Six months after Iranian drones hit AWS facilities in Bahrain and the UAE, AWS is asking customers to migrate to other countries, exposing a single region risk in the AI build out.
Six months after Iranian drones hit Amazon's data centers in the UAE and Bahrain, AWS is telling customers it cannot restore their workloads, and is asking them to migrate to other countries. The company's regional redundancy was designed to absorb a single data center going down. It was not designed to absorb correlated damage across multiple availability zones in one country, the failure pattern that hit Bahrain and the UAE in March and again in April.
An availability zone is a cluster of data centers inside a single AWS region, physically separated to ride out localized failures but close enough to act as one logical site. Multi-AZ redundancy is sold as protection against a single data center going down. The September 15 update is the first time a major cloud provider has publicly told customers to migrate to a different country because of wartime damage. Reuters reported the company's statement that it was "unable to restore access to the resources and data hosted" on the affected zones (Reuters). AWS's own language is more careful than some of the coverage. Ars Technica's headline used the phrase "permanent loss of customer data" (Ars Technica), but the company has not made that blanket claim. The September 15 update said only that AWS was "unable to restore access," which is a serious admission and is not the same as a claim that every record is gone.
The initial strikes hit AWS facilities in the UAE and Bahrain in March 2026, with a second wave in April. According to AWS, the strikes caused "structural damage, disrupted power delivery to our infrastructure, and in some cases required fire suppression activities that resulted in additional water damage" (CNBC). The recovery window closed without restoration. CNBC's coverage framed the timeline as "6 months after Iran strikes" (CNBC). AWS's usual playbook after a regional incident is to bring zones back online, not to tell customers to leave the region entirely.
The event is reshaping AI infrastructure math. Gulf states have been the fastest-growing destination for AI data center build-out, drawn by cheap power, available land, and state-backed investment incentives. Putting a 500-megawatt training cluster on that land assumes the political geography stays quiet. The Insurance Journal's coverage of the AWS update and the broader risk picture puts the event in the context of insurance and war-risk liability for cloud infrastructure (Insurance Journal). Rest of World's reporting traces the human and operational fallout for customers who had built around Gulf availability (Rest of World).
For customers, the practical question is contractual. Standard cloud contracts put the recovery burden on the customer, with service credits as the main remedy for outages. AWS's recommendation to migrate to other regions, not just other AZs, implies the recovery path is not "wait for the next zone to come back." It is a multi-month, multi-country migration. CryptoBriefing's coverage notes the same concentration risk for crypto firms that had built out in the region (CryptoBriefing). AWS has not published a customer count or a record count for the loss. The damage is reported at the zone and service level, not in records or dollars. Until AWS publishes a regional incident report, the scale of the loss is unrecoverable in the same sense as the data: it is not visible in any disclosure.
The September 15 update will be measured against the next round of Gulf investments. If hyperscalers keep adding capacity in the UAE and Bahrain at the same pace, the update will read as a warning nobody acted on. If they start siting the next wave of 500-megawatt clusters further from active conflict zones, the geography of AI infrastructure will start to follow the geography of the risk.