All episodes

AI & Tech Daily

AI’s Next Constraint Is the Electricity Grid

17:56

AI companies are asking regulators to treat data centres as flexible grid resources, with workloads, batteries and generation responding when electricity networks are strained. Jesse examines what operators would need to prove before that proposal can shorten connection queues or reduce upgrade costs. Also covered: Salesforce’s specialised Koa model for CRM agents, Europe’s proposed cross-border AI project, Huawei Cloud’s international agent-stack rollout, two new Indian semiconductor production lines, and a Windows spyware campaign targeting exposed people. In What Changes for You, Qwen’s compact image model brings native transparency and local editing with a non-commercial licence, while GitHub adds enforceable controls over who and what can start Actions workflows.

Full transcript

Read the episode.

I'm Jesse Owen. This is AI and Tech Daily.

AI Meets the Electricity Grid

The next constraint on AI may not be chips. It may be whether a data centre can prove it will ease off when the electricity grid is under strain.

Our main story today looks at a new plan to make AI facilities flexible electricity users, and the question regulators now have to answer: can those promises be measured and enforced well enough to justify faster grid connections?

Emerald AI, Google and NVIDIA launched the AI Energy Management Alliance on 16 September. It brings together 20 technology, utility and energy organisations, including Anthropic, National Grid, AES, Constellation, NRG and RWE. The group is developing technical standards and policy frameworks for data centres that can reduce or shift demand when the grid is constrained.

There are several ways that could work. A facility might move a computing workload to another time or place, discharge on-site batteries, use generation paired with the site, or accept a defined obligation to curtail its demand. The attraction for a grid operator is straightforward. A large new load that can respond on command is easier to accommodate than one that expects full power at every moment, regardless of what the rest of the network is doing.

For AI operators, that flexibility could become part of the case for connecting a new facility sooner and avoiding some network upgrades. But the alliance hasn’t secured a regulatory fast lane. It also hasn’t demonstrated that the proposal lowers electricity prices across the system. It is building the framework and advocating for changes to interconnection rules; regulators still have to decide whether the commitments are dependable enough to count.

That word, dependable, carries most of the weight. Shifting a batch training job may be manageable. Cutting demand during a critical inference workload may be much harder. Batteries have finite capacity. Paired generation has its own operating limits. A curtailment promise only helps the grid if the facility performs during the few difficult hours when that help is needed. The enforcement method, the baseline used to measure a reduction and the consequences for missing an obligation are all unresolved.

A useful standard therefore has to describe more than the amount of demand a site can shed in ideal conditions. Regulators need confidence that the response is available when the network calls for it, that operators can verify what happened, and that a promised reduction has not merely been shifted onto another constrained part of the system. The alliance’s mix of technology companies and energy providers gives it a place to work through those details. It does not settle how a regulator will judge them.

My read is that electricity orchestration is becoming as strategically important to AI expansion as access to accelerators. Securing GPUs doesn’t achieve much if a site sits in a connection queue or requires years of grid work. That gives data-centre operators a reason to design computing, storage and power systems together, rather than treating electricity as a fixed input purchased after the technical architecture is settled.

For utilities and large operators, the immediate value is a common proposal they can take into regulatory discussions. The harder test comes later: verifiable performance under real grid stress. Until that evidence exists, faster connections, lower upgrade costs and community benefits remain possible outcomes, not established ones.

A CRM Model Built for Tool Use

That takes us from managing the power behind AI to narrowing the model in front of a business user.

Salesforce and NVIDIA announced Koa on 15 September, a reasoning model designed for multi-step work in customer relationship management. Salesforce created it by post-training NVIDIA’s open-weight Nemotron-3-Super-120B model on public and synthetic workflow data. The goal is not another general chatbot. Koa is meant to reason across a sequence of CRM actions and use tools over several turns.

Salesforce says it used no customer data for training, and that inference runs inside Salesforce infrastructure. Those boundaries matter to organisations assessing where their business records travel, although they don’t make Koa independently deployable. The model is available only to selected Agentforce pilot customers. Salesforce expects general availability in US regions during winter 2026, so that wider release is still a forecast rather than a finished launch.

The reported results are promising but need the right label. Salesforce’s own research says Koa improved on the Nemotron base model for multi-turn tool use and exceeded GPT-4.1 on the benchmarks it tested. The same research places Koa behind the strongest frontier models. These are vendor-authored evaluations, not independent proof of performance across a customer’s messy production workflows.

The interesting trade-off is specialisation. A company may not need the largest available model if a smaller, controlled model has been trained around the actions, vocabulary and failure patterns of one business domain. That can make multi-step automation more practical. It can also deepen dependence on the platform that owns the model, the tool layer and the runtime.

