Can Regulation Keep Pace with AI Infrastructure?

 

 

 

Can Regulation Keep Pace with AI Infrastructure?

The race to build AI infrastructure is moving at extraordinary speed. The regulatory debate is not.

Headlines around AI infrastructure are increasingly dominated by the exceptional demands being placed on power systems, and by the strategies governments, regulators and operators are adopting to manage them. But while power may be the most visible regulatory pressure point, it is only one dimension of the challenge.

Every AI workload also raises questions about data, intellectual property, accountability, jurisdiction and control. Who has the right to use information for training? What happens when proprietary data is used to fine-tune a third-party model? Who is responsible when a model developer, cloud provider, application company and enterprise customer all sit in different parts of the value chain? Which law applies when data is generated in one country, processed in another and used by a model developed in a third?

These questions increasingly influence where AI workloads can run, how infrastructure is designed, which providers can serve regulated customers and whether a market can attract investment at scale.

The central challenge is that AI does not sit within a single regulatory category. It cuts across data protection, copyright, competition, energy, planning, environmental regulation, cybersecurity and increasingly AI-specific legislation.

The technology stack is integrated. The regulatory system is not.

That may prove to be one of the defining infrastructure challenges of the AI era.

AI is collapsing previously separate regulatory domains

For most of the digital economy’s development, different layers of infrastructure could be governed through relatively distinct frameworks.

Telecommunications regulators dealt with networks. Planning authorities dealt with buildings. Energy regulators dealt with grid connections. Data protection authorities dealt with personal information. Sector regulators oversaw specific applications.

AI is making those boundaries much harder to sustain.

Consider a relatively straightforward enterprise deployment. A company takes an AI model developed by one provider and adapts it using proprietary information. The model may run on a major cloud platform, use compute supplied by another specialist provider and sit inside a third-party data centre. It may also connect to internal company databases and generate new information through use.

Which regulator governs the system?

The answer may be several.

Data protection law may apply to personal information. Copyright law may apply to training material. AI-specific rules may apply to the model or its intended use. Sector regulation may apply to the organisation deploying it. Energy and environmental rules govern the physical infrastructure.

The problem is not simply that there are many rules. The same AI system can face different obligations depending on how it is trained, modified and used.

Europe’s AI Act illustrates the difficulty. Obligations can vary depending on whether an organisation develops, modifies or deploys an AI system, as well as on how that system is classified and used. The European Commission has acknowledged that a company adapting or fine-tuning a third-party model may, in some circumstances, take on new regulatory responsibilities of its own.

A company can therefore move from being a customer of AI technology towards becoming a regulated provider because of what it does to an existing model.

The boundary of regulation is moving with the technology.

Who owns value once data enters the AI stack?

One of the most important questions is also one of the most deceptively simple.

Who owns the data?

In practice, the answer is often less straightforward than the question suggests.

Data does not necessarily fit neatly into conventional concepts of property ownership. The EU Data Act, for example, focuses heavily on rights to access and use data rather than creating a simple universal ownership regime.

AI makes that complexity commercially significant.

Imagine an industrial company with decades of proprietary operational data. It uses that information to fine-tune a third-party model.

Several layers of value may emerge: the original dataset, a cleaned or structured version, changes made to the model, outputs generated through use and new information created through customer interactions.

Calling all of this “the data” obscures the real problem.

Different rights may attach to different layers. Personal data law, database rights, copyright, trade-secret protection and contractual restrictions may all apply differently. Some elements may not attract conventional property rights at all.

For enterprise buyers, this changes the procurement question.

Boards increasingly need to understand what information enters the system, what new information is created, who can access and use it, whether interaction data can be used to improve the service, what happens when a contract ends and whether a model or resulting information can be moved elsewhere.

These issues have direct consequences for infrastructure.

A regulated bank, hospital, industrial company or government body may require a more controlled AI environment because it needs clarity over where data goes, who can access it and how it is retained or deleted. Those requirements can influence whether workloads run in shared cloud environments, private infrastructure or more isolated deployments.

Increasingly, decisions about where and how AI workloads run will follow the legal requirements attached to the data they use.

Training data is becoming an infrastructure question

The debate becomes more complex when data is used to train models.

In the US, the Copyright Office’s 2025 report on generative AI training highlighted the scale of the legal uncertainty, with dozens of lawsuits already examining whether copyrighted material can be used to train AI models. Its conclusion was broadly that existing copyright law can address these questions, but that the answer will depend heavily on how data is sourced and used.

Europe has taken a different regulatory route.

Since August 2025, providers of general-purpose AI models within scope of the EU AI Act have been subject to obligations including technical documentation, a copyright-compliance policy and publication of a summary of training content. The Commission’s template asks providers to disclose information about major sources used in training.

This is more than a transparency requirement.

Knowing where training data came from is increasingly becoming a compliance requirement.

Companies may need clearer records of where data came from, how it was processed and whether they had the right to use it. Different categories of data may also need to be handled separately, with evidence retained after the original training process is complete.

If developers increasingly have to prove what data was used and whether they had the right to use it, those record-keeping requirements become part of the infrastructure needed to develop AI.

The economic implications could be significant.

If jurisdictions adopt materially different rules for training data and copyright, developers may face pressure to maintain different datasets, processes or model variants for different markets.

The cost of different regulatory regimes could therefore appear not only in legal budgets, but in duplicated infrastructure.

Can traditional data rules govern an AI lifecycle?

AI also challenges a basic assumption behind much modern data regulation: that organisations can clearly define why information is being collected and how it will be used.

Traditional data governance is often built around a sequence. Information is collected. A purpose is defined. A lawful basis is established. The data is processed, retained and eventually deleted.

AI development is less linear.

A dataset collected for one purpose may later become valuable for model development. A model built for one application may be adapted for another, while user interactions can generate entirely new information.

The UK Information Commissioner’s Office has focused directly on this issue. Its work on generative AI has examined how personal data is collected and reused, what rights individuals retain and how responsibility should be divided between the organisations involved.

The question is no longer simply whether data was lawfully collected. It is whether later model development, adaptation and reuse remain compatible with the conditions under which that data originally entered the system.

For C-suite decision-makers, this is increasingly a governance issue rather than a technical detail.

Some of the most important compliance decisions may be made long before deployment, when contracts are signed, datasets are selected and responsibility between suppliers is allocated.

AI is global by architecture, but regulation remains territorial

The modern AI stack is inherently international.

A single service may involve a model developed in the US, enterprise data generated in Europe, a cloud provider headquartered elsewhere, compute infrastructure located in the Gulf and users distributed across multiple markets.

Law remains largely territorial.

A single workload may simultaneously face data-protection and transfer rules where information originates, AI-specific obligations where the service is offered, sector regulation governing the customer and infrastructure requirements where the compute is located.

The result is not simply regulatory complexity.

It is the possibility of regulatory conflict.

One jurisdiction may permit a particular use of data while another restricts it. A disclosure requirement in one country may conflict with confidentiality rules elsewhere. Even the same AI model can face different obligations depending on how and where it is used.

Cross-border data rules are also evolving. The UAE’s federal data-protection framework places requirements on the transfer and sharing of personal data outside the country, while Saudi Arabia has its own rules governing international transfers.

The point is not that one system is necessarily more restrictive than another. It is that regional and global AI services increasingly have to operate across several legal frameworks at once.

That can directly affect infrastructure decisions. Some workloads may need to remain in particular locations. Certain datasets may need to be kept separate. Customers may require clearer visibility over where data is processed and which third parties can access it.

This is why data regulation is also becoming an infrastructure issue.

A law does not need to mention data centres to influence where compute demand emerges.

The accountability gap across the AI stack

Perhaps the hardest issue is responsibility.

AI services increasingly depend on many connected companies, with responsibility divided across them. A single service can involve a data provider, model developer, cloud platform, specialist compute provider, data centre operator, application company and enterprise customer.

When something goes wrong, who is responsible?

The model developer may not control the eventual use. The enterprise deploying the system may not understand the original training process. The cloud provider may supply infrastructure without controlling the application. The data centre operator may host the servers while having no meaningful visibility over the workload itself.

Regulators are beginning to address this gap.

The UK ICO has examined how responsibility should be divided across the generative AI supply chain, while the EU AI Act places different obligations on organisations depending on whether they develop, modify or use an AI system.

But the commercial implications extend beyond formal legal liability.

Unclear responsibility will affect contracts. Enterprise customers may demand greater visibility and stronger audit rights. Technology providers may place tighter limits on how their systems can be used. Insurers and regulated companies are likely to require more evidence that risks are being managed.

Data centre operators may not be directly responsible for how an AI model behaves, but that does not make them immune from the consequences. Customers may increasingly expect infrastructure providers to demonstrate stronger security, access controls, incident response, clear geographic processing boundaries and support for regulatory audits.

Regulatory expectations can reach infrastructure providers even when legal responsibility for the AI system sits elsewhere.

What exactly is being regulated?

There is another problem.

AI systems do not remain static.

A conventional infrastructure asset can usually be assessed against a relatively stable design. AI systems are different. They can change through software updates, new training data, further customisation or connections to additional tools.

This raises a difficult question.

Is the regulated entity the original model, a modified version, the application built on top or the complete system as it is actually used? And when that system is updated or connected to new tools, at what point should new obligations apply?

The EU is already grappling with this problem. Its guidance recognises that modifying an existing AI model can, in some circumstances, create new regulatory responsibilities. But it also acknowledges that not every update should be treated in the same way.

The significance goes beyond Europe.

A model that generates text presents one level of risk. The same model connected to financial systems, industrial controls or autonomous tools may present a very different one.

The underlying model may be similar, but what it can do has fundamentally changed.

Regulation therefore cannot focus only on the model itself. It must also consider how that model is used and what systems it can access.

Power is where the regulatory debate becomes physical

None of this reduces the importance of physical infrastructure.

The IEA’s latest analysis shows the scale of the change. Data centre electricity demand grew by 17% in 2025, while consumption from AI-focused facilities increased by 50%.

But the regulatory challenge is not simply how much electricity AI consumes.

It is how scarce capacity is allocated.

The UK offers a striking example. In March 2026, the government reported that the queue for demand connections to the transmission network had grown by 460% in only six months to June 2025. It said speculative applications were contributing to waits of up to 15 years and proposed reforms to prioritise strategically important demand, including AI data centres and industrial projects.

That represents an important shift.

Once capacity is scarce, regulators must ask harder questions. Is the project credible? Will the load materialise? Should strategically important demand receive priority? Who should pay for the infrastructure required to support it? And how long should scarce capacity remain reserved for projects that are not progressing?

These are questions about economic policy as much as engineering.

Ireland demonstrates another model. Data centres accounted for 23% of metered electricity consumption in 2025, up from 5% a decade earlier. In December 2025, the Commission for Regulation of Utilities introduced a new connection policy requiring new data centres to meet at least 80% of annual demand with additional renewable generation in Ireland, subject to a six-year development pathway, alongside requirements relating to generation and storage.

The regulator is therefore influencing how new data centre capacity must be configured to fit within the wider electricity system.

The infrastructure is no longer merely regulated.

It is being actively shaped by regulation.

Planning and sustainability are becoming industrial policy

The same change is visible in planning.

AI infrastructure has become too large and too strategically important for many governments to treat development purely as a sequence of individual applications.

The UK’s AI Growth Zones combine infrastructure planning with attempts to accelerate grid access and direct investment towards priority locations. The government’s 2025 delivery plan argued that combined interventions could reduce time to power by up to five years.

Europe is pursuing an even broader approach.

In June 2026, the European Commission proposed the Cloud and AI Development Act, aiming to at least triple EU data centre capacity within five to seven years while simplifying permitting and improving access to energy, land, water and finance.

At the same time, Europe is tightening the sustainability framework surrounding data centres. The Commission is advancing an energy-efficiency package covering areas including energy efficiency, water use, clean energy and waste-heat reuse, alongside work towards minimum performance standards.

This apparent contradiction is important.

Europe wants more AI infrastructure. It also wants more demanding oversight of the resources that infrastructure consumes.

Governments are not simply choosing between development and regulation. They are attempting to accelerate strategic capacity while managing its wider impacts.

For investors, the challenge lies increasingly in the gaps between policies. A market can accelerate planning while leaving grid access unresolved. It can demand higher environmental performance without creating a credible route to new clean generation.

The GCC has an opportunity to regulate the system, not individual layers

For the Gulf, these questions are becoming urgent.

Saudi Arabia’s Ministry of Communications and Information Technology reported in April 2026 that national operational data centre capacity had increased from 68MW in 2021 to more than 440MW in 2025, with more than 60 data centres developed by over 20 companies. At LEAP 2025, the Ministry reported more than US$14.9Bn of announced investments and projects across AI and emerging technology.

Across the wider GCC, governments are simultaneously pursuing cloud investment, domestic compute, AI adoption, international technology partnerships and new data infrastructure.

The regulatory opportunity is significant.

Many mature markets are now attempting to coordinate systems that evolved separately over decades. The Gulf has the chance to build greater coordination earlier.

That does not mean creating a single law to govern every aspect of AI. Overly broad legislation could create more uncertainty.

The better objective is to ensure that rules covering data, AI, power, planning and infrastructure work together rather than develop in isolation.

A major AI project should not be assessed as a planning application in one process, a power request in another, a data question somewhere else and a strategic investment by a fourth institution without a clear view of the complete system.

Governments need a connected view of how data moves, who is responsible at each stage, which cross-border rules apply, how the project affects the electricity system and which authority leads when obligations overlap.

Greater regional alignment will also matter.

AI workloads will not necessarily remain within national borders simply because regulations do. Enterprises may operate across Saudi Arabia, the UAE, Bahrain, Qatar, Oman and Kuwait. Cloud platforms may serve several markets, while processing and backup capacity may sit in different locations.

If every market develops very different definitions, reporting requirements and approval processes, the cost and complexity of operating across the region will increase.

Greater alignment around core principles, even without identical laws, could therefore become a regional advantage.

The opportunity is not to eliminate regulation.

It is to make the rules clearer, more consistent and easier for companies to navigate across the GCC.

The deeper challenge is coherence

The phrase “regulation cannot keep pace with technology” is often used as though speed were the only problem.

It is not.

A government can move quickly and still create conflicting obligations. Planning rules can accelerate projects that cannot secure power. Data laws can make it harder to move information across systems or borders. AI regulation can assign responsibility to organisations that may not have the information or control needed to meet it.

This is becoming increasingly visible in Europe, where rules covering AI, personal data, cybersecurity, cloud services, energy performance and digital markets increasingly overlap. The Data Act has applied since September 2025, while obligations for general-purpose AI models under the AI Act began in August 2025. At the same time, the Commission is developing further guidance on responsibility across the AI ecosystem and proposing new legislation to expand cloud and AI infrastructure capacity.

Each initiative has its own logic.

The strategic question is whether the combined system remains clear and workable.

For industry, this matters more than the strictness of any single rule.

Capital can price compliance.

It struggles to price contradiction.

A more effective approach would begin by recognising that AI infrastructure operates as a connected system.

Responsibility should sit with the organisations capable of managing the relevant risk. A model developer should not face the same obligations as a data centre operator or enterprise customer, but responsibility should not disappear simply because several organisations are involved.

Regulation must also recognise that AI systems continue to change after deployment. Clear thresholds are needed for deciding when updates or new uses are significant enough to trigger further obligations.

Greater coordination is needed across jurisdictions and government institutions. Identical laws are unrealistic, but clearer cross-border rules and stronger alignment between energy, planning, digital policy and economic development would make it easier for companies to invest across multiple markets.

Finally, infrastructure regulation should focus on measurable outcomes and better information. Governments should be cautious about locking rapidly changing engineering choices into prescriptive rules. At the same time, power systems cannot be planned effectively without credible demand forecasts, and sustainability rules are difficult to enforce without reliable data on energy and water use.

Transparency is not an end in itself.

It is what allows better decisions to be made.

Regulatory coherence will become a competitive advantage

So, can regulation keep pace with AI infrastructure?

Not if keeping pace means writing a new rule every time the technology changes.

The model cycle is too fast.

The infrastructure cycle is too long.

And the AI ecosystem is too interconnected for regulation built around isolated sectors to remain sufficient.

The more important task is to create systems that can adapt without becoming contradictory.

Who has the right to use data? Who is responsible when several companies contribute to one AI service? Which jurisdiction governs a workload spread across multiple markets? When does a modified model trigger new obligations? How should scarce electricity capacity be allocated?

These questions will increasingly influence where AI infrastructure is built and how capital is deployed.

The winning markets are therefore unlikely to be those with the fewest rules.

Nor will they necessarily be those with the most.

They will be the jurisdictions able to provide clear, workable answers across data, AI, power and infrastructure.

A market with abundant power but unclear data rules can still lose investment. A market with ambitious AI legislation but no route to energise new compute will struggle to scale. A market with strong protections but conflicting obligations may simply push complexity into contracts and infrastructure design.

The competitive advantage is coherence.

AI is collapsing boundaries between software and infrastructure, data and energy, and digital policy and industrial strategy.

Regulation will need to do the same.

Because the question is no longer simply whether governments can regulate fast enough.

It is whether the rules can work together before the infrastructure they are intended to govern moves on.

We value your privacy
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Read More