Author: Deepak Jain

  • NIST Rewrites PNT Cybersecurity Guidance for the CSF 2.0 Era

    NIST Rewrites PNT Cybersecurity Guidance for the CSF 2.0 Era

    The U.S. National Institute of Standards and Technology (NIST) has revised its cybersecurity guidance for positioning, navigation and timing (PNT) services, realigning it to version 2.0 of the NIST Cybersecurity Framework and expanding its treatment of GPS disruption, artificial-intelligence risk and supply-chain threats, according to trade coverage published on 12 May 2026.

    PNT services are the satellite and terrestrial systems that tell equipment where it is and, more importantly for infrastructure operators, what time it is to within billionths of a second. The revision is guidance rather than regulation: it gives operators of data centers, power grids, financial systems and telecom networks a structured way to inventory their dependence on those signals and to defend the systems that consume them.

    Executive Summary

    NIST’s foundational PNT profile was written to satisfy Executive Order 13905, signed in February 2020, which directed the federal government to help critical-infrastructure owners use PNT services more responsibly. That original profile was built on the first-generation Cybersecurity Framework (CSF 1.1). CSF 2.0, published in February 2024, added a sixth core function — Govern — alongside Identify, Protect, Detect, Respond and Recover, and pushed supply-chain risk management from a subcategory into a first-class concern. A PNT profile pinned to the older framework was, over time, going to drift out of step with how organizations actually structure their security programs.

    The substantive additions matter more than the renumbering. Deliberate GPS jamming and spoofing have moved from a theoretical concern to a routinely reported operating condition in several regions, particularly for aviation and maritime users, and the same interference affects any fixed receiver in range. Adding explicit treatment of AI risk acknowledges that machine-learning systems are increasingly used both to detect anomalous timing signals and, on the other side, to generate more convincing spoofed ones. Supply-chain coverage addresses a quieter problem: most operators do not buy PNT directly, they buy it embedded inside a network switch, a phasor measurement unit or a timing appliance from a vendor they have never audited on this dimension.

    For infrastructure buyers, the practical value is leverage. Voluntary NIST profiles tend to become procurement language, insurance questionnaires and audit checklists within a few budget cycles, which is usually how they change behaviour.

    Timing Is Infrastructure, Even When Nobody Owns It

    Precise time is the least-discussed dependency in modern digital infrastructure. Distributed databases use timestamps to order transactions and resolve conflicts; if clocks in two availability zones diverge, writes can be applied out of order or reject each other. Mobile networks use tight synchronization to keep adjacent cells from interfering, and time-division and 5G radio schemes are particularly unforgiving of drift. Electrical grids use time-stamped phasor measurements — sampled tens of times per second across hundreds of miles — to detect instability, which only works if every sampler agrees on the moment of sampling. Financial venues are required to timestamp orders to prove sequence. In each case the clock is not a feature of the system; it is a precondition for the system being correct.

    The awkward part is that most of this timing arrives free, from space, via GPS and its counterparts. A rooftop antenna the size of a coffee mug feeds a receiver that disciplines a local oscillator, and the resulting signal is distributed inside the building over NTP or the more precise Precision Time Protocol. Nobody is billed for it, so it rarely appears on a dependency map, and it is frequently owned by facilities or network engineering rather than by security. A NIST profile that forces the question — which of our systems fail, and how visibly, if this signal degrades — is doing useful work before it recommends a single control.

    Degradation is also the hard case. An antenna that goes dark is easy to detect and fail over. A receiver that is being spoofed reports a confident, plausible, wrong time, and a good spoof walks the clock slowly enough that naive threshold alarms never fire. That failure mode propagates silently into logs, transaction ordering and forensic timelines, which is precisely why it belongs in a cybersecurity framework rather than a facilities runbook.

    What CSF 2.0 Actually Changes for a PNT Program

    The addition of the Govern function is not cosmetic. Under CSF 1.1, an operator could describe technical PNT controls without ever assigning accountability for them. Govern asks who owns the risk, how it is expressed in policy, what the risk tolerance is, and how third-party dependencies are managed. For timing, that maps onto a real organizational gap: the team that installs the GPS antenna, the team that runs the NTP servers and the team that would be blamed for a corrupted transaction log are usually three different teams with no shared document.

    The supply-chain emphasis lands on a genuinely under-examined surface. PNT capability is overwhelmingly delivered as a component — a receiver module, a timing card, an oscillator, firmware that parses satellite messages. Buyers evaluating a timing appliance typically compare holdover specifications and price, not the provenance of the receiver chipset or the vendor’s firmware-update practices. Asking suppliers to document that lineage is the kind of requirement that is trivial to write and expensive to satisfy, and it will surface differences between vendors who have anticipated the question and those who have not.

    The AI dimension is the newest and, on the evidence available in the headline alone, the least defined. There are at least three distinct concerns worth separating: machine-learning models used to classify anomalous PNT signals, which can be evaded or poisoned; AI-assisted generation of spoofing waveforms, which lowers the skill required to mount an attack; and AI systems that consume PNT data as an input, where corrupted timing quietly corrupts inference. Guidance that treats these as one topic would be less useful than guidance that treats them as three.

    Who Benefits, and What It Costs to Comply

    The clearest commercial beneficiaries are vendors of resilient timing: makers of rubidium and cesium clocks and high-quality oven-controlled oscillators that let a facility ride out signal loss in holdover for hours or days, suppliers of multi-constellation receivers that can fall back from GPS to Galileo, GLONASS or BeiDou, providers of terrestrial and fibre-delivered time services, and the smaller field of anti-spoofing and signal-authentication products. None of these are new categories. What a widely cited framework profile changes is the buyer’s ability to justify the line item, because “NIST’s profile asks us to demonstrate holdover capability” is a more durable argument than an engineer’s professional unease.

    The cost falls unevenly. Large hyperscale and carrier operators have generally engineered timing redundancy already, often with multiple antennas, atomic holdover and diverse distribution; for them the work is documentation, governance and supplier attestation rather than capital equipment. Regional colocation providers, industrial operators and mid-sized utilities are the ones more likely to discover a single receiver feeding a single time server with no holdover behind it. That asymmetry is worth naming plainly: guidance of this kind tends to raise the floor, and raising the floor is more expensive for whoever is standing on it.

    It is also worth being precise about what this announcement is and is not. It is a revision to voluntary guidance, aligned to a voluntary framework, from a standards body with no enforcement authority. It does not compel any operator to buy anything or meet any deadline. The realistic mechanism of influence is indirect — contract language, insurer questionnaires, sector regulators who cite NIST documents by reference — and that mechanism works on a timescale of years, not quarters. Readers should treat the substantive question as open until the document text itself is examined: alignment to CSF 2.0 is a structural claim, and whether the underlying technical recommendations have materially advanced is something only the revised profile can answer.

    Background

    NIST is the U.S. federal standards body whose cybersecurity publications are used far beyond the federal government, both domestically and internationally, as a common vocabulary for security programs. Its Cybersecurity Framework, first issued in 2014 and revised as CSF 2.0 in February 2024, is descriptive rather than prescriptive: it organizes outcomes into core functions and lets each sector write a “profile” mapping those outcomes to its own risks. The PNT profile is one such sector-style profile, created after Executive Order 13905 in February 2020 identified over-reliance on satellite timing as a national infrastructure risk.

    That concern has only sharpened. GPS and its peer constellations broadcast extremely weak signals from roughly 20,000 kilometres away, which makes them inherently easy to overpower locally with modest equipment. Widespread interference has been reported around several conflict zones in recent years, affecting aviation and maritime navigation, and the same physics applies to any fixed rooftop receiver. Meanwhile the number of systems that silently depend on nanosecond-accurate time — cloud databases, 5G radio networks, grid phasor measurement, financial timestamping — has grown considerably faster than the redundancy protecting it.

    Source: NIST revises PNT services cybersecurity guidance under CSF 2.0 to address GPS disruption, AI risks, supply chain threats — Industrial Cyber, 12 May 2026, reporting NIST’s realignment of its positioning, navigation and timing profile to version 2.0 of the Cybersecurity Framework.

  • AiOnX Lands Hyperscale Tenant Outside Dublin: Ireland’s Power Test

    AiOnX Lands Hyperscale Tenant Outside Dublin: Ireland’s Power Test

    Data Center Dynamics reported on 12 May 2026 that developer AiOnX has secured a hyperscale tenant for its data centre campus outside Dublin. A “hyperscale” tenant is one of the very large cloud, platform or AI operators that lease capacity in blocks measured in tens of megawatts rather than in racks or cabinets.

    The report establishes the commercial fact — a large anchor customer has been signed for an Irish campus located outside the Dublin city area — but does not, in the material available to us, identify the tenant, the contracted capacity, the lease term, the power arrangement or the delivery schedule.

    Executive Summary

    The significance of this announcement is less about one lease and more about what it says about Ireland. Since 2022, the practical constraint on data centre growth in the Dublin region has not been land, capital or fibre; it has been electricity. The grid operator has held back new large connections in the Dublin area, and regulatory policy has moved toward requiring large energy users to arrive with their own generation or storage rather than simply adding load to a system already under strain.

    Against that backdrop, a signed hyperscale anchor tenant is a meaningful data point. Hyperscalers do not commit to a campus without visibility on when power will actually be available and on what terms. A signature implies that AiOnX has presented a credible answer to the energy question — but the report as published does not tell us what that answer is.

    For buyers, investors and policymakers, the useful posture is interested but unsatisfied. The deal is evidence that Irish demand persists and that at least one developer has found a route through the constraint. It is not yet evidence about capacity, cost, carbon profile or timeline, because none of those figures have been disclosed.

    An Anchor Tenant Is a Financing Event, Not Just a Lease

    In data centre development, the anchor tenant is the hinge on which everything else turns. A campus is an enormous fixed-cost bet: land, planning consent, grid or on-site generation, shells, cooling and electrical plant all have to be paid for years before revenue arrives. Lenders and infrastructure funds price that risk heavily until someone with an investment-grade balance sheet signs a long-dated lease. Once that signature exists, the project stops being speculative real estate and starts being a contracted cash-flow stream, which is a fundamentally cheaper thing to finance.

    That is why an announcement of this kind matters commercially even without disclosed numbers. It typically signals that the developer has moved past the hardest phase. It also usually implies that the campus design has been validated against a demanding customer’s technical requirements — power density per rack, cooling approach, redundancy, security and connectivity — because hyperscalers audit these things closely before committing.

    The caution is that “secured a tenant” covers a wide range of commitments in practice, from a full take-or-pay lease across an entire phase to a smaller first tranche with options on later capacity. Those are very different economic events, and the reporting available does not distinguish between them. Readers should treat the deal as directionally positive and quantitatively unknown.

    Ireland’s Constraint Has Moved From Land to Electrons

    Ireland spent two decades building one of Europe’s densest data centre clusters, drawing hyperscalers with an English-speaking workforce, EU membership, favourable corporate tax treatment, cool weather that helps with cooling, and dense subsea and terrestrial fibre. The result is that data centres now account for roughly a fifth of Ireland’s metered electricity consumption — a share without close parallel in Europe, and one that turned an economic development story into an energy-planning problem.

    The policy response has reshaped the market. New large grid connections in the Dublin region have been effectively paused, and regulatory policy has pushed new large energy users toward what the industry shorthands as “bring your own power”: arriving with on-site generation, storage or contracted supply so that the campus does not simply add unmatched demand to a constrained system. That shifts a large slice of cost and complexity from the utility onto the developer, and it changes who can compete. Building a campus is a real estate and construction skill; building a campus plus its power is an energy-development skill, with its own permitting, fuel, emissions and interconnection questions.

    A hyperscale tenant signing outside Dublin fits this pattern. Sites beyond the immediate Dublin constraint zone have been the natural next move for developers, offering more headroom on land and, potentially, on network access — though “outside Dublin” is not a synonym for “unconstrained,” since Ireland’s transmission system and generation adequacy are national issues, not purely metropolitan ones. Whether this campus solves the problem with on-site generation, batteries, a firm or non-firm grid connection, or some combination, is precisely the detail the announcement does not supply.

    Who Gains, Who Waits, and Whose Claims Deserve Testing

    The clearest beneficiaries of a bring-your-own-power regime are developers with genuine energy capability and access to patient capital, and the vendors that serve them: gas and hydrogen-ready generation suppliers, grid-scale battery integrators, switchgear and transformer manufacturers, and engineering firms that can carry both a build and an energy project. The clearest losers are speculative developers holding land in the expectation that a grid connection will eventually arrive. For enterprise buyers, the practical effect is that Irish capacity is likely to remain tight and priced accordingly, with lead times set by power procurement rather than by construction.

    The debate around Irish data centres is genuinely contested, and both sides make claims worth examining rather than accepting. Critics — including community groups, environmental organisations and some political parties — argue that the sector’s electricity share competes with housing and household demand and complicates Ireland’s emissions targets. Those are legitimate, evidence-based concerns rooted in published consumption statistics, and they should not be dismissed as reflexive opposition. The fair questions to put to them concern counterfactuals and attribution: how much of the projected system strain is data centres specifically versus general electrification of heat and transport, and does new on-site generation add net emissions or displace higher-carbon marginal supply?

    Industry claims deserve identical scrutiny. Developers routinely argue that large campuses fund grid reinforcement, add flexible or dispatchable capacity, and anchor high-value employment. Those claims are testable, and this announcement tests none of them, because it discloses no capacity, no energy source, no emissions profile and no employment figure. The honest reading is that a commercial milestone has been reported and the public-interest questions remain exactly where they were the day before.

    Background

    Ireland built one of Europe’s most concentrated data centre clusters over roughly two decades, drawing in the largest cloud and platform operators. The concentration eventually collided with the electricity system: data centres came to represent about a fifth of national metered electricity consumption, and from 2022 the grid operator effectively paused new large connections in the Dublin region while regulatory policy moved toward requiring new large energy users to bring their own generation or storage capacity.

    That shift redefined what it takes to develop in Ireland. Developers now compete on energy strategy as much as on land, construction and connectivity, and campuses outside the Dublin constraint zone have become a natural focus. AiOnX is the developer of the campus described in this report; the source material does not detail the company’s history, portfolio or backing, so those aspects remain outside what can be verified here.

    Source: AiOnX secures hyperscale tenant for Irish data center campus outside Dublin — Data Center Dynamics, 12 May 2026, reporting that developer AiOnX has signed a hyperscale anchor customer for its campus outside Dublin.

  • JLL Brokers Japan’s Largest-Ever Data Center Transaction

    JLL Brokers Japan’s Largest-Ever Data Center Transaction

    Real estate services and capital markets firm JLL announced on 12 May 2026 that it acted as adviser on what it describes as the largest data center transaction ever recorded in Japan. The announcement establishes the superlative — a national record for the asset class — but the material commercial terms were not set out in the material available to us.

    That means the headline is currently the whole of the disclosure: no confirmed purchase price, no named buyer or seller, no megawatt capacity, and no statement of whether the deal covered a single facility, a portfolio, or a corporate platform. The transaction lands in a market where Greater Tokyo and Greater Osaka absorb the overwhelming majority of Japanese data center demand and where new supply is gated by power, land and construction capacity rather than by tenant appetite.

    Executive Summary

    A record transaction in Japan matters less for its own sake than for what it says about where global capital is going. Data centers have moved, over the past several years, from a niche real estate category into a core institutional allocation — infrastructure funds, sovereign investors, insurers and REITs now compete for the same stabilized assets. A national record in Japan is a marker that Asia-Pacific has become a destination for that capital rather than an afterthought behind North America and Western Europe.

    The immediate reason is demand for AI compute. Training and inference workloads need dense, power-hungry halls that most enterprises will never build for themselves, and the operators who can deliver them are capital-hungry. When building new capacity is slow, buying existing capacity — or buying the platform that holds the development pipeline — becomes the faster route to scale. Brokered transfers of this size are one visible symptom of that constraint.

    The caution is equally important. A superlative announced by a transaction adviser, without a disclosed price or asset description, is a claim about scale rather than evidence of it. It is plausible on the direction of travel in this market, and JLL is well positioned to know, but readers should treat the record as reported rather than as demonstrated until the parties or a regulatory filing put numbers behind it.

    A Record Claim, Not Yet a Record Disclosed

    What is substantiated here is narrow and worth stating precisely: JLL, a global commercial real estate services firm, says it advised on a Japanese data center transaction that it believes is the largest in the country’s history, and it said so on 12 May 2026. Everything a professional buyer would want to interrogate — consideration, capacity, counterparties, structure, closing conditions — sits outside that statement.

    This is not unusual and not, by itself, a criticism. Confidentiality is the norm in private capital markets transactions; buyers and sellers routinely restrict what advisers may say, and a firm that broke those terms would not keep winning mandates. But a superlative is a comparative claim, and comparative claims need a metric. “Largest ever” could be measured by headline enterprise value, by equity cheque, by IT load in megawatts, by gross floor area, or by number of facilities transferred. Those four or five measures do not always crown the same deal.

    The fair reading is that the advisory firm has an interest in the transaction being seen as landmark — reputation and future mandates follow league-table position — while also being one of the few parties with the market data to make the comparison credibly. Both things are true at once. The appropriate posture is neither dismissal nor amplification: record the claim, note its source, and flag exactly what would confirm it.

    Why Institutional Capital Keeps Landing in Japan

    Japan has spent this decade becoming one of the most sought-after data center markets outside the United States, and the drivers are structural rather than faddish. It is a large, wealthy economy with a deep enterprise base still working through cloud migration, a domestic telecom and internet sector that anchors network traffic, and a regulatory environment that has generally favored keeping Japanese data on Japanese soil for sensitive workloads. That combination produces durable, creditworthy demand — which is what infrastructure investors actually buy.

    Layer AI on top and the arithmetic changes again. AI training clusters draw far more electricity per square meter than the enterprise racks that filled Japanese halls a decade ago, so a given building supports fewer, denser, more valuable tenancies. Global hyperscalers — the largest cloud and platform operators — have publicly committed to expanding Japanese capacity, and the operators serving them need balance sheet to keep pace. Selling stabilized assets, or selling equity in a platform, is how growth gets funded.

    Currency and rates have also mattered. Through this cycle a comparatively weak yen has made Japanese hard assets cheaper for dollar- and euro-denominated buyers than domestic pricing alone would suggest, while Japanese financing costs, even after normalization, have stayed low relative to Western markets. That spread between what an asset yields and what it costs to fund is the engine of leveraged real asset investing, and Japan has offered a more favorable version of it than most developed markets.

    Tokyo, Osaka and the Scarcity Behind the Price

    Japanese data center demand concentrates almost entirely in two metropolitan clusters: Greater Tokyo, where latency to financial, government and enterprise customers is decisive, and Greater Osaka, which serves as the country’s principal disaster-recovery and secondary region. Latency — the delay between a request and a response — falls with physical proximity, which is why customers pay a premium to sit inside those two orbits rather than in cheaper prefectures.

    Supply in both clusters is constrained by things money cannot quickly fix. Grid connection capacity is allocated over multi-year horizons, suitable land near existing substations is scarce and expensive, and construction labor and long-lead electrical equipment are rationed globally. A developer who wants live megawatts in central demand zones cannot simply outspend the queue; the queue is the product. That is the mechanism that turns operational, powered, leased capacity into a genuinely scarce asset.

    Scarcity of that kind reprices the secondary market. When you cannot build fast, buying becomes the substitute, and the bidding is against replacement cost plus the time value of years you do not have to wait. A national record transaction is consistent with that dynamic — but only consistent with it. Without a disclosed price per megawatt or a yield, the deal cannot be used as a pricing benchmark, and buyers should resist treating an unpriced record as evidence that valuations have moved to any particular level.

    Winners, Losers and the Risks Nobody Should Skip

    The clearest beneficiaries of a market like this are incumbent operators holding powered land and grid rights in Tokyo and Osaka: their existing positions appreciate without further effort. Sellers of stabilized assets recycle capital into development at attractive spreads. Advisers and lenders capture fees on volume. Domestic operators without access to global capital face the opposite pressure — they compete for the same land and power against buyers with a lower cost of funds.

    Enterprise and mid-market colocation customers are the constituency most likely to feel the squeeze. When institutional owners underwrite assets on AI-era assumptions, renewal pricing and available contiguous space in prime metros tend to tighten for smaller tenants. The practical response is longer planning horizons, earlier renewal conversations, and genuine consideration of secondary Japanese regions or hybrid architectures for workloads that are not latency-critical.

    For investors, the risks in this asset class are well known and currently unfashionable to dwell on: tenant concentration, where a handful of hyperscale customers carry most of the income and hold most of the negotiating power; obsolescence, as cooling and power-density requirements shift faster than 20-year building assumptions; and the possibility that AI capacity commitments moderate before the buildings underwriting them are stabilized. None of these makes a record transaction unwise. All of them are reasons that a record announced without terms should be read as news, not as validation.

    Background

    JLL is one of the largest global commercial real estate services firms, with a capital markets arm that advises owners on selling, recapitalizing and financing assets. Over the past decade it has built a specialist data center practice alongside the broader industry’s shift from treating server halls as corporate overhead to treating them as an institutional asset class comparable to logistics or student housing.

    Japan is one of Asia-Pacific’s largest data center markets, anchored by Greater Tokyo and Greater Osaka. Historically it was served largely by domestic telecom and IT operators, but the arrival of global hyperscale cloud providers, followed by AI workloads that demand far higher power density, has pulled in international developers and foreign institutional capital. Supply growth is now constrained less by demand than by access to grid power, suitable land and construction capacity — the conditions under which existing, operational facilities become scarce and expensive.

    Source: JLL Advises on Largest Ever Japan Data Center Transaction — JLL’s 12 May 2026 announcement that it acted as adviser on what it calls the biggest data center deal in Japanese market history; commercial terms were not disclosed in the available material.

  • Goldman Sachs Calls Optical Networking the Next AI Infrastructure Mega-Trend

    Goldman Sachs Calls Optical Networking the Next AI Infrastructure Mega-Trend

    Goldman Sachs has identified optical networking as the next mega-trend in AI infrastructure, according to a report headline published May 12, 2026. The thesis, as framed in the headline, is that the networks stitching together AI compute clusters are becoming a defining investment theme as those clusters scale beyond what traditional electrical interconnects handle comfortably.

    Executive Summary

    The announcement itself is brief: a major investment bank is elevating optical networking — moving data as light over fiber rather than as electrical signals over copper — from a component-level niche to a headline infrastructure theme. That framing matters because analyst ‘mega-trend’ designations tend to shape where institutional capital, corporate strategy decks, and procurement attention flow next.

    The underlying engineering logic is well established even where the report’s specifics are not public. Modern AI training clusters connect thousands of accelerators that must exchange enormous volumes of data continuously; interconnect bandwidth, latency, and power draw increasingly gate cluster performance as much as the chips themselves. Copper’s practical reach shrinks as data rates climb, which pushes more of the network — potentially including links inside the rack, not just between racks — toward optics. If Goldman Sachs is correct that this transition is a durable trend rather than a cycle, it has implications for component suppliers, network equipment makers, data center designers, and the operators who buy from all of them.

    Why Copper Runs Out of Road

    Inside a data center, data moves over two broad media: copper cables carrying electrical signals, and fiber-optic cables carrying light. Copper is cheap, mature, and power-efficient over short distances, which is why it has dominated in-rack connections for decades. But as link speeds climb from 400 gigabits per second toward 800G, 1.6 terabits and beyond, electrical signals degrade over ever-shorter distances — a physics problem, not a manufacturing one. Each speed generation shrinks copper’s usable reach, until links that once comfortably spanned a row of racks struggle to span a single rack.

    AI clusters make this acute. Training a large model is a collective effort across thousands of GPUs that must synchronize constantly, so the network is not a peripheral — it is part of the computer. When interconnects bottleneck, expensive accelerators sit idle. That is the structural argument behind treating optical networking as a trend that compounds with AI buildout rather than a one-time upgrade cycle.

    Who Stands to Benefit — and Where the Value Concentrates

    An optics-heavy buildout touches a long supply chain: laser and photonic component makers, optical transceiver manufacturers (the pluggable modules that convert electrical signals to light and back), switch and networking equipment vendors, fiber and connectivity providers, and the test-and-measurement firms that validate all of it. Emerging architectures such as co-packaged optics — placing the optical conversion directly beside the switch or accelerator silicon instead of at the faceplate — and silicon photonics, which fabricates optical components using chip-manufacturing techniques, could shift value toward semiconductor players if they mature on schedule.

    For data center operators and connectivity providers, the trend cuts both ways. Optics can reduce network power per bit at high speeds, a meaningful lever when power is the scarcest resource in the industry. But optical components have historically been a cyclical, margin-volatile business, and transitions between module generations have repeatedly caught suppliers with the wrong inventory. A mega-trend label does not repeal that cyclicality.

    Reading an Analyst Call for What It Is

    It is worth being clear about what this news is: an investment bank’s thematic designation, as conveyed by a headline, not a technology breakthrough or a customer commitment. The engineering pressures behind the thesis are real and independently observable — hyperscalers have been discussing optical scale-up interconnects publicly for years. But the report’s specifics, including any market-size estimates, timelines, or named beneficiaries, are not in the public source material, and analyst themes can outrun deployment reality. Investors and buyers should treat the designation as a prompt to examine the underlying demand signals — accelerator shipment trajectories, switch port speed transitions, transceiver order books — rather than as evidence in itself.

    Background

    Goldman Sachs is one of the world’s largest investment banks, and its research designations — from ‘BRICs’ onward — have a history of shaping how institutional investors frame emerging themes. Optical technology, meanwhile, has followed a steady march inward: light replaced copper first in ocean-crossing and long-haul telecom routes, then in links between data centers, then between racks inside them. The open question for the AI era is how far that march continues — whether optics displaces copper inside the rack and eventually alongside the processors themselves.

    The backdrop is the largest data center construction wave in history, driven by AI training and inference demand. As hyperscalers and cloud providers commit unprecedented capital to GPU clusters, each layer of the infrastructure stack — power, cooling, silicon, and networking — has taken its turn as the perceived bottleneck and, consequently, as an investment theme.

    Source: Optical Networking: The Next Mega Trend in AI Infrastructure — Goldman Sachs, a report headline published May 12, 2026, identifying optical networking as the next mega-trend in AI infrastructure.

  • FERC Weighs Federal Oversight of AI Data Center Grid Connections: What Could Change

    FERC Weighs Federal Oversight of AI Data Center Grid Connections: What Could Change

    According to a May 12, 2026 report from Engineering News-Record, the Federal Energy Regulatory Commission (FERC) is weighing federal oversight of how AI data centers connect to the electric grid. The report signals that the commission — the U.S. regulator of interstate transmission and wholesale power markets — is considering a more direct role in the interconnection of the very large loads that hyperscale AI facilities represent.

    Executive Summary

    The headline development is straightforward but consequential: FERC is reportedly considering whether the federal government should assert oversight over AI data center grid connections — the physical and contractual arrangements that let a large computing facility draw power from the bulk electric system. Historically, connecting a new load (a consumer of power, as opposed to a generator) has been governed largely by state regulators and local utilities. A federal framework would be a meaningful shift in who sets the rules for the fastest-growing category of electricity demand in decades.

    Why it matters: power availability has become the binding constraint on AI infrastructure buildout. Data center developers routinely cite interconnection timelines and grid capacity — not chips or capital — as the limiting factor on new capacity. Whoever writes the rules for large-load interconnection will influence where hyperscale campuses get built, how fast they energize, and who pays for the grid upgrades they require. Based on the available report, FERC is weighing action, not announcing a final rule; the scope, mechanism, and timeline remain to be seen.

    Why the Grid Connection Became the Bottleneck

    AI training and inference clusters concentrate enormous electrical demand in single facilities — individual campuses now request capacity measured in the hundreds of megawatts, and some multi-site plans reach into the gigawatts. That is utility-scale demand appearing at a pace the interconnection process was never designed for. Utilities and grid operators must study whether the local transmission network can serve a new load without degrading reliability for existing customers, and those studies, plus any required upgrades, can take years.

    For the AI infrastructure sector, the interconnection queue is now a competitive battleground. Access to a firm, timely grid connection has become as strategically valuable as access to GPUs. Any change in who governs that process — and under what standards — goes directly to the economics of the buildout.

    The Jurisdictional Line FERC Would Be Redrawing

    FERC’s authority under the Federal Power Act covers interstate transmission and wholesale electricity sales; states and their utility commissions traditionally govern retail service, distribution, and the siting of both power plants and large customers. Load interconnection has mostly lived on the state side of that line. But recent disputes have pulled FERC in — most visibly the fights over co-located load, where a data center connects directly to a power plant (such as a nuclear station) and questions arise about whether it is fairly using, or bypassing, the shared transmission system. FERC’s 2024 rejection of an expanded co-location arrangement at a Pennsylvania nuclear plant, and its subsequent review of co-location rules in the PJM region, established the commission as an active referee in this space.

    Weighing broader oversight of AI data center connections would extend that trajectory. The legal theory matters: rules framed around transmission access and wholesale-market effects sit comfortably within FERC’s mandate, while anything resembling federal siting authority over customer facilities would be contested territory. Expect states, utilities, and hyperscalers to litigate exactly where that line falls.

    Winners, Losers, and the Price of Certainty

    A single federal framework could benefit large developers by replacing a patchwork of state-by-state and utility-by-utility processes with predictable national rules — much as FERC’s generator interconnection reforms sought to standardize the queue for power plants. Uniformity lowers diligence costs and could speed projects in regions where local processes are slow or opaque.

    The countervailing risk is that new federal process layers add time before they save it, and that cost-allocation rules — who pays for the transmission upgrades a gigawatt-scale campus triggers — shift in ways developers cannot yet price. Utilities in high-growth regions may welcome clearer rules for protecting existing ratepayers; states courting data center investment may resist anything that dilutes their leverage. Ratepayer advocates, who have pressed regulators to ensure ordinary customers do not subsidize hyperscale growth, would likely see federal engagement as validation of their concerns — though the substance of any rule will determine whether they view it as protection or preemption.

    What Is — and Is Not — Substantiated Here

    It is worth being direct about the sourcing: this is a single trade-press report that FERC is weighing oversight. The available material does not establish whether the commission has opened a formal proceeding, issued a proposed rule, or merely discussed the topic at a conference or in commissioner statements. “Weighing” can describe anything from staff inquiry to an imminent order. Readers should treat the direction of travel — growing federal attention to large-load interconnection — as well supported by the past two years of docket activity, while treating any specific regulatory outcome as unconfirmed until FERC itself acts.

    Background

    FERC was created to regulate the interstate wholesale electricity system, leaving retail service and facility siting to states — a division written long before any single electricity customer could demand a gigawatt. That division has come under strain as AI-driven data center growth produced the fastest load expansion the U.S. grid has seen in decades, with grid operators across the country reporting unprecedented volumes of large-load interconnection requests.

    The pressure surfaced first in co-location disputes: FERC’s 2024 rejection of an expanded data-center arrangement at a Pennsylvania nuclear station, followed by a broader review of co-located load rules in the PJM region, made the commission a central player in data center power policy. The reported deliberations over direct oversight of AI data center grid connections are the logical next chapter in that story.

    Source: FERC Weighs Federal Oversight of AI Data Center Grid Connections — Engineering News-Record report, May 12, 2026, on FERC deliberations over federal jurisdiction of large-load grid interconnection.

  • Industry Coalition Aims to Lead US Critical Infrastructure Cyber Defense

    Industry Coalition Aims to Lead US Critical Infrastructure Cyber Defense

    A newly formed cybersecurity industry coalition has said it intends to take a leading role in protecting United States critical infrastructure — the power grids, pipelines, water systems, telecommunications networks and data centers that other services depend on. The formation was reported on 11 May 2026 by Cybersecurity Dive.

    The coverage available to us is headline-level: it establishes that the coalition exists and states its ambition, but the membership roster, funding model, governance structure and operating timeline are not detailed in the material we can verify. This article analyzes the structural question the announcement raises — what an industry-led body can and cannot do for national cyber defense — and sets out the specifics that remain open.

    Executive Summary

    The announcement is best understood as a positioning move in a shifting division of labor. For roughly a decade, US critical infrastructure cyber defense has been organized around a federal hub — the Cybersecurity and Infrastructure Security Agency (CISA) — surrounded by sector-specific industry groups. Through 2025 and into 2026, CISA absorbed widely reported workforce reductions and proposed budget cuts, while the statutory liability protections that encouraged companies to share threat data with the government lapsed in late 2025 and became the subject of ongoing legislative debate. A vacuum, real or anticipated, invites someone to fill it.

    Why it matters for infrastructure operators: cyber defense at national scale is fundamentally a coordination problem, not a product problem. Attacks on one utility or carrier are previews of attacks on the next, and the value of any defensive body lies almost entirely in how fast and how completely warning travels between competitors. Whoever convenes that exchange sets the terms — what gets shared, with whom, under what legal cover, and at what price.

    What is not yet established: the coalition’s claim to leadership is, at this stage, a stated intention rather than a demonstrated capability. Nothing in the available reporting confirms who has joined, what the group will fund, or how it will relate to the federal agencies and existing sector bodies already occupying this space. Those are the tests worth applying, and they are answerable within months.

    Why Industry Is Volunteering for a Job It Once Resisted

    For most of the past decade, the private sector’s posture toward critical infrastructure cybersecurity policy was defensive: resist mandates, negotiate reporting rules, worry aloud about liability. A coalition announcing that it intends to lead is a notable inversion. The plainest explanation is not altruism but exposure. Roughly the great majority of US critical infrastructure is privately owned and operated, which means the operators absorb the losses — outage costs, ransom payments, regulatory penalties, insurance repricing — regardless of who holds the coordinating role in Washington.

    If federal coordinating capacity contracts, the risk does not disperse; it lands on balance sheets. Under those conditions, funding a shared defensive apparatus becomes a rational cost, in the same way that competing airlines jointly fund safety data programs because a crash at one carrier damages all of them. The economics here are the economics of a public good that private parties have decided to buy for themselves.

    The counter-reading deserves equal weight. Industry coalitions are also lobbying vehicles, and a group that positions itself as the operational leader of critical infrastructure defense acquires substantial influence over the regulation of its own members — including which standards become de facto requirements and which incidents are deemed reportable. Neither reading is disprovable from a formation announcement. Both should be held open until the governance documents appear.

    What a Coalition Can Do — and What Only Governments Can

    A well-run private body can do a great deal. It can pool threat intelligence faster than any agency clears it; it can run joint exercises, publish detection signatures, fund shared tooling for smaller utilities that cannot afford their own security teams, and set procurement standards that vendors must meet to sell into the sector. These are genuine capabilities, and where they already exist — in the sector-based Information Sharing and Analysis Centers, or ISACs, and in cross-vendor groups like the Cyber Threat Alliance — they have measurable value.

    What no coalition can do is exercise state power. It cannot compel a reluctant operator to patch, cannot seize infrastructure used by an adversary, cannot see foreign signals intelligence, cannot indict anyone, and cannot grant legal immunity to a company that hands over customer-adjacent telemetry. That last point is not a technicality. The 2015 information-sharing framework worked largely because it told general counsels that sharing indicators would not create antitrust or privacy liability. With that protection lapsed and its restoration unresolved, a private coalition asking members to share aggressively is asking them to accept legal risk that only Congress can remove.

    The realistic model, then, is complementary rather than substitutive. Industry can carry operational tempo — the fast, technical, day-to-day work of spotting and blocking. Government retains the coercive and intelligence functions. The failure mode to watch for is a coalition that markets itself as a replacement for federal capacity, because that framing tends to reduce political pressure to fund the functions industry structurally cannot perform.

    Winners, Losers, and Who Pays for Coordination

    If the coalition matures, the clearest beneficiaries are large operators with mature security programs. They already generate high-quality telemetry, they can absorb membership costs, and they gain influence over standards they were going to meet anyway. Hyperscale cloud providers and major data center and network operators sit in a particularly strong position: they see enormous volumes of attack traffic, which makes them the most valuable contributors and therefore the most powerful voices at the table.

    The parties at risk of being left out are the ones the country most needs covered — small municipal water systems, rural electric cooperatives, regional hospitals, mid-sized carriers. These organizations often run legacy operational technology, employ few or no dedicated security staff, and cannot pay meaningful dues. Any coalition serious about critical infrastructure rather than large enterprise defense has to answer how those operators are subsidized. A pricing model that tracks ability to pay is a strong signal of seriousness; a flat corporate membership fee is a signal that the group’s practical scope is narrower than its name.

    There is also a vendor question worth watching without prejudging it. Security suppliers have a legitimate operational role in any such body — they hold much of the visibility — and also a commercial interest in defining the standards their products satisfy. Governance that separates threat-sharing operations from standards-setting, with disclosed member lists and recusal rules, is the ordinary remedy. Its presence or absence will be visible in the founding documents.

    The Evidence Test to Apply Over the Next Two Quarters

    Announcements of this kind are cheap; sustained coordination is expensive. Four observable markers separate the two. First, a published member list with named operators from more than one sector — a coalition drawn from a single industry is a trade association with a broader title. Second, a funded budget and paid technical staff, rather than a volunteer steering committee. Third, a concrete first deliverable with a date: a joint exercise, a shared detection feed, a subsidized tooling program for small utilities.

    Fourth, and most diagnostic, an explicit statement of how the group relates to CISA, to the sector coordinating councils, and to the existing ISACs. Critical infrastructure defense is not an empty field; it is a crowded one with a decade of institutional plumbing. A new body that names its interfaces is doing engineering. A new body that does not is, for now, doing communications.

    None of this is a reason for skepticism about the underlying need. The threat picture that plausibly motivated the coalition — persistent adversary pre-positioning inside operational technology networks, ransomware against hospitals and municipalities, the exposure of long software supply chains — is well documented and does not depend on this announcement being substantive. The question is narrower and fairer: whether this particular vehicle is built to carry that weight.

    Background

    US critical infrastructure cyber defense has been organized since the mid-2010s around a public-private model: a federal coordinating hub, formalized as CISA in 2018, working alongside sector coordinating councils and the Information Sharing and Analysis Centers that circulate threat data within industries. The Cybersecurity Information Sharing Act of 2015 supplied the legal foundation, giving companies liability protection for passing indicators of compromise to the government and to each other. In 2021, CISA added the Joint Cyber Defense Collaborative to bring major technology and security firms into planning alongside federal agencies.

    That arrangement has come under strain. CISA sustained widely reported staffing reductions and proposed budget cuts through 2025 and into 2026, while the 2015 law’s information-sharing protections lapsed in late 2025 with restoration still contested in Congress. At the same time, publicly documented threats to operational technology networks — the industrial control systems that run grids, pipelines and water treatment — have grown more persistent. Roughly the great majority of the affected assets are privately held, meaning the operators carry the financial consequences regardless of how federal capacity evolves. That combination is the setting into which this coalition has announced itself.

    Source: New cybersecurity industry coalition aims to lead US critical infrastructure protection — Cybersecurity Dive, 11 May 2026, reporting the formation of an industry group intending to take a leading role in US critical infrastructure cyber defense.

  • Hydronic Design Rethink: Direct-to-Chip Cooling Outgrows Legacy Plant Assumptions

    Hydronic Design Rethink: Direct-to-Chip Cooling Outgrows Legacy Plant Assumptions

    Data Center Knowledge published an analysis on May 11, 2026, titled “Redefining Hydronic Design for D2C Liquid Cooling,” addressing how the shift to direct-to-chip (D2C) liquid cooling is changing the way data center water systems — the hydronic plant — must be designed. The piece lands amid an industry-wide transition in which AI-driven rack power densities have climbed beyond what traditional air-cooled facility designs were built to handle.

    Executive Summary

    The core issue flagged by the headline is straightforward but consequential: direct-to-chip liquid cooling — where coolant is piped through cold plates mounted directly on processors, rather than cooling servers with chilled air — does not simply bolt onto the chilled-water infrastructure most data centers already have. Hydronic design, meaning the engineering of the pumps, piping, heat exchangers, and control systems that move liquid through a facility, was historically sized around air handlers serving racks of modest power draw. D2C changes the temperatures, flow rates, water quality requirements, and failure modes the plant must support.

    Why it matters: liquid cooling has moved from niche to mainstream as AI accelerators push per-rack power well beyond what air can economically remove. Operators deciding between retrofitting existing plants and building new liquid-native facilities are making capital decisions that will constrain them for decades. A trade-press focus on hydronic fundamentals — rather than just on the servers or cold plates — signals that the industry’s bottleneck conversation is shifting upstream, from the rack to the plant room.

    The Plant Room Becomes the Bottleneck

    For two decades, data center cooling design treated the white space and the plant as loosely coupled: air handlers absorbed variation on the floor, and the chilled-water loop behind them changed slowly. Direct-to-chip cooling collapses that buffer. The coolant loop now terminates inches from the silicon, typically through a coolant distribution unit (CDU) — a device that isolates the clean, tightly controlled technology loop serving the servers from the facility water loop. That coupling means plant-side decisions about supply temperature, flow stability, and redundancy propagate directly to chip behavior, and legacy assumptions about acceptable temperature bands and transient response no longer hold automatically.

    This is why hydronic design is having its moment in the trade press. The hard problems in liquid cooling are increasingly civil and mechanical engineering problems — pipe sizing, pump redundancy, water treatment, commissioning — not server-vendor problems. Operators who treat D2C as a rack-level product purchase, rather than a facility-level design change, risk discovering the mismatch after the equipment is on the dock.

    Warm Water Changes the Economics

    A frequently underappreciated aspect of D2C cooling is that cold plates can generally accept much warmer supply water than air-cooling systems require. Warmer facility water expands the hours in which outside air can reject heat without running chillers — so-called free cooling — which can reduce energy consumption and, in some designs, eliminate mechanical refrigeration for part or all of the year. But capturing that benefit requires designing the hydronic system around it: heat exchangers, dry coolers, and controls sized for warm-water operation, not a legacy chilled-water loop running at temperatures chosen for air handlers.

    The economics cut both ways. A retrofit that simply taps an existing chilled-water plant may work, but it can leave the efficiency upside of liquid cooling unrealized and burden an aging plant with duty it was never sized for. A purpose-designed warm-water system costs more up front and demands different operational expertise. The Data Center Knowledge piece’s framing — redefining hydronic design rather than extending it — suggests the editorial judgment that incrementalism has limits here, a view worth testing against each facility’s actual constraints.

    Winners, Losers, and the Skills Gap

    If hydronic design is the new frontier, the beneficiaries are the firms that own that competence: mechanical engineering consultancies, CDU and heat-rejection equipment manufacturers, and colocation providers that invested early in liquid-ready plants. Operators of large fleets of air-era buildings face harder choices — retrofit selectively, densify only some halls, or cede the highest-density workloads to newer facilities. There is also a human dimension: hydronic systems at this criticality level need commissioning agents and operators fluent in water chemistry, two-phase transients, and leak response, and that talent pool is thin relative to the pace of AI buildout.

    None of this makes air cooling obsolete. Most enterprise workloads remain comfortably air-coolable, and hybrid facilities — liquid for accelerator rows, air for everything else — are likely the dominant pattern for years. The design challenge the article’s title points to is precisely that hybridity: one plant serving two very different thermal customers.

    Background

    Data centers have been overwhelmingly air-cooled since the industry’s beginnings: chillers or outside air cool water, water cools air handlers, and air cools servers. That chain held while racks drew a few kilowatts each. The AI buildout of the mid-2020s broke the assumption, as accelerator-dense racks pushed power draw to levels where moving enough air became impractical, driving rapid adoption of direct-to-chip liquid cooling across hyperscale, colocation, and enterprise deployments.

    The transition has unfolded in stages — first server-level cold plates, then rack-level manifolds and CDUs, and now, as this Data Center Knowledge piece reflects, a reckoning with the facility-level hydronic plant itself. Industry bodies and operators have been working toward common temperature classes and reference designs, but practice is still consolidating, which is why plant-level design questions remain live editorial territory in 2026.

    Source: Redefining Hydronic Design for D2C Liquid Cooling — Data Center Knowledge analysis, published May 11, 2026, on how direct-to-chip liquid cooling is reshaping data center water-system design.

  • OpenAI Launches Daybreak: An AI-vs-AI Turn in Cyber Defense

    OpenAI Launches Daybreak: An AI-vs-AI Turn in Cyber Defense

    On May 11, 2026, CIO Dive reported that OpenAI has launched Daybreak, a product aimed at combating cyber threats. The launch moves the company best known for ChatGPT and its GPT model family directly into the cybersecurity market, where it will compete with established security vendors that have spent the past three years bolting AI assistants onto their platforms.

    Public details at launch are limited: the report identifies the product and its defensive mission, but headline coverage does not spell out pricing, availability, deployment model, or named customers.

    Executive Summary

    OpenAI’s entry into cyber defense is notable less for what Daybreak is — the initial reporting leaves much of that undefined — than for what it signals: the leading frontier-model lab now believes security operations is a market worth owning directly, rather than one to serve indirectly through partners building on its models. Cybersecurity is one of the few enterprise software categories where AI’s value proposition is immediate and measurable, because defenders are chronically outnumbered and attackers have already begun using AI tooling of their own.

    For security and infrastructure leaders, the announcement crystallizes a shift that has been building since 2023: threat detection and response is becoming an AI-versus-AI contest, where the speed and quality of a defender’s models matter as much as the size of its analyst team. Whether Daybreak can convert OpenAI’s model advantage into security outcomes depends on factors the launch coverage does not yet address — chiefly what telemetry it sees, how it deploys, and what evidence backs its detections.

    Why a Frontier AI Lab Wants the Security Business

    OpenAI’s move up the stack from model provider to security product vendor follows a clear commercial logic. Security operations centers — the teams (often called SOCs) that monitor an organization’s networks for intrusions — generate exactly the kind of high-volume, high-stakes text and log analysis that large language models handle well: triaging alerts, summarizing incidents, correlating signals across systems, and drafting response actions. Security budgets are also among the most resilient lines in enterprise IT spending, making the category attractive for a company under pressure to show durable enterprise revenue against its enormous compute costs.

    OpenAI has also been edging toward this market for years. It has published periodic reports on threat actors abusing its models, run a cybersecurity grant program to fund defensive AI research, and operated a public bug bounty. Daybreak, as reported, converts that adjacency into a product. The strategic question is whether a model lab can succeed in a market where incumbents own something OpenAI historically has not: the security telemetry itself.

    The AI-vs-AI Arms Race Reaches the SOC

    The defensive case for AI is grounded in an asymmetry every security leader knows: attackers need one gap, defenders must cover everything, and skilled analysts are scarce. AI-assisted attackers have raised the tempo — more convincing phishing, faster reconnaissance, quicker exploitation of newly disclosed vulnerabilities — while defenders drown in alerts, most of them false positives. An AI system that can triage that flood credibly, around the clock, addresses a genuine and well-documented operational pain, not a manufactured one.

    But the AI-vs-AI framing cuts both ways. Detection models can be probed, evaded, and manipulated; a defensive AI that acts autonomously can be turned into a liability if an attacker learns to trigger false responses or poison its inputs. The launch coverage does not indicate how much autonomy Daybreak exercises, and that distinction — assistant that recommends versus agent that acts — is the single most consequential design choice in this product category.

    A Crowded Field Where Incumbents Hold the Telemetry

    OpenAI arrives late to a race its own models helped start. Microsoft ships Security Copilot atop its Defender and Sentinel telemetry; CrowdStrike has Charlotte AI woven into the Falcon platform; Google pairs its models with Mandiant threat intelligence and its security operations suite; Palo Alto Networks, SentinelOne, and others market AI-driven detection as core product. These incumbents hold an advantage that raw model quality does not erase: continuous, privileged visibility into endpoints, networks, and identity systems, plus years of labeled incident data to ground their detections.

    OpenAI’s plausible counters are the strength of its frontier models and its distribution — ChatGPT’s enterprise footprint gives it a door into companies that security-only vendors lack. There is also an awkward dependency to watch: Microsoft is simultaneously OpenAI’s largest partner and, in security, now a direct competitor. How Daybreak positions against Security Copilot will say a great deal about how far the two companies’ interests have diverged.

    What Buyers and Infrastructure Operators Should Watch

    For prospective buyers, the practical bar is unchanged by the vendor’s fame: measurable detection efficacy, tolerable false-positive rates, clear data-handling terms, and compliance attestations that security teams require before routing sensitive telemetry through any third party. Feeding an external AI service your security logs — among the most sensitive data an organization holds — demands stronger guarantees than a chatbot subscription, and the launch reporting does not yet describe them.

    For infrastructure operators, security AI is another driver of the inference boom: always-on analysis of logs and network traffic is compute-intensive and latency-sensitive, and regulated customers will push for regional or on-premises processing. Whether Daybreak runs purely in OpenAI’s cloud or supports customer-controlled deployment will shape which organizations can adopt it at all — and adds one more workload class to the demand already straining data center capacity.

    Background

    OpenAI, founded in 2015 and propelled to household-name status by ChatGPT’s late-2022 launch, has spent the years since expanding from research lab to enterprise software vendor, backed by a multibillion-dollar partnership with Microsoft and revenue from API access and ChatGPT subscriptions. Its security involvement had previously been defensive housekeeping — threat reports on model misuse, a cybersecurity grant program, a bug bounty — rather than product.

    The market it now enters has been the proving ground for enterprise AI since 2023, when Microsoft’s Security Copilot kicked off a wave of AI security assistants from CrowdStrike, Google, Palo Alto Networks, and others. The underlying driver is structural: a long-running shortage of security analysts colliding with attack volumes that AI tooling has helped adversaries scale.

    Source: OpenAI launches Daybreak to combat cyber threats — CIO Dive’s May 11, 2026 report on OpenAI’s entry into the cyber-defense market.

  • FERC Targets Data Center Interconnection Delays: The Grid Chokepoint for AI

    FERC Targets Data Center Interconnection Delays: The Grid Chokepoint for AI

    The Federal Energy Regulatory Commission (FERC) — the U.S. agency that oversees interstate electricity transmission and wholesale power markets — is taking aim at the delays data centers face when connecting to the power grid, according to a May 11, 2026 report from Broadband Breakfast. Interconnection, the formal process by which a large new electricity load or generator gets studied and physically wired into the transmission system, has become one of the tightest bottlenecks in the AI infrastructure buildout.

    Executive Summary

    According to the report, FERC is targeting the interconnection delays that have left large data center projects waiting — often years — for grid connections. The report available to us is brief and does not detail the specific mechanism, so it is not yet clear whether the action takes the form of a rulemaking, an order directed at grid operators, or a preliminary inquiry. What is clear is the direction: the federal regulator most responsible for transmission access is treating data center connection timelines as a problem worth its attention.

    Why it matters: capital, chips, and land have largely stopped being the binding constraints on AI data center construction — power is. A hyperscale campus can be financed and built in two to three years, but securing a firm grid connection can take longer than that in constrained regions. Any FERC move that compresses those timelines, or that standardizes how utilities and regional grid operators study large new loads, goes directly to the pace at which announced AI capacity actually energizes.

    The Queue Is the Chokepoint

    For most of the grid’s history, interconnection processes were designed around new power plants, not new consumers. A data center drawing hundreds of megawatts — comparable to a small city — inverts that model: it is a load so large that utilities must run detailed studies to confirm the transmission system can serve it without destabilizing service to everyone else. Those large-load studies are handled inconsistently across the country, often utility by utility, with no uniform federal timeline. The result is a patchwork in which functionally identical projects can face wait times that differ by years depending on jurisdiction.

    FERC has already spent years reforming the generator side of this problem — its Order 2023 overhauled generator interconnection queues with clustered, first-ready-first-served studies after backlogs stretched to multi-year waits. The load side, where data centers sit, has had no equivalent national framework. FERC has also been drawn into adjacent fights, most visibly over co-location arrangements that would place data centers directly at existing power plants, a structure that raised contested questions in the PJM region about who pays for the grid and who gets access to scarce capacity. An action targeting data center interconnection delays fits a pattern of the Commission being pulled, docket by docket, into the collision between AI demand growth and grid process.

    What Federal Action Can and Cannot Fix

    FERC’s leverage is real but bounded. It regulates interstate transmission and the regional grid operators (RTOs and ISOs) that administer most of the U.S. bulk power system, so it can standardize study timelines, impose deadlines, and clarify cost responsibility for network upgrades. That could meaningfully shrink the procedural portion of interconnection delays — the months lost to sequential studies, restudies, and ambiguity about process.

    What FERC cannot conjure is physical capacity. Where delays reflect genuinely constrained transmission — lines and transformers that do not yet exist — faster paperwork simply delivers a faster “no” or a large upgrade bill. Transformers and high-voltage equipment carry their own multi-year supply lead times, and retail-level service decisions remain with states and local utilities. The honest framing is that federal reform can remove artificial delay, not engineering reality; both matter, and the report available does not indicate which FERC believes is dominant.

    Winners, Losers, and the Cost Question

    Faster, more predictable interconnection most benefits large, well-capitalized developers — hyperscalers and major colocation operators — who can meet readiness requirements and post financial commitments quickly. It also benefits regions competing for data center investment, where interconnection uncertainty has begun steering projects toward states or utilities perceived as faster. Utilities face a more mixed picture: standardized deadlines add pressure and potential liability, but a clearer process also protects them from accusations of arbitrary treatment.

    The hardest question any reform must answer is cost allocation: when a multi-hundred-megawatt load triggers transmission upgrades, does the data center pay, or do those costs spread across all ratepayers? Consumer advocates have pressed this issue sharply as residential bills rise in data-center-heavy regions, and it was central to the co-location disputes FERC has already handled. A reform that accelerates connections without settling who pays would relocate the fight rather than resolve it — and that question deserves scrutiny regardless of which side raises it.

    Background

    FERC’s involvement in the data center power crunch has been building for several years. U.S. electricity demand, flat for roughly two decades, began rising sharply in the mid-2020s as AI training and cloud workloads drove a wave of hyperscale construction, and grid operators repeatedly raised their load forecasts in response. The Commission modernized generator interconnection with Order 2023, but large consuming loads had no comparable national framework, leaving data centers subject to a patchwork of utility-specific processes. FERC was also pulled into high-profile disputes over co-locating data centers at power plants, which crystallized the cost-allocation and market-access questions that any broader interconnection reform will have to answer. Action targeting data center connection delays is the logical next step in that progression.

    Source: FERC Targets Data Center Interconnection Delays — Broadband Breakfast report, May 11, 2026, on federal regulatory action addressing grid connection delays for data centers.

  • The Inference Shift: Why AI’s Economics Are Moving From Training to Serving

    The Inference Shift: Why AI’s Economics Are Moving From Training to Serving

    On May 11, 2026, technology analyst Ben Thompson published an essay on his influential Stratechery newsletter titled “The Inference Shift,” arguing that the economic center of gravity in artificial intelligence is moving from training — the one-time, compute-intensive process of building a model — to inference, the ongoing work of running that model every time a user asks it a question.

    Thompson’s framing matters because Stratechery is widely read by technology executives and investors, and because the training-versus-inference balance directly shapes where the next wave of infrastructure spending — chips, data centers, power, and networks — actually lands.

    Executive Summary

    The essay’s core contention, as its title signals, is that the AI buildout’s defining workload is changing. Training a frontier model is a bounded project: enormous, but finite, concentrated in a handful of massive facilities run by a handful of well-capitalized labs. Inference is different in kind. It scales with usage — every chatbot session, coding assistant, and AI-powered search query consumes compute — so as AI products find real adoption, serving them becomes a continuous, growing operating cost rather than a one-time capital project.

    For infrastructure providers, that distinction is not academic. Training demand rewards maximum-density campuses wherever cheap power and land exist, with latency largely irrelevant. Inference demand rewards something closer to the traditional internet: capacity distributed nearer to users, resilient connectivity, and economics measured in cost per query rather than cost per training run.

    Because the full essay sits behind Stratechery’s subscription, this analysis works from the thesis itself — the shift from training to inference economics — rather than from the piece’s specific figures or examples, and examines what that shift would re-rank across the infrastructure landscape.

    Two Very Different Kinds of Compute Demand

    Training and inference stress infrastructure in almost opposite ways. Training jobs run for weeks or months across thousands of tightly interconnected accelerators, which pushes builders toward gigantic single-site campuses where power is cheap and abundant — remoteness is a feature, not a bug. Inference workloads are short, bursty, and user-facing: a response has to come back in a second or two, which puts a premium on proximity to population centers, redundancy, and network quality.

    The economics diverge just as sharply. Training is capital expenditure that a company chooses to make; it can be deferred, right-sized, or cancelled. Inference is tied to revenue-generating usage — if customers are querying your model, you must serve them, and your margins depend on how cheaply you can do it. A market organized around inference is one where efficiency per query, not raw peak capacity, becomes the competitive battleground.

    What Gets Re-Ranked in Infrastructure Demand

    If Thompson’s thesis holds, several categories of infrastructure move up the priority list. Metro and regional data centers — including colocation capacity near enterprise users — regain relevance after a period in which headlines were dominated by remote gigawatt-scale training campuses. Connectivity providers benefit, because distributed inference multiplies traffic between users, edge sites, and core facilities. Power demand becomes more geographically dispersed and steadier in profile, a different planning problem for utilities than a handful of enormous point loads.

    The chip layer re-ranks too. Training has been dominated by the most powerful general-purpose GPUs, where flexibility justifies premium pricing. Inference, being a more predictable and repetitive workload, is friendlier to specialized silicon and to cost-optimized accelerators — which is precisely why cloud providers have invested in custom inference chips and why competition at this layer is more open than in training hardware.

    Winners, Losers, and the Margin Question

    The clearest beneficiaries of an inference-led market are operators with distributed footprints, strong interconnection, and the ability to sell capacity in smaller, latency-sensitive increments — along with any vendor that reduces cost per query, from silicon designers to cooling and power-efficiency specialists. The more exposed parties are those whose plans assume training demand grows indefinitely on its current trajectory: single-tenant mega-campuses purpose-built for one lab’s training runs carry concentration risk if that lab’s training appetite plateaus while its serving needs move elsewhere.

    There is also a margin story embedded in the shift. When inference is the dominant cost, AI application companies face a squeeze between what users pay and what serving costs — which pressures them to negotiate hard with infrastructure suppliers, adopt cheaper hardware, and shrink models where quality allows. Infrastructure revenue may keep growing, but the pricing power within the stack could redistribute.

    Reasons for Caution

    The thesis has honest counterarguments, and they deserve equal scrutiny. Frontier labs continue to spend heavily on training, and newer techniques that make models “think longer” at answer time blur the line — they raise inference costs, supporting the thesis, but also keep demand for dense, training-class hardware high. It is also possible that both curves rise together, in which case “shift” overstates a rebalancing. And headline-level analysis of a subscription essay cannot verify which evidence Thompson marshals; readers should treat the thesis as a framework to test against disclosed capital-spending and usage data, not as settled fact.

    Background

    Stratechery, founded by Ben Thompson in 2013, is a subscription publication analyzing the strategy and economics of the technology industry, and it has been one of the more influential independent voices in debates over the AI buildout. The training-versus-inference question it takes up here has become central to that buildout: the industry’s first phase was defined by a race to train ever-larger foundation models, concentrating spending on top-end GPUs and massive single-site campuses.

    As AI products have moved from demos to daily tools, attention has turned to the cost of actually serving them at scale. Cloud providers have developed custom inference chips, model developers have released smaller and cheaper model variants, and newer ‘reasoning’ models that consume extra compute per answer have pushed inference costs up further — all of which forms the backdrop against which Thompson’s May 2026 essay lands.

    Source: The Inference Shift — Stratechery by Ben Thompson, an analytical essay published May 11, 2026, arguing that AI economics are moving from model training to inference.