On July 14, 2026, the US Department of Energy temporarily authorized PJM Interconnection to direct eligible backup resources at large-load sites, including data centers, as a last resort before firm load interruption or during an Energy Emergency Alert Level 3. The emergency order covered auxiliary, standby and directly connected generation, battery storage and other backup resources, while excluding assets serving a critical reliability or backup need. The document set a one-week term, through July 21, unless renewed.

The order did not allow PJM simply to switch off servers. But during those emergency conditions, an eligible backup resource at an affected site was no longer exclusively internal. External authority could require a change in live electrical state inside the site boundary.

That boundary is the point. When an authorized grid instruction or accepted market signal can start generation, discharge storage, change cooling, or reschedule compute, it has crossed into production control. It should be governed as a production change, a change to the live facility or service state, not electricity production. The label matters because the response can consume reserve, alter customer performance, or change the recovery path after a fault.

Ireland has moved further. Under its regulator’s December 2025 policy, some qualifying data center connections of ten megavolt-amperes (MVA) or more must link covered demand to dispatchable generation or storage. The nominated asset must be delivered before the covered load can come online or ramp. EirGrid’s transmission process records an active judicial review. That turns an energy-policy condition into a dependency of the live facility.

Flexibility is a live permission

Data center power architecture is usually designed inward from the meter: condition power, carry critical load through disturbances, and preserve service. A grid request enters a system that already has customer obligations and a required operating margin. Those demands can conflict.

The grid may see available megawatts. The site may see a power train under maintenance, protected UPS reserve, and no cooling margin. The platform requesting a response may not know that a tenant has never authorized workload movement. Flexibility is not a permanent slice of nameplate load.

A grid-facing battery energy storage system (BESS) can respond quickly when its state of charge, reserve floor and interconnection allow it. An uninterruptible power supply (UPS) battery has a different first duty: continuity of critical load. Similar cells do not create the same operating contract. Standby generators are not automatically continuous or market-participating generation. Cooling can use thermal inertia, but operating conditions and the later rebound constrain it. Moving a batch job is not instantaneous curtailment. Accepted demand response is also distinct from involuntary load shedding.

Compute flexibility is real but bounded. In March 2026, Google said it had integrated one gigawatt of data center demand response into long-term US utility contracts by limiting or shifting part of its machine-learning workloads. The company also said flexibility was limited and available only at certain locations. That is contracted capacity, not a delivery record. A schedulable workload is not every workload at every site.

A technical flexibility envelope describes what a site can sustain over time within equipment and recovery limits. That is capability, not permission. Permission comes from the live state: equipment health, maintenance, weather, fuel or battery state, protected reserves, eligible workloads and customer terms.

A two-hour reduction may be safe when storage and schedulable compute are fully available. The same promised response can become unsafe when a generator is down, cooling is constrained, or a customer workload is nearing a deadline. The hardware has not changed. Safe capacity has.

Govern the response as a production change

Production changes are bounded because a valid instruction can be wrong for the system’s current state. Before accepting a grid response, the operator needs a defined scope, exclusions, maximum duration, ramp, protected reserve, approval owner, abort trigger, and recovery path. If the state changes, promised capacity must be recalculated. A contract does not make unavailable reserve safe to use.

Fast signals do not require a change-advisory meeting. Governance belongs upstream. Automation may act inside a tested, pre-authorized envelope; an alarm, maintenance state or reduced margin closes it. Local controls must reject or abort the response when those conditions no longer hold. Those paths must be tested. One accountable owner must decide when grid, facilities, platform and customer priorities conflict.

The North American Electric Reliability Corporation’s May 2026 voluntary guideline for emerging large loads reinforces this discipline. It recommends 24/7 operational contacts, telemetry and forecasts, advance notice of step changes, ramp and reconnection protocols, testing of demand-response signals and recommissioning after material changes. It also treats restoration as a system risk when many large loads return together.

A component can pass its test while the response path still fails. A battery discharge test does not prove that the external signal, energy controller, building controls, protected power path, and compute scheduler will coordinate during a degraded state. Commissioning must follow the command end to end and cover stale or lost telemetry, unavailable resources, local override, orderly abort, and rebound.

Governance should follow the coupling

Not every grid interaction needs heavy IT change control. An electrically and logically segregated BESS, with coordinated protection, can provide a bounded service without consuming UPS reserve or changing customer work. A hyperscaler that controls its job queue and holds the necessary contractual rights can create opt-in flexibility tiers.

That works only if the separation is real, not just visible on the architecture diagram. Grid service may still share batteries, controls, switchgear, cooling margin, or workload rights with production. Redundancy is not independence when resources share a failure path. Governance should follow the coupling. The less a response can affect customer service or protected reserves, the lighter its production controls can be; electrical protection, interconnection and asset-maintenance obligations remain.

At the moment of response, operators need to know what is actually available and who has authority to use it. They also need a hard stop when conditions change and a tested way back to normal. Until the command path, local override, abort sequence, and recovery have been commissioned end to end, the megawatts are installed capacity—not operational capacity.