What Do AI Risk, Data Centers And Bananas Have In Common?
The banana most Americans eat today isn’t the banana most Americans ate a century ago. I know that seems like a pretty wide departure from artificial intelligence, data centers and the possibility that increasingly capable AI systems might do things we don’t intend. Bear with me.
This week, President Donald Trump and executives from Google, Anthropic, Meta, OpenAI, xAI and Nvidia agreed to the “ White House Accord on Super Intelligence ,” a voluntary framework establishing four layers of controls and audits around frontier AI development. The first stands out. The companies agreed to implement controls and monitoring “around areas like cybersecurity, biosecurity, and chemical threats,” and to ensure their models do not “hack or access technical systems in unintended ways.” The accord adds expectations around internal monitoring, independent external auditors and board-level oversight, with the possibility that some of these steps could eventually become laws or regulations.
All very reasonable precautions. But they raise another question: What exactly are we granting these extraordinarily capable AI systems access to?
Just this week, I gave ChatGPT access to many parts of my Google identity. I did it because it was useful. I am absolutely not alone. In 2026, AI has moved from something we ask questions, almost like a much more capable search box, to something connected into the fabric of the systems around which we build our work and personal lives.
Many AI risk conversations focus on the models themselves. Can we keep models aligned, recognize when their capabilities take a dangerous turn and trust the companies developing them to maintain control of their own products? Those questions matter. But we aren’t paying anywhere near the same attention to the environment into which these systems are being deployed .
Over the past three decades, the internet has become completely enmeshed in nearly every part of our daily lives. Healthcare, banking, navigation, communications, power and, increasingly, government all depend on interconnected and interdependent digital environments. We built this digital world well before modern AI arrived. Now we are connecting AI directly to it.
Which brings me back to the banana.
A century ago, the Gros Michel dominated the commercial banana industry. Or, as I prefer to call it, “Big Mike.” Panama disease nearly wiped out Gros Michel plantations, making the variety commercially unviable. We changed to the Cavendish. Many consider it less sweet, but it was resistant to the strain of fungus wreaking havoc at the time.
Today, the Cavendish itself faces the Tropical Race 4 strain of Panama disease. Why does this keep happening? One word: sameness.
Commercial bananas aren’t typically grown from seed. They’re propagated from shoots, meaning plants across enormous commercial populations are genetically very similar. That sameness is useful for agriculture, but it also creates vulnerability: a disease capable of attacking one plant may be capable of attacking nearly all of them.
I probably know more about bananas than I should. I once accidentally stabbed myself with a machete while cutting down a banana plant after it fruited, as one does. This is relevant, I promise.
The comparison between bananas and technology architecture isn’t entirely new. In 2013, computer scientists Julio Hernandez-Castro and Jeremy Rossman used Gros Michel and Cavendish bananas to describe the security implications of software monocultures. Their point was that diversity can create robustness, while widespread similarity can allow a vulnerability to propagate rapidly. More than a decade later, that concern extends beyond software monocultures to the infrastructure underneath them.
From Server Rooms To Hyperscale
In the earliest days of my career, I was a sales engineer at Dictaphone, a company whose roots stretched back to Alexander Graham Bell. I dealt with infrastructure firsthand as we helped transition healthcare from microcassettes to speech recognition. We would even occasionally encounter the novelty wax cylinder that some physicians and lawyers still preferred.
These were not modern systems that could be spun up with a few clicks. I had to calculate the number of physical phone lines that would plug into the back of the machines, along with the British thermal units these enormous racks of metal would generate so they didn’t overwhelm a hospital’s air conditioning. We worried about battery backups, local firewalls, storage and literally whether there was enough space inside the building. Every project was essentially a miniature infrastructure deployment involving thousands of pounds of hardware.
Across healthcare, thousands of these environments existed independently. A hospital might have a room dedicated to its servers, a data center somewhere in the community or even a secondary data center nearby. Different servers, different routers, different firewalls, different backups. They were expensive and fragile, and sometimes not secured all that well. That’s a very real reason computing moved away from them so rapidly.
Now, it’s not all bad. Cloud computing has dramatically reduced the need for every organization to maintain its own infrastructure and hardware expertise. Companies like Amazon, Microsoft, Google and Oracle can dedicate teams of security experts that an individual hospital, or even a large health system, could never reasonably put together on its own. They can also build redundancy at a scale those organizations simply can’t match.
Data centers aren’t new. The scale is.
Chris Platt, field chief technologist for healthcare and life sciences at Hewlett Packard Enterprise, pointed out when we spoke that the history is more cyclical than a simple march from distributed computing toward centralization. “We’ve gone from mainframe to client-server to virtualization to cloud to AI,” Platt told me. “Those are the seismic shifts in the last 40 years of IT.”
In some ways, today’s massive data centers and hyperscale clouds are simply the latest swing of that pendulum, from the centralized mainframes of the 1970s to the distributed PCs of the 1980s and back again. Reliability reduces the likelihood of failure. Resilience limits its consequences.
The new White House accord implicitly recognizes that AI can change the threat model when it specifically calls for preventing models from hacking or accessing technical systems in unintended ways.
David Metcalf, director of the Mixed Emerging Technology Integration Lab at the University of Central Florida, sees AI less as creating an entirely new category of cyber risk than as accelerating what is already possible. “It increases the blast radius. It increases the repeatability of the attack vector, and it increases the quality of the attack,” Metcalf told me. “That is different. And AI is the differentiator.”
Put that repeatability together with shared infrastructure, and vulnerabilities that were once difficult to exploit across many different environments can become much easier to scale.
But Metcalf doesn’t see AI as only increasing the threat. He points to UCF’s “Knights of the Round Tables” model for bringing humans and artificial intelligence together as part of the defense. Whether humans are directing AI or responding when an AI system behaves in unexpected ways, the idea is to use both to improve our ability to respond. “Let’s just say we have a chance to protect and defend,” he said.
What Happens When Everything Goes Down?
At Health Datapalooza, Christian Dameff, an emergency physician and co-director of the UC San Diego Center for Healthcare Cybersecurity, joined a discussion about patient data safety, privacy and trust. I caught up with him afterward to talk more specifically about resilience.
Dameff’s team is working on CRASHCART , an ARPA-H-supported effort designed to rapidly restore clinical connectivity when a hospital’s primary digital infrastructure becomes unavailable. Rather than just dusting off the paper and fax machines (see Season 2 of The Pitt ), the goal is to create what Dameff calls a “digital lifeboat” that can restore enough familiar digital capability to keep caring for patients.
“There are clear patient safety, care and quality impacts to patients during cyberattacks,” Dameff told me. “How do we take catastrophic failures and make them more like speed bumps?”
His team has also documented what correlated technology failure can look like. After the July 2024 CrowdStrike outage, researchers found detectable network disruptions coinciding with the event at 759 of 2,232 U.S. hospitals studied. They identified 1,098 disrupted digital services, including 239 associated with direct patient care.
That’s the banana problem without the banana.
David West, CEO of Downtime PACS, reduces the same challenge to a simple principle: “Application redundancy alone isn’t enough. It doesn’t matter how resilient your systems are if you can’t reach them.”
None of this means dismantling the cloud or returning giant servers to hospital closets. I spent enough time dealing with those things the first time around. Infrastructure resilience also cannot solve alignment, governance or every conceivable threat from advanced AI. It answers a narrower question: When something goes wrong, how much of the system goes with it?
That means understanding whether supposedly independent systems actually share dependencies, deciding what capabilities need to remain available locally and designing systems that degrade gracefully rather than simply disappear.
Metcalf describes part of the goal as getting “left of bang,” identifying and interrupting threats before they become incidents. “How can we be preemptive?” he asked. “Before we have a problem that takes 100 hours to clean up, do 10 hours of prevention before that.”
The Cavendish became dominant because it solved a real problem. Modern computing did too. Cloud infrastructure is more efficient, capable and, in many respects, more secure than what came before it. Concentration can also change the consequences of failure.
Artificial intelligence didn’t create the extraordinarily interconnected world we are deploying it into. We did. Now we are connecting increasingly capable systems directly to it.
We have spent years debating what enormously powerful AI might someday do. We should spend more time asking what happens when it discovers just how interdependent the civilization we already built has become.
Bananas have been warning us about that problem for a long time.