The AI/semiconductor research newsletter SemiAnalysis tested specialized GPU rental providers serving AI labs and surfaced five recurring security patterns.
The AI buildout has spawned a new layer of specialized GPU-rental providers called neoclouds, distinct from AWS, Azure, and Google Cloud, built to serve AI training and inference workloads. SemiAnalysis put that layer through ClusterMAX 3.0 testing and surfaced what it calls "horror stories": five recurring security patterns that buyers, builders, and operators should read as a procurement problem, not a vendor footnote.
The largest AI companies are stitching together a multivendor infrastructure supply chain at "Mach speed," the publication notes, and each new vendor arrives with its own subcontractors and subprocesses. The risk is repeatable across providers. The piece calls this counterparty risk: any vendor in the stack can become the security weak link, including the vendors that vendor brings with it.
Neolab CISOs, the security chiefs at the AI labs that rent compute from these providers, are gaining a seat at the negotiating table as security becomes a gating concern. ClusterMAX testing runs in three phases (audit, performance, and reliability), and the full criteria are public, so the methodology is auditable.
What remains unknown without full subscriber access is the specifics of the five patterns. The audit names the problem; the buyer-side work is translating those patterns into questions, checks, and contract demands.