top of page

Who regulates AI's environmental footprint?

  • Rafael Rzayev
  • Aug 20
  • 10 min read

A single AI training run touches four regulatory systems, and none of them sees the whole of it. The chips are fabricated in East Asia, the data center connects to the grid under a US utility tariff, the corporate parent reports in Europe, and the model itself is regulated under the EU's AI Act. Each instrument attaches to a different legal object (a product, a rate, an undertaking, a model), and their thresholds share no common unit. Together the four regimes still fail to cover the footprint they are supposed to govern, and an operator can lawfully place each layer where its regulator sees the least of it.


Transmission lines, data center construction, and a silicon wafer illustrating the layered regulation of AI infrastructure | Gasilov Group 2026

A January 2026 paper by Thomas Le Goff, now on arXiv after a pre-COP30 presentation, reaches a parallel verdict from the legal texts. The AI Act contains almost no environmental obligation, sustainability reporting records emissions without correcting them, due diligence law is too generic to reach model training, and data center measures rely on voluntary codes. Each regime fails on its own terms, and the four also fail jointly, because no two of them attach to the same legal object. That joint failure is the part an operator can arrange around, and it appears in three practice areas: rates and siting, disclosure, and the border.


What each regime attaches to


The AI Act binds the model's provider, the Corporate Sustainability Reporting Directive (CSRD) binds the reporting undertaking, the Corporate Sustainability Due Diligence Directive (CSDDD) binds the corporate group, and energy regulation binds the facility or its grid connection. Each instrument can compel information or money from its own object and from nothing else.


Under Article 53 and Annex XI of the AI Act, a provider placing a general-purpose AI model (the Act's category for models usable across many tasks) on the EU market must document the computational resources used in training and the model's known or estimated energy consumption. Estimated training energy also counts among the criteria for designating a model as carrying systemic risk. Nothing in those provisions obliges anyone to reduce anything, and environmental impact otherwise is left to Article 95's voluntary codes of conduct. The disclosure itself has an exemption built in, because the general-purpose AI Code of Practice lets a provider claim relief from the energy figure when its compute or hardware supplier withholds the underlying data. A frontier lab can therefore comply in full by filing an estimate assembled from chip counts, while the true meter reading stays in a landlord's records.


The CSRD, as amended by the Omnibus directive (Directive (EU) 2026/470, which simplified both sustainability regimes) in force since March 2026, requires a sustainability statement from EU undertakings above 1,000 employees and €450 million in net turnover. The statement covers both what the company does to the climate and what the climate does to the company. A reporting obligation covers the entities inside the consolidation boundary, and the electricity behind a group's AI workloads is often bought or consumed outside that boundary. Training compute bought as a cloud service is reported in the buyer's scope 3 (the category for indirect emissions in a company's value chain), where estimation methods are loosest. The physical megawatt-hours appear instead in the provider's own statement, or in no statement at all when the provider reports as a non-EU parent on a later schedule. In practice the company that uses the electricity and the company that reports it are often two different companies.


The CSDDD, after the same Omnibus, applies to companies above 5,000 employees and €1.5 billion in worldwide turnover, with compliance starting in July 2029. The Omnibus also deleted the directive's obligation to adopt and put into effect a climate transition plan, which had been the one provision across the four regimes with an implementation duty attached to climate. Hyperscalers exceed the new thresholds by a wide margin. Most AI-native developers, some of them contracting for gigawatts of capacity, employ well under 5,000 people today and do not enter the directive's scope on the current tests.


The facility layer in the EU is governed by Article 12 of the Energy Efficiency Directive. Every EU data center with at least 500 kW of installed IT power demand reports annually, by May 15, into a European database. The report covers energy use, power usage effectiveness (total facility energy divided by IT equipment energy), water usage effectiveness (water used per unit of IT energy), waste heat, and renewable share. Reporting is the whole of the EU-level obligation, while the performance floor comes from national law where it exists at all. Germany's Energy Efficiency Act requires new facilities commissioned from July 2026 to reach a power usage effectiveness of 1.2 within two years. The database is limited to EU facilities, and most new AI training capacity is being built outside the EU.


The United States regulates the same facilities through money, and the operative documents are utility tariffs and interconnection studies with no environmental content in them. On June 18, 2026, the Federal Energy Regulatory Commission (FERC) issued show cause orders to all six regional grid operators, the regional transmission organizations (RTOs). A show cause order requires its recipient to justify why a proposed change should not apply, and these orders propose to treat any new load above 50 MW connecting above 69 kilovolts as a large load. A load in that class would owe minimum revenue contributions and credit support, with curtailable service (service the utility can interrupt during periods of system stress) offered as a faster way to reach energization. The six regional responses came due on August 17, two days ago, with public comments now opening on each filing.


Our regulatory tracking separately counted 23 states with approved large-load tariffs of their own as of May 2026, a count the Edison Electric Institute's public tracker matches. None of these instruments contains an environmental test, a carbon term, or a water term (the tariff sheet never mentions sustainability, and it does not need to). The water side of the same buildout follows a similar permit-by-permit pattern, which we covered in our analysis of data center water use.


Which of these instruments binds a given group is a threshold question. Our free Regulatory Readiness Assessment runs that check from headline company facts against these same instruments.




Figure 1. One AI deployment and six regulatory attachment points across the AI Act, CSRD, CSDDD, the Energy Efficiency Directive, the FERC show cause orders, and the EU border instruments. No two instruments attach to the same legal object, and the thresholds do not nest. An EU facility becomes reportable at 500 kW of installed IT load, the US orders propose treating a load as large from 50 MW upward, and group due diligence binds above 5,000 employees. Those are three triggers measured in units that cannot be compared, attached to objects that never coincide. The US large-load definition remains at the proposal stage pending FERC rulings. Analysis: Gasilov Group, our cross-reference of the instruments linked in this post, current as of August 2026.


Where the layers fail to overlap


The regimes that force action do not see AI, and the regime that sees AI forces documentation, leaving three seams: energy economics without environmental content in the US, disclosure without binding consequences in the EU, and chips screened for forced labour while carbon crosses unpriced.


The fastest-binding rules on AI's physical footprint in 2026 are American rate proceedings that never mention the environment. Data center electricity demand grew 17% globally in 2025, with AI-focused facilities up 50%, on the International Energy Agency's (IEA) April 2026 numbers. In the US that growth is governed through rate design: who pays for network upgrades, what credit support a developer posts, which loads can be curtailed during system stress. Those dockets (the formal rate proceedings before each commission) decide how much AI capacity gets built, where, and on whose balance sheet, and they never ask what the capacity emits or evaporates.


Community opposition to data centers wins at the county level and loses in the rate dockets, a point Arif made to Newsweek. Coordinated backlash can stop an individual data center while leaving bill increases untouched, because the bill is set in commission proceedings that nobody protests. That leaves anyone trying to govern the footprint arguing environmental points in the one venue with binding power, where those points are procedurally out of place.


On the disclosure side, the EU now holds detailed facility data and aggregated entity data, and the two do not reconcile. The Energy Efficiency Directive database receives facility-level indicators, incl. water, from every EU data center above the threshold. The same operators' climate statements under the ESRS (the European Sustainability Reporting Standards issued under the CSRD) aggregate to entity level on market-based accounting choices, with cloud customers left to make scope 3 estimates.


A reader holding both documents cannot trace a training run through them. The revised reporting standards are due from the European Commission in a delegated act by September 18, 2026, and will fix which climate datapoints the statements keep. The datapoint cuts were negotiated with no reference to the facility database being populated in parallel.


At the border, the EU operates two product-level instruments, and neither of them reaches the semiconductors that AI hardware depends on. The Carbon Border Adjustment Mechanism (CBAM) entered its definitive phase on January 1, 2026, pricing embedded emissions across cement, iron and steel, aluminium, fertilisers, electricity, and hydrogen. Semiconductors sit outside that list. As a result of this, a GPU crosses the EU border with no carbon price attached. The December 2025 expansion proposal covers steel- and aluminium-intensive downstream goods, and compute stays outside its scope.


The forced-labour instruments do reach the substrate, the silicon and polysilicon the chips are made from, and they reach it with the strongest enforcement mechanism among the six instruments, a market ban backed by customs enforcement. Silica-based products, incl. polysilicon, have been a high-priority enforcement sector under the US Uyghur Forced Labor Prevention Act since the Act's first enforcement strategy in 2022, and the entity list added 43 companies on July 31, its largest single expansion, in sectors from aluminum to cotton. The EU's own Forced Labour Regulation applies from December 14, 2027 to every product on the Union market. Meanwhile fabrication concentrates where disclosure is thinnest: TSMC (Taiwan Semiconductor Manufacturing Company) alone drew about 8% of Taiwan's electricity in 2023 on S&P Global figures, and is projected to reach almost a quarter by 2030. The physical substrate of AI is screened at the border for forced labour, priced at the border for nothing, and disclosed at the source barely at all.


One corporate structure placed across the three seams produces the arbitrage (placing each layer of one operation where its rules cost least) on its own, with no lawyer needing to design it. An operator can train in a non-RTO state on a negotiated utility contract, hold its EU presence below the reporting thresholds or under the later non-EU parent schedule, and buy chips whose fabrication footprint no importing regime prices. Its Annex XI filing can then carry an energy estimate assembled from hardware specifications. Every step is lawful, and every regulator involved sees full compliance with its own instrument.


Our read is that the arbitrage today is mostly passive, given that footprint currently follows cheap power and available land, but the incentive now is to make it deliberate, because the same megawatt carries a different regulatory cost depending on which legal object holds it.


What a coherent framework would require


A coherent framework would require the four regimes to exchange data about the same physical object, and the three datasets that would feed that exchange already exist. The AI Act's training-energy figures, the Energy Efficiency Directive database's facility metrics, and the ESRS climate datapoints describe one footprint from three angles, and no process currently reconciles them.


Setting up that exchange would take little new legislation, because the necessary powers were drafted into instruments already in force. Article 53(5) of the AI Act lets the Commission set measurement and calculation methods for the training-energy figure by delegated act, and the facility database already publishes aggregates at EU and country level. A methodology that reconciles a model's reported kilowatt-hours to a facility's reported kilowatt-hours to an entity's reported emissions would connect three instruments with no new statute. The IEA's base case has data center electricity demand approximately doubling to about 950 TWh by 2030. If the three regimes are not linked before that growth occurs, the doubled footprint will be governed by whichever regime each operator prefers.


For an operating team the same logic applies in the opposite direction: build one measurement architecture that can answer all four regimes from the same meter. A facility-level energy and water record designed to fill the EU database template will also carry an ESRS datapoint, support an Annex XI estimate, and withstand a rate-case data request, while a record built regime by regime gets rebuilt at each new deadline.


Supplier contracts deserve the same treatment ahead of the December 2027 forced-labour date, because chip and server vendors can be asked today for embedded-emissions data and for supply-chain tracing to the raw silicon stage that customs authorities already demand. And curtailability has become environmental strategy in practice, since the flexible service products in the FERC template trade energization speed against consumption during system stress.


The academic proposals converge on a fifth instrument, a dedicated sustainable-AI law that would operate above the four existing regimes. The enforcement half of that hypothetical law already operates in the US tariff instruments, the measurement half already exists in the EU disclosure instruments, and neither jurisdiction currently wants the other's half. A coherent framework is, on this record, a linkage problem, and linkage can start unilaterally, e.g. with the Commission's Article 53(5) methodology referencing the facility database the same institution already runs.


The nearest concrete decision is pending before FERC, which will accept, modify, or reject each regional large-load package in orders that could begin arriving late in 2026, covering regions that serve around two-thirds of the load under its jurisdictional rates. Those rulings will set the binding economics of AI infrastructure in the world's largest AI market, and as drafted they will do it without a single environmental datapoint. Whether any regime ever sees the whole footprint starts with what the commission does with those six filings.


Which of these layers applies to your organization depends on entity structure, load size, and supply chain facts that differ case by case. If you already know what you need, or want help finding out, get in touch and we can scope it.



  • Arif Gasilov is partner for Natural Resources & Built Environment at Gasilov Group, where he works on energy regulatory analysis, water governance, utility rate cases, and the resource footprint of large development.

  • Seyfi Gasilov is partner for Sustainability Reporting & Governance at Gasilov Group, where he works on CSRD and ESRS compliance, ISSB, internal controls, and supply-chain due diligence.

  • Rafael Rzayev is partner for Trade, Customs & Sustainability Regulation at Gasilov Group, where he works on CBAM, EUDR, the EU Forced Labor Regulation, and cross-border compliance.


Frequently Asked Questions (FAQ):


Does the AI Act's energy documentation duty apply yet, and to whom?

It has applied to general-purpose models placed on the EU market since August 2, 2025, and models already on the market before that date have until August 2, 2027 to comply. Models released open source under the Act's conditions are exempt from the documentation duty, while models designated as carrying systemic risk face the full set regardless of licence.


Will semiconductors enter CBAM scope in 2028?

No pending proposal brings them in: the December 2025 proposal would add about 180 downstream products from January 1, 2028, selected for their high steel or aluminium content, and chips sit outside it. Including semiconductors would require a further legislative proposal after the Commission's scheduled scope reviews, which have so far prioritised sectors already priced under the EU emissions trading system.


Last updated: August 2026


bottom of page