NIST is writing the security baseline for AI data centres
· re: AI Data Center Security Analysis: A High-Performance Computing (HPC) Driven Approach (Draft SP 800-239) (NIST CSRC)

If you run storage or AI infrastructure, go read the two draft security guidelines NIST just opened for comment, because the baseline that auditors will quote at you for the next decade is being written right now.
Two drafts, both open. SP 800-209r1, “Security Guidelines for Storage Infrastructure” (comments to 8 September), and SP 800-239, “AI Data Center Security Analysis”, which contrasts AI data centres with traditional supercomputing “across architecture, hardware, software stacks, workflows, and storage systems” to find where the gaps are (comments to 25 September).
My read: the part that matters is not the content, it is that NIST is treating AI data centres and storage as their own security problems, not an afterthought bolted onto network security. That is the right instinct. The blast radius moved to the data layer years ago, where the models train and the objects sit, and most security programs still spend their budget at the perimeter, guarding a door the attacker walked around.
The other thing worth noticing: it is a draft, open for comment. That is the rare window where the people who actually run this infrastructure get to shape the baseline instead of just complying with it, and both windows close in September. If you have opinions about how a governed data centre should be secured (I do, apparently at length), this is where they count.
I would not skim these. Storage and AI infra are exactly the surfaces where “we assumed it was handled” turns into an incident report.