The Data Centers in LEO
Part II — THE PHYSICS YOU CANNOT ARGUE WITH

Radiation

What is actually out there

Three distinct populations, with three different consequences: 1. Trapped particles. Protons and electrons captured by Earth’s magnetic field into the Van Allen belts. In low orbit you mostly miss them, except over the South Atlantic Anomaly, where the inner belt dips low, and near the poles, which is precisely where sun-synchronous orbits go. A polar or sun-synchronous data centre takes more dose than an equatorial one. That is a real cost of the full-sun orbit Chapter 4 recommended. 2. Galactic cosmic rays. Very high energy nuclei from outside the solar system. Low flux, extremely penetrating, effectively impossible to shield with any mass you would launch.

3. Solar particle events. Sporadic, occasionally enormous, and the reason a spacecraft needs a safe mode rather than merely an average-case design. These do two categorically different things to electronics. Total ionising dose is cumulative and gradual: charge builds up in insulating layers, thresholds shift, leakage rises, and eventually the part is out of spec. It is a wear-out mechanism, measured in rad(Si), and it defines a lifetime. Single event effects are instantaneous: one particle deposits enough charge in the wrong place to flip a bit (an upset), glitch a signal (a transient), or, worst case, trigger a parasitic structure that draws destructive current until power is removed (latch-up). Upsets are a reliability nuisance. Latch-up destroys hardware.

What Google’s test actually showed, and why it matters so much Until recently, the honest answer to “can a modern AI accelerator survive orbit?” was that nobody had published a test. In late 2025 Google published one, and it is the most important single data point in this sector. Google tested a Trillium v6e TPU and its host server in a 67 MeV proton beam. Behind roughly 10 mm aluminiumequivalent shielding, they put the expected dose in their target sun-synchronous LEO at about 150 rad(Si) per year, a five-year mission dose near 750 rad(Si). The high-bandwidth memory was the most sensitive subsystem and began showing irregularities only after about 2 krad(Si), close to three times the five-year dose. No hard failures attributable to total dose appeared up to the maximum tested 15 krad(Si).9 Read that carefully, because it is easy to over-read. It does not say frontier silicon is immune to space. It says that for one accelerator, in one orbit, behind realistic shielding, cumulative dose is not the binding constraint over a five-year life. Single event effects, long-duration behaviour, and thermal cycling are not settled by a beam test. But it moves the argument. The old assumption was that space compute required bespoke radiation-hardened silicon, which runs generations behind commercial parts and costs five to ten times more. If commercial accelerators survive with shielding and software discipline, the cost premium collapses toward something like oneand-a-half to two times and the difference between those two worlds is the difference between this sector being arithmetic and being fantasy.

Figure 6.1 — Shielding has a knee, and then it stops paying

The shielding calculation, and why you shield the box

Shielding is mass, and mass is area × thickness × density. Aluminium is 2.7 g/cm³, so 10 mm of it over a one-squaremetre surface is 27 kg.

That is the whole reason the correct architecture shields the electronics enclosure, not the spacecraft. Wrap a compute box of, say, 12 m² of surface in 10 mm equivalent and you have spent roughly 320 kg, real, but affordable inside a 30-tonne vehicle. Wrap the whole vehicle, radiators included, and you have spent your entire mass budget protecting panels that do not care. And note the shape of Figure 6.1. The first few millimetres do nearly all the work, because they stop the soft trapped electrons and lower-energy protons that dominate the flux. After the knee, you are adding mass against penetrating protons and cosmic rays that mostly ignore it and at high thickness, incoming particles produce secondary showers inside the shield, so the returns can go worse than flat. There is an optimum, it is a few millimetres to a centimetre, and past it you are launching lead for nothing.

The three answers that are not shielding

Orbit selection. Altitude and inclination change dose by more than any plausible shielding decision. This is a free variable and it is coupled to Chapter 4’s full-sun orbit preference and Chapter 5’s sink temperature. These trades are not separable, which is why spacecraft design is iterative and why “we’ll just put it in SSO” is not a design. Software. Error-correcting memory, checkpointing, redundant execution, watchdogs that reset a hung device. Hyperscale software already assumes hardware fails constantly; that culture is an asset here, and it is why the compute layer may prove more tractable than the mechanical layers. Current-limited power. Latch-up is survivable if the supply detects the current spike and cycles the device before it cooks. This is a power-electronics design decision, and it is one of the few places where a supplier can differentiate on something other than price.

The reframe that matters for an investor

Radiation is not a wall. It is a depreciation schedule.

That is the right way to hold radiation risk in your head. It does not decide whether orbital compute works. It decides the margin, and therefore the price you should be willing to pay for a company that has not yet demonstrated multi-year hardware life on orbit.

Where radiation breaks

Long-duration behaviour of dense HBM stacks; the absence of any five-year on-orbit dataset for frontier accelerators; extreme solar particle events; and thermal cycling, which is technically Chapter 5’s problem but kills hardware on the same timescale and is much less discussed.


Download as PDF