NextAI+ Praxis--:----UTC
AI Governance Weekly

Europe & US: EU Adopts Data Centre Ratings and Consults on Performance Standards; UK Assesses Agentic Defence; California Enacts Data Centre Laws and Names AI Safety Advisers; FTC Examines Platform Ad Optimisation

29 September 2026
Long read · 12 min
By NextAI+ Praxis

On 21 September 2026, the European Commission adopted a delegated regulation on data centre ratings and launched a consultation on minimum performance standards, creating a common basis for comparing energy and water use at European computing facilities; the rating regulation remains subject to scrutiny. The same day, the UK's National Cyber Security Centre proposed five dimensions for assessing agentic defensive actions, helping enterprises gauge the reach and recoverability of automated responses; California Governor Gavin Newsom signed seven data centre bills addressing resource use disclosures and the allocation of electricity supply costs. On 23 September, the Governor named four advisers on AI safety governance to examine independent evaluations of frontier models and emergency shutdown proposals, without imposing new obligations on companies. On 24 September, the US Federal Trade Commission sought comment on advertising optimisation tools that may promote impersonation scams, gathering evidence on platforms' roles in generating, placing and responding to risky ads; no new rule has been adopted.

§ i

EU Adopts Data Centre Rating Scheme, Consults on Minimum Performance Standards

On 21 September 2026, the European Commission adopted the Commission Delegated Regulation establishing a common Union rating scheme for data centres (C(2026) 3472 final) and launched a public consultation on minimum performance standards covering data centres' energy and water use and related sustainability performance.

The delegated regulation has not yet entered into force and is subject to two months of scrutiny by the European Parliament and the Council. The scheme builds on reporting by data centres with an installed information technology power demand of at least 500 kW. The database will generate electronic labels grading Power Usage Effectiveness (PUE) and Water Usage Effectiveness (WUE) separately from A to G, alongside information on low-emission energy and readiness for waste heat utilisation. PUE compares total facility energy consumption with the energy used by IT equipment; WUE measures freshwater consumption per unit of IT equipment energy. Rating labels and minimum performance thresholds are separate measures: the regulation envisages generating the first labels by 15 August 2027, whereas the minimum performance standards remain under consultation and no common qualifying values have been set.

When procuring GPU hosting or cloud inference in Europe, enterprises can incorporate facility ratings into supplier assessments and ask which data centre actually hosts the workload, which year the label covers, and whether the indicators reflect measured results or design estimates. Facility grades should be assessed separately from the resource use of a specific AI workload: a lower PUE indicates relatively less overhead for power and cooling, but does not by itself establish that a model uses less energy to complete an equivalent task. Subject to accuracy, latency and capacity requirements, teams can compare model size, hardware configuration and energy per task, while checking local water conditions rather than choosing a site on a single grade. Operators of their own data centres can check the metering boundaries for total facility energy, IT equipment energy and freshwater use in advance, and agree with hosted customers who supplies and validates the data. Contracts can also address cost sharing for facility relocation, indicator updates and subsequent upgrades. These are deployment recommendations drawn from the rating and metering arrangements; the regulation does not require ordinary users of model APIs to report the energy consumed by each inference request.

The EU established its data centre database and reporting mechanism in 2024. The latest measure turns collected indicators into comparable public labels and develops an evidence base for later minimum performance standards. The related public consultation closes on 14 December 2026; the Commission plans to propose legislation in the second quarter of 2027, with the substance still to be determined. China, meanwhile, implemented the mandatory national standard Minimum Allowable Values of Energy Efficiency and Energy Efficiency Grades for Data Centers (GB 40879-2021) on 1 November 2022, incorporating efficiency limits and grades into its standard. The schemes' scope, measurement methods and grade meanings must be checked separately; a Chinese efficiency grade cannot simply be converted into an EU label. Cross-border purchasers of computing capacity can reuse metering evidence while assessing each jurisdiction's rules. In the EU, the next developments to track are the scrutiny outcome and any transition or retrofit provisions in the minimum performance proposal.

§ ii

UK Proposes Agentic Defence Assessment, Clarifies Boundaries for Automated Response

On 21 September 2026, the UK's National Cyber Security Centre (NCSC) published the blog post on agentic cyber defence, “One does not simply defend agentically,” setting out five dimensions for assessing the risk of automated defensive actions and helping enterprise security teams determine which tasks to assign to agents.

This is non-binding technical advice and creates no new compliance obligations. The post evaluates specific defensive actions and their consequences for the business across five dimensions: potency, scope, criticality, rollout confidence and recoverability, each described at levels 0–4. Rollout confidence addresses whether the likely scope and impact can be demonstrated before execution; recoverability concerns how quickly an erroneous action can be undone and business operations restored. The NCSC provides no single aggregate score or approval threshold. It suggests starting with lower-risk tasks such as analytical assistance before assessing constrained autonomous responses.

For security agents capable of isolating endpoints, disabling accounts or changing firewall rules, enterprises can first establish which assets each action affects, whether shared services are implicated, and who has approval authority. If routine maintenance is misclassified as an attack, for example, automatically disabling a service account could disrupt several business systems at once; pre-deployment tests should simulate this case and check whether permission limits contain the impact. Stopping the agent and restoring business systems it has modified should be tested separately: after revoking tool credentials, teams still need to verify that firewall rules, account permissions and service connections can be restored, and identify who is responsible. Acceptance records can link the prior configuration, approval basis, actual calls and restoration outcomes; procurement terms can require suppliers to support pilot operation, reversal of actions and incident investigation. These are implementation recommendations based on the assessment dimensions. Attack detection accuracy or one successful demonstration alone is insufficient to determine whether automated response is ready for production.

On 20 August 2026, the NCSC published Managing the cyber risk of agentic AI, with interim advice on isolation, permissions, monitoring and emergency shutdown. The latest post further examines how cyber-defence actions affect business operations. The AI Safety Governance Framework 3.0, published on 14 September 2026 by China's National Information Security Standardization Technical Committee, also offers agent controls covering least privilege, human approval of critical actions and rollback, but addresses a broader range of agent use cases. Cross-border teams can reuse permission and recovery tests while setting autonomy limits for each business context. The NCSC also announced a forthcoming “AI for Cyber Defence” problem book. Further monitoring should focus on how it proposes to prove that ostensibly low-risk actions will not disrupt operations and whether the research yields repeatable deployment tests.

§ iii

California Signs Data Centre Laws, Strengthening Disclosure and Cost Allocation

On 21 September 2026, California Governor Gavin Newsom signed seven data centre bills addressing energy and water disclosures, the allocation of electricity supply costs and land-use approvals.

Among them, AB 1577 requires qualifying data centres with at least 10 MW of electric capacity to submit energy consumption and energy use efficiency information to the California Energy Commission (CEC). Reporting is at least annual and generally broken down by month, with details to be determined by the CEC; public data will be anonymised and aggregated. On electricity supply, SB 886 requires the California Public Utilities Commission (CPUC) to establish or update relevant tariff rules by 1 January 2028. AB 2383 further provides that applicable electric service payment mechanisms last at least ten years and include security or prepayments, minimum payments and exit fees. The central aim is to prevent the costs of expanding capacity and reserving unused power from shifting to other customers.

Enterprises planning to build or lease AI computing clusters in California over the long term should model load forecasts, capacity expansion commitments and exit costs together. A training project may initially plan continued growth but later use fewer GPUs as models become more efficient; reduced electricity use may not reduce all payment obligations. Project budgets can model on-time commissioning, delayed commissioning and lower-than-expected load separately, checking who bears grid upgrade costs, power procurement, minimum payments and early exit fees. When renting racks or cloud capacity, customers should assess whether suppliers can pass through such costs, and review price adjustment triggers, notice periods and termination terms. A data centre's liability to a utility should not be treated as a direct statutory obligation of its end customers. Operators of their own facilities should also meter IT equipment, cooling and on-site generation separately, retaining calculation methods and reporting evidence. These are deployment and procurement recommendations. AB 1577's 10 MW reporting threshold should not be applied to the tariff rules; the applicable generation service tariff threshold under AB 2383 is to be set by the regulator and may not exceed 25 MW.

SB 57, signed by California on 11 October 2025, had already authorised the CPUC to examine whether new data centre loads shift costs to other customers; the new laws go further on reporting and tariff mechanisms. The principal laws described above take effect under the ordinary legislative timetable on 1 January 2027, but specific reporting arrangements and tariffs still require further proceedings. The signing date does not mean new tariffs took immediate effect. The EU's existing energy performance reporting scheme for data centres likewise gathers energy and sustainability indicators, but its reporting requirements do not replace California's review of electricity costs. Cross-border enterprises can reuse metering data while maintaining separate reporting definitions and power contract obligations. The next milestones are the CEC's reporting procedures and the CPUC's decisions on eligibility thresholds, minimum payments and cost allocation.

§ iv

California Names AI Safety Experts, Advancing Independent Evaluation and Emergency Shutoff Research

On 23 September 2026, California Governor Gavin Newsom announced four advisers on AI safety governance to inform implementation of an earlier AI executive order and examine independent validation of frontier models, embedded assessments and emergency shutoff mechanisms.

The advisers are Jason Goldman, Gillian Hadfield, Alondra Nelson and Rob Reich, whose backgrounds span technology products, legal institutions, technology policy and frontier technology governance. Working with technical researchers, they will help assess proposals for embedded third-party review, independent verification of safety frameworks and risk reporting, and continued validation that emergency shutoff mechanisms work. The announcement appoints advisers; mandatory measures remain under study. It does not grant these four individuals direct powers to inspect companies or shut down models, nor does it immediately require developers to deploy a standard “kill switch.”

Frontier model developers preparing for external safety evaluations can begin with a specific safety claim—for example, “the model cannot continue to invoke a code-execution tool after authorisation is revoked”—and assemble the relevant version, test conditions, failure cases and remediation records so that evaluators can replicate the test independently. Evaluation contracts should define access to evidence and protect the independence of conclusions: they can provide for necessary test interfaces, confidentiality controls and disclosure of evidence gaps, rather than only a summary score or compensation tied to a favourable outcome. Emergency shutoff tests can check whether a stop instruction reaches instances in multiple regions, derivative tasks and automatic retries, while documenting activity that cannot be stopped and who approves a restart. Enterprises using models through APIs can ask suppliers about emergency service interruption notices, cooperation in incident investigations and business continuity arrangements. These are preparation recommendations based on issues under study; the ability to stop a task in an enterprise application is not equivalent to a potential future shutoff requirement for frontier models.

California signed SB 813, Independent verification organizations, and AB 1405, Artificial intelligence: auditors: registration, on 9 September 2026, laying out accreditation and auditor registration arrangements, respectively. SB 813 expressly does not make hiring an independent verification organisation a prerequisite for all AI development, deployment or operation. The SB-813 bill text contains that limitation. Executive Order N-9-26 of 18 September directed the Government Operations Agency (GovOps), in consultation with the emergency management agency, to consult experts and submit legislative recommendations by 16 November; the latest appointments give that consultation concrete form. In the same week, the UK's NCSC advice on agentic defence focused on the impact and recoverability of automated enterprise actions, whereas California's inquiry concerns an external verification system for frontier developers. Both offer distinct inputs to test design. The next points to watch in California are recommended evaluator access rights, shutoff triggers and the range of models covered.

§ v

FTC Seeks Comment on Ad Optimisation Liability, Examining Platforms' Role in Impersonation Scams

On 24 September 2026, the US Federal Trade Commission (FTC) sought public comment on platform ad optimisation, considering whether to amend its Rule on Impersonation of Government and Businesses or take other steps to address the role of search engines, social media and digital marketplaces in promoting impersonation scams.

The agency issued an Advance Notice of Proposed Rulemaking (ANPRM), without proposing specific amendment text or imposing new platform obligations. Its inquiry asks how platforms participate in producing and placing ads, beyond identifying who uploaded them, including copy generation, image and video creation, audience targeting and delivery optimisation. The FTC also asks whether advertiser verification, ongoing monitoring, complaint investigation, ad removal and cessation of optimisation services should be required, and how a platform's knowledge or participation should affect liability. Some measures could instead serve as conditions for an affirmative defence; the precise approach has yet to be decided. The inquiry is not limited to tools using generative AI.

Platforms operating AI ad generation and automated placement tools can test their controls against a scenario in which a third-party repair provider is presented as a brand's official after-sales service: the advertiser's original materials do not claim authorisation, but the system's combination of a brand name, headline and button could leave viewers with that false impression. Review should cover the ad as actually optimised and displayed, as well as its landing page, checking whether the advertiser, brand authorisation and payee align, and whether dynamic combinations or later edits bypass the original review. Following a complaint, the platform should be able to connect source materials, generated variants, placement settings, displayed output and response records to determine whether misleading content came from the advertiser or the platform's optimisation. Once impersonation is confirmed, teams can rehearse suspending the relevant creative, automated generation and placement jobs, so that deleting one variant does not cause the system to generate a similar ad. Enterprises procuring third-party ad tools can contract for edit permissions, evidence delivery and responsibility for emergency suspension. These are deployment recommendations based on the inquiry; the notice sets no uniform review process or log retention period.

The FTC's existing impersonation rule took effect on 1 April 2024, providing an enforcement basis for impersonation of governments and businesses. A broader provision addressing the supply of means or instruments of impersonation was not adopted previously; the new inquiry returns to digital platforms' ad optimisation and should not be read as imposing liability on every AI tool provider. Article 26 of the EU Digital Services Act (DSA) already requires covered platforms to disclose advertising identity information, including the person on whose behalf an ad is displayed and, if different, the payer. That transparency duty serves a different purpose from the anti-impersonation liability conditions the FTC is exploring. Cross-border platforms can share records of advertisers and creative provenance while checking disclosure and risk response requirements separately. Comments are due 60 days after the notice appears in the Federal Register. The next question is whether the FTC proposes a formal rule and how it defines platform participation, reasonable safeguards and the boundaries of liability.

← Back to AI Governance Weekly

Cite as · AI Governance Weekly · 29 September 2026

§ Recent signalsBack to Governance Weekly→
28 Sep 2026China publishes on-device AI filings, Korea expands data innovation zones and debates agent privacy, and Japan studies consumer remedies.22 Sep 2026UK lawmakers call for dedicated AI legislation, the EU moves to limit AI companions for children, and California enacts synthetic-performer disclosure.21 Sep 2026China issues AI Safety Governance Framework 3.0 and four security guidelines, consults on secure agent development, and Hong Kong pilots procurement declarations.18 Sep 2026US agencies issue a distillation advisory, the EU proposes an Innovation Act, and the UK confronts shadow AI.17 Sep 2026China rules on AI-fabricated reviews and answers distillation claims, Korea tightens breach notification, and Japan weighs consumer AI risks.

One quarterly digest, no weekly drip.

If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.