🎧 ▶ Listen: 5-minute briefing
▶ Play audiobook (Google Drive)
Locally synthesized AI audiobook (Qwen3-TTS)

If you run an AI data center or build services on top of one, the most expensive risk of the first half of 2026 has shifted. It is no longer about which model you choose, but about how you protect the infrastructure itself. This year’s news has quietly pointed to one conclusion: as AI’s value moved from the model down to the infrastructure, the thieves after that infrastructure arrived right along with it.

An image visualizing the concept of 3.2 kilometers of copper in a single GB200, and why thieves came for the data center A visual representation of the article’s core concept.

How a Single Cable Became a Strategic Resource

The most symbolic scene came from copper. A single Nvidia GB200 rack contains roughly 3.2 kilometers, about 2 miles, of copper cabling. With thousands of data centers going up simultaneously around the world right now, that demand flipped the supply and demand outlook for the refined copper market within a single year. According to figures reported by Global Economic, the 2026 forecast reversed sharply from a 209,000 ton surplus to a 150,000 ton deficit. Copper has been re-rated from a raw material into a strategic resource.

When prices rise, thieves follow. The problem is that the nature of these thieves has changed. Where cable theft used to be small-scale, subsistence crime, it has now evolved into industrial organized crime: cutting large volumes of cable in a short time with professional cutting equipment, then laundering it through global scrap distribution networks and smuggling it out. In the United States, high-value IT assets such as servers, storage, and even cryptocurrency mining rigs have become targets of cargo theft. In effect, the entire physical asset base that makes up AI infrastructure has been absorbed into a new criminal market.

What makes this scene unsettling is that the technology we consider the most advanced is exposed to one of the oldest crimes there is. The availability of a GPU cluster worth tens of billions of won can be shaken by a single pair of cutters slipping over a substation fence at night. The more a world is defined by software, the simpler and more stealable the physical layer underneath it becomes.

Korea is no exception. As data center and power grid expansion accelerates in a rush, physical security, an item that had not been given much attention until now, has resurfaced. Measures such as physical intrusion detection along buried cable routes, tracing the distribution history of scrap copper, and reinforcing sensors and CCTV around substations and base stations have actually begun to be discussed. Regional industrial complexes and outlying sites on the edge of the capital area, where new data centers are concentrated, tend to have relatively thin security staffing, which raises the likelihood that they become targets of the kind of industrial-scale theft already seen overseas. The spike in copper prices itself is also pushing up construction costs, affecting the timeline for expanding GPU clusters. In other words, the risk of physical asset theft has become a variable that now shakes both service availability and cost.

Why the Value Moved Down to Infrastructure

Behind the arrival of thieves at infrastructure is a movement of capital. Just looking domestically, the three telecom carriers and big tech companies are pouring in trillion-won-scale investments. SK Telecom set up a dedicated AI data center subsidiary and has signaled roughly 140 trillion won in spending, including foreign capital, for a 2GW facility in the Yeongnam region, while KT said it would secure 1GW of capacity with 5 trillion won over five years. Naver is pushing forward a 14 trillion won data center. LG Uplus fully pre-sold an entire building at its Paju site while construction progress stood at just 20 percent. The fact that real demand in the form of server contracts is piling up ahead of groundbreaking itself means that AI computing capacity is already sold out before it even becomes a product to sell.

Government-level momentum is layered on top of this. An announcement came that President Lee Jae-myung’s sales diplomacy tour wrapped up with $950 billion worth of AI investment commitments. If that capital is actually deployed, it will push domestic data center, power, and workforce demand up another notch.

An interesting side effect emerges here. When supply is fundamentally scarce and only operators who have power, land, and cooling technology all at once can capture real demand first, most companies gain a stronger incentive to lease capacity from already-proven operators or pivot to indirect access through cloud and MSPs rather than building their own data centers. The sellout at 20 percent construction progress in the LG Uplus case is exactly the sign of that tilt. In other words, the more value concentrates in a handful of large facilities, the more important the software layer that shares out those resources actually becomes. Even when physical assets are monopolized by a few players, orchestrating them so that multiple customers can share them safely remains a separate problem.

Wherever value concentrates, bottlenecks form alongside it. A power story compiled by eToday shows the substance of that bottleneck. No matter how many GPUs you secure, they are useless without a power grid to run them on, and cases are piling up where a nuclear plant takes at least 10 years to complete, or a new data center takes more than 7 years after groundbreaking to actually connect to the power grid. The capacity to manufacture transformers, generators, and cooling equipment has itself become another supply chain bottleneck. Korea has confirmed the construction of two nuclear reactors in Yeongdeok, North Gyeongsang Province, and a small modular reactor in Gijang, Busan, but there isn’t enough time to cover short-term demand. Power and copper both tell the same story in the end: they are scarce resources of the physical world. AI’s center of gravity has shifted down from abstract algorithms to tangible equipment.

The scarcity of power also carries an interesting implication from a defense standpoint. Even as Korea is named a key market for data centers, uncertainty around nuclear power policy and electricity rate structures has been flagged as a source of anxiety for attracting investment. In a phase where how quickly you can supply cheap, stable power decides competitiveness, actual cost comes down not just to how many GPUs you have running, but to how efficiently you run them. The ability to redeploy idle resources and shift workloads during periods of heavy power constraint used to be a secondary optimization just a few years ago, but it is now moving closer to the core of cost competitiveness. The more valuable a resource is, the larger the role software plays in allocating it without waste.

The Second Thief Arrived Through Software

If copper theft is visible theft, invisible theft grew far faster over the same period. In first-half statistics released by the Ministry of Science and ICT and KISA, reported breach incidents reached 1,236 cases, the highest figure in five years. The breakdown shows a clear direction. Server hacking declined, while DDoS attacks surged 56.7 percent and ransomware surged 76.8 percent. That means the center of gravity in attacks shifted from quietly infiltrating a system to paralyzing services and holding data hostage for a double extortion. In second-quarter figures compiled by AhnLab, the share of registered vulnerabilities linked to ransomware also nearly doubled, from 8.5 percent the prior year to 16.0 percent.

What especially stands out is that the government explicitly named supply chain attacks and AI misuse as new threats. Physical theft that cuts cables and supply chain attacks that dig into open source dependencies look like completely unrelated incidents on the surface, but they share a single root. Both target points where value concentrates. Copper gains value inside the rack, and data and computation gain value on top of that rack. Thieves gather wherever value is, regardless of whether it is physical or digital.

So the language of defense has to change too. Perimeter-style security built to block server hacking alone struggles to respond to traffic surges and double extortion. Small and mid-sized companies lack the resources to build their own DDoS defenses and ransomware backup systems, which is likely to concentrate the damage on them. Regulation and certification, such as tightening ISMS-P and expanding discussions of cloud providers’ security responsibility scope, are likely to follow this trend as well.

In multi-tenant environments, this requirement rises a further level. When multiple customers’ workloads run on the same GPU cluster, isolating one tenant’s breach so it does not spread to the tenant next door becomes a condition of trust. This is also why more companies are considering on-premises and sovereign AI as double-extortion ransomware spreads. Where data is kept, how it is backed up, and which namespace it is isolated and operated in have become items reviewed before the model’s performance sheet.

Treating the Execution Environment Like a Vault

By this point the question becomes clear. If value has moved down to infrastructure and thieves are converging from both the physical and digital sides, how should a company treat its own AI execution environment? The answer is simple. Treat it like a vault, the way you would treat any high-value asset. Lock the door, record who did what and when, and control exactly where things are physically located. It is the same principle as a bank not stacking gold bars in just any room. Anything of value should move only within isolated spaces, and every one of those movements should leave a complete record.

This is why ThakiCloud designed Paxis as an Agent-Native Cloud, placing Skills, Tools, Policies, and Audit Logs side by side as first-class resources. Every moment an agent calls a tool or communicates with the outside world is exactly the point that the supply chain attacks and data extortion we just looked at dig into. A structure that runs work inside isolated sandboxes, controls autonomy through policy gates from L0 to L3, and leaves every action in an audit log is not building one more fence. It is making sure that anything of value only moves inside the vault. It is a way of narrowing, at the design stage, the unisolated execution and unaudited access that ransomware targets.

The supply chain attacks the government named as a new threat read through the same lens. In an era where agents pull in external tools, connectors, and skills, every single connection point becomes a supply chain entry. Restricting which skill can call what with which permission through policy, and being able to trace it back through an audit log, is what stops attacks that dig into open source dependencies from spreading inward through the execution environment. Treating connectors and skills as first-class resources is not a decorative convenience. It means controlling for yourself how many supply chain doors you leave open.

The lesson from the physical layer carries over into sovereign infrastructure. Whoever knows where the copper cable is buried and which region the data sits in ultimately holds control. On-premises Kubernetes-based sovereign infrastructure that answers to National Intelligence Service requirements starts its defense from knowing exactly where its own assets physically are. Cost routing, which picks the right model for each task, is a separate problem of cutting waste on top of that foundation, another axis for running resources where value has concentrated as efficiently as possible.

Reduced to one sentence, this year’s signal reads as follows. AI became something valuable, so thieves came, and they did not discriminate between cable and traffic. Competitiveness going forward will not be decided by calling on a bigger model. It will be decided between companies that know how to treat their own execution environment like a vault, and companies that do not.

Sources

This article was compiled from the following news sources.

Tags: agentops, enterprise-ai, paxis, thakicloud

Categories:

Updated: