← Back to Guides
5

Series

Agentic AI for the Data Center Boom· Part 5

GuideFor: AI Engineers, ML Engineers, Platform Engineers, AI Systems Architects

Data Center Power: Being Right Doesn't Grant Grid Authority

Every other use case caps autonomy on physics. This one caps it on jurisdiction - and the agent can't measure a law.

#data-center#power-grid#energy-management#demand-response#epistemic-restraint

A power-management agent watches the energy market and the facility's own generation. Prices spike, a grid-stress signal arrives, and the agent does the locally optimal thing: it transfers the facility's load onto behind-the-meter backup generation to ride out the expensive window. Fast, automatic, correct by every metric it can see - cheaper power, load shed from a stressed grid, exactly what a demand-response program is supposed to reward.

And across a cluster of data centers doing the same calculation at the same moment, the synchronized, automatic transfer of hundreds of megawatts off the grid produces a voltage and frequency excursion the grid operator did not model and could not absorb cleanly. This is not a hypothetical. Rapid data center dispatches and automatic load transfers to behind-the-meter backup generation have already triggered massive, unintended grid impacts, including severe voltage and frequency excursions. Separately, the reliability authority has issued a formal alert flagging exactly this class of risk.

Notice what is different about this failure. In cooling, the agent damaged hardware it owned. In SRE, it broke a service it ran. In placement, it lost work that belonged to its own fleet. Here, the agent did something correct inside the fence and the damage landed outside it - on a shared electrical system the facility does not own, governed by entities the agent has never heard of. The blast radius left the building.

This is Part 5 of the series. Part 1 set out the Operational Authority Gradient (OAG): four bands - Observe, Advise, Act-within-bounds, Closed-loop - with authority set by the irreversibility and blast radius of an action. Parts 2 through 4 placed cooling, SRE, and workload placement on that gradient, and in every one the authority ceiling was a property of physics: thermal inertia, action reversibility, checkpoint state. Power and grid management is where that stops being true.

The thesis: jurisdiction, not physics, caps the authority

In cooling, the wall was the junction temperature. In SRE, it was reversibility. In placement, it was the checkpoint. All three are physical facts an engineer can measure and a control plane can enforce, and all three sit inside the facility.

Here is the claim this article owns: at the grid boundary, the thing that caps the agent's authority is not physics. It is jurisdiction. The interconnection of large loads to the transmission system is being pulled into the federal regulator's authority through an active and contested rulemaking, the reliability authority is moving toward auditable standards that would let it mandate operating protocols for large-load operators, and the line the agent must not cross is a legal and contractual one - drawn in tariffs, interconnection agreements, and demand-response program rules - not a physical one.

This matters because an agent cannot measure a law the way it measures a temperature. There is no sensor for "this action violates our interconnection agreement." The regulatory boundary is invisible to the optimisation, which means it cannot be discovered by the agent and must be imposed on it from outside - encoded as hard constraints in the control plane by humans who read the tariff. Every prior article argued the boundary must be enforced outside the agent because the agent's self-assessment is untrustworthy. This one argues something stronger: at the grid boundary the binding limit has no physical signal at all. Be precise about what that means, because the opening excursion can mislead. Voltage and frequency are things the agent can sense; the excursion was a physical effect, and part of the failure was not modelling the aggregate. The regulatory limit is different in kind. A cleaner example than the excursion makes it: a locally-correct, profitable frequency-response bid the facility was never registered to place is a violation with no physical symptom at all - nothing a sensor could catch, only the tariff says no. That is the limit with no sensor. Its ground truth lives in a legal document that changes on regulatory deadlines, so it must be authored into the control plane by a human who read it, and kept current as it changes.

That is why grid-touching actions sit at Advise by default and reach Act-within-bounds only for assets the operator fully owns, and why Closed-loop grid interaction is, as Part 1 put it, a regulatory question before it is an engineering one.

Why this matters: the power grid is the binding constraint, and the regulator just said so

The reason this use case is suddenly urgent rather than academic is that power has become the limiting reagent of the entire boom, and the regulatory structure around it is being written right now.

The demand picture is stark: data center electricity consumption is projected to more than double, and by some estimates surge over 300 percent, by the end of the decade, and the grid cannot absorb that without dispatchable, flexible capacity at scale. That has turned the data center from a passive load into an active participant in grid operations - one that can shed load, dispatch batteries, and lean on behind-the-meter generation. Battery storage has gone from backup equipment at the edge of the power strategy to a primary tool for securing grid connections and managing AI's extreme power demands. The agent's action space here is genuinely powerful: real-time procurement against volatile prices, battery charge and discharge, demand-response participation, behind-the-meter generation dispatch.

And precisely because that action space is powerful, the regulator has moved to fence it. The federal energy regulator has clarified that large-load interconnection to the interstate transmission system is within its jurisdiction, has been directed to issue a final rule, and has ordered the largest grid operator to rewrite its tariff for co-located generation and load, with compliance filings due on fixed 2026 dates. The reliability authority issued a Level 2 Alert flagging grid disturbances, inadequate modeling, insufficient technical interconnection requirements, and a lack of operating protocols for the influx of large loads - and has signaled a Reliability Standard may follow that would let it audit large-load operators and mandate compliance.

Read that last clause as an engineer. "Audit" and "mandate compliance" mean the agent's actions at the grid boundary may soon be subject to after-the-fact regulatory inspection, with penalties. An action that is locally optimal and provably correct can still be a compliance violation, and the agent has no way to know, because the rule lives in a document, not a sensor feed. This is the environment the power agent operates in, and it is the reason its authority ceiling is set in a tariff filing, not a thermal model.

The boundary that splits the use case

The single most important line in this use case is the facility boundary - specifically, the meter. It cleanly separates two regimes with completely different authority ceilings, and getting the split right is most of the design.

Behind the meter, the operator owns the assets: the on-site batteries, the backup generators, the internal distribution, the UPS. Actions confined to these - charging a battery from owned solar, discharging it to shave the facility's own peak, shifting internal load between owned circuits - have a blast radius that stays inside the fence. These are the grid-management actions that can legitimately reach Act-within-bounds, because they are, in the OAG's terms, the cooling problem again: physical, bounded, and owned. The envelope is the battery's state-of-charge limits and the facility's own electrical ratings.

In front of the meter, the action touches the shared grid: exporting power, participating in a demand-response dispatch, transferring load in a way that changes what the grid sees, providing frequency response. The blast radius of these actions is the grid itself, and the ceiling on them is not the agent's confidence or even the action's reversibility - it is whether the action is permitted under the interconnection agreement and the program rules, and whether executing it autonomously is something the regulator allows. These are Advise by default. The agent can be certain the frequency-response bid is profitable and correct, and that certainty is irrelevant to whether it is allowed to place it without a human in the loop.

The opening failure is precisely what happens when this line is ignored - when an action that feels behind-the-meter (switching to my own generators) has a front-of-the-meter consequence (the grid sees hundreds of megawatts vanish at once). The meter is not always where the blast radius ends. That is the subtlety the envelope has to capture.

The meter boundary splits power actions into two authority regimesBehind the meter the operator owns the assets and actions reach act-within-bounds inside an electrical envelope. In front of the meter actions touch the shared grid and stay at advise. A trap arrow shows owned-generator dispatch can still be grid-visible and cross the line.Behind the meterowned assets, in the fencebatteries within state-of-chargeinternal load shiftingowned generation dispatchAct-within-boundselectrical envelopeIn front of the metershared grid, out of the fencedemand response, curtailmentfrequency, voltage supportwholesale market bidsAdviseregulator owns the ceilingthe metercan be grid-visible
The meter splits the use case. Behind it, owned-asset actions reach Act-within-bounds inside an electrical envelope. In front of it, grid-visible actions stay at Advise. Owned-generation dispatch can cross the line - the opening failure.

The wrong way: optimise the whole energy position as one problem

The naive agent treats energy management as a single optimisation over price, carbon, and reliability, with every actuator - batteries, load, generators, grid bids - as an equivalent lever.

code
# The seductive, wrong shape: every actuator is the same kind of lever,# and "profitable" is treated as "permitted".async def manage_energy(state: GridState, assets: Assets) -> list[Action]:    plan = optimizer.solve(        objective=minimize(cost) + maximize(grid_revenue) - penalty(emissions),        levers=[assets.batteries, assets.load, assets.generators, assets.grid_bids],    )    for action in plan.actions:        await action.execute()        # batteries and grid bids, treated alike    return plan.actions

The optimiser is not wrong about the economics. The bug is that assets.grid_bids and assets.generators are in the same levers list as assets.batteries, and action.execute() fires them all the same way. Discharging an owned battery within its state-of-charge limits and placing a frequency-response bid into the wholesale market are not the same kind of action, and treating them as interchangeable levers in one optimisation is how a profit-maximising plan walks straight across a regulatory line it cannot see. The optimiser will happily synchronise a load transfer across the fleet because the math says so - and reproduce the opening failure at scale.

The right way: classify by jurisdiction before you optimise

The correct agent does not optimise first and act uniformly. It classifies every candidate action by which side of the meter its blast radius lands on, and routes by jurisdiction before any execution - the same control-plane-decides pattern as the cooling envelope and the SRE gate, with the classifier keyed on ownership and regulation rather than reversibility.

code
# Jurisdiction is decided before execution, in the control plane, from a# machine-readable encoding of the tariff and interconnection agreement -# NOT from the optimiser's sense of what is profitable.async def manage_energy(state: GridState, assets: Assets) -> list[Action]:    plan = optimizer.solve(                         # economics first, as a PROPOSAL        objective=minimize(cost) + maximize(grid_revenue) - penalty(emissions),        levers=[assets.batteries, assets.load, assets.generators, assets.grid_bids],    )    results = []    for action in plan.actions:        scope = jurisdiction_of(                     # the load-bearing classifier            action,            owned=assets.owned_set,                  # is every affected asset ours?            grid_visible=grid_impact(action, state), # does the grid SEE this?            agreement=INTERCONNECTION_AGREEMENT,      # machine-readable tariff terms            program_rules=DEMAND_RESPONSE_RULES,        )        if scope is Scope.BEHIND_METER and scope.within_envelope:            # Owned assets, no grid-visible effect, inside electrical ratings.            results.append(await execute_within_envelope(action, assets))        elif scope is Scope.GRID_PERMITTED_AUTOMATED:            # The agreement EXPLICITLY allows this action to be automated            # (e.g. a pre-registered fast frequency response within a cap).            results.append(await execute_within_envelope(action, assets))        else:            # Anything grid-visible without explicit automation authority.            results.append(advise_human(action, scope))    return results

The differences carry the argument. The optimiser still runs, but it produces a proposal, not a command. Every action passes through jurisdiction_of, which reads a machine-readable encoding of the interconnection agreement and program rules - the tariff, translated into constraints, by humans. Behind-the-meter actions on owned assets reach Act-within-bounds inside an electrical envelope. The one front-of-meter case that may be automated is the narrow, explicitly pre-authorised one: a fast frequency response a human cannot execute in time, pre-registered with the operator within an agreed cap - the genuine exception, allowed because the regulator and the agreement allow it, not because the agent judged it safe. Everything else grid-visible drops to Advise. The classifier, not the optimiser, holds the authority.

One honest limit of this design: it classifies one facility's actions. The opening failure was synchronized across many facilities, and a single operator's agent cannot see its peers dispatching at the same moment. A 100-megawatt owned-generator transfer can classify as not grid-visible in isolation and still be one contributor to a fleet-wide excursion. So grid_impact has to treat synchronized, fleet-correlated load transfer as front-of-meter by default, and lean on operator or ISO coordination signals rather than the facility's own view. Per-facility jurisdiction classification is necessary. It is not sufficient for aggregate effects, and the agent that assumes it is reproduces the opening failure one facility at a time.

Regulatory Opacity

The pattern here is worth naming because it is the sharpest case of a problem the whole series circles.

Call it Regulatory Opacity: the binding constraint on the agent's authority is a rule the agent cannot perceive, because it lives in law, contract, or program terms rather than in any signal the agent senses. The agent can measure price, frequency, state-of-charge, and grid load with perfect fidelity and still have no representation of the sentence in the interconnection agreement that makes its profit-maximising action a violation. Unlike thermal headroom, which the agent fails to account for but could in principle sense, the regulatory limit is categorically outside its perceptual world.

Regulatory Opacity changes what "enforce the boundary outside the agent" means. In the earlier articles, external enforcement was a safeguard against the agent's poor self-judgement - the envelope existed because the agent could not be trusted to respect a limit it could in principle perceive. Here, external enforcement is not a safeguard, it is the only possible mechanism, because there is no version of the agent that perceives the limit at all. The tariff has to be translated into machine-readable constraints by a human who read it, and kept in sync as it changes - the compliance filings have fixed dates, the rules are being rewritten this year, and an envelope encoding last year's tariff is a liability. The boundary is not just enforced outside the agent. It is authored outside the agent, by someone who can read.

Regulatory Opacity: the binding constraint sits outside the agent's perceptual worldThe agent perceives price, frequency, and state-of-charge with perfect fidelity and produces an action. But the binding constraint is the tariff and interconnection agreement, which the agent cannot sense. A human reads the tariff and authors it into machine-readable constraints in the control plane, which gates the action.the agent's perceptual worldpricefrequencystate-of-charge, loadAgentproposes actionTariff and agreementthe binding constraintHuman reads itauthors constraintsControl plane gatepermits or refusesthe constraint never enters the agent's senses
Regulatory Opacity: the agent senses price, frequency, and charge perfectly, but the binding constraint - the tariff - lives outside its perceptual world and must be authored into the control plane by a human who can read it.

This is also why the agentic-smart-grid research frontier should be read carefully by data center teams. That literature is racing toward autonomous distributed-energy-resource control - reinforcement-learning agents actuating inverter set-points, battery dispatch, frequency response, and microgrid islanding without human intervention - and the techniques are real and impressive. But most of that work targets the grid operator's side, or fully-owned microgrids, where the actor has the authority to act on the grid. A data center is a load with a powerful actuator and no such authority. Importing autonomous-DER-control techniques across the meter, without importing the authority that legitimises them, is exactly how a correct agent causes a compliance event.

Where each action sits

The band placement for the power agent's real action set, pinned by ownership and jurisdiction - never by the profitability of the action.

Charging and discharging owned batteries within state-of-charge limits and the facility's electrical ratings is Act-within-bounds. Owned assets, blast radius inside the fence, a clean electrical envelope. This is the safest autonomous power action and the place to start.

Internal load shifting between owned circuits, with no grid-visible change, is Act-within-bounds. Same reasoning - it is the workload-placement problem from Part 4, confined to owned electrical infrastructure.

Behind-the-meter generation dispatch is Act-within-bounds only if the dispatch has no grid-visible effect - and Advise the moment it does, because the opening failure proves that switching to owned generators can have a front-of-meter consequence the agent did not intend. The grid-visibility check is the envelope.

Demand-response participation and load curtailment in response to a grid signal is Advise by default, and reaches a narrow automated band only where the program explicitly pre-authorises automated response within a defined cap. The program rules are the envelope, and they are written by the operator, not the agent.

Frequency response, voltage support, and any wholesale-market bid are Advise, escalating to a human, regardless of how profitable and correct the agent judges them - because these are front-of-meter actions on a regulated system, and the authority to automate them is the regulator's to grant, not the agent's to assume.

Anything whose permissibility under the current tariff is unknown or stale is refused until the encoding is updated. With the rules being rewritten on fixed 2026 deadlines, "we are not sure if this is still allowed" is a stop condition, not a judgement call.

The adoption sequence

The order follows ownership and authority, not the revenue opportunity - and the revenue is largest exactly where the authority is least, which is the trap.

Start entirely behind the meter, with owned-battery optimisation and internal load shifting inside clean electrical envelopes, where the blast radius cannot leave the fence. Prove the agent's economics there, where a mistake costs you and only you. Then, before any front-of-meter automation, invest in the thing that actually gates it: a machine-readable, version-controlled encoding of your interconnection agreement and every demand-response program you participate in, owned by someone who tracks the regulatory filings. That encoding is the power agent's envelope, and like the checkpoint layer in Part 4, it has to exist before the autonomy it supports. Only then, and only for narrowly pre-authorised actions like a capped fast frequency response, enable any automated front-of-meter action - with the grid-visibility classifier mandatory and a human in the loop for everything else. Treat every grid-visible action as Advise for far longer than the revenue math wants, because the revenue math does not price a NERC audit finding.

And watch the regulatory calendar as a system dependency. The compliance filings, the final rule, the reliability standard - these change the envelope. A power agent whose constraint encoding is not maintained against the live regulatory state is not a bounded agent. It is an unbounded one that happens to be compliant with a tariff that no longer exists.

Regulatory Opacity checklist

Before a power agent takes any grid-touching action autonomously, confirm:

  • Every action is classified by side of the meter. A jurisdiction classifier keyed on ownership and grid-visibility runs before execution - the classifier holds the authority, not the optimiser.
  • The tariff is machine-readable and owned. Your interconnection agreement and each demand-response program are encoded as constraints, version-controlled, and owned by someone who tracks the regulatory filings.
  • Grid-visible actions default to Advise. Front-of-meter actions escalate to a human unless the agreement explicitly pre-authorises automation within a defined cap.
  • Owned-generation dispatch is checked for grid-visibility. Switching to backup generation reaches Act-within-bounds only when it has no front-of-meter consequence - the opening failure is what happens when it does.
  • The encoding is synced to the live regulatory state. An envelope encoding a superseded tariff is a liability; "unsure if this is still allowed" is a stop condition, not a judgement call.

Where this lands

Power and grid management is the use case where the OAG's logic reaches its hardest case. The authority ceiling is not physics, which the agent could eventually learn to sense, but jurisdiction, which it cannot. The boundary is invisible to the optimisation, lives in documents that change on regulatory deadlines, and is enforced not as a safeguard against the agent's judgement but as the only possible mechanism, because the agent has no faculty for perceiving a law.

The discipline that follows is narrow and strict. Classify by which side of the meter the blast radius lands. Keep behind-the-meter, owned-asset actions inside an electrical envelope and let them act. Treat everything grid-visible as Advise until the regulator and the agreement explicitly say otherwise. Encode the tariff as constraints, author them outside the agent, and keep them synced to the live regulatory state. And remember the lesson the opening failure teaches and the reliability alert confirms: at the grid boundary, an agent being right is not the same as an agent being allowed - and only one of those two keeps the lights on for everyone else connected to the same wires.

Part 6 steps back from running the building to building it: agentic AI in construction, commissioning, and the supply chain for the buildout itself, where the orchestration problem is coordinating many specialised agents - and the authority question becomes which trade-offs a coordinator may make alone, and which must escalate to a human.

References

The grid constraint and real disturbances

The regulatory structure (FERC / NERC / PJM)

Agentic energy management techniques


Agentic AI

Follow for more technical deep dives on AI/ML systems, production engineering, and building real-world applications:


Comments