Back to site Swales Consulting
Market & Risk

The Data Centre Boom: Massive Scale, Unprecedented Risk

By Bruce Swales · Swales Consulting

Over the last three years, data centre construction has transformed from a niche enterprise real estate sector into one of the largest industrial construction markets on Earth. Global capital expenditure hit an estimated $700 billion in 2025, and the top five “hyperscalers” alone are projected to spend over $600 billion in 2026—a massive year-on-year increase of more than a third.

As AI workloads accelerate, individual campuses are scaling from hundreds of megawatts into gigawatts, pushing the insurable value of a single site up to $30 billion. This blistering pace has completely outrun traditional risk management frameworks, putting unprecedented strain on power grids, labour pools, insurance capacity, and cooling physics simultaneously.

Two Distinct Models, Shared Vulnerabilities

While hyperscale and colocation developers compete for the same strained resources, they distribute operational and financial exposure in fundamentally different ways:

Hyperscale Campuses: Built for, financed by, or leased entirely to a single tech giant for massive compute, storage, or AI training. These sites feature highly concentrated ownership and risk retention, often paired with dedicated on-site power generation. The hyperscaler maintains strict control over engineering standards, but a single incident represents a massive, non-diversified loss event.

Colocation Facilities: Multi-tenant environments where enterprises, cloud providers, and AI "neocloud" startups share power, cooling, and security infrastructure. This model successfully disperses credit and demand risk across many customers. However, it introduces a volatile operational dynamic: a single infrastructure failure can simultaneously take down dozens of unrelated organisations, multiplying legal and reputational fallout.

Construction-Phase Chaos: Navigating the Bottlenecks

The Grid Power Stranglehold

Access to power has officially replaced land availability as the primary constraint on delivery. Grid interconnection queues now stretch to four or five years in constrained markets, delaying roughly 30% of announced projects into 2028. This gridlock has forced a shift toward "Bring Your Own Power" (BYOP) strategies—such as on-site gas turbines, micro-nuclear options, and massive battery storage. While BYOP bypasses utility timelines, it turns data centre developers into accidental power plant operators, layering intense energy-sector regulatory and execution risks onto the project.

Labor Scarcity and Schedule Deadlines

The sector faces a global skilled-labour shortfall measured in the hundreds of thousands of workers, even as single hyperscale projects require thousands of tradespeople at peak construction. Because a facility generates zero revenue until it is fully energised, "ready-for-service" date certainty is the ultimate variable in project risk. Even minor delays cascade into catastrophic revenue losses and triggering harsh contractual penalties.

Geography and the Insurance Capacity Gap

To secure power, developers are moving into secondary and tertiary markets, inadvertently exposing assets to severe convective storms, tornadoes, hail, and wildfires. Insurers now rank severe weather as the leading cause of loss in U.S. builders' risk portfolios.

Simultaneously, the sheer financial value of these campuses is breaking the traditional insurance market. No single carrier can absorb a $30 billion site, requiring programs to layer dozens of insurers. Conventional markets currently cover only a third to a half of total campus values, forcing mega-developers to self-insure the remainder via captive arrangements. Global data centre premiums are set to hit $10 billion in 2026 and are projected to double by 2030.

Operational Reality: The New Failure Modes

Power and the UPS Bottleneck

Once live, power-related failures—most frequently originating within Uninterruptible Power Supply (UPS) systems—remain the leading cause of major downtime, accounting for nearly half of all significant outages. While redundant architectures have slightly decreased the frequency of component failures, residual risk has become heavily concentrated in complex, multi-system interactions that are far harder to diagnose and prevent.

The Challenges of Liquid Cooling

The rapid transition to Direct Liquid Cooling (DLC), mandated by the intense heat generation of modern AI accelerators, introduces a severe new threat vector. Coolant distribution unit (CDU) pump failures, leaks, or blocked fittings can destroy multimillion-dollar GPU hardware in seconds—entirely eliminating the thermal buffer zone that traditional air-cooled facilities relied on. Recent high-profile cooling failures highlight a critical structural flaw: parallel cooling units offer zero protection if they share upstream piping headers, controls, or power feeds, creating hidden "common-mode" risks that standard N+1 or 2N labelling conceals.

Human Factors and Edge Dependencies

Human error—specifically configuration and change-management mistakes during maintenance windows—remains a core driver of network outages, underscoring that operational discipline is just as vital as engineering design.

Furthermore, a majority of publicly reported outages now originate outside the facility walls. Third-party telecom carriers, upstream cloud providers, and building-management software (DCIM) vendors represent external dependencies that cannot be engineered away, debunking the myth that outsourcing to a third party completely transfers operational risk.

Fire and Evolving Security Threats

The proliferation of lithium-ion batteries in UPS setups has driven a gradual rise in data centre fires, prompting standards bodies to tighten guidance in 2026 by demanding higher fire-resistance wall ratings for battery rooms. On the security front, AI clusters are now viewed as strategic national security assets, elevating the threat profile to include physical sabotage and state-sponsored cyber/ransomware attacks. Cyber incidents pose a distinct risk profile, often resulting in long-term data loss and regulatory penalties long after physical systems are restored.

Contractual Shifts and Market Responses

The balance of power in lease negotiations has fundamentally shifted. Modern, financeable offtake agreements increasingly force hyperscale tenants to commit to firm rent-commencement dates regardless of construction delays, stripping away the unilateral termination rights they once held.

Concurrently, insurers are deploying new "lifecycle" insurance products to bridge the high-risk gap between builders' risk policies (which end at substantial completion) and operational property programs. This continuity is essential because modern phased campuses frequently feature active construction, hardware commissioning, and live data operations happening simultaneously on the exact same site.

Lessons Learned (or forgotten) from the Semiconductor Industry

What They Learned: Borrowing the Fab Playbook

Data centre developers have actively adopted several core operational strategies that the semiconductor industry (“Fabs”) spent decades perfecting:

Modularisation and Offsite Manufacturing: Fabs pioneered the use of prefabricated "skids" for complex chemical, gas, and water systems to bypass on-site labour constraints. Data centre builders are heavily duplicating this—building entire UPS, chiller, and generator assemblies offsite so they can simply be dropped onto the slab and hooked up.

Parallel Procurement: Fabs learned long ago that you order your long-lead heavy machinery (like lithography tools or massive sub-station switchgear) before the final building blueprints are even finished. Data centres are now forced to adopt this exact method, buying up transformers and cooling infrastructure years in advance to avoid getting choked out by supply chain backlogs.

Digital Twins and Dynamic Design: Fabs live or die by 3D reality capture and digital twins to ensure that complex tooling matches the facility layout flawlessly. Data centres are adopting this to handle the blistering pace of changing chip roadmaps, ensuring an unexpected mid-build silicon upgrade doesn't break the entire power and cooling blueprint.

What They Forgot (or Ignored): The Blind Spots

The sheer pressure of the AI race has caused developers to rush past some of the hard-learned lessons of high-tech manufacturing:

The Labour Illusion: The massive global semiconductor push has run face-first into a brutal reality check: there simply aren't enough specialised electricians, pipefitters, and cleanroom engineers to build these sites. Data centre developers are walking right into the same trap by fleeing to secondary or rural markets to find cheap power, completely ignoring the fact that the local skilled labour pool doesn't exist.

Common-Mode Vulnerabilities: Fabs have historically suffered catastrophic yield losses from subtle shared system failures (e.g., a tiny pressure drop in a shared chemical line). Yet, as data centres rapidly pivot to direct liquid cooling, they are repeating this design flaw—hooking up redundant cooling units to single upstream piping headers or control loops. They are prioritising speed over deep fault-isolation.

The "Accidental Utility" Shock: Fabs are built with the understanding that permitting and grid integration takes years of bureaucratic and environmental manoeuvring. Data centre teams, used to historical 18-month build timelines, thought they could bypass the grid bottleneck with "Bring Your Own Power" (BYOP) gas or nuclear strategies. They are now discovering the hard way that building a co-located power plant places them squarely into the long, brutal regulatory timelines that fabs have battled for decades.

The Strategic Takeaway

Redundancy is Not Resilience: Simply adding N+1 or 2N components is insufficient if hidden, shared upstream systems (like piping headers or control software) can cause a single-point, common-mode failure.

Risk Has Migrated to the Edges: With core mechanical and electrical engineering highly matured, the vast majority of modern outage risks stem from external grid vulnerabilities, third-party software dependencies, and human process errors.

Unified Risk Programs Win: The financial and engineering components of data centre development are converging. The developers, lenders, and operators who successfully navigate this boom will be those who treat engineering design, power procurement, and insurance risk transfer as a single, continuously coordinated system.

Learn from the lessons learned by the semiconductor industry: These two industries are very similar in many ways: construction challenges, lengthy build programmes, power requirements, labour shortages, risks “outside of the facility”.

Enjoyed this piece? Discuss your own case with Bruce.

Get in touch