AI infrastructure is creating a new class of high-value facilities, but the technology protecting their doors can look surprisingly familiar. A new U.S. survey commissioned by Alcatraz AI finds that 58% of Americans have never heard the term “tailgating” used to describe an unauthorized person following someone else through a secured entrance. The finding points to a broader problem for data centers and other critical facilities: digital defenses have advanced rapidly while physical access controls still often depend on a credential being presented at the door.
As companies pour billions of dollars into AI data centers, physical security is becoming an increasingly important part of the enterprise AI infrastructure equation.
The issue is not simply whether an employee has a valid badge. It is whether the person carrying that credential is actually the person authorized to enter — and whether another individual can slip through the same door behind them.
That practice, commonly known as tailgating or piggybacking, is the focus of a new national survey commissioned by physical access-control company Alcatraz AI. The survey found that 58% of Americans have never heard the term “tailgating” used in this security context, while 45% said they had personally experienced or witnessed someone entering a secured space without using their own credentials.
The findings arrive as data centers become increasingly strategic infrastructure for cloud computing, generative AI and machine learning. A physical intrusion at an AI facility could expose equipment, disrupt operations or compromise environments where multiple customers share the same physical campus.
The stakes are measurable. IBM’s 2025 Cost of a Data Breach Report puts the global average cost of a breach at $4.44 million, while the U.S. average reached $10.22 million. The figure covers digital breaches rather than physical intrusions specifically, so it should not be interpreted as the cost of tailgating. It does, however, illustrate the financial scale of enterprise security incidents.
The badge problem
Traditional access control generally answers a narrow question: does this credential have permission to open this door?
A badge reader cannot necessarily determine whether the employee presenting the credential is the credential’s legitimate owner. It also cannot, by itself, reliably determine whether a second person enters immediately afterward.
That creates an interesting contrast with enterprise cybersecurity.
Organizations have spent years deploying multifactor authentication, endpoint detection, identity management and zero-trust architectures to make digital identities harder to abuse. Physical security has increasingly gained similar capabilities, but adoption varies significantly by facility, risk profile and existing infrastructure.
Alcatraz AI’s CEO Tina D’Agostin argues that physical access should move toward a comparable identity-centric model.
The company’s approach uses facial authentication and computer vision alongside existing access-control systems. Its Rock platform is designed to verify a person’s identity at the point of entry and identify potential tailgating events in real time. Alcatraz says its system converts facial information into anonymized biometric representations rather than storing conventional photographs or personal information.
That distinction matters for enterprises considering biometric access. Facial recognition can strengthen authentication, but it also introduces privacy, consent, data-retention and regulatory questions that conventional badges do not.
Data centers raise the stakes
The physical-security question becomes more complicated inside hyperscale and colocation facilities.
A modern data center can contain multiple tenants, restricted data halls, networking areas and server racks. Access may need to be controlled not only at the building entrance but at increasingly granular zones within the facility.
Alcatraz says more than half of roughly 17 U.S.-headquartered hyperscale data center operators use its technology. That is a company claim rather than an independently verified market-share statistic, and it should be treated accordingly.
The underlying market opportunity is broader than one vendor. Physical security companies are increasingly combining access-control systems with cameras, edge AI and analytics to detect anomalous behavior.
Verkada, for example, integrates video security with access control and uses camera-based analytics to flag tailgating when multiple people enter following a single access authorization.
Other platforms are taking different approaches. HID continues to emphasize credential, reader and turnstile technologies, including mechanisms designed to prevent tailgating. LenelS2’s ecosystem also supports integrations for AI-assisted unauthorized-entry and tailgating detection.
This means Alcatraz is not creating an entirely new category. Its differentiation is more specifically around AI-powered facial authentication, tailgating detection and deployment alongside existing access-control infrastructure.
AI makes the door another data-driven security layer
For enterprise security teams, the important shift is from treating the door as a binary mechanism to treating it as a source of security telemetry.
A modern access system can combine credential events, video, identity signals, door state and behavioral analytics. That can allow security operations teams to investigate not just whether a door opened, but who entered, whether the event matched the authorization and whether the surrounding behavior was anomalous.
That approach mirrors a larger trend in enterprise security: context is becoming as important as authentication.
It also explains why AI is moving into physical security. Computer vision can analyze events at the edge, reducing the need for security personnel to watch every camera feed manually. In a large data center campus, that can make the difference between a system that records an incident and one that alerts an operator while the incident is unfolding.
Privacy remains the counterweight.
Enterprises deploying facial authentication will need to assess local biometric privacy laws, employee expectations, data governance, retention policies, vendor security and the accuracy of the underlying recognition technology. Claims that biometric identities are anonymous should also be evaluated against the actual architecture, contractual terms and applicable regulations.
The enterprise adoption question
The most important lesson from the survey is therefore not that every badge system is obsolete. It is that organizations operating high-value facilities may need to reconsider what a “verified” physical identity actually means.
For ordinary offices, the cost and complexity of biometric systems may outweigh the risk reduction. For hyperscale data centers, financial institutions, laboratories, airports and critical infrastructure, the calculation can be very different.
AI is making those facilities more valuable while increasing their dependence on continuous physical availability. That puts physical access control closer to the core of enterprise resilience.
Alcatraz plans to release additional findings ahead of GSX 2026, scheduled for September 14–16 in Atlanta, including a second national study examining U.S. attitudes toward physical security since September 11.
The larger industry direction is already visible: the next generation of enterprise access control will increasingly combine credentials, cameras, AI analytics and identity verification. The question for security leaders is no longer simply whether the door is locked. It is whether the organization knows who actually walked through it.
Market Landscape
The physical access-control market is moving toward convergence between identity, video surveillance, AI analytics and building security.
Legacy providers such as HID and LenelS2 remain deeply embedded in enterprise environments, while newer cloud-native platforms such as Verkada are combining cameras and access control into unified management systems. Verkada, for example, supports tailgating alerts using door events and camera-based people counting.
For data centers, the trend is particularly significant because physical security increasingly has to operate at multiple layers: perimeter, building entrance, data hall, cage, rack and administrative area.
The competitive question is therefore shifting from “Which credential opens the door?” to “Which combination of identity, video and analytics provides sufficient assurance without creating unacceptable privacy or operational costs?”
That is a more demanding technology problem — and one that AI vendors are increasingly targeting.
Top Insights
- Alcatraz AI’s survey highlights limited public awareness of tailgating, exposing a physical-security gap for enterprises protecting increasingly valuable AI infrastructure.
- AI-powered facial authentication can supplement badges by verifying people rather than credentials, while computer vision can identify multiple entrants behind one authorization.
- Data centers face higher physical-security stakes because colocation facilities may contain multiple customers, restricted data halls and sensitive computing infrastructure.
- Competitors including Verkada, HID and LenelS2 already address tailgating through video analytics, access-control integration and credential technologies.
- Enterprise buyers must weigh security improvements against biometric privacy, compliance, deployment complexity and the operational cost of replacing or augmenting legacy systems.
Power Tomorrow’s Intelligence — Build It with TechEdgeAI