For organisations already committed to Agentforce, Koa offers a pilot path to test whether domain post-training produces more reliable CRM actions. For everyone else, there is nothing to deploy yet and no downloadable Koa weights to evaluate independently. My judgement is that specialised models will earn their place when they reduce operational errors on real workflows, not when they win a vendor-selected benchmark. Koa gives selected customers a way to start gathering that evidence, while keeping the model firmly inside Salesforce’s estate.

Europe Plans a Full-Stack AI Project

The model layer is only one part of the industrial contest, and Europe is trying to coordinate more of the stack.

On 16 September, the European Commission welcomed a proposal designed jointly by 19 member states for the first Important Project of Common European Interest focused on artificial intelligence. The proposed scope is broad: AI and compute-management technologies, applications, industrial products and decentralised AI services. In other words, the participating states are not limiting the effort to training models or building data centres. They are proposing coordination from enabling infrastructure through to products and services.

The label can sound more final than the announcement really is. This is a design proposal, not a funding approval. Eleven of the participating states that intend to grant state aid said they would begin pre-notifying projects to the Commission in September. The Commission then has to assess the individual projects. No company received money from this announcement, and no total investment figure, final participant list or approval timetable was disclosed.

For prospective participants, the concrete change is that a coordinated state-aid review process can begin. That may make it easier to assemble cross-border projects whose costs, suppliers and customers sit across several countries. It also means the practical result depends on which proposals survive assessment and reach deployment. A full-stack ambition on paper can still produce a patchwork if the selected projects don’t connect technically or commercially.

My assessment is that European AI industrial policy is moving towards cross-border coordination rather than a collection of isolated national bets. That could help organisations working on compute management, industrial AI or decentralised services find partners and public support at a scale that a single market might not provide. But there is no new service to buy and no approved pool of money to pursue yet. The next useful evidence will be the projects the Commission accepts, the funding attached to them and whether they produce infrastructure or products that organisations can actually use.

Huawei Bundles the Agent Stack

A different full-stack strategy is coming from a cloud provider with firm rollout dates, but plenty still to prove.

Huawei Cloud announced an integrated infrastructure stack for enterprise agents on 18 September. It combines its latest AI Cluster Service with context-memory storage, a multi-model service and the AgentArts platform. The pitch reaches beyond renting accelerator capacity: schedule the compute, retain the context an agent needs, provide access to several models and connect the agent to tools in one environment.

Availability is staged. Huawei says the new cluster service is scheduled to become commercially available in China on 30 September and in other markets on 30 November. AgentArts is scheduled to become available outside China on 30 December. Organisations in international markets can assess the architecture and integration path now, but they cannot yet buy those announced services there. Pricing was not disclosed.

Huawei also supplied some sizeable performance and ecosystem figures. It claims the cluster service delivers 20 per cent higher token throughput than its previous generation, can recover faults within ten minutes and has supported training runs lasting more than 40 days. The company says the platform exposes more than 5,000 general Model Context Protocol assets and more than 1,000 industry-specific ones. Those figures describe the tool and data connections Huawei says agents can draw on. The numbers and performance claims have not been independently validated, so they are useful for defining what to test, not for assuming an operating result.

The bundle shows where cloud competition for enterprise agents is heading. An organisation choosing an agent platform increasingly chooses its scheduling, memory, model access and tool ecosystem at the same time. Integration becomes easier because fewer pieces need to be assembled and operated separately. Switching later can become harder for exactly the same reason.

For organisations comparing agent infrastructure, the sensible judgement is to evaluate the bundle as an operating system for agent workloads, not as a menu of unrelated services. Throughput is only one part of that test. Fault recovery, the quality of the available tools, data boundaries and the effort required to move an application elsewhere will shape the real cost. Huawei has now put dates against its international offer. Independent performance, pricing and production adoption remain open questions.

India Adds Chip Packaging Capacity

The semiconductor supply chain is also getting broader, although these new lines sit at the back end rather than the leading edge.

India inaugurated commercial production at two more semiconductor operations on 17 September. CDIL Semiconductor’s Mohali operation covers assembly, testing, marking and packaging for discrete devices. Suchi Semicon’s facility in Gujarat is an outsourced semiconductor assembly and test operation, usually shortened to OSAT. The government also outlined an expanded Semicon 2.0 programme.

The openings bring the reported number of Indian semiconductor projects in commercial production to five. That is tangible manufacturing capacity, and chip customers gain more options for packaging and testing within India. It is important, though, to be precise about what opened. These are back-end and discrete-device operations. They are not new leading-edge wafer fabrication plants.

Packaging and test are the stages that turn fabricated silicon into a finished, checked component that a customer can use. They are essential parts of the supply chain, and building them can develop operating experience, supplier relationships and a manufacturing workforce. They don’t remove reliance on overseas advanced fabrication, where the most technically demanding wafers are produced. The announcements also didn’t disclose production volumes, customer allocations or ramp schedules, so the near-term scale is unclear.

My reading is that India’s semiconductor strategy is producing visible capacity first in packaging, test and discrete devices. That gives buyers an additional sourcing option and gives the industry a base it can expand from. The tougher measure comes later: whether front-end fabrication follows at commercial scale and whether these facilities ramp to meaningful volumes. For now, this is a real addition to the supply chain, with a narrower effect than the phrase semiconductor production can sometimes imply.

Spyware Moves to Personal Devices

There is a much more personal security story in the briefing, and the delivery method is deliberately patient.

The UK National Cyber Security Centre, the US Federal Bureau of Investigation and the Netherlands’ intelligence service published technical details and indicators on 15 September for a malware campaign called CHOSEN BRICK. The agencies say it has targeted dissidents, activists and journalists internationally since at least 2025. The malware has only been observed on Windows.

The operators don’t rely on a single generic attachment sent at scale. They build rapport through messaging services including WhatsApp and Telegram, then disguise malicious payloads as familiar applications or documents. Telegram is also used for command and control after infection. That combination of social trust and technical disguise makes the approach harder to solve with an email filter alone.

Observed capabilities include capturing the screen and microphone, stealing email and browser messaging data, delivering additional payloads, and wiping files or the system. The advisory doesn’t quantify the number of victims. It also warns that filenames and installation paths can change, which means defenders cannot treat one static list of names as a complete detection strategy.

The organisational consequence is easy to miss because the lure may arrive away from work. The operators deliberately shift towards personal devices when delivery to protected corporate equipment fails. An employer may have strong controls on a managed laptop while an exposed staff member continues the same sensitive conversations on a personal Windows machine with less monitoring and support.

For organisations employing journalists, activists or other people at elevated risk, personal digital safety belongs inside the security model. The agencies’ published indicators give defenders material to hunt now, but the response also needs support that reaches the devices and messaging habits attackers are choosing. My assessment is that this campaign exposes a boundary problem as much as a malware problem: an attacker will work around the corporate perimeter if the person’s role makes their private communications valuable. Security teams protecting exposed staff need a plan for that reality, rather than assuming the managed device is the whole attack surface.

What Changes for You

Two releases now have a practical effect at a developer’s desk, though each arrives with a boundary that is easy to overlook.

Qwen released the weights for Qwen-Image-2.1 on 20 September. Its visual generation component has seven billion parameters, making it comparatively compact for a system that combines text-to-image generation and editing. Researchers and non-commercial builders can generate and edit transparent RGBA images, extract a subject from a photograph and provide up to ten reference images. Local edits can be marked with circles, painted annotations or separate masks, which gives a builder more direct control over the part of an image that changes.

The limitation is the licence. Qwen describes the release as open source, but the supplied research licence permits research and evaluation only. Commercial use needs a separate licence. The published quality and efficiency comparisons also come from Qwen and have not been independently validated. Weight access makes local experimentation possible; it does not give a product team unrestricted permission to ship.

GitHub’s change is available to administrators now. Actions workflow-execution protections became generally available on 17 September, with policies that can restrict triggering actors and events at enterprise, organisation, repository or individual-workflow level. The release also adds workflow-file targeting, policy insights and REST APIs, so organisations can manage those protections as code instead of relying on a manual setting in each repository.

The time-sensitive part concerns the pull request target event in affected public repositories. That event can be risky when a workflow handles untrusted pull-request content while holding access to repository privileges or secrets. GitHub is introducing a default rule that disables it where no applicable event policy exists. The rule starts in evaluation mode and is scheduled for enforcement on 2 November 2026. Private and internal repositories are excluded.

Public-repository maintainers can inspect the evaluation results before enforcement and decide whether a workflow needs redesign or an explicit, reviewed policy. That makes secure behaviour easier to enforce centrally, but existing workflows may stop unexpectedly if nobody checks how they depend on the event. The useful window is the one before 2 November: enough time to replace an unsafe trigger or document the narrow exception a repository genuinely needs.

You'll find the sources and full transcript at owenonthenet.com. Thanks for listening.

Sources

Reporting behind this episode.

  1. blogs.nvidia.com/blog/ai-energy-management-alliance
  2. axios.com/2026/09/16/tech-giants-launch-flexible-power-coalition-data-centers
  3. qwen.ai/blog
  4. github.com/QwenLM/Qwen-Image-2.1/blob/main/LICENSE
  5. salesforce.com/news/press-releases/2026/09/15/koa-reasoning-model
  6. arxiv.org/abs/2609.15066
  7. digital-strategy.ec.europa.eu/en/news/commission-welcomes-design-first-important-project-common-european-interest-ai
  8. github.blog/changelog/2026-09-17-workflow-execution-protections-in-github-actions-generally-available
  9. huawei.com/en/news/2026/9/hc-agentic-infra-industry-ai
  10. pib.gov.in/PressReleasePage.aspx
  11. newindianexpress.com/india/2026/Sep/17/pm-modi-pitches-india-as-trusted-semiconductor-manufacturing-destination
  12. ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists