On 29 July 2026, a tribunal in Cape Town cleared Equinix to press ahead with two new data centres in the city’s King Air Industria precinct. Once complete, the facilities are expected to draw close to 170MW of power – not far off the roughly 189MW that Teraco, Africa’s largest data centre operator, currently draws across every campus it runs in South Africa combined.
That is one project, in one part of one city. South Africa now hosts more than 50 operating data centres, with close to R50 billion committed to new capacity over the next three years, most of it clustered around Johannesburg and Cape Town. Every one of these projects is being justified the same way: South Africa’s AI ambitions need somewhere to physically sit. The public debate around each build tends to circle three questions – water use, power draw, and job creation. Almost nobody is asking what happens to the systems running these buildings if someone gets past the login screen rather than the fence.
When the cloud becomes a target
In March, Iranian drones struck Amazon Web Services facilities in the United Arab Emirates and Bahrain, damaging physical infrastructure and disrupting cloud services across the region – the first time in modern conflict that commercial hyperscale data centres became military targets rather than incidental casualties. The World Economic Forum’s response was blunt: it is time to start treating AI infrastructure as critical infrastructure, on the same footing as power stations and ports.
South Africa is by no means at war, but the buildings going up in Cape Town and Johannesburg share the same physical shape as the ones hit in the Gulf: concrete boxes packed with servers, backup generators and cooling plants, sitting on fixed coordinates anyone can look up. Although, that address was never really the point. What makes a data centre a target is what runs inside it – and attacking it doesn’t require a drone. An unpatched control system will do the job just as well, from anywhere in the world.

The cooling system has become part of the attack surface
No physical fence solves this problem. Inside a modern data centre, the systems keeping the servers alive – power distribution, cooling, access control – are themselves networked and computerised.
They are cyber-physical systems, products of increasing IT/OT convergence, carrying the same vulnerabilities as any other connected device on the network they support.
An attacker does not need to breach a server rack to take a facility offline. A manipulated cooling system or a falsified access log can achieve the same goal, with less effort and far less evidence left behind.
AI depends on physical infrastructure
This matters more this year than it did last year. Gartner’s 2026 CIO and Technology Executive Survey found that only 17% of South African and global organisations have deployed AI agents so far, but more than 60% expect to within two years – the fastest adoption curve of any technology the survey tracks. Every one of those agents runs somewhere physical. As organisations hand routine decisions to autonomous systems, the building housing that system stops being IT infrastructure and starts being operational infrastructure, in the same category as the till system in a retail chain or the signalling network on a rail line.
Ports, power stations and telecommunications exchanges have long carried the legal weight that comes with being classified as critical. The buildings now hosting the country’s AI ambitions have not. Until that changes, a breach of the systems running Cape Town’s newest data halls falls under general IT policy rather than critical infrastructure protocol – the same accountability gap Fortinet’s OT practice has flagged for years in ports, water utilities and power stations. The tribunal ruling is a reminder that this one is still open.
- Gary Peel, Cloud Business Development Manager, Southern Africa at Fortinet
