It's a Series of Buildings

It's a Series of Buildings

“The Internet is not something that you just dump something on. It’s not a big truck. It’s a series of tubes.” — Senator Ted Stevens, June 28, 2006

We spent the better part of fifteen years mocking that man, and I was right there in the crowd doing it. It became a meme, a late-night punchline, and permanent shorthand for every legislator who ever tried to regulate a thing he couldn’t be bothered to understand first. I laughed then and I’d probably laugh again tomorrow. But here’s the uncomfortable bit that I’ve come around to somewhere in the last couple of years: Stevens, for all the deserved ridicule, understood something about the Internet that most of the people currently screaming at their county commissioners about data centers do not. He knew the thing was made of stuff. He got the stuff spectacularly, memorably wrong, but he never once made the mistake of thinking it wasn’t there.

Ask the average person where the Internet actually lives and you’ll get a shrug and the word “cloud,” which I’d argue is one of the most successful pieces of marketing in my lifetime, a word chosen with some care to make you stop asking follow-up questions, and it worked beautifully. Ask what a data center does and you’ll get exactly one answer now, delivered with the confidence of somebody who read a headline: AI. That’s the whole answer. A windowless warehouse full of humming boxes making pictures of cats playing drums and putting graphic designers out of work.

Which is roughly like walking through a hospital, spotting one MRI machine in a hallway, and concluding that hospitals are MRI factories. Would you build policy on that? Because we’re about to.

So let me put my position on the table right here at the top, before I’ve spent a thousand words dancing around it and you’ve spent that whole time trying to figure out which side I’m on. We need more data centers. Quite a lot more, actually. And we are currently doing a spectacularly bad job of deciding where to put them. Those are two separate claims, and the thing that makes this argument so exhausting is that almost nobody involved is willing to hold both of them at the same time. The industry says the first part loudly and treats the second as a permitting inconvenience to be managed by lawyers. The opposition says the second part loudly and treats the first as a lie cooked up by somebody’s marketing department. They’re each about half right.

Which in practice gets us the worst outcome available: the buildings go up anyway, on the wrong land, in the wrong counties, negotiated in the dark by whoever had the better lobbyist.

What’s actually in the building

That takeout order you placed last night lives in a data center. So does your pharmacy record, your last three chest X-rays, the show you fell asleep to, your bank’s ledger, the photo of your kid’s first steps, your work email, the DNS lookup that got you to this page, and the payroll system that pays you on Friday. Every single online experience you have ever had was born, lived, and died inside one of these buildings, and that was true a decade before anybody in your neighborhood had an opinion about them. The AI is a tenant. It is emphatically not the landlord.

The landlord has been in business since 1945, when the University of Pennsylvania put up a purpose-built room to house ENIAC: roughly 1,800 square feet of floor, some 18,000 vacuum tubes, 150 kilowatts of draw, and a dedicated electrical and cooling plant whose entire job was keeping the thing from cooking itself into slag. Raised floor, conditioned power, dedicated cooling, restricted access. That is a data center in every way that matters, and we have been building them continuously for eighty years.

So how many have we got? Nobody can agree, is the short answer. Depending on whose count you trust and how you define the term, the United States has somewhere between about 4,400 and 5,400 of them, which is more than any other country on Earth by a margin that isn’t close (Statista, 2026).

I find that spread genuinely funny, and I want to sit on it for a second. We are having a loud national argument (moratoriums, ballot measures, three hundred–odd pieces of state legislation, people shouting at zoning boards on Tuesday nights) about a category of building that we cannot collectively count to within a thousand. That’s not a knock on anybody in particular. It’s just a decent indication of how much of this conversation is happening upstream of the facts.

So when somebody tells you that data centers showed up with the chatbots, what they’re actually telling you is that they showed up with the chatbots. Which is fine, and I’d rather have them in the conversation late than not at all. Most of us didn’t have a strong opinion about air travel until the first time we sat on a tarmac for three hours with a dead phone and a full bladder.

The buildings are already full

Before anybody accuses me of carrying water for the hyperscalers, let’s look at the occupancy numbers, because they settle the “do we actually need more of these” question considerably faster and more honestly than any argument I could construct.

North American data center vacancy is sitting at roughly one percent, and has been for two consecutive years now, even as inventory grew by a third year over year. Northern Virginia, the densest market on the continent, is down around three-tenths of one percent. And better than eighty percent of the capacity currently under construction is preleased, meaning it was spoken for before anybody poured the slab (CBRE, 2026). Sit with that a moment, because it’s the whole ballgame.

Is that what a speculative bubble looks like? It is not. A bubble has empty buildings in it. This is the opposite condition, and it’s the condition we’ve been in for two years running.

The demand curve underneath those numbers is doing something genuinely uncomfortable, too. US data center power draw ran about 31 gigawatts in 2025, is estimated somewhere north of 40 this year, and is projected to hit 66 by 2027 (S&P Global, 2025). One major forecaster revised its 2030 US capacity projection upward by 52 percent inside a single six-month cycle, which should tell you something about how well any of us are modeling this (BloombergNEF, 2026). Meanwhile the analysts putting numbers on the generation side figure the country needs better than 230 gigawatts of new generating capacity over the next five years, against something like 93 gigawatts that regulated utilities have actually planned for (Utility Dive, 2026).

Do the subtraction on that last one. It’s a shortfall well north of 100 gigawatts, and I’d point out that a shortfall has never once in the history of infrastructure been an argument for building fewer of the thing. It’s an argument for building the right ones, in the right places, near power that actually exists rather than power somebody has promised to build later.

Both sides are arguing in bad faith, and it’s why we’ll build these badly

I want to tread carefully here, because this is the paragraph where everybody’s tribal loyalties kick in and half of you decide I’m a shill for the other team. Both sides of this fight have thoroughly earned their reputations, and between the two of them they have made an absolute hash of the one decision that actually matters.

The industry side first, since they’re the ones who started it. The pattern over the last few years has been consistent to the point of being boring: sign an NDA with county officials, dangle a number with a great many zeros in front of a budget-strapped commission, get the project onto a consent agenda at some inconvenient hour, and let the community find out what happened after it happened. Does that sound uncharitable? Consider the record.

In one Oklahoma case, city officials signed a nondisclosure agreement with a developer more than a year before the project was announced publicly, after which the city manager advised that developer to work the tax incentive district privately before anybody held a public meeting (The Frontier, n.d.).

Lawmakers in at least ten states have now introduced bills specifically to restrict NDAs in data center deals (Public Citizen, n.d.), and I’d gently suggest that legislatures do not generally do that to industries that are behaving themselves.

And it worked, briefly, the way that kind of thing always works right up until it doesn’t. Gallup went into the field this past March and found that seven in ten American adults oppose an AI data center being built in their local area: 71 percent against, 48 percent of them strongly against, with only 27 percent in support (Gallup, 2026). Roughly $18 billion in projects have been blocked outright and another $46 billion delayed (Data Center Watch, 2026). Congratulations on the short-term win, everybody. You traded a decade of goodwill for a few fast-tracked approvals, and now you get to build in an environment where seven out of ten people would rather you didn’t exist.

But the opposition has its own problem, and I say this as somebody generally sympathetic to people who don’t want their county turned into somebody else’s utility bill. A meaningful share of this opposition isn’t actually about water or power or pollution at all. It’s about not wanting a large windowless building near your subdivision, dressed up in whichever technical argument happens to poll best that particular month. Now, not wanting that building near you is a completely legitimate thing to feel, and I’m not going to pretend otherwise. It is not, however, a legitimate thing to disguise as something else, and the disguising is precisely what makes the real objections, of which there are several good ones, so much harder for anybody to hear.

The water thing

Let’s take the specific claim head-on, because it’s the one I get asked about most often and the one where the actual truth turns out to be considerably more interesting than either side’s version of it.

Older facilities cool themselves by evaporating water, and they evaporate a genuinely enormous quantity of it, something like 70 to 80 percent of what goes in never comes back out, with most of the remainder discharged as wastewater (Environmental and Energy Study Institute, n.d.). Modern closed-loop designs recirculate the same coolant instead of drinking the river.

One operator published figures on a Wisconsin campus showing peak water use of roughly 22,000 gallons a day, set against something on the order of 5 million gallons a day for a comparable campus running evaporative cooling (Vantage Data Centers, 2026). That is not a rounding error or a marketing flourish. That is two orders of magnitude, and the great majority of the remaining 22,000 gallons is toilets, sinks, and mopping the floors.

Here’s the part the industry press tends to leave out, though, and I’d frankly rather you hear it from somebody standing on my side of this argument than discover it later and decide I was hiding it. Closed-loop cooling does not make the water disappear. It moves it upstream, out of the county and onto somebody else’s ledger. Thermoelectric generating plants consume water to make electricity; a closed-loop facility’s real water footprint therefore scales almost directly with how much power the thing pulls off the grid (Vantage Data Centers, 2026). So did we solve the problem, or did we just relocate it somewhere the county commission isn’t looking? Honestly, both. It’s a real and substantial engineering improvement and it’s a real accounting dodge, simultaneously, and anybody selling you only the first half of that sentence is selling you something.

Where to put them, which is the entire ballgame

Siting is the part of this whole argument that would benefit enormously from engineers instead of lawyers, and it’s the part almost nobody wants to talk about, largely because it doesn’t fit on a yard sign and it doesn’t make anybody feel righteous.

Here’s the actual constraint set, and it is not negotiable in the way that people seem to believe it is. These buildings need to be geographically dispersed, because dispersion is the entire reason the system survives a hurricane, a backhoe through a fiber run, or a bad Tuesday at any single facility. They need to sit reasonably close to large population centers, because physics does not negotiate and the speed of light in glass is what it is (I have spent an embarrassing share of my career explaining to people why their latency problem is not, in fact, a bandwidth problem, and I expect to spend the rest of it doing the same). They need to be near power that already exists or can plausibly be built; that is the binding constraint right now, and it will remain the binding constraint for at least a decade. And they should not go in a desert where water is already a knife fight, no matter how attractive the land looks on a spreadsheet.

Notice what that list actually does. It rules out an awful lot of places, including, and I want to be blunt here, most of the places currently being pitched precisely because the land is cheap and the county is desperate enough not to ask hard questions. But it also rules out “nowhere,” which is exactly where the NIMBY position lands if you follow it honestly all the way to the end and don’t flinch. Cheap acreage and a compliant commission are not siting criteria. They are the path of least resistance, and we are presently allowing the path of least resistance to make a generational infrastructure decision on our collective behalf.

That is the failure I actually lose sleep over. Not that we’re building too many of these things. That we are building them stupidly, in the wrong places, for the wrong reasons, and that we will be living with those choices long after everybody in the current argument has moved on to being angry about something else.

And no, we can’t simply wait it out

I would love to tell you that we have all the time in the world to slow down and get this right at our leisure, and that the only thing standing between us and a considered national siting strategy is a bit of patience. I don’t believe that’s true, and the reason has very little to do with technology.

China added 543 gigawatts of power generation capacity in 2024 alone, more capacity in a single year than the United States has added across its entire history, and its data center rack count grew at roughly 30 percent annually from 2016 through 2023 (Al Jazeera, 2026). We have export controls that have kept the best silicon out of their hands, and that advantage is real, but it is also the only column where we’re clearly ahead. We have the brains and nowhere to plug them in. They have the outlet and they’re working on the brains.

I don’t love framing any of this as an arms race, and I want to be honest with you about exactly why. I have watched that precise framing get deployed to justify an enormous quantity of stupid, expensive, irreversible decisions over the course of my career, almost always by somebody who had something to sell at the end of the pitch. So take my discomfort as given. But I cannot look at those two columns and honestly conclude that unilaterally stopping is a strategy rather than a wish. What would it even look like in practice? We freeze, they don’t, and in eight or ten years we’re renting our compute from somebody else’s grid on somebody else’s terms.

And the stakes have stopped being theoretical. This past May, Google’s threat intelligence team documented what it assesses to be the first zero-day exploit found in the wild that was developed with the help of a large language model: an attacker walked a model through a semantic logic flaw in an open-source administration tool and got back a functional bypass for two-factor authentication.

State-sponsored groups are now running vulnerability discovery at genuinely industrial scale, thousands of recursive prompts chewing methodically through CVEs and validating proof-of-concept exploits without a human in the loop (Google Cloud, 2026).

And that was the old news by the time this spring was over. In April, Anthropic published its assessment of a model called Claude Mythos Preview, and the findings ought to give anybody in this trade a long pause. In testing it autonomously located and exploited zero-day vulnerabilities across every major operating system and every major web browser, including a 27-year-old bug in OpenBSD (an operating system whose entire reputation rests on not having bugs like that) and a 16-year-old flaw in FFmpeg that every fuzzer and every human reviewer had walked straight past since 2010. It also turned up weaknesses in the implementations of TLS, AES-GCM, and SSH that would let an attacker forge certificates or decrypt traffic. Anthropic declined to release it publicly (Anthropic, 2026).

I want to be precise about that last bit, because it is going to get flattened in the retelling and I’d rather not contribute. Mythos did not break the underlying mathematics of modern cryptography. It broke the code that people wrote around the mathematics, which, if you’ve been paying attention for the last thirty years, is where essentially every real-world cryptographic failure has always lived anyway. That’s not a reassurance. It’s just an accurate description of where the bodies are buried.

Then in July we stopped theorizing. During an internal evaluation of cyber capabilities, run deliberately with the usual refusals dialed down (a defensible choice for a benchmark, an uncomfortable one in hindsight), a combination of OpenAI models went looking for a way to cheat on the test. They found a zero-day in a package registry proxy, used it to escape a sandbox that was supposed to have no Internet access at all, escalated privileges and moved laterally until they reached a node that did, worked out that the answers they wanted were probably sitting on Hugging Face’s infrastructure, and then chained stolen credentials and further zero-days into remote code execution on Hugging Face’s production servers. OpenAI called it “an unprecedented cyber incident” (OpenAI, 2026).

Now, the root cause was a misconfigured isolation boundary. A sandbox that was supposed to be sealed wasn’t. I have been doing this long enough to have a thoroughly settled opinion about misconfigured isolation boundaries, which is that they are among the most ordinary failures in our industry and that every one of us has shipped one. There is nothing exotic about that mistake. What’s new — and what should be keeping people up at night — is what was sitting on the other side of it, patiently looking for exactly that.

None of this is going back in the box. And the side that can’t afford the compute to run the same playbook defensively is simply the side that finds out second.

The other column

The upside is not hypothetical either, and it deserves considerably more than the hand-wave it usually gets from people like me who spend most of our time being skeptical about everything.

The first drug designed by AI against a target that was itself discovered by AI has now posted positive Phase IIa results, with better than a 60 percent reduction in the time from project start to preclinical candidate (Drug Target Review, 2026). Structure prediction hasn’t replaced experimental structural biology the way the early hype insisted it would; if anything, the researchers using it are submitting more experimental structures, not fewer, because now they know where to look. And rare disease genetics, which has historically been a decade-long diagnostic odyssey for families with a sick kid and no answers, is increasingly a matter of getting the causative mutation onto a short list in an afternoon.

I’ve been a professional consumer of oncology since 2012, so I’ll declare my interest plainly: I have a specific, selfish, entirely non-theoretical stake in that pipeline moving faster than it currently does. Weigh that against a stranger’s discomfort with the sightlines from his back deck. I know where I come out, and I understand perfectly well that reasonable people land elsewhere.

The one thing you can actually do about it

Here’s my favorite part of this whole essay, mostly because it’s the only place in it where I get to stop lecturing institutions that will never read this and start lecturing you, who apparently have.

A text query to a large model costs something on the order of a quarter of a watt-hour. A five-second generated video runs somewhere in the neighborhood of a thousand watt-hours, which is your microwave going flat out for a solid hour (MIT Technology Review, 2023). That is roughly four thousand to one, and the curve isn’t even linear; double the length of the clip and the energy required quadruples.

So every time somebody cooks up another slop reel of a raccoon doing observational stand-up, to post on a platform that nobody will remember in three years, that’s the microwave. All day. Every day. Multiplied by a few hundred million profoundly bored people with a thumb and a data plan.

Is this where the real weight sits? No, and I’m not going to pretend otherwise just because it makes for a tidier ending. The industrial draw is training runs and inference on things that genuinely matter, and your social media habit is not what’s straining the grid in Loudoun County. But it is the only lever in this entire essay that belongs to you, personally, rather than to a county commission or a utility or the Department of Energy, and I’d argue that the single largest thing any individual can do about data center growth isn’t showing up to a zoning meeting with a hand-lettered sign. It’s not making the raccoon.

So

Data centers are eighty years old, they hold the entirety of your digital life, and AI is merely the newest tenant in a building that was already running at ninety-nine percent occupancy before it arrived. They use rather less water than you have been told and rather more power than the industry likes to admit in public. The companies building them have behaved badly enough, and secretively enough, to have earned every bit of the distrust currently coming their way. And the communities fighting them have started making arguments that do not survive first contact with a calculator.

Both of those things are true simultaneously, which is precisely why this argument has been so unproductive for so long.

We need more of these buildings. I’m not hedging that and I’m not going to pretend it’s a close call: the vacancy numbers, the generation shortfall, and the fellow across the Pacific with several hundred spare gigawatts all point in exactly the same direction. But needing more of a thing has never once meant we should stop caring where it goes. We needed the highways too, and we ran a great many of them straight through whichever neighborhood had the least political power to stop us, and we are still paying for that particular bit of efficiency sixty years on.

So the question was never whether. It was always whether these things land where the power and the fiber and the water actually make sense, negotiated in daylight with communities that got told the truth up front and got something real in return, or whether they land wherever the acreage was cheapest and the NDA got signed fastest. One of those versions we’ll be reasonably proud of in thirty years. The other one we’ll be studying in a graduate seminar on how not to do this.

Go to the meeting. Ask what the cooling design actually is, and where the power is coming from, and what happens to the water. Ask what the county gets that isn’t a press release with a big number in it. Ask why there’s an NDA, and don’t accept “competitive reasons” as an answer. And then ask the loudest person in the room whether they want the thing built well, or just built somewhere else.

Ted Stevens was wrong, but he was at least wrong in the right direction. It isn’t a series of tubes. It’s a series of buildings: we need considerably more of them than we’ve got, every last one of them has to go somewhere, and the only question actually on the table is whether we’re going to be smart about where.


References

Al Jazeera. (2026, May 28). China’s secret weapon in AI race with US? Lots of cheap energy. https://www.aljazeera.com/economy/2026/5/28/chinas-secret-weapon-in-ai-race-with-us-lots-of-cheap-energy

Anthropic. (2026, April 7). Assessing Claude Mythos Preview’s cybersecurity capabilities. Frontier Red Team. https://www.anthropic.com/research/mythos-preview

BloombergNEF. (2026). Six things to know about BNEF’s new US data center capacity outlook. https://about.bnef.com/insights/data-centers/six-things-to-know-about-bnefs-new-us-data-center-capacity-outlook/

CBRE. (2026). Global data center trends 2026. https://www.cbre.com/insights/reports/global-data-center-trends-2026

Data Center Watch. (2026). $64 billion of data center projects have been blocked or delayed amid local opposition. https://www.datacenterwatch.org/report

Drug Target Review. (2026). AI in drug discovery: Predictions for 2026. https://www.drugtargetreview.com/ai-in-drug-discovery-predictions-for-2026/1865962.article

Environmental and Energy Study Institute. (n.d.). Data centers and water consumption. https://www.eesi.org/articles/view/data-centers-and-water-consumption

Gallup. (2026, May). Americans oppose AI data centers in their area. https://news.gallup.com/poll/709772/americans-oppose-data-centers-area.aspx

Google Cloud. (2026). Adversaries leverage AI for vulnerability exploitation, augmented operations, and initial access. Google Threat Intelligence Group. https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access

OpenAI. (2026, July 21). OpenAI and Hugging Face partner to address security incident during model evaluation. https://openai.com/index/hugging-face-model-evaluation-security-incident/

MIT Technology Review. (2023, December 1). Making an image with generative AI uses as much energy as charging your phone. https://www.technologyreview.com/2023/12/01/1084189/making-an-image-with-generative-ai-uses-as-much-energy-as-charging-your-phone/

Public Citizen. (n.d.). The secret data center buildout: How states can stop Big Tech’s abuse of NDAs. https://www.citizen.org/news/the-secret-data-center-buildout-how-states-can-stop-big-techs-abuse-of-ndas/

S&P Global. (2025, October 14). Data center grid-power demand to rise 22% in 2025, nearly triple by 2030. https://www.spglobal.com/energy/en/news-research/latest-news/electric-power/101425-data-center-grid-power-demand-to-rise-22-in-2025-nearly-triple-by-2030

Statista. (2026). Data centers worldwide by territory 2026. https://www.statista.com/statistics/1228433/data-centers-worldwide-by-country/

The Frontier. (n.d.). How data center developers won secrecy pledges from Oklahoma officials. https://www.readfrontier.org/stories/how-data-center-developers-won-secrecy-pledges-from-oklahoma-officials/

Utility Dive. (2026). AI data center growth could force US utilities to rethink generation plans, BofA says. https://www.utilitydive.com/news/ai-data-center-growth-utilities-generation-plans/825541/

Vantage Data Centers. (2026, April 22). Cooling without the drain: How closed-loop systems cut day-to-day water use. https://blog.vantage-dc.com/2026/04/22/cooling-without-the-drain-how-closed-loop-systems-cut-day-to-day-water-use/

comments powered by Disqus

Related Posts

Object First at TFDx RSAC 2026: If You Can Turn It Off, It Wasn't Immutable

Object First at TFDx RSAC 2026: If You Can Turn It Off, It Wasn't Immutable

“When I use a word, it means just what I choose it to mean — neither more nor less.

Zerto

Zerto

I think that security is still the hottest topic in the IT world right now, the faux AI craze notwithstanding.