Site selection for compute-intensive projects has run on one map: power, land, water, fiber, permitting and incentives. That map now governs only the building. Rules attaching to developers, deployments, customers and procurement form a second map that moves independently of the first. A third map, governing where a project can be certified and sold, is forming beneath both. The binding constraint is whichever of four conditions (build, operate, certify, sell) cannot be satisfied, and conventional scorecards have no row for it.
Information cutoff September 27, 2026. This landscape has produced material corrections inside single days. Verify anything time-sensitive before relying on it.
Two years ago, a compute-intensive project was evaluated on one map. Power. Land. Interconnection queue position. Water. Fiber. Permitting posture. Labor. Incentives. I have sat in that room many times, in many jurisdictions, and the analysis was hard but bounded. Every variable on the scorecard described a place, and the place was where the building went.
The object being sited is no longer just the facility. It is the commercial compute project around it: physical infrastructure, plus the developer relationship, the deployment environment, the customer pathway, and the assurance pathway that makes the whole thing sellable. Those things do not sit in the same place, and they are no longer governed by the same map.
A second map has separated from the first. A third is now forming underneath both. Its components are being mapped carefully by others. The siting implications are not.
Some of this the market has already absorbed. Counsel now routinely advise that regulatory climate belongs in site selection and that contingency locations are mandatory, because moratoria and cost-allocation fights have made permitting posture a live variable.
All of that is real, but it is still primarily a facility-level analysis.
The argument here concerns rules that attach to something else: actors, activities, transactions, deployments, customers and procurement relationships. Those rules can bind a project whose building has cleared every test in the jurisdiction where it stands.
Sorted by attachment point rather than by statute, the patchwork resolves into four points, and only one of them is the building.
1. Developer nexus. California's Transparency in Frontier Artificial Intelligence Act, operative since January 1, 2026, regulates frontier developers directly through published frameworks, transparency disclosures and catastrophic-risk reporting. [1]
2. Deployment and use location. Texas's Responsible Artificial Intelligence Governance Act took effect the same day, structured principally around entities deploying artificial intelligence. Colorado's successor statute reaches automated decision-making in consequential decisions from January 1, 2027. [2]
3. Customer location. Where the purchasing entity sits, and which legal, contractual or procurement requirements may attach to the transaction as a result.
4. Procurement jurisdiction. Whose purchasing standards the sale of the compute or the AI service must satisfy.
The third and fourth are worth separating, because a customer can be headquartered in one state, operate the system through a national platform, have the consequential decision occur in a third place, and buy under the procurement rules of a fourth.
That is not a complication in the argument. It is the argument.
An AI model trained in one state, deployed into a consequential decision in a second, sold to a government buyer in a third, hosted on compute in a fourth: four regulatory regimes, one power grid. The jurisdiction that governs the activity is often not the jurisdiction that governs the building, and the site selection scorecard has no row for the difference.
Federal policy has begun to describe the same split. The White House framework of March 2026 would preserve state authority over zoning, including the placement of AI infrastructure, while precluding states from regulating AI development, which it characterizes as inherently interstate. [3] Read this as a siting document rather than a policy document: it would assign the building and the activity to different sovereigns.
The thresholds determining who sits inside these regimes are policy choices, not physical measurements, and the drafters have not hidden it.
California defines a frontier model using a threshold above 10 to the 26th power computational operations, counted cumulatively across initial training and subsequent modification, with the heavier obligations attaching at a second test: 500 million dollars in prior-year revenue, counted across the developer and its affiliates. [1]
The European Union AI Act uses a presumption of high-impact capability above 10 to the 25th power floating-point operations, one order of magnitude below. [4]
The two are different statutory constructs, not two measurements of the same thing. But both use compute as a proxy for frontier capability, both draw the line somewhere, and each places the authority to move it in a different institution. The line is policy, not physics.
The two California tests also behave differently over time. If training costs fall while the statutory compute threshold stays fixed, more developers cross it without any change in the law. The revenue test does not move that way, because it is tied to company economics rather than to the cost of a training run. The test that looks like the technical safeguard is the one exposed to erosion; the financial one may end up doing the scope-limiting.
Both regimes contain mechanisms for revisiting their thresholds, and they sit in different places. California separates the body that measures from the body that may revise: the Department of Technology assesses and recommends, and the Legislature amends. [1]
The European Union requires the Commission to amend thresholds by delegated act as technology evolves. [4] How quickly those mechanisms can move the line is an institutional question, and for a project with a fifteen-year capital recovery period that is a planning input rather than a footnote.
Most people watching this space are watching legislatures and bill trackers. I think the near-term constraint is more likely to arrive somewhere else.
On March 30, 2026, California signed Executive Order N-5-26, directing the Department of General Services and the Department of Technology to develop artificial intelligence vendor certification standards within 120 days. It applies to vendors nationwide that seek California state agency business, and is forward-looking rather than applied to existing contracts. [5] The order does not itself create a certification regime. It creates a procurement pathway through which certification standards could become contract requirements.
The sequence is worth noting. Ten days earlier, the White House recommended that Congress broadly preempt state artificial intelligence law while preserving specified state authorities, among them state government procurement and use. [3] California then exercised its purchasing power rather than enacting a generally applicable mandate. Counsel reading the order have suggested that this insulates the requirements from a preemption challenge. Whether it does has not been litigated.
A regulatory gate reaches every developer inside a jurisdiction. A market gate reaches only those who want a particular buyer, which is a smaller and self-selecting set. It is the narrower instrument, and it can move through a contracting process without waiting for a generally applicable rule. It is also close to invisible, because it appears as a contract clause rather than as a rule.
That layer is already active commercially. Large enterprise and defense-adjacent buyers have begun conditioning frontier-model use on data handling: one pressing for irrevocable zero-data-retention guarantees before carrying a model inside its own software, another confining a vendor's models to less sensitive internal work, a third barring staff from using a commercial model on projects touching proprietary code. [6]
The supply side has answered in the product - the most capable model released in September ships with zero data retention for eligible API customers. [7] Buyer requirement and product feature are the same mechanism from opposite sides.
And the market gate has now been tested in court, with opposite results under different statutes.
On August 27, 2026, a federal district court in California vacated one supply-chain designation against Anthropic, finding First Amendment retaliation and inadequate process, while expressly recognizing that the government remains free to choose its AI vendor.
On September 25, the D.C. Circuit, ruling 2-1 on a parallel designation under a different statute, upheld the exclusion. The majority held that the vendor's built-in usage restrictions, together with an unresolved dispute over contract terms, gave the Department of War (DoW) ample support to find a supply-chain risk; the dissent read the statute as reaching only covert, intentionally subversive conduct.
Neither ruling disturbed the other, and further review is likely. [8] Neither court held procurement restrictions unlawful as such. What they contested was the mechanism used to exclude one vendor.
That distinction is the one that matters for project siting. A procurement gate does not have to look like a regulation to change an addressable market. It can arrive as a vendor-eligibility condition, a contract clause, or a supply-chain designation - and it can become consequential enough to reach federal court.
A third version of the same layer is operated by the seller.
On September 1, 2026, a frontier model developer determined that its new model met a Critical cybersecurity capability threshold under its own published framework, the first so designated, and that safeguards were sufficient for release.
The model shipped two days later with the public version refusing advanced offensive tasks, enterprise access off by default, and the restricted capabilities routed to a vetted-access program. [7] The consequence of crossing the threshold was differentiated access and safeguards, not a prohibition on release - a provider-controlled governance decision doing some of the work that, elsewhere, a regulatory or procurement requirement might do.
If your project's economics depend on a particular buyer, that buyer's standards are a siting input. They can change without any legislature acting.
The third geography now asks where a project can actually obtain what it needs in order to be certified and sold. Qualified evaluators. Accredited testing capacity. Evaluation environments secure enough to hold frontier weights. Government access arrangements. Certification. Procurement eligibility. Insurance, which remains unresolved in its own right.
I want to be careful here, because this is not virgin ground. The literature on assurance is already substantial and growing. Policy researchers have mapped the ecosystem (its components, providers and gaps) and recommend that governments align procurement, funding and data-access frameworks to support it. [9]
That work is written for policymakers and compliance buyers. It is not written for anyone choosing a site.
So separate the three things that are easy to blur.
1. What demonstrably exists: an assurance ecosystem with identifiable providers, standards and gaps, already documented.
2. What is developing: capacity constraints in that ecosystem, including a shortage of qualified safety and validation expertise and conformity-assessment infrastructure still under construction.
3. What I am putting forward as a hypothesis: some of these inputs may not distribute evenly, and a few may behave less like purchasable services than like geographic constraints. Evaluation expertise appears to concentrate in a small pool of organizations and specialists. Secure evaluation environments have the characteristics of capital projects, with their own power, security and permitting requirements. Government access arrangements are jurisdiction-specific, negotiated with public authorities rather than purchased as fungible services.
The test is straightforward: watch whether these inputs begin appearing as location-dependent rather than as services purchasable from anywhere.
The question has been: where can you build and operate. It becomes: where can you build, operate, certify, and sell into the customers that matter.
Those four conditions do not have to be satisfiable in the same place. The constraint binds wherever one of them cannot be satisfied, even if the other three can.
Simply: A project can clear every test on the physical scorecard, secure power at a good price, win its incentives, and still be unable to sell into the customer that justified the model. That is a failure mode conventional scorecards can miss, and the people who build them have not yet had reason to add it.
The nuclear comparison gets made constantly in this sector, and the version that circulates is narrower than the evidence.
After 1979, the United States did not ban nuclear power. It applied new safety requirements to plants already under construction, and the cost record separates along that line. The most cited study of global construction costs also reports substantially milder escalation in France, Japan and South Korea over comparable periods, and concludes that cost trends depend on regional, historical and institutional factors; its methodology has been contested in the same journal. [10]
Taken at its most defensible, the finding is that countries deploying similar technology over overlapping periods built different institutional architectures and got very different cost curves. Three Mile Island mattered enormously to the United States regulatory trajectory. It did not, by itself, determine the international cost history of nuclear power.
What transfers is narrower than "regulation raises costs": changing requirements after engineering decisions are made creates a second-order cost, and whether it compounds or stabilizes depends on how predictable the review regime is.
Here the predictability problem takes a different form. Executive Order 14409, signed June 2, 2026, directs Treasury, DoW through the Director of the National Security Agency, and Homeland Security through the Director of the Cybersecurity and Infrastructure Security Agency to develop a classified benchmarking process determining the threshold at which a model is designated a covered frontier model, and to design a voluntary framework for developer engagement. The order disclaims any mandatory licensing, preclearance or permitting requirement, and does not define the covered-model category it creates. The framework was completed in early August; it has not been published, the threshold is classified, and the operating rules are available only to participants. [11]
The issue is not simply whether requirements may change after engineering decisions are made. It is whether a developer can know the threshold and review conditions at all before committing to a long capital cycle.
The signal I would watch first is interconnection commitments and withdrawals. Queue withdrawals and deferrals may surface before a slowdown appears in capital-expenditure guidance, because a project can be deferred quietly long before a company changes its public outlook. That is a hypothesis, but it is cheap to monitor.
Two adjustments follow for anyone holding a live project.
1. Stress-test any project whose capital recovery period extends materially beyond the current model cycle.
2. Add the customer's jurisdiction to the site analysis, not only your own.
For an economic development organization, the version of that is harder and more useful. Ask a prospect where its critical customers sit before you build the package, and know that the answer is now a legitimate part of the conversation. Your standard incentive and infrastructure offer addresses one of the maps.
If a prospect walks away, the reason may sit on a map it does not reach.
SelectGlobal LLC works with allied-nation manufacturers and the economic development organizations that serve them. If you are preparing your community for the next industrial cycle, we would like to talk. www.selectglobal.net
[1] California Transparency in Frontier Artificial Intelligence Act (SB 53), signed September 29, 2025, effective January 1, 2026. Frontier model defined at a compute threshold greater than 10 to the 26th power integer or floating-point operations, including computing for the original training run and any subsequent fine-tuning, reinforcement learning or other material modification. Large frontier developer defined as a frontier developer that, together with its affiliates, collectively had annual gross revenues in excess of 500 million dollars in the preceding calendar year. The Act requires the California Department of Technology to assess developments annually and recommend updates to the definitions of frontier model, frontier developer and large frontier developer to the Legislature. The compute figure matches the threshold in the rescinded Executive Order 14110.
[2] Texas Responsible Artificial Intelligence Governance Act, enacted June 22, 2025, effective January 1, 2026. Colorado SB 24-205 (2024), delayed by SB 25B-004 from February 1 to June 30, 2026; enforcement stayed by federal court order April 27, 2026 following suit by xAI, in which the Department of Justice intervened; repealed and reenacted by SB 26-189, passed May 9, signed May 14, 2026, effective January 1, 2027, replacing the algorithmic-discrimination framework with a narrower disclosure and human-review regime for automated decision-making technology in consequential decisions. Colorado Attorney General rulemaking was in a pre-rulemaking phase as of mid-2026; the successor statute is itself subject to legal challenge.
[3] The White House, A National Policy Framework for Artificial Intelligence: Legislative Recommendations, March 20, 2026. Non-binding. Recommends congressional preemption of state artificial intelligence laws deemed unduly burdensome while preserving state police powers for laws of general applicability, including zoning and the placement of AI infrastructure, consumer protection, and state AI use and procurement; and recommends precluding states from regulating AI development as an inherently interstate activity.
[4] Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 51(2)-(3). Article 51(2) establishes a presumption of high-impact capabilities when cumulative training computation exceeds 10 to the 25th power floating-point operations. Article 51(3) requires the European Commission to adopt delegated acts amending the thresholds and supplementing benchmarks and indicators as technology evolves, including through algorithmic improvements and increased hardware efficiency. The delegated-acts procedure is set out at Article 97.
[5] Cal. Exec. Order No. N-5-26, "Trusted AI Procurement" (Mar. 30, 2026). Directs the Department of General Services and the Department of Technology to submit recommendations within 120 days for artificial intelligence vendor certification standards that may be incorporated into state contracting processes. Applies to vendors nationwide seeking California state agency business; forward-looking only, not applied to existing contracts.
[6] The Information, September 14, 2026, reported by Reuters the same day. Palantir, Nvidia and Booz Allen Hamilton restricting or conditioning use of frontier models over data-retention and intellectual-property exposure: Palantir pressing for irrevocable zero-data-retention guarantees before making a model available through its software; Nvidia confining the vendor's models to less sensitive internal tasks; Booz Allen barring staff from using the commercial model on cybersecurity work involving proprietary software. Traced to a June 2026 policy change introducing 30-day retention of usage logs. Both named model providers state that they do not train on customer data by default.
[7] OpenAI, "Path to Astra: critical capabilities and frontier safeguards," September 1, 2026, stating that Astra meets the Critical cybersecurity capability threshold under the company's Preparedness Framework, that it is the first model designated at that level, that parts of its development and release were delayed while protections were strengthened, and that safeguards sufficiently minimize the risk of severe harm for release. OpenAI, "GPT-6 Astra," September 3, 2026, and GPT-6 Astra System Card, Deployment Safety Hub. Reporting on the launch records that the public version refuses advanced offensive tasks such as generating proof-of-concept exploits, with those restrictions to be loosened for vetted defenders through a program called OpenAI Daybreak; that enterprise administrators must manually enable the model, access being off by default; and that Astra supports Zero Data Retention for eligible API customers. Benchmark and safeguard-efficacy figures in the company's launch materials are self-reports and are not relied on here.
[8] Anthropic PBC v. U.S. Department of War, No. 3:26-cv-01996-RFL (N.D. Cal.), Hon. Rita F. Lin. Order on cross-motions for summary judgment and Order of Final Relief and Judgment entered August 27, 2026. The court granted summary judgment to the plaintiff on First Amendment retaliation, Fifth Amendment due process and Administrative Procedure Act challenges to the designation under 10 U.S.C. 3252 and the related directives, and on claims under 5 U.S.C. 558(b), vacating that designation. The court recognized that the Department of War remains free to choose its AI vendor. The government's earlier appeal of the preliminary injunction, Ninth Circuit No. 26-2011, was held in abeyance pending the D.C. Circuit proceedings; the time to appeal the final judgment runs into late October 2026. Anthropic PBC v. U.S. Department of War, No. 26-1049 (D.C. Cir. Sept. 25, 2026), on petition for review of the exclusion under the Federal Acquisition Supply Chain Security Act of 2018, 41 U.S.C. 4713. Katsas, J., joined by Rao, J., denied the petitions, holding that the Department had ample support for finding a statutorily covered supply-chain risk and rejecting the due-process and First Amendment claims; Henderson, J., dissented on the scope of the statutory definition of supply-chain risk. Rehearing en banc and certiorari remain available.
[9] Partnership on AI, "Strengthening the AI Assurance Ecosystem," Part 1, February 18, 2026, mapping the assurance ecosystem and recommending that governments review procurement, funding and data-access frameworks to support it. Capacity-constraint characterizations in the body are general and are not sourced to quoted market figures.
[10] Lovering, J.R., Yip, A., and Nordhaus, T. "Historical construction costs of global nuclear power reactors." Energy Policy 91 (2016): 371-382, examining construction cost histories across seven countries and finding substantial variation in cost trends attributable to regional, historical and institutional factors. The study's methodology has been contested: see Koomey, J., Hultman, N.E., and Grubler, A., "A reply to 'Historical construction costs of global nuclear power reactors,'" Energy Policy 102 (2017): 640-643, objecting to the reliance on overnight costs and to the treatment of certain country data including the French series; Gilbert, A., Sovacool, B.K., Johnstone, P., and Stirling, A., "Cost overruns and financial risk in the construction of nuclear power reactors: A critical appraisal," Energy Policy (2017); and the authors' reply, Lovering, Nordhaus and Yip, "Apples and oranges: Comparing nuclear construction costs across nations, time periods, and technologies," Energy Policy 102 (2017): 650-654. No cost figure or multiple from this literature is carried into the argument here.
[11] Executive Order 14409 of June 2, 2026, "Promoting Advanced Artificial Intelligence Innovation and Security," 91 FR 34565-34567, published June 5, 2026, FR Doc. 2026-11415. Section 3 directs the Secretary of the Treasury, the Secretary of War through the Director of the National Security Agency, and the Secretary of Homeland Security through the Director of CISA, in consultation with the White House Chief of Staff through the National Cyber Director, the Assistant to the President for Science and Technology, and the Secretary of Commerce through the Director of NIST, within 60 days to develop and maintain a classified benchmarking process determining the covered-frontier-model threshold, and to design a voluntary framework through which developers may engage the government on designation and provide access to covered frontier models for up to 30 days before releasing them to other trusted partners. Section 3(c) provides that nothing in the section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance or permitting requirement. Congressional Research Service analysis notes that the order does not define covered frontier model. The Section 3 deliverable was due by August 1, 2026 and was reported as finalized in early August; the administration does not plan to publish it, and the benchmark criteria and operating rules remain non-public.
Michael T. Edgar is the Founder and CEO of SelectGlobal LLC. SelectGlobal is a jurisdictional intelligence firm that maps how policy mechanics, procurement authorities, appropriations cycles, and geographic realities converge to create time-bounded windows of validated federal demand, and connects allied-nation manufacturers to those windows before capital is committed. Edgar is a licensed architect (NCARB certified), a former member of the U.S. Investment Advisory Council, and a current board director of the International Trade Association of Greater Chicago. His analytical work on institutional transition, reindustrialization geography, and allied-nation market entry draws on 30 years of advisory and project delivery across architecture, real estate development, and international economic development. www.selectglobal.net