White Paper | AI Data Center & AI Factory Security Blueprint | Check Point Software
White Paper | AI Data Center & AI Factory Security Blueprint
Introduction
The adoption of private AI and LLM (Large Language Model) infrastructures by enterprises introduces a new class of risks. Unlike traditional IT workloads, AI data centers manage sensitive training data, powerful GPU clusters, distributed inference services, and high-throughput pipelines that can easily become attack vectors. Another segment building their own AI factories are Neocloud providers, who deliver GPU-as-a-Service, building hyperscale AI factories powered by NVIDIA and other leading GPU platforms to give enterprises on-demand, high-performance compute for training and inference. Organizations face threats to data, intellectual property, AI models, and end-users. Building AI capabilities without embedding security increases exposure to poisoning, data leakage, and governance failures. To ensure resilience, AI data centers must be secured end-to-end — from the fabric and GPU clusters to Kubernetes workloads, and API-driven inference workloads and services.
Value Check Point provides for AI Factory Security
Check Point enables organizations to confidently adopt and scale AI by addressing both traditional IT threats and the new, unique risks of AI-driven environments. Check Point solutions based on modern security technologies and integration with advanced 3rd party products, part of the general open-garden strategy; provides embedded cyber security by design to cover all sensitive blocks of AI-Data Center and Private LLMs.
The solution provides layered protection approach from the access towards AI workloads:
- Perimeter Layer Protection – external access control zone, entry point to the AI Data Center fabric, secured by Zero-Trust (ZTNA) enabled Hyper Scale NGFW (Maestro)
- Application Layer Protection – API based security of AI application and Agentic / LLM layer protection which is different from “traditional” API security
- AI-Server Layer Protection – HW embedded NGFW to take security close to the AI workloads, segment servers (DGX) and protect Management traffic.
- Kubernetes Layer Protection – ensure East-West traffic inside K8s cluster visibility and containers micro-segmentation policy enforcement.
High-Level Overview of AI Data Center Architecture
An AI data center is based on model training and inference domains at scale, combining high-performance GPU clusters (e.g., NVIDIA), secure connectivity, and orchestration layers. At the edge, a frontend application layer with API gateways, load balancers, firewalls, and WAFs manages and protects user and application traffic, while a dedicated management layer hosts DevOps, SecOps, and control functions over isolated VLANs.
Inference Cluster hosts deployed AI models that process user queries and application requests in real time. It consists typically of GPU-powered DGX servers orchestrated by Kubernetes with Cilium or other K8s CNI technologies. This cluster handles model inference requests, ensuring high-performance execution and efficient resource utilization across distributed nodes.
AI Infrastructure Security Risks
AI infrastructure introduces unique risks that extend beyond traditional IT systems. These risks directly affect the confidentiality, integrity, and availability of sensitive data, models, and applications. Unlike standard data centers, AI environments combine high-performance computing, large-scale data pipelines, and distributed training clusters — all of which create new attack surfaces, regulatory challenges, and risks of misuse.
Key Risks
Infrastructure & Platform Risks
- Compromise of servers, workloads, or system integrity
- Lateral movement through East-West traffic within AI clusters
- Compromise of containers or workloads via malicious libraries from GitHub
- Exploitation of misconfigured FWs, API GW, or exposed MGMT interfaces / DevOps misuse
- API gateway bypass or misuse exposing model endpoints directly
Data & Training Risks
- Training data poisoning creating hidden backdoors
- Unauthorized access or exfiltration of proprietary datasets
Model Risks
- Model poisoning attacks compromising training integrity
- Adversarial attacks causing targeted misclassification
Compliance & Regulatory Risks
- Violations of AI-specific regulations (EU AI Act, U.S. Executive Order 14110)
- Non-compliance with industry frameworks (HIPAA, PCI-DSS, ISO 42001)
AI Security by Design
“AI must be Secure by Design. This means that manufacturers of AI systems must consider the security of the customers as a core business requirement, not just a technical feature, and prioritize security throughout the whole lifecycle of the product, from inception of the idea to planning for the system’s end-of-life.” - CISA, Software Must Be Secure by Design, and Artificial Intelligence Is No Exception.
AI Data Center Generic Security
This design illustrates a typical secure AI data center architecture that separates training and inference clusters while enforcing strict controls across dedicated network zones (Training, Inference, Storage and Management VLANs and segments). The access control is enforced for east-west traffic between clusters and storage, for segmentation and monitoring. Key principles such as AI-aware security, Zero Trust access, and continuous inspection of both API and DevOps traffic ensure that sensitive models, data, and workloads remain protected against tampering, leakage, and misuse.
Check Point AI Data Center Security Architecture
The Check Point AI Data Center Security architecture delivers end-to-end protection for both training and inference domains by tightly integrating network, application, and AI-specific security controls. Check Point embeds AI runtime security and prompt defense in all Check Point firewalls, Check Point WAF, and runs natively in AI Factory Firewall on NVIDIA BlueField DPUs.
Use Cases and Security Components
Use Case Table
| Use Case | Check Point Component | Value |
|---|---|---|
| Segregating Training and Inference Domains and Servers | Check Point NGFW running on DGX BlueField | Reduces risk of lateral movement |
| Zero Trust User and DevOps Access | Check Point Maestro NGFW Security Groups (SGs) | Ensures least-privilege access and improves compliance |
| AI Application Security | Check Point WAF integrated with AI security | Protects AI applications from novel attacks |
| Container and Namespace Segmentation | Check Point integration with Illumio | Prevents unauthorized east–west traffic inside clusters |
Runtime Security for your GenAI
Check Point AI Agent Security provides real-time visibility and control over GenAI applications by intercepting both inputs (prompts) and outputs (generated content).
Protecting Public Cloud AI
In public cloud environments, AI workloads and private LLMs are deployed across managed Kubernetes platforms such as Amazon EKS, Azure AKS, and Google GKE. The same layered security approach used in AI data centers is applied here, ensuring protection across network, application, and workload levels.
Security Technologies Full Stack for AI security
- Check Point WAF with AI Security
- Check Point Maestro Hyperscale Firewall
- NVIDIA BlueField DPU integrated for access control and IPS.
Alignment of Check Point AI Factory Security with AI Governance Frameworks
Check Point’s AI Factory security blueprint protects infrastructure and workloads and also enables governance, trust, and compliance per NIST AI RMF and Gartner AI TRiSM Framework.
Check Point aims to extend beyond perimeter security to address policy-driven AI risks, ensuring organizations can meet governance standards, pass audits, and deploy AI responsibly.