The Sequencing Has Inverted: FERC, Computational Load, and What Comes Next
FERC is expected to act on Docket No. RD26-7-000 before NERC finishes drafting the standard. That inversion has direct consequences for registered entities, large load operators, and AI governance functions that have not yet connected their work to grid reliability obligations.
Disclaimer: This article intentionally analyzes the likely regulatory trajectory before FERC acts. If the Commission's final order materially differs from the sunshine notice, I will update my analysis accordingly.
The sequencing has inverted
On July 16, FERC is expected to act on Docket No. RD26-7-000, "Reliability Standard(s) Pertaining to Computational Load Integration." The item sits on the sunshine notice as a sua sponte action, meaning the Commission is initiating the proceeding on its own motion rather than responding to a NERC filing.
Consider what that implies. NERC has not filed a standard. Project 2026-02 targets an initial Reliability Standard by the end of 2026, with broader work beginning in 2027. FERC appears prepared to set scope and schedule before the drafting team finishes.
The story of the last six months was NERC pacing itself through a redesigned standards process. The story of the next six months is a federal regulator setting that pace from above.
This matters for anyone tracking the security implications, because a FERC directive defines the outer boundary of what the resulting standards may address. NERC's own project scope is a floor. FERC's directive establishes the ceiling.
What was true in May, and what has changed
Patrick Miller's May 2026 article notes that computational loads are not subject to CIP today, and that the interconnection agreement is therefore the only durable instrument through which a connecting utility can extend CIP-equivalent practice to a large load facility. That reading was correct, and the Reliability Guideline's security chapter supports it.
The unstated premise of that argument deserves examination. Treating the interconnection agreement as the vehicle is a workaround for a jurisdictional gap. Workarounds persist only while the gap does.
NERC is currently drafting Rules of Procedure revisions that would create a Computational Load Entity as a registered functional entity type. Registration is the mechanism by which the reliability framework has always expanded.
Once an organization appears on the compliance registry, the standards that apply to it are determined by the applicability sections of those standards, not by the intent of the project that created the registration.
The more important question is no longer whether CIP reaches computational loads. It is what replaces today's contractual workaround if registration eliminates the jurisdictional gap.
The Essential Actions describe an interface, not just a model
Read the May 4 Level 3 Alert as a security practitioner rather than a planner, and a different document emerges. The seven Essential Actions do not merely ask transmission planners to model data centers better. They describe the construction of an operational interface between the bulk power system and facilities that are not currently registered entities.
Essential Action 1 directs planners to collect uninterruptible power supply settings and configurations, the parameters of protection and control devices that can isolate the load or reduce facility demand, reconnecting voltage and timing, and information on on-site generation including battery energy storage operated in parallel with the BPS.
Essential Action 4 directs Transmission Owners to establish a commissioning process that functionally tests SCADA points, functionally tests remedial action schemes where behind-the-meter generation is not permitted to export, and verifies after energization that all parties hold consistent SCADA data and one-lines identifying the responsibilities of the TO and the computational load.
Essential Action 6 directs Transmission Owners to install and use dynamic fault recording devices at computational load facilities, or to obtain access to existing ones, and to supply that data to planners, Reliability Coordinators, Regional Entities, and the ERO.
Essential Action 7 directs Transmