Over the past 120 days, the online conversation around artificial intelligence has taken on a sharper edge. Anger at AI executives, opposition to new data centers, and grievance over the resources these facilities consume have moved from background hum to a sustained discussion. In some corners of the internet, that discussion has crossed into rhetoric about sabotage, attacks, and direct action against the people and infrastructure driving the AI buildout.
We wanted to understand the shape of that conversation. Using the Liferaft platform, our team built a query focused on data center sabotage rhetoric and ran it across 13 public social platforms.
The result: 7,714 posts captured between mid-February and mid-June 2026, which we synthesized into an intelligence brief now available as a free PDF download.
The headline finding is one of arc. Daily post volume grew roughly seven times over from late February through May, with two distinct spike weeks driven by very different dynamics. Then, in June, something interesting happened. The conversation began to moderate, with weekly volumes declining throughout the month. The drop is meaningful enough to suggest the steepest part of the escalation has passed, even though levels remain well above where they started. Whether this is a real cooling or a pause before another spike is something we are watching closely.
A second finding lies beneath the volume story and matters more to anyone tasked with protecting people or assets in this space. The language people are using is shifting. In April, intent constructions skewed heavily toward the individual: "I want to," "I'm going to." By May, group framing had surged: "we will," "let's." That kind of shift, from personal frustration to coordinative rhetoric, is something threat intelligence professionals pay close attention to, because it tracks with how movements organize. We break down three intent categories side by side in the PDF, with representative examples and a clear note on how we filtered for sabotage-relevance.
The brief also surfaces a counterintuitive platform finding. One platform that represents only 12% of related posts is generating more than half of the content our analysts have flagged as high risk. That kind of asymmetry is exactly what manual review would miss, and exactly what the Liferaft platform was built to detect.
There is more in the data than these three findings. Threat-themed language, including direct references to arson, sabotage, Molotov cocktails, and explosives, appears in roughly one in three posts across the full 120-day window. Sentiment runs deeply negative, with the average post scoring nearly two-thirds of the way toward the floor of our negative scale. A single AI executive accounts for the majority of named-individual mentions, with the next-most-named figure trailing by a factor of eight. And the conversation about how an attack might actually be carried out, as opposed to whether one should happen, has begun showing up in its own measurable signal, which we treat as a separate category in the brief.
The brief was produced using the Liferaft platform, which is how our team handles threat monitoring and synthesis work behind analyses like this one. The PDF includes both volume charts, the stated intent breakdown, and the editorial caveats we apply when sharing this kind of material externally.
If you work in physical security, executive protection, corporate intelligence, or the data center industry, the brief is designed to give you a clear, defensible read on the current landscape, and a starting point for the conversations your stakeholders are going to have about this in the months ahead.