal architectures must increasingly be designed together, and the industry is responding with integrated reference designs covering drawings, bills of material, schematics, and performance specifications before the first rack arrives.[33]

From a sovereignty perspective, thermal infrastructure introduces another layer of supply-chain questions. Where are pumps manufactured? Who supplies coolant-distribution hardware? Which firms produce sensors and controllers? Which systems contain remote-management capabilities? What are the lead times for replacements? Can facilities stock standardized spares? Are components interoperable or vendor-locked? Can domestic suppliers surge production during an emergency?

An AI policy that secures accelerators while ignoring thermal dependencies protects only part of the machine.


2.6 Firmware Sovereignty: Every Component Contains Another Computer

The greatest hidden transformation in physical infrastructure may be software.

Modern industrial equipment is rarely purely mechanical. Switchgear contains digital controllers. Cooling systems contain software. Network switches contain operating systems. Servers contain baseboard management controllers. Battery systems contain management software. Robots contain multiple processors, sensors, communications systems, and AI models. Power converters contain firmware. Security cameras contain network stacks.

The distinction between hardware security and software security is therefore dissolving.

A component can be physically manufactured in one country, assembled in another, run firmware written in a third, use chips manufactured in a fourth, receive software updates from a fifth, and send telemetry to a cloud service in a sixth. “Made in” becomes an inadequate description. The FCC has already recognized this: its router Covered List entry treats a device as foreign-produced if any major production stage — including design or development — occurs abroad, explicitly rejecting final assembly location as determinative.[37]

Rack Sovereignty therefore requires another question:

Who can control the component after it has been installed?

That question includes code-signing authority, firmware-update mechanisms, administrative credentials, remote diagnostic access, embedded communications modules, cloud dependencies, security-patch policies, and end-of-life support. The Unitree case illustrates the stakes: security researchers disclosed a wormable vulnerability granting root access to robots deployed in American research institutions, with no firmware patch issued — a reminder that lifecycle control is not hypothetical.

NIST’s July 8, 2026 finalization of Special Publication 1326 is particularly relevant. The Cybersecurity Supply Chain Risk Management Due Diligence Assessment Quick-Start Guide organizes supplier due diligence around five components: Foreign Ownership, Control, or Influence (FOCI); Provenance; Resilience; Foundational Cyber Practices; and Supply Chain Tiers.[17]

Those categories map almost perfectly onto Rack Sovereignty.

The future AI factory therefore needs more than a Bill of Materials. It needs a Bill of Control.

Who built it? Who owns it? Who maintains it? Who updates it? Who can communicate with it? Who can replace it? And who can turn it off?


Section 3: The Sovereign Rack Bill of Materials


3.1 From BOM to SR-BOM

Manufacturing companies have long used Bills of Materials to document the components inside products. Artificial-intelligence infrastructure now requires something more ambitious.

I propose the concept of a Sovereign Rack Bill of Materials, or SR-BOM.

The SR-BOM would not merely identify part numbers. It would map geopolitical and operational dependencies across the infrastructure necessary to produce intelligence.

A conventional BOM might state that an optical transceiver is installed. An SR-BOM would ask who manufactures it, where its critical components originate, who owns the supplier, whether the supplier is exposed to foreign government influence, where the firmware comes from, whether remote updates are permitted, what replacement suppliers exist, how long replacement takes, where spare inventory is stored, and what happens if the component becomes unavailable. The same analysis would apply to networking, power, cooling, storage, accelerators, management processors, robots, sensors, and security systems.

This is not purely speculative.

The White House moved in a similar direction for defense supply chains on July 20, 2026. Executive Order 14415, “Securing America’s Defense Supply Chains and Ensuring Domestic Acquisition of Critical Materials,” directs the Department of War to develop requirements under which contractors supporting designated national-security acquisitions must submit “a complete indentured Bill of Materials that traces all components, parts, equipment, software, and materials back to the origin of raw materials in their supply chains,” establish written procedures to vet suppliers and subcontractors for risks including financial uncertainty, foreign ownership, control, or influence, and reliance on sole-sourcing, and notify the Department of identified risks with tracked mitigation plans.[18][19] The order restricts long-routine statutory sourcing waivers involving China, Russia, North Korea, and Iran beginning January 1, 2027, and even authorizes the Pentagon to deploy artificial intelligence to map vulnerabilities across its own supply chains — AI mapping the supply chains that build AI.[19]

The defense model is significant because today’s AI infrastructure increasingly possesses characteristics once associated primarily with strategic military supply chains. It is capital intensive. It has long equipment lead times. It depends on globally concentrated manufacturing. It contains dual-use technology. Its failure can affect economic and national security. Its components are difficult to replace quickly. And governments increasingly regard access to advanced AI as a source of national power.

A civilian AI-factory equivalent of supply-chain illumination is therefore plausible — and one consulting firm’s description of EO 14415 as “the supply chain equivalent of what CMMC did for cybersecurity” suggests the compliance industry is already preparing for it.


3.2 Provenance Must Extend Beyond the Tier-One Supplier

The difficult part is supply-chain depth.

A hyperscaler may buy a server from a well-known American company. That does not mean every component inside the server is American. The server manufacturer may purchase subsystems from Taiwan. Those suppliers may purchase optical components from China. Power electronics may contain semiconductors from several countries. Cooling systems may use controllers manufactured elsewhere. The original equipment manufacturer may not have full visibility into sub-tier sourcing. Nvidia’s own disclosure that Vera Rubin is manufactured across 350-plus factories in roughly 30 countries is simultaneously a testament to industrial coordination and a map of provenance complexity.[10]

This creates what can be called provenance depth.

Tier-one provenance asks: who sold the finished equipment? Tier-two provenance asks: who produced the major subsystems? Tier-three provenance asks: where did their components originate? Deeper provenance eventually reaches wafers, substrates, chemicals, specialty metals, magnets, lasers, power semiconductors, capacitors, connectors, and raw materials. NIST SP 1326 formalizes this with its Supply Chain Tiers component, asking organizations to define how much foreign exposure they can tolerate in critical suppliers and at which tier.[17]

At some point, perfect knowledge becomes expensive or impossible. Rack Sovereignty therefore cannot require infinite traceability for everything. It needs a hierarchy based upon consequence of failure.

A decorative plastic component deserves less scrutiny than an externally connected management controller. A commodity screw is different from a network switch. A rack door is different from a power inverter. A mechanical bracket is different from firmware controlling a cooling distribution unit.

The SR-BOM should therefore classify components by strategic function. The most critical categories are those capable of producing one or more of four consequences: compute denial, data compromise, remote control, or systemic disruption.


Trust TierComponent CharacteristicsExamplesProvenance Requirement
Tier S — SystemicCan deny compute, compromise data, enable remote control, or disrupt the gridOptical transceivers, switches, BMCs, power inverters, cooling controllers, DPUs, firmwareFull SR-BOM to raw materials; FOCI vetting; qualified second source; verified spare inventory
Tier A — OperationalFailure degrades capacity but cannot be remotely exploitedPumps, heat exchangers, busways, power shelves without connectivityTier-2 provenance; replacement lead-time mapping; allied sourcing preferred
Tier B — CommodityGeneric, substitutable, non-connectedFasteners, enclosures, passive cabling, structural steelStandard procurement diligence

Table 3. A consequence-based trust-tier classification for the Sovereign Rack Bill of Materials. Risk combines origin and function; the closer a component sits to control, the greater the sovereignty requirement.


That classification allows policymakers to focus attention where sovereignty matters most.


3.3 Replaceability Is as Important as National Origin

Supply-chain security debates often make a conceptual mistake. They confuse domestic production with resilience.

Domestic production can strengthen resilience, but it does not guarantee it. A single domestic factory can be a chokepoint. A trusted allied supplier with multiple geographically distributed plants may provide greater resilience than one concentrated domestic manufacturer.

Rack Sovereignty should therefore measure replaceability, not merely nationality.

A component becomes strategically dangerous when five characteristics converge: it is necessary; it is difficult to substitute; production is concentrated; replacement lead times are long; and the supplier sits within a geopolitical risk zone. That combination is more informative than a simple “Made in China” or “Made in America” label.

This is particularly important because global AI infrastructure is extraordinarily international. Attempting to recreate every one of the capabilities embodied in Nvidia’s 350-factory, 30-country ecosystem within the United States would be enormously expensive and might slow AI deployment.[10]

The objective should instead be what might be called Sovereign Substitutability.

Under Sovereign Substitutability, critical infrastructure can rely on global suppliers provided that high-consequence components have trusted alternative sources, verified inventories, interoperable standards, or realistic emergency replacement plans. That approach preserves the efficiency of allied globalization without accepting dangerous single points of geopolitical failure.


3.4 The Optical Example Shows Why Substitution Takes Time

Optical networking illustrates the challenge.

If a government suddenly decides that an incumbent supplier poses unacceptable national-security risk, the response cannot simply be “buy from someone else.” Alternative manufacturers must possess sufficient production capacity. Their products must meet performance specifications. Datacenter operators must qualify them. Firmware and management interfaces must integrate. The components must satisfy reliability requirements. Supply agreements must be negotiated. Manufacturing equipment and raw materials must be available.

The quantitative gap is sobering. Chinese manufacturers hold roughly 60 percent of the 800G market at prices 20 to 25 percent below Western incumbents; Counterpoint estimates Lumentum, Coherent, and other Western suppliers would need 12 to 24 months to ramp replacement volume — and their transceivers still depend on Chinese-controlled indium phosphide.[2][3] Re-qualifying an optical supplier is not instant: hyperscalers typically require months of interoperability, thermal, and reliability testing before deploying a new module at fleet scale.

This is why Nvidia’s investments in Lumentum and Coherent deserve to be seen as strategically important. The agreements support research, manufacturing capacity, and future access rather than merely immediate purchases.[12][13] It is also why policy sequencing matters.

Restrict too slowly, and dependency deepens. Restrict too rapidly, and the security policy can reduce America’s own AI-building capacity. The optical market is already experiencing extraordinary AI-driven demand while alternative capacity remains constrained — which is precisely why the draft FCC rule targets only new models, preserving the installed base while redirecting future flows.[1][3]

This produces one of the central dilemmas of Rack Sovereignty:

The component considered insecure may also be the component the AI boom cannot immediately afford to lose.


3.5 Raw Materials Can Recreate Dependence Beneath Domestic Manufacturing

The problem becomes even more complicated at lower supply-chain tiers.

A transceiver manufactured in the United States may still require wafers, crystals, lasers, specialty chemicals, or minerals linked to China. A power converter assembled domestically may still depend upon imported components. A domestic datacenter may contain globally sourced copper, transformers, permanent magnets, semiconductor substrates, cooling equipment, and battery materials.

Moving final assembly home therefore does not automatically eliminate strategic exposure.

The White House’s July 30, 2026 Presidential Determination concerning recoverable critical minerals and materials emphasized this broader problem, finding that “America’s inadequate supply of CMMs poses an increasing risk to our national defense and security” and authorizing the Secretary of Commerce to act under Section 101 of the Defense Production Act to secure supplies of black mass, end-of-life rare-earth permanent magnets, swarf, and other critical-mineral-bearing waste and scrap.[20] Within a week, the Bureau of Industry and Security published a temporary final rule requiring, as of August 27, 2026, that U.S. sellers of black mass and tungsten waste and scrap allocate 100 percent of monthly sales to U.S. persons absent a license — an extraordinary use of Defense Production Act allocation authority over what was, until recently, considered scrap.[21]

Rack Sovereignty consequently moves downward as well as outward.

First the GPU becomes strategic. Then networking becomes strategic. Then optics. Then lasers. Then wafers. Then power semiconductors. Then chemicals and materials. Eventually industrial policy reaches geology — and even the recycling bin.

The physical AI economy is a pyramid, not a stack of interchangeable boxes. The higher layers can only operate because enormous industrial systems sit beneath them.


3.6 A Practical Rack Sovereignty Score

Corporations and governments therefore need a measurement framework.

A Rack Sovereignty Score could evaluate each critical system across six dimensions, aligned deliberately with the NIST SP 1326 due-diligence vocabulary so that corporate compliance work and national policy can share a common language.[17]


DimensionCore QuestionIllustrative Metric
1. ProvenanceHow well are origin and ownership understood?% of Tier-S components with verified tier-3 provenance
2. IntegrityCan the component and its software be authenticated and secured?% of firmware with attested code-signing under owner control
3. ReplaceabilityHow quickly can another trusted supplier substitute?Weighted average qualified-second-source lead time (days)
4. Connectivity ControlCan communications, remote management, and telemetry be constrained?% of connected devices operable in fully offline mode
5. Energy & Operational ControlCan the owner operate equipment independently of external vendor/cloud services?% of power/cooling systems free of mandatory external dependencies
6. Lifecycle ControlCan patches, spares, maintenance, and support be sustained under geopolitical stress?Months of verified strategic spare inventory for Tier-S components

Table 4. The six dimensions of a Rack Sovereignty Score. Because the dimensions multiply rather than add, a near-zero score in any one dimension collapses the total.


A datacenter could therefore possess a strong security perimeter while still receiving a low sovereignty score because too many critical components have long replacement times or opaque control relationships. Conversely, a system using many foreign components could receive a relatively high sovereignty score if suppliers are trusted, diversified, auditable, replaceable, and located across allied countries.

This distinction prevents Rack Sovereignty from collapsing into simplistic economic nationalism.

The objective is not to create an American-only rack.

The objective is to create a rack that America can continue operating regardless of external coercion.


Section 4: From Corporate Procurement to National AI Policy


4.1 The FCC Is Becoming an Unexpected AI Infrastructure Regulator

One of the most surprising developments of 2026 is the increasingly important role of the Federal Communications Commission in technology competition with China.

The FCC is not the first agency that comes to mind when discussing AI industrial policy. Export controls are associated with the Commerce Department. Semiconductor subsidies are associated with Commerce and Congress. Electricity regulation involves FERC, state public-utility commissions, regional grid organizations, and utilities. Cybersecurity involves CISA. Defense technology involves the Pentagon.

Yet communications equipment increasingly contains the connective tissue of digital infrastructure, and the FCC controls the gate through which most connected electronics enter the American market: equipment authorization. Because nearly every modern device — router, robot, inverter, transceiver — contains radio or network communication capability, nearly every modern device passes through the FCC’s jurisdiction on its way to an American loading dock. In the space of nine months, the agency has used that gate four times against broad product categories: drones in December 2025, consumer routers in March 2026, advanced robotic devices and connected power inverters in July 2026, and — in draft form — datacenter optical transceivers in August 2026.[1][5][7] Reuters and industry observers have described the agency as the unexpected spearhead of the administration’s China technology policy.[1]

This bureaucratic development matters because Rack Sovereignty crosses traditional regulatory boundaries.

An optical module is simultaneously a communications device, a datacenter component, an AI infrastructure dependency, a cybersecurity surface, a manufacturing product, and potentially a national-security concern. A connected inverter is simultaneously an energy device, an electronic communications system, a grid component, a cybersecurity surface, and an industrial product. A humanoid robot is simultaneously a machine, an AI system, a sensor platform, a communications device, and potentially critical-infrastructure equipment.[34]

Twenty-first-century infrastructure does not respect twentieth-century bureaucratic categories.

Rack Sovereignty therefore creates an institutional coordination problem. Under the Secure and Trusted Communications Networks Act, the FCC can update its Covered List only at the direction of national-security authorities — which is why each of the 2025–2026 actions was preceded by a National Security Determination from a White House-convened interagency body, with the Department of War and the Department of Homeland Security empowered to grant Conditional Approvals.[5][7] The FCC has become the enforcement instrument of an interagency perimeter; the perimeter itself is drawn elsewhere.


4.2 NIST Provides the Due-Diligence Vocabulary

If the FCC represents the enforcement frontier, NIST provides much of the conceptual infrastructure for evaluating suppliers.

NIST finalized SP 1326, the Cybersecurity Supply Chain Risk Management Due Diligence Assessment Quick-Start Guide, on July 8, 2026. Authored by Jon Boyens, Rebecca McWhite, and LaChelle Calloway and building on the widely adopted SP 800-161 Revision 1, the guide organizes supplier due diligence around five factors: Foreign Ownership, Control, or Influence; Provenance; Resilience; Foundational Cyber Practices; and Supply Chain Tiers.[17] It asks organizations to define their own systems of trust: which countries are considered low, moderate, or high risk; how much foreign exposure the organization can tolerate in critical suppliers; and how to balance limited supplier diversity against concentration risk.

These categories can be translated directly into AI infrastructure procurement.

Before buying a critical component, an operator should understand who controls the supplier. It should understand where the product comes from. It should understand whether the supplier can survive disruption. It should understand whether adequate cybersecurity practices exist. And it should understand the deeper supply chain beyond the immediate vendor.

These principles become increasingly important as datacenters evolve into national-scale industrial assets. The future compliance model could therefore combine FCC equipment authorization, NIST supply-chain due diligence, CISA cyber-threat intelligence, Commerce export controls, Department of Energy infrastructure standards, and national-security supply-chain mapping under Executive Order 14415.

No single agency currently embodies Rack Sovereignty. The concept exists at the intersection.


4.3 Defense Supply-Chain Rules Could Become the Template

The defense sector offers the closest analogy.

Executive Order 14415 goes beyond identifying where the finished product was manufactured. It directs supply-chain illumination through an indentured Bill of Materials tracing every component, part, equipment, software element, and material back to raw-material origin; supplier vetting for foreign ownership, control, or influence and sole-source reliance; mandatory risk notification and tracked mitigation; a hard January 1, 2027 cutoff for routine sourcing waivers involving adversary countries; and future regulations prohibiting components from “unreliable foreign suppliers” — all on a 180-day policy clock followed by a 90-day regulatory clock.[18][19]

That model matters because strategic AI infrastructure is increasingly dual use.

The same computing architectures that train consumer models can support scientific simulation, cybersecurity, military planning, intelligence analysis, autonomous systems, logistics, advanced manufacturing, and national laboratories. An AI factory serving civilian applications can therefore simultaneously form part of a country’s strategic computational reserve.

This raises a future policy question: should certain classes of extremely large AI facilities be treated more like ordinary commercial datacenters or more like strategic infrastructure?

The answer does not need to be all or nothing. A small enterprise datacenter should not face the same requirements as a multibillion-dollar cluster capable of training frontier-scale models. Policy could instead use thresholds. Facilities above specified computational capacity, electricity demand, government-contract involvement, or national-security relevance could be subject to stronger component-provenance and resilience requirements. The principle would resemble differentiated regulation already familiar in banking, energy, telecommunications, and defense: the larger the systemic consequence of failure, the stronger the resilience obligation. Banking regulation designates systemically important financial institutions; AI infrastructure policy may eventually designate systemically important computational facilities.


4.4 Hyperscalers Could Become Their Own Supply-Chain Intelligence Agencies

Amazon, Microsoft, Google, Meta, Oracle, xAI, and other hyperscale infrastructure developers increasingly operate at a scale where ordinary procurement departments may no longer be sufficient.

A company building $200 billion of annual capital projects — Amazon’s 2026 guidance — cannot simply ask whether a component is inexpensive and available.[28][29] It must anticipate geopolitical interruption. Investors are already forcing the discipline: when Alphabet raised its 2026 capex ceiling to as much as $205 billion alongside second-quarter earnings, its shares slid 7 percent, and Amazon, Meta, and Microsoft fell in sympathy, underscoring intensified scrutiny of infrastructure investments with uncertain returns.[35] Rising component prices are themselves becoming a line item: Statista estimates that chip-price inflation added as much as $25 billion to Microsoft’s 2026 spending alone.[28]

The hyperscaler of the late 2020s therefore needs capabilities resembling a combination of procurement organization, cybersecurity agency, industrial intelligence unit, commodity trader, utility planner, and geopolitical risk office.

These firms will need to know which suppliers depend on Chinese materials. Which components have eighteen-month lead times. Which parts lack second sources. Which firmware creates remote-access risks. Which suppliers sit on government watchlists — the Pentagon’s Section 1260H list, which added Innolight in June 2026 with procurement consequences phasing in through June 2027, now functions as exactly such a watchlist.[4] Which factories could be affected by a Taiwan Strait crisis. Which logistics corridors would fail during conflict. Which components can be stockpiled. Which systems can be redesigned around alternatives. And which strategic suppliers deserve direct investment.

Nvidia’s optics investments provide one early model. Instead of waiting for market shortages to determine its fate, Nvidia deployed billions of dollars into suppliers whose technologies are essential for scaling future AI networks.[12][13][14] Hyperscalers may increasingly do the same across transformers, power systems, nuclear generation, gas turbines, batteries, optics, cooling, memory, packaging, fiber networks, and other constrained inputs.

Artificial intelligence is turning technology companies into industrial planners. Rack Sovereignty accelerates that transformation. And as Stanford economist Erik Brynjolfsson predicts, the measurement infrastructure to hold these bets accountable is arriving at the same moment:

“In 2026, arguments about AI’s economic impact will finally give way to careful measurement.”

— Erik Brynjolfsson, Director, Stanford Digital Economy Lab, Stanford HAI [32]

What Brynjolfsson forecasts for labor-market dashboards applies equally to infrastructure: the era of unmeasured AI claims — economic or industrial — is ending. Sovereignty, like productivity, is about to be quantified.


4.5 Governors and States Will Eventually Enter the Rack

The politics of AI infrastructure has so far concentrated heavily on land, electricity, water, taxes, employment, and community impact.

But state governments offering billions of dollars of tax incentives for AI factories may eventually ask another question: what exactly is being installed?

This matters because many of the largest infrastructure decisions occur below the federal level. A governor wants investment. A county wants tax revenue. A utility wants a large customer. A community wants jobs. A hyperscaler wants fast permitting. But if the facility eventually becomes part of nationally critical AI capacity, component sourcing may no longer be purely a private procurement decision.

State incentive agreements could eventually include supply-chain disclosure or cybersecurity provisions. Public utilities could establish requirements for remotely connected power equipment — a natural extension of the federal inverter determination into state-jurisdiction distribution systems.[7] Government-funded datacenters could require trusted equipment. State procurement rules could parallel federal Covered List restrictions. Critical-infrastructure programs could require reporting of foreign-controlled operational technologies.

The result would be another example of the Five-Layer AI Economy becoming politically integrated. A governor negotiating a datacenter project is no longer merely negotiating real estate development. That governor may indirectly influence national compute capacity, electricity infrastructure, cyber exposure, water demand, semiconductor demand, and supply-chain resilience.

The rack becomes local politics.


4.6 The SR-BOM as a Policy Tool

The Sovereign Rack Bill of Materials could provide a practical bridge between federal security requirements and corporate infrastructure planning.

Rather than banning entire national categories indiscriminately, policymakers could establish graduated classifications. A component could be categorized by its ability to access sensitive data; send external communications; alter computing operations; control electricity; control cooling; physically interact with equipment; receive remote software updates; or create catastrophic failure if unavailable.

The higher the operational consequence, the higher the required provenance and resilience standard.

This would produce a more sophisticated policy than simple country bans. A passive metal part made in China may present almost no cyber risk. A network-connected controller made anywhere with unverifiable firmware may present substantial risk. Risk should therefore combine origin and function — which is, notably, the direction the FCC’s own definitions already point: the robotics entry turns on connectivity, autonomy, and sensing capability, not merely on nationality.[9]

This also creates a useful principle: the closer a component sits to control, the greater the sovereignty requirement.

A sovereign-rack regime could eventually classify equipment into several trust levels and require multiple sourcing options for the most critical categories. Such a system would not eliminate globalization. It would make dependence visible.

And visibility is the first requirement for resilience.


Section 5: Two Physical AI Systems


5.1 The U.S.–China Split Is Moving Beneath the Model Layer

The public debate over AI bifurcation often concentrates on models.

American companies have OpenAI, Anthropic, Google, Meta, xAI, and other frontier laboratories. China has DeepSeek, Alibaba, Moonshot, Z.ai, Baidu, Tencent, Huawei-linked ecosystems, and many other developers. The resulting competition appears to be about whose model performs better.

But models are only Layer 4.

Rack Sovereignty suggests the more durable bifurcation may occur underneath them. The United States and China could increasingly develop separate ecosystems of accelerators, networking, optical components, power electronics, cloud infrastructure, firmware, industrial software, robots, cybersecurity standards, supply-chain verification, and technical alliances.

The result would not simply be American models versus Chinese models. It would be American-aligned intelligence-production machinery versus Chinese-aligned intelligence-production machinery.

That is a much deeper separation.


5.2 Pax Silica Moves the Contest Toward Alliances

An important sign of this shift appeared on August 14, 2026.

Reuters reported that the United States was preparing to tell dozens of countries they must pick sides in the artificial-intelligence race with China, warning they will be excluded from the U.S.-led AI coalition if they also sign up for Beijing’s competing framework. Washington’s Pax Silica initiative, launched in 2025, is designed around secure supply chains for AI models, semiconductors, and critical minerals; about two dozen countries have joined, including close allies Japan, South Korea, and Australia — and, awkwardly, Kazakhstan, a key critical-minerals source that has also joined China’s coalition. A draft State Department letter to the 35 signatories of June’s “AI Opportunity Statement” declares that Pax Silica membership “cannot be held alongside membership in duplicative initiatives whose expectations conflict with our own,” and urges countries to “choose deliberately.”[23] The trigger was unmistakable: in July, Chinese President Xi Jinping launched a rival World Artificial Intelligence Cooperation Organization, promoting China’s open-weight technology as a challenge to U.S. influence over the sector.[23] A U.S. official put the administration’s position bluntly:

“It’s difficult to see how a country can credibly position themselves as trusted partners in one technology ecosystem while simultaneously signing up for an initiative designed by China to advance a competing vision for AI.”

— Senior U.S. Official, quoted by Michael Martina, Reuters [23]

This development is highly relevant to Rack Sovereignty.

The United States cannot realistically create sovereign AI infrastructure entirely by itself. Taiwan remains fundamental to advanced semiconductor manufacturing — and, as Chris Miller has emphasized, the AI-server and advanced-packaging wave has upgraded Taiwan from a component supplier into a critical R&D partner, deepening rather than diluting its centrality. South Korea matters enormously for memory. Japan possesses critical semiconductor materials, equipment, and industrial capabilities. European firms remain important across lithography, power systems, electrical equipment, photonics, automation, and semiconductor technologies. Australia contributes critical-mineral resources.

The real strategic alternative to dependence on China is therefore not American autarky.

It is an allied rack.

An allied rack would combine trusted production across a coalition whose members retain deep economic interdependence but have sufficiently aligned security interests to reduce coercive vulnerability. This could ultimately turn technical standards into alliance architecture. Membership in an AI industrial bloc may determine which suppliers are trusted, which certifications are recognized, which equipment receives export licenses, which components qualify for government incentives, and which projects receive public financing.

The rack could become a physical manifestation of geopolitical alignment.


5.3 Japan Shows What National AI Infrastructure Can Look Like

Japan provides an early illustration.

On July 16, 2026, Nvidia announced a national AI infrastructure project with Noetra Corp., supported by Japan’s Ministry of Economy, Trade and Industry. The system is planned around 13,750 Vera CPUs and 27,500 Rubin GPUs deployed across 382 Vera Rubin NVL72 racks, delivering approximately 140 megawatts of datacenter capacity on Nvidia’s DSX platform with Spectrum-X Ethernet networking and BlueField DPUs — the computing foundation for Japan’s FRONTia physical-AI program spanning manufacturing, logistics, healthcare, robotics, and digital twins.[24] Noetra itself is a consortium founded by SoftBank, Sony, NEC, and Honda with investment from 44 companies and organizations; the FRONTia project carries ¥387.3 billion (roughly $2.4 billion) in first-year public funding and up to ¥1 trillion (roughly $6.1 billion) over five years, subject to annual stage-gate reviews.[25] Huang framed the project as industrial history repeating at a higher level of abstraction:

“Japan invented modern manufacturing. Now, it is building the AI factories that will power the next industrial revolution.”

— Jensen Huang, Founder and CEO, NVIDIA [25]

This is more than another datacenter.

It represents the convergence of industrial strategy, national compute capacity, advanced semiconductors, physical AI, government policy, and private-sector infrastructure — a governance model that sits deliberately between the American hyperscale model and China’s state-directed ecosystem, blending public R&D funds, an industrial consortium, and open-weight licensing obligations.[25]

Rack Sovereignty adds another dimension. A national AI infrastructure program eventually has to determine not just which GPU architecture it uses but which optical equipment, power systems, cooling systems, storage, networking, firmware, and suppliers are considered trustworthy — and Japan’s planners must also close a very concrete gap: procuring 140 megawatts of reliable electricity before operations begin.

Sovereign AI therefore eventually descends from policy speeches into procurement spreadsheets.

That is where sovereignty becomes physical.


5.4 China Will Build Its Own Sovereign Rack

The United States is not the only country pursuing resilience.

Restrictions can accelerate substitution. If Chinese access to American GPUs, optical systems, software, manufacturing equipment, or other technologies becomes unreliable, China’s strategic response is predictable: develop domestic replacements. Huawei’s expansion from telecommunications equipment into accelerators, cloud infrastructure, networking, software, operating systems, automobiles, and industrial technologies demonstrates the potential direction. Nvidia’s own guidance now assumes zero data-center compute revenue from China — an extraordinary admission that the world’s largest AI-chip company plans around the permanent loss of the world’s second-largest AI market.[26]

China possesses another structural advantage. It has enormous manufacturing ecosystems extending across electronics, power equipment, batteries, renewable energy, telecommunications, robotics, industrial machinery, and materials processing. It shipped roughly 80 percent of the world’s humanoid robots in 2025.[8] It dominates the 800G optical segment.[2] It controls indium phosphide licensing and much of the world’s rare-earth processing.[3][20] And each new American restriction hands Beijing both a grievance and a market-protection subsidy for its domestic champions: China’s pattern of responses — rare-earth controls after chip bans, drone-component restrictions after drone bans, mineral licensing after equipment bans — suggests the reflex is now institutionalized.

The United States therefore should not assume that restrictions permanently prevent technological development. They can also produce forced integration. A Chinese AI ecosystem facing repeated foreign restrictions has increasing incentives to design the full stack domestically.


The ultimate outcome could be two competing rack architectures.

Stack LayerU.S.-Aligned Rack (Pax Silica)China-Aligned Rack
AcceleratorsNvidia Rubin, AMD, hyperscaler custom siliconHuawei Ascend, domestic accelerators
FabricationTSMC (Taiwan/Arizona), Samsung, IntelSMIC and domestic foundries
MemorySK Hynix, Samsung, Micron HBMCXMT and domestic HBM programs
NetworkingNvidia Spectrum-X/NVLink, Broadcom, AristaHuawei networking, domestic Ethernet
OpticsLumentum, Coherent, allied photonicsInnolight, Eoptolink, domestic photonics
Power electronicsEaton, Schneider, Vertiv, Delta; U.S./EU/Japan GaN & SiCChinese inverter and power-semiconductor ecosystem
CoolingAllied liquid-cooling suppliers, OCP designsDomestic liquid-cooling ecosystem
RobotsBoston Dynamics, U.S./allied humanoidsUnitree, AgiBot and successors
Standards & certificationFCC authorization, NIST SP 1326, OCP 800 VDCChinese national standards, WAICO framework
Minerals & substratesAllied sourcing, DPA-secured recovery streamsDomestic mining, refining, and export licensing

Table 5. The emerging bifurcation of the physical AI stack. Neither column is complete or self-sufficient today — the two systems remain deeply interpenetrated — but capital, standards, and policy are pulling them apart layer by layer.


Neither system would be perfectly isolated. Global supply chains resist clean separation: Chinese transceivers contain American DSPs; American transceivers depend on Chinese indium phosphide.[2][3] But the direction could still be toward reduced interoperability.


5.5 Security Versus Speed: The Central American Dilemma

The United States faces a difficult trade-off.

America wants to build AI infrastructure rapidly. America also wants that infrastructure to be secure. Those objectives can conflict.

If Chinese components are inexpensive, high performing, and immediately available, removing them from supply chains can raise costs. Alternative suppliers may need years to expand capacity. Factories must be financed and constructed. Products need qualification. Workers need training. Raw materials need sourcing. Manufacturing yields must improve. Customers need confidence.

Nvidia’s decision to invest $4 billion collectively in Lumentum and Coherent demonstrates the scale of capital that may be required simply to expand one strategically important segment of AI infrastructure — and even that capital buys time measured in years, not quarters.[12][13][14]

The policy objective therefore cannot be maximum exclusion at any cost. Nor can it be maximum buildout regardless of vulnerability.

The rational objective is: Secure Acceleration.

Secure Acceleration means expanding AI capacity while reducing high-consequence strategic dependencies fast enough that security does not become the constraint that stops deployment. This requires sequencing. Identify the most dangerous dependencies. Expand alternatives. Create inventories. Standardize components. Qualify second sources. Invest in domestic and allied production. Then tighten restrictions where justified. The FCC’s consistent design choice — restricting new models while grandfathering the installed base, paired with DoW/DHS conditional-approval valves — is recognizably an attempt at exactly this sequencing.[5][7]

Security without industrial capacity creates shortages. Industrial capacity without security creates vulnerability.

Rack Sovereignty requires both.


5.6 The 2027–2029 Scenario: Procurement Becomes Geopolitics

Over the next two to three years, the strategic AI debate may shift substantially.

A hyperscaler preparing a gigawatt AI campus could begin with a geopolitical risk map. The procurement organization would identify every high-consequence component. Software systems would automatically trace suppliers — the AI-assisted supply-chain illumination that EO 14415 authorizes for the Pentagon will migrate quickly to the private sector.[19] Firmware would require cryptographic attestation. Network devices would operate under zero-trust policies. Remote-management pathways would be isolated. Strategic spare inventories would be geographically distributed. Critical equipment would require second-source qualification. Long-term supply agreements would increasingly resemble energy offtake contracts — Nvidia’s capacity-rights deals with Lumentum and Coherent are the prototype.[12][13] Governments would offer financing to domestic and allied component manufacturers. Security agencies would publish trusted-vendor categories. Insurers and lenders could incorporate component concentration into project risk. Datacenter financing documents could eventually contain supply-chain covenants.

That last possibility is important.

Once AI factories cost tens of billions of dollars, their lenders care whether those factories can continue operating. If a $20 billion infrastructure asset can be impaired by a $50,000 controller that cannot be replaced, the controller becomes financially material. With the four largest hyperscalers alone committing roughly three-quarters of a trillion dollars in a single year — and Goldman Sachs modeling $7.6 trillion through 2031 — the pool of capital exposed to component-level geopolitical risk is now among the largest concentrations of infrastructure investment in economic history.[28][29]

Rack Sovereignty therefore does not stop with national security. It can migrate into project finance. Credit underwriting. Insurance. Procurement. Datacenter valuation. Government incentives. Mergers and acquisitions. Corporate strategy.

The sovereign rack becomes an economic institution.


Section 6: What Have We Learned? Seven Pillars of Rack Sovereignty


Pillar 1 — The GPU Is No Longer the Correct Unit of AI Sovereignty

The first lesson is the most important.

The geopolitical discussion about artificial intelligence has concentrated excessively on the accelerator because the accelerator was initially the most visible scarce resource. But advanced AI is transitioning from chip-scale competition toward system-scale competition. Nvidia’s Vera Rubin architecture makes this physical reality difficult to ignore: seven chips, five rack classes, CPUs, GPUs, DPUs, SuperNICs, switches, optical networking, storage, security, power, cooling, and software increasingly operate as one coordinated computing machine assembled by 350-plus factories across 30 countries.[10][11]

Therefore possession of GPUs is necessary but insufficient.

The meaningful question is not how many processors sit inside a country’s borders. It is how much operational intelligence capacity can remain online during disruption. This distinction separates Installed Compute from Sovereign Compute.

The accelerator is the engine. The rack is the machine. And the AI factory is the industrial system.

A national AI strategy that protects only the engine misunderstands how the machine works.


Pillar 2 — Every Connected Component Can Become a Strategic Component

The second lesson is that strategic importance is increasingly determined by connectivity and control rather than merely computational sophistication.

A router can redirect traffic — and PRC state actors have demonstrably modified routers to maintain persistent, long-term access to networks.[22] An optical module can interrupt connectivity. An inverter can influence power flow. A cooling controller can affect thermal operation. A robot can move physically through infrastructure. A management processor can access servers. A firmware update can change component behavior. A telemetry service can transmit operational information.

The divide between “IT equipment” and “industrial equipment” is disappearing. Almost every piece of infrastructure is becoming computational. That means almost every connected component can theoretically enter the cybersecurity perimeter — which is exactly the jurisdictional logic by which the FCC now reaches robots and inverters: they contain embedded radio communication equipment, and therefore they pass through the equipment-authorization gate.[9]

The consequences will be substantial for procurement. Buyers will increasingly care about code signing, remote-access capabilities, supplier ownership, update servers, component provenance, manufacturing geography, vulnerability-management policies, and replacement support.

The future trusted supplier will not merely offer the lowest price. It will offer verifiable control.


Pillar 3 — AI Security Is Moving from Export Control to Import Security

The third lesson is geopolitical.

For years, the major U.S. policy question was how to stop advanced American technology from strengthening Chinese AI capabilities. Rack Sovereignty introduces the inverse: how should the United States prevent potentially risky foreign technology from becoming deeply embedded in American AI infrastructure? The shift is visible across drones, routers, power inverters, robots, and now proposed optical-transceiver restrictions.[1][5][7]

This represents the transition:

Export Control → Import Security → Infrastructure Assurance.

Export control protects technological advantage. Import security protects domestic infrastructure. Infrastructure assurance attempts to guarantee that critical systems can remain trusted and operational under geopolitical stress. Those functions will increasingly converge. Future technology policy may therefore operate simultaneously at the border in both directions: governments will determine which advanced technologies may leave the country and which strategic technologies may enter it.

The AI economy becomes a two-way customs regime for intelligence infrastructure.


Pillar 4 — Provenance and Replaceability Will Become Corporate Assets

The fourth lesson concerns business strategy.

Supply-chain visibility was once regarded primarily as a procurement-management problem. Rack Sovereignty turns it into a competitive asset. A hyperscaler that knows exactly where its critical components originate can manage disruption better. A datacenter with multiple qualified suppliers can recover faster. A company with secure firmware processes can reduce cyber exposure. A manufacturer with domestic or allied production can benefit when governments tighten restrictions — the single-day stock surges of Lumentum, Coherent, and Applied Optoelectronics on August 4 were the market pricing exactly this premium in real time.[3] A supplier with transparent provenance can become more valuable than an otherwise cheaper competitor.

This suggests that provenance itself may acquire economic value.

The SR-BOM could eventually become analogous to a financial balance sheet for physical infrastructure. Investors examine debt. Lenders examine cash flow. Regulators examine compliance. Insurers examine catastrophe exposure. Future AI infrastructure investors may examine supply-chain sovereignty.

This could produce an entirely new category of corporate reporting. How much of the datacenter’s critical equipment has only one supplier? How much comes from adversarial jurisdictions? What is the average replacement lead time? How much spare inventory exists? Which systems require cloud connections? Which suppliers control firmware? How much capacity could remain online after a major trade rupture?

Those questions convert geopolitical resilience into measurable corporate value.


Pillar 5 — Energy and Materials Are Re-Entering the Heart of Technology Policy

The fifth lesson reaches below the datacenter floor.

The 800 VDC transition makes power electronics part of the computer;[15][36] the inverter determination makes grid-edge devices part of the national-security perimeter;[7] the July 30 Defense Production Act determination makes even recyclable magnet scrap and battery black mass instruments of defense policy;[20][21] and the copper arithmetic of megawatt racks — 200 kilograms of busbar per rack under legacy voltages, 200,000 kilograms per gigawatt campus — reconnects the AI boom to the oldest commodities in industrial history.[15]

The lesson is that technology policy is being re-materialized. For three decades, digital policy could largely ignore matter: software scaled without smokestacks. The AI factory ends that abstraction. Electricity, copper, gallium, indium phosphide, rare-earth magnets, transformers, and cooling water are now inputs to intelligence production, and every one of them carries its own geography, its own chokepoints, and its own politics. A complete Rack Sovereignty strategy therefore runs from the model weights at the top of the stack to the mineral rights at the bottom.


Pillar 6 — Alliances Are Becoming Supply Chains, and Supply Chains Are Becoming Alliances

The sixth lesson is diplomatic.

Pax Silica formalizes what the component-level record already implies: the United States is organizing its AI strategy around a coalition-scale supply chain — models, semiconductors, and critical minerals inside one framework — and is prepared to make membership exclusive.[23] Japan’s Noetra project shows the same logic operating in the opposite direction: an ally converting access to the American-aligned rack architecture into a national industrial program, with METI funding, consortium governance, and open-weight obligations layered atop Nvidia hardware.[24][25]

The strategic consequence is that trust is becoming a tradable industrial input. Certification regimes, covered lists, conditional approvals, and coalition memberships now function like tariff schedules for confidence. A country’s position inside or outside the trusted perimeter will increasingly determine which components its factories can sell, which AI infrastructure its firms can build, and which computing capacity its government can rely upon in a crisis.

Alliance architecture and rack architecture are converging into a single design problem.


Pillar 7 — The AI World May Divide Through Hardware Before It Divides Through Intelligence

The seventh lesson is the most consequential.

Many analysts imagine AI bifurcation as a competition between American and Chinese models. But models remain relatively portable. Weights can be copied. Algorithms diffuse. Research spreads. Engineers move. Open models accelerate knowledge transfer — indeed, China’s July 2026 launch of the World Artificial Intelligence Cooperation Organization is explicitly built on exporting open-weight models.[23]

Physical infrastructure is harder to replicate. Factories take years. Power plants take years. Optical manufacturing takes 12 to 24 months merely to add marginal capacity.[3] Semiconductor fabs cost tens of billions of dollars. Transformer factories have limited capacity. Grid infrastructure has long development cycles. Specialized materials come from concentrated supply chains.

Hardware therefore creates deeper path dependency than software.

The true long-term division of the AI economy may consequently emerge first underneath the model. One bloc builds intelligence using one trusted hardware architecture. Another bloc builds intelligence using another. Standards diverge. Supply chains separate. Firmware ecosystems differ. Government certifications diverge. Capital flows toward different suppliers. AI factories become physically aligned with geopolitical blocs.

At that point, the world will not merely have American AI and Chinese AI.

It will possess increasingly different industrial systems for manufacturing intelligence.

That is the ultimate implication of Rack Sovereignty.


Conclusion: Who Controls Everything That Makes the GPU Work?

Artificial intelligence began as a software story. Then it became a semiconductor story. Then it became a datacenter story. Now it is becoming an industrial-system story.

The transition is visible everywhere.

Nvidia no longer describes its future merely through faster individual GPUs. Vera Rubin is a rack- and pod-scale architecture integrating computation, networking, photonics, storage, security, and infrastructure, with hundreds of companies across more than 350 factories involved in bringing that ecosystem into production, and with Spectrum-X Ethernet Photonics in production on the road to million-GPU factories.[10][11]

Power architecture is changing as rack densities rise toward levels that would have been extraordinary for conventional datacenters. Nvidia is promoting an 800 VDC architecture designed for future megawatt-class Kyber racks, coordinated through the Open Compute Project with Microsoft, Google, and more than 80 ecosystem companies, making electrical equipment inseparable from computing architecture.[15][16][36]

Optical networking is becoming important enough that Nvidia committed $2 billion each to Lumentum and Coherent to expand advanced optics, future capacity, research, and U.S.-based manufacturing.[12][13][14]

At the same time, Washington’s security perimeter is expanding. Foreign drones entered the Covered List in December 2025. Foreign-produced consumer routers followed in March 2026, subject to a conditional-approval regime.[5][6] Connected power inverters and foreign humanoid and quadruped robots entered the perimeter on July 28, 2026.[7][8][9] Then, on August 4, attention turned directly toward Chinese datacenter components, particularly optical transceivers.[1] Meanwhile, NIST finalized supply-chain due-diligence guidance emphasizing foreign control, provenance, resilience, cybersecurity, and deeper supply-chain tiers;[17] the White House ordered extensive supply-chain mapping and indentured Bills of Materials for critical defense procurement;[18] a Presidential Determination extended Defense Production Act authority down to recyclable critical-mineral scrap;[20][21] and the State Department prepared to ask thirty-five countries to choose a side.[23]

These are not isolated events.

Together they reveal the emerging physical politics of artificial intelligence. The United States is beginning to ask not merely whether it can design the world’s fastest AI processors but whether the infrastructure surrounding those processors can be trusted.

That distinction explains why I chose Rack Sovereignty as the title of this paper. The term deliberately narrows sovereignty from an abstract national ambition to a physical object. A sovereign model sounds powerful. A sovereign cloud sounds secure. A sovereign semiconductor supply chain sounds strategically important. But none of those concepts alone answers the operational question:

Can the intelligence factory actually keep running?

The rack forces that question into the open. Inside the rack, abstract geopolitical strategy encounters the physical world. Electricity must arrive. Voltage must be converted — increasingly at 800 volts direct current. Heat must be removed — increasingly by liquid. GPUs must communicate. Optical signals must travel. Packets must be routed. Storage must remain available. Firmware must remain trustworthy. Management systems must remain secure. Components must be repaired. Replacement parts must exist. Software updates must be authenticated. Suppliers must remain available. And the entire machine must continue operating through market shortages, cyberattacks, sanctions, export controls, diplomatic crises, and potentially conflict.

That is sovereignty measured not in speeches but in uptime.

Rack Sovereignty also provides a bridge across the Five-Layer AI Economy. Layer 1 supplies energy. Layer 2 supplies chips. Layer 3 assembles those resources into intelligence-producing datacenters. Layer 4 consumes that compute to train and operate models. Layer 5 turns those models into applications, autonomous agents, robots, industrial systems, and economic activity.

The rack sits at the hinge.

If the rack fails, electricity cannot become useful compute. If compute fails, the model loses capacity. If the model loses capacity, the application and agentic economy above it becomes constrained. The dependency therefore runs upward — Component → Rack → Cluster → AI Factory → Model → Agent → Economy — and strategic risk runs in exactly the same direction.

This is why an inexpensive component can matter enormously. A government can spend billions subsidizing semiconductor fabs and still discover that a shortage of optics restricts deployment. A hyperscaler can purchase billions of dollars of GPUs and still wait for power equipment. A state can approve a gigawatt datacenter and still lack transformers. A model laboratory can develop extraordinary algorithms and still face networking constraints. A country can possess enormous theoretical compute capacity and still depend on an adversarial supplier for the components that keep that capacity connected, cooled, powered, and maintained.

The AI race therefore cannot be understood from the top of the technology stack alone.

We must look downward. Down into the racks. Down into the power shelves. Down into the network switches. Down into optical modules. Down into cooling controllers. Down into firmware. Down into the factories producing those components. Down into their suppliers. And eventually down into the minerals and materials from which the infrastructure is manufactured — down, in 2026, even into the black mass of recycled batteries and the swarf of machined magnets that the Defense Production Act now guards.[20][21]

That downward movement produces a different conception of AI sovereignty.

It is not economic isolation. It is not an argument that every screw, cable, semiconductor, pump, or connector must be manufactured domestically. Modern AI infrastructure is too complicated and global for that standard to be realistic. Rack Sovereignty instead means possessing enough visibility, trust, diversity, substitution capacity, operational control, and allied industrial depth that no single external actor can credibly threaten the continued production of intelligence.

The objective is therefore not an American-only rack.

It is an uncoercible rack.

That distinction is crucial. The United States will continue to depend upon Taiwan. It will continue to depend upon South Korea. It will continue to rely on Japan. European electrical, semiconductor, optical, and industrial companies will remain important. Global manufacturing networks will remain economically valuable. But dependence inside an alliance is strategically different from dependence upon a country with which political and military tensions are escalating.

The emergence of Pax Silica makes that logic increasingly explicit. In August 2026, Washington was already signaling that technology cooperation could become tied more closely to geopolitical alignment, with secure AI, semiconductor, and critical-material supply chains forming part of the emerging coalition architecture — and with the price of admission being an exclusive commitment.[23]

The next stage may therefore involve something larger than semiconductor alliances. It may involve AI infrastructure alliances. Countries could coordinate trusted vendors. They could recognize one another’s component certifications. They could co-finance optical fabs. They could expand transformer manufacturing. They could secure critical-mineral supplies. They could develop common cybersecurity standards. They could maintain emergency component reserves. They could standardize rack architectures — the Open Compute Project’s 800 VDC work is a prototype of exactly this kind of allied standardization.[16] They could jointly qualify alternative suppliers. They could coordinate export restrictions. They could establish rules for firmware provenance. They could construct national and allied computing reserves. And they could make the ability to manufacture and sustain AI infrastructure part of collective economic security.

China is likely to respond with its own industrial ecosystem. Indeed, repeated restrictions increase China’s incentive to do so. A country denied reliable access to foreign GPUs eventually develops domestic accelerators. A country denied foreign networking builds domestic networking. A country facing restrictions on optics invests in optics. A country threatened with power-electronics restrictions strengthens power electronics. The consequence may not be technological isolation of China. It may be the accelerated construction of an alternative physical AI stack — one already anchored in 80 percent of the world’s humanoid robots, two-thirds of its optical transceiver units, and commanding positions in the minerals beneath both.[2][8]

Thus the most important long-term outcome of the current technology conflict may not be that one country permanently prevents the other from acquiring artificial intelligence. It may be that both countries gradually construct different machines for producing it.

That possibility returns us to the title.

Rack Sovereignty fits because the rack represents the point where national AI ambition becomes physical. A GPU can be smuggled. A model can be downloaded. An algorithm can be copied. A paper can be reproduced. A software framework can spread globally overnight.

But an industrial ecosystem cannot be downloaded. A power system cannot be copied with a keystroke. A photonics factory cannot be reproduced overnight. A transformer cannot be transmitted across the internet. A cooling plant cannot be reverse-engineered into existence instantly. A semiconductor supply chain cannot be conjured by possessing its design files.

Physical infrastructure has geography. It has factories. It has labor. It has lead times. It has electricity requirements. It has materials. It has maintenance. It has suppliers. It has political jurisdictions. It has vulnerabilities.

That physical reality may ultimately determine who can convert artificial intelligence from software capability into durable economic power.

For the first phase of the AI race, policymakers asked: Who owns the chips?

For the second phase, they asked: Who owns the datacenters?

The next phase will demand a much more granular question:

Who controls everything that makes those chips and datacenters actually work?

The answer lies inside the rack.

And that is why the coming contest is not merely about semiconductor sovereignty, model sovereignty, cloud sovereignty, or even compute sovereignty.

It is about Rack Sovereignty.


Footnotes / Endnotes:

[1]  Michael Martina, David Shepardson et al., Reuters — “US mulling ban on key Chinese networking tech in data center component crackdown” (coverage via Tom’s Hardware, August 4–5, 2026). https://www.tomshardware.com/tech-industry/data-centers/us-mulling-ban-on-key-chinese-networking-tech-in-data-center-component-crackdown-white-house-wants-to-impose-restrictions-in-2026-china-says-it-will-respond-if-necessary

[2]  Counterpoint Research — “Innolight, Coherent, Lumentum: Who Wins and Loses in the Proposed FCC Ban on Chinese Transceivers?” (August 2026). https://counterpointresearch.com/en/insights/fcc-china-ban-ai-component

[3]  TechTimes — “FCC Transceiver Ban Would Cut 60% of AI Data Center Supply; Western Replacements Need Chinese Indium” (August 5, 2026). https://www.techtimes.com/articles/323104/20260805/fcc-transceiver-ban-would-cut-60-ai-data-center-supply-western-replacements-need-chinese-indium.htm

[4]  MLQ News — “FCC weighs ban on new Chinese optical transceivers used in AI data centers” (August 2026). https://mlq.ai/news/fcc-weighs-ban-on-new-chinese-optical-transceivers-used-in-ai-data-centers/

[5]  Federal Communications Commission — “FACT SHEET: FCC Updates Covered List to Include Foreign-Made Consumer Routers” (March 23, 2026). https://docs.fcc.gov/public/attachments/DOC-420034A1.pdf

[6]  Wiley Rein LLP — “FCC Adds Foreign-Produced Consumer-Grade Routers to Covered List” (March 24, 2026). https://www.wiley.law/alert-FCC-Adds-Foreign-Produced-Consumer-Grade-Routers-to-Covered-List

[7]  Federal Communications Commission — “FACT SHEET: FCC Updates Covered List to Include Foreign-Produced Advanced Robotic Devices and Power Inverters” (July 28, 2026). https://docs.fcc.gov/public/attachments/DOC-423682A1.pdf

[8]  Sara Mosqueda, ASIS Security Management — “In the Doghouse: FCC Bans New Foreign-Made Humanoid, Quadruped Robots” (August 2026). https://www.asisonline.org/security-management-magazine/latest-news/today-in-security/2026/august/FCC-Bans-Humanoid-Quadruped-Robots/

[9]  Skadden, Arps, Slate, Meagher & Flom LLP — “FCC Updates Covered List to Include Foreign-Produced Advanced Robotic Devices and Power Inverters on National Security Grounds” (August 2026). https://www.skadden.com/insights/publications/2026/08/fcc-updates-covered-list-to-include-foreign-produced-advanced-robotic-devices

[10]  NVIDIA Newsroom — “NVIDIA Vera Rubin Ramps Into Full Production to Power Agentic AI Factories Worldwide” (GTC Taipei, May 31, 2026). https://nvidianews.nvidia.com/news/vera-rubin-full-production-agentic-ai-factory

[11]  NVIDIA Newsroom — “NVIDIA Vera Rubin Opens Agentic AI Frontier” (GTC 2026). https://nvidianews.nvidia.com/news/nvidia-vera-rubin-platform

[12]  NVIDIA Newsroom — “NVIDIA Announces Strategic Partnership With Lumentum to Develop State-of-the-Art Optics Technology” (March 2, 2026). https://nvidianews.nvidia.com/news/nvidia-announces-strategic-partnership-with-lumentum-to-develop-state-of-the-art-optics-technology

[13]  NVIDIA Newsroom — “NVIDIA and Coherent Announce Strategic Partnership to Develop Optics Technology to Scale Next-Generation Data Center Architecture” (March 2, 2026). https://nvidianews.nvidia.com/news/nvidia-and-coherent-announce-strategic-partnership-to-develop-optics-technology-to-scale-next-generation-data-center-architecture

[14]  Ryan Browne, CNBC — “Nvidia to invest $4 billion into photonics companies Coherent and Lumentum” (March 2, 2026). https://www.cnbc.com/2026/03/02/nvidia-investment-coherent-lumentum.html

[15]  NVIDIA Technical Blog — “NVIDIA 800 VDC Architecture Will Power the Next Generation of AI Factories”. https://developer.nvidia.com/blog/nvidia-800-v-hvdc-architecture-will-power-the-next-generation-of-ai-factories/

[16]  Data Center Dynamics — “Nvidia prepares data center industry for 1MW racks and 800-volt DC power architectures” (June 2026). https://www.datacenterdynamics.com/en/news/nvidia-prepares-data-center-industry-for-1mw-racks-and-800-volt-dc-power-architectures/

[17]  Jon Boyens, Rebecca McWhite, LaChelle Calloway, NIST — Special Publication 1326, “NIST Cybersecurity Supply Chain Risk Management: Due Diligence Assessment Quick-Start Guide” (Final, July 8, 2026). https://csrc.nist.gov/pubs/sp/1326/final

[18]  The White House — Executive Order 14415, “Securing America’s Defense Supply Chains and Ensuring Domestic Acquisition of Critical Materials” (July 20, 2026). https://www.whitehouse.gov/presidential-actions/2026/07/securing-americas-defense-supply-chains-and-ensuring-domestic-acquisition-of-critical-materials/

[19]  Wiley Rein LLP — “New Executive Order Expands Supply Chain Due Diligence for Defense Contractors” (July 2026). https://www.wiley.law/alert-New-Executive-Order-Expands-Supply-Chain-Due-Diligence-for-Defense-Contractors

[20]  The White House — Presidential Determination No. 2026-19, “Presidential Determination Pursuant to Section 101 of the Defense Production Act of 1950, as Amended, on Recoverable Critical Minerals and Materials” (July 30, 2026). https://www.whitehouse.gov/presidential-actions/2026/07/presidential-determination-pursuant-to-section-101-of-the-defense-production-act-of-1950-as-amended-on-recoverable-critical-minerals-and-materials/

[21]  Bureau of Industry and Security, Federal Register — “DPAS Directive Allocation Order and Additional Requirements for Recoverable Critical Minerals and Materials” (August 6, 2026). https://www.federalregister.gov/documents/2026/08/06/2026-16078/dpas-directive-allocation-order-and-additional-requirements-for-recoverable-critical-minerals-and

[22]  CISA, NSA, FBI and international partners — Joint Cybersecurity Advisory AA25-239A, “Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System” (August 27, 2025). https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a

[23]  Michael Martina, Reuters (via CNBC) — “U.S. to tell partners they must pick sides in AI race with China” (August 14–15, 2026). https://www.cnbc.com/2026/08/15/us-to-tell-allies-they-must-pick-sides-in-ai-race-with-china-reuters.html

[24]  NVIDIA Newsroom — “Japan Government, Industrial Leaders and NVIDIA Launch the World’s First National AI Infrastructure” (July 16, 2026). https://nvidianews.nvidia.com/news/japan-government-industrial-leaders-and-nvidia-launch-the-worlds-first-national-ai-infrastructure

[25]  Mark Tyson, Tom’s Hardware — “Nvidia and Japan unveil world’s first national AI infrastructure — Noetra consortium to build a 140MW Rubin AI factory with 27,500 GPUs” (July 16, 2026). https://www.tomshardware.com/pc-components/gpus/nvidia-and-japans-noetra-consortium-to-build-140mw-rubin-ai-factory-with-27500-gpus

[26]  NVIDIA Corporation — CFO Commentary on Fourth Quarter and Fiscal 2026 Results (SEC Form 8-K, February 2026). https://www.sec.gov/Archives/edgar/data/1045810/000104581026000019/q4fy26cfocommentary.htm

[27]  Tech Insider — “Nvidia Earnings 2026: $81.6B Record Quarter” (Q1 FY2027 results, May–June 2026). https://tech-insider.org/nvidia-earnings-81-billion-quarter-2026/

[28]  Statista — “Big Tech’s AI Spending to Reach $760 Billion in 2026” (Q2 2026 earnings analysis, July 2026). https://www.statista.com/chart/35046/capital-expenditure-of-meta-alphabet-amazon-and-microsoft/

[29]  Brian Sozzi, Yahoo Finance (citing Goldman Sachs Research) — “Meta, Microsoft, Amazon, and Alphabet are about to spend a shocking amount of money to dominate the AI era” (June 2026). https://finance.yahoo.com/sectors/technology/article/meta-microsoft-amazon-and-alphabet-are-about-to-spend-a-shocking-amount-of-money-to-dominate-the-ai-era-115359575.html

[30]  Carnegie Mellon Institute for Strategy & Technology — “Chips and Chokepoints: Chris Miller on the Geopolitics of the AI Supply Chain” (March 2026). https://www.cmu.edu/cmist/news-archive/news/2026/march/chips-and-chokepoints-chris-miller-on-the-geopolitics-of-the-ai-supply-chain.html

[31]  Chris Miller, interviewed by Ondrej Burkacky, McKinsey & Company — “Author Chris Miller on the global influence of semiconductors”. https://www.mckinsey.com/industries/semiconductors/our-insights/author-chris-miller-on-the-global-influence-of-semiconductors

[32]  Stanford Institute for Human-Centered Artificial Intelligence (HAI) — “Stanford AI Experts Predict What Will Happen in 2026” (Erik Brynjolfsson contribution). https://hai.stanford.edu/news/stanford-ai-experts-predict-what-will-happen-in-2026

[33]  Schneider Electric — “NVIDIA and Schneider Electric get in sync at NVIDIA GTC 2026 to deliver Vera Rubin AI Factories” (May 2026). https://blog.se.com/datacenter/2026/05/08/nvidia-and-schneider-electric-get-in-sync-at-nvidia-gtc-2026-to-deliver-vera-rubin-ai-factories/

[34]  John Koetsier, Forbes — “United States Bans Chinese Humanoid And Quadruped Robots, Citing National Security” (July 28, 2026). https://www.forbes.com/sites/johnkoetsier/2026/07/28/united-states-bans-chinese-humanoid–quadruped-robots-citing-national-security/

[35]  CNBC — “Amazon, Meta and Microsoft face skeptical investors this week after Google report sparked sell-off” (July 28, 2026). https://www.cnbc.com/2026/07/28/hyperscalers-face-higher-capex-scrutiny-after-alphabet-report-panned.html

[36]  NVIDIA — “800 VDC Architecture for AI Data Centers” (technology overview). https://www.nvidia.com/en-us/data-center/technologies/800-vdc-architecture/

[37]  Baker McKenzie — “United States: FCC Adds Foreign-Made Routers to Covered List” (April 2026). https://www.bakermckenzie.com/en/insight/publications/2026/04/united-states-fcc-adds-foreign-made-routers-to-covered-list