Data centres on pause: how power shortages and security are reshaping the market
Getty Images
Getty Images· 11 min read
Only a few years ago, the cost and availability of IT equipment were among the main constraints on data-centre construction. Today, the industry faces a different problem: computing capacity can often be purchased much faster than the electricity infrastructure needed to run it can be built.
The problem is increasingly visible across Europe. Major data-centre hubs such as Frankfurt, London, Amsterdam, Dublin and Paris are competing for increasingly scarce grid capacity with electrification of transport, heat pumps, industrial decarbonisation and renewable-energy projects. In some locations, new data-centre connections can require several years of planning, grid reinforcement and permitting.
Russia provides another example of the same structural problem. In 2025, the amount of new data-centre capacity commissioned there fell to its lowest level in a decade despite record demand, largely because of electricity and engineering-infrastructure constraints.
The underlying trend is broader: energy rather than servers is becoming the scarce resource of the digital economy.
The rapid expansion of cloud computing, artificial intelligence and digital services has transformed the economics of data centres.
Traditional data-centre development was largely constrained by land, capital expenditure and access to servers. Electricity could normally be treated as an infrastructure input that followed demand.
That assumption is increasingly breaking down.
In many European metropolitan areas, available grid capacity has already been allocated years ahead. A company may therefore be able to order thousands of GPUs within months while waiting several years for a sufficiently large electricity connection.
The effects can already be seen in established European data-centre markets. Grid congestion and planning restrictions have encouraged developers to look beyond traditional hubs towards locations with stronger electricity availability, including the Nordic countries, Spain, parts of Central and Eastern Europe and regions close to major renewable-generation assets.
A similar development occurred around Moscow, where grid companies began limiting some new high-power connections as available capacity tightened. New projects consequently started looking towards cities such as Yekaterinburg, Kazan, Novosibirsk and Nizhny Novgorod.
This illustrates an increasingly important trade-off. Moving outside major digital hubs may solve the electricity problem, but it can also increase network latency, reduce access to specialised labour and move infrastructure farther away from large concentrations of customers.
Economics are another constraint. Modern data centres are highly capital-intensive assets, while their technological components depreciate considerably faster than their buildings. Depending on design, market and financing conditions, investment can take close to a decade to recover.
As a result, the question facing developers is changing from "Where is demand?" to "Where can demand actually be supplied with power?"
The transformation is particularly visible in AI infrastructure.
A conventional server rack may consume roughly 5–10 kW. A rack designed for GPU-intensive AI workloads can require 30–60 kW, while the most demanding configurations can exceed 100 kW per rack.
That means an AI rack can require three to twelve times more electricity than a conventional rack, and the difference becomes enormous when multiplied across hundreds or thousands of racks.
The implications extend far beyond electricity procurement. Higher power densities require:
Electricity therefore determines not only where a data centre can be built but also its architecture.
AI is accelerating this shift because operators increasingly need campuses measured in hundreds of megawatts rather than individual facilities measured in tens of megawatts.
The result is a new geography of computing.
Instead of placing every data centre close to a major financial or technology centre, developers are increasingly considering locations close to abundant generation — renewable-energy clusters, hydroelectric resources, nuclear plants or areas where new grid capacity can be added relatively quickly.
Europe has several natural beneficiaries. The Nordic countries combine abundant low-carbon electricity with cool climates, while Spain and Portugal have rapidly expanding renewable-generation fleets. France benefits from its large nuclear system, while other markets are exploring combinations of renewables, batteries, flexible generation and long-term power-purchase agreements.
The shift also changes the relationship between energy and digital infrastructure. Electricity is no longer simply an operating expense for the data-centre industry. Energy availability is becoming a strategic determinant of where AI infrastructure can exist at all.
Scarcity of commercial capacity and rising colocation costs are also encouraging some large companies to reconsider captive data centres — facilities designed primarily for their own workloads.
The logic is particularly compelling for AI.
A company building its own infrastructure can optimise the facility around a relatively predictable workload rather than designing it for a wide variety of customers. It can specify higher rack densities, specialised cooling, customised network architecture and particular redundancy requirements.
For hyperscalers and companies operating very large AI clusters, that flexibility can outweigh the advantages of conventional colocation.
However, the entry barrier is high.
International industry estimates commonly place the construction cost of a modern Tier III-class facility at roughly $10–12 million per megawatt of IT capacity, although costs vary substantially between markets and designs.
For a 50 MW project, that translates into an investment of around $500–600 million before accounting for some site-specific costs. A 100 MW campus can consequently approach or exceed $1 billion.
Crucially, most of the money is not spent on the building itself.
Almost half of project expenditure can be associated with electricity supply, distribution and redundancy, while another 15–25% can go into cooling. The expensive part of a data centre is therefore increasingly the engineering infrastructure that keeps computing equipment operating continuously.
This creates an unusual mismatch between asset lifetimes.
The building and electrical infrastructure may remain operational for decades, while servers and accelerators can become technologically outdated after only a few years.
Captive infrastructure therefore works best for organisations with large, predictable and persistent computing demand. For smaller companies, cloud services and colocation generally remain economically more flexible.
But owning the infrastructure does not eliminate the next challenge: keeping it continuously operational and secure.
As data centres become larger and more valuable, physical security is also changing.
Video surveillance was historically treated primarily as a security function: cameras recorded who entered the premises and provided evidence after an incident.
Modern facilities increasingly use these systems as part of their operational infrastructure.
The reason is simple: downtime is extraordinarily expensive. Even a short interruption can disrupt banking applications, e-commerce platforms, cloud services, communication networks and business systems simultaneously.
Traditional layers of protection remain essential: controlled perimeters, checkpoints, access-control systems, continuous surveillance and restricted access to server and engineering rooms.
But physical-security technologies are increasingly connected with DCIM — Data Centre Infrastructure Management — platforms, environmental monitoring, access control, cooling systems and fire protection.
That integration allows a facility to move from recording incidents to responding to them.
For example, when a thermal camera detects abnormal heating around an electrical connection, the system can simultaneously preserve the relevant video, alert an operator and trigger inspection or cooling procedures.
Thermal monitoring is particularly valuable because many infrastructure failures develop gradually.
Loose electrical contacts, overheating components and abnormal temperature patterns can often be identified before they cause equipment failure or fire.
Modern video analytics can also identify perimeter intrusions, objects left in restricted areas, unusual movements near critical equipment and potentially dangerous interactions with cables, power systems or fire-suppression controls.
As one data-centre security specialist explains: "The reliability of data centres determines whether banks, cloud platforms, public services and online marketplaces remain operational. Video surveillance has therefore become part of the engineering infrastructure rather than simply a security system. Cameras increasingly monitor not only the presence of people, but whether procedures are being followed and whether there are early indications of technical failure."
The most important requirement is consequently shifting away from camera resolution alone. Reliability under continuous 24/7 operation, analytics, integration with engineering systems and supply-chain resilience increasingly matter more.
For European operators, physical-security design also has to coexist with data-protection requirements. Video-surveillance systems may process personal data and therefore need to be designed with privacy, access controls, retention policies and cybersecurity in mind.
Facilities handling payment-card information may additionally need to comply with PCI DSS, where physical access controls form one part of a much broader security framework.
Physical protection, however, covers only one side of the problem.
The more economic activity moves into data centres, the more attractive they become to cybercriminals and state-linked threat actors.
Attackers do not necessarily need to compromise the data-centre operator itself. They can target customers, contractors, software vendors, maintenance companies, equipment suppliers or management platforms.
This makes supply-chain security particularly important.
A sophisticated data centre may have strong internal controls while relying on dozens or hundreds of external companies for cooling equipment, electrical systems, software, maintenance and security. Compromising a less protected supplier can provide attackers with an indirect route into a much more strongly protected organisation.
The issue is especially relevant in Europe as data centres increasingly support systems classified as essential or critical services. Operators and their customers must therefore consider cybersecurity not as a standalone IT problem but as a component of operational resilience.
European frameworks such as NIS2, alongside national critical-infrastructure rules and GDPR requirements, are reinforcing this approach. The direction of regulation is clear: organisations are expected to understand not only their own cyber risks but also dependencies on suppliers, infrastructure providers and service partners.
The concept of shared responsibility is particularly important in cloud and colocation environments.
A data-centre operator may secure the building, electricity infrastructure, network backbone and certain platform components, while customers remain responsible for applications, identities, access rights and data.
Problems frequently emerge between those layers.
If both sides assume the other party is protecting a particular component, a gap appears — and attackers actively look for exactly these gaps.
Backups remain one of the most fundamental protections.
The traditional 3-2-1 rule provides a useful baseline: maintain at least three copies of data, on two different types of storage, with one copy kept away from the primary production environment.
Increasingly, organisations add another layer: immutable or isolated backups that cannot easily be modified even if an attacker obtains administrative access to the main network.
Backup infrastructure itself must also be protected. Copies should be encrypted during transfer and storage, checked for malicious software and tested regularly through recovery exercises. Otherwise, an organisation may discover during an incident that its backup environment has been compromised together with production systems.
The recovery plan matters just as much as the backup.
A company needs to know beforehand how applications will be restored, in which order, how identities will be recovered and whether workloads can be temporarily transferred to another on-premise or cloud environment.
Perhaps the most important change is that the distinction between physical and cybersecurity is disappearing.
Consider a security employee connecting an infected USB drive to a workstation controlling the access-control system. A cybersecurity incident can suddenly become a physical-security incident.
Likewise, malware delivered to an operator responsible for cooling infrastructure could potentially disrupt environmental controls and ultimately shut down IT equipment.
Conversely, unauthorised physical access to networking, power or cooling equipment can create cyber risks.
For this reason, engineering technologies such as cooling controls, access systems, cameras, building-management systems and power-management equipment increasingly require their own cybersecurity architecture.
Segmentation, privileged-access management, endpoint protection, network monitoring, controlled software updates and staff training are becoming as relevant to operational technology as they already are to conventional IT.
This convergence is particularly important as data centres become more automated.
AI-based video analytics, smart cooling, automated power management and predictive maintenance can improve reliability, but every connected system also creates another potential interface that needs to be protected.
The transformation of the industry ultimately extends beyond AI or cloud computing.
A modern data centre depends on four closely connected layers: energy, engineering infrastructure, physical security and cybersecurity.
Weakness in any one of them can compromise the entire facility.
A data centre with unlimited computing hardware but no available grid connection cannot operate. A facility with abundant electricity but inadequate cooling cannot support high-density AI workloads. Strong cyber defences cannot compensate for uncontrolled physical access, while sophisticated physical security cannot protect infrastructure whose operational systems have been digitally compromised.
This is why the competitive advantage of future data centres will increasingly be measured not simply in rack capacity or computing performance, but in resilience per megawatt: how reliably an operator can obtain electricity, remove heat, maintain uptime and protect infrastructure against both physical and digital threats.
The digital economy may be virtual, but its fastest-growing constraint is becoming very physical.
illuminem Voices is a democratic space presenting the opinions of leading Sustainability Thought Leaders, their views do not necessarily represent those of illuminem.
The world needs sustainability knowledge. At illuminem, no interest group or shareholder can influence our work. Thank you for supporting our mission to make high-quality and independent sustainability information free for all. Every contribution helps. Thank you for donating today.
Diego Balverde

Battery Metals · Energy Transition
illuminem briefings

Energy · Public Governance
illuminem briefings

Energy · Public Governance
Ads Advance

Energy · Sustainable Mobility
The Guardian

Energy · Public Governance
Oil Price

Energy · Oil & Gas