The GPU lease used to be a shopping problem: how much compute, how soon, and how badly the invoice would haunt finance. Now the sharper question is whether the provider holding your training run is also holding the next incident report. SemiAnalysis has put a flare over an uncomfortable truth for AI teams racing to rent capacity: neocloud security is becoming part of the AI infrastructure supply chain. The GPUs may be shiny, but the trust boundary is doing unpaid overtime. ## What happened: the GPU lease became a trust boundary SemiAnalysis frames the issue in a piece titled Most Neoclouds Suck At Security, which explicitly ties the topic to OpenAI vs HuggingFace, container escapes, kernel bypass, network policies, security keys, multi-tenant Grafana, and a ClusterMAX 3.0 preview. According to SemiAnalysis, the largest AI companies are building a multivendor infrastructure supply chain at high speed, and every new vendor becomes counterparty risk, including subcontractors and subprocesses that need to be checked. That is the part procurement decks tend to render in tasteful gray text, right before security inherits the blast radius. The useful shift here is that the conversation moves from generic cloud confidence to concrete diligence. SemiAnalysis says its ClusterMAX 3.0 testing surfaced security horror stories and five frightening patterns across neocloud environments. The evidence provided does not disclose those patterns in full, so the responsible read is narrower and more actionable: the named areas in the SemiAnalysis framing should become buyer questions before a team moves sensitive workloads. ## What was exposed: diligence gaps, not just machines SemiAnalysis names the technical neighborhoods that should make any AI infrastructure buyer sit up straighter: multi-tenant isolation, container escapes, kernel bypass, network policies, security keys, and multi-tenant Grafana. I am not going to invent a neat little exploit chain here, because that is how security theater gets a cape and a LinkedIn post. The point is simpler and more durable: if a provider cannot explain how it handles these areas, the missing answer is itself useful evidence. That matters because AI workloads concentrate valuable things in one place: models, data pipelines, credentials, experiments, and the operational habits of teams moving too fast. SemiAnalysis says neolab CISOs are getting a seat at the negotiating table because serious customers are taking security seriously. Good. Security should be in the room before the contract is signed, not after someone discovers that the incident response plan was vibes in a PDF trench coat. ## Why the blast radius travels through partners SecurityAffairs reports that third-party access remains a weak link in supply chain security, citing a Thales Digital Trust Index report, Third-Party Edition, that found 51% of surveyed professionals keep access to partner systems for days or even a month after they no longer need it. SecurityAffairs also describes weak authentication, exceptions, delayed revocation, stale permissions, and long-lived sessions as ways everyday collaboration can quietly accumulate risk. That is not exotic. That is Tuesday, wearing a badge that says contractor. This is why the neocloud question is not just whether a provider has enough GPUs. It is whether its access model, tenant boundaries, network controls, key practices, and monitoring boundaries are mature enough for the work you are putting there. Threat actors do not need character development when the plot hands them a trusted third party with loose controls. They simply follow the dependency graph and let everyone else explain later that lessons were learned. ## What it actually means for you The practical translation from SemiAnalysis and SecurityAffairs is this: treat neoclouds like critical suppliers, not temporary compute vending machines. Ask how the provider checks subcontractors and subprocesses, how it governs access, how quickly unnecessary partner access is revoked, and how it can show evidence for controls in the areas SemiAnalysis names. If the answer is mostly adjectives, keep digging. Adjectives do not isolate tenants. For builders, the next move is to add security gates to AI infrastructure selection before workloads land. For security teams, the opportunity is to turn vague third-party risk into specific contract language, audit requests, access limits, and incident notification expectations. The AI infrastructure race is not slowing down, but buyers can still make speed less radioactive. Watch whether neocloud vendors begin publishing clearer security evidence, because in this market, the provider that can prove trust may become more valuable than the one that merely has inventory. ## Sources - Most Neoclouds Suck At Security

Sources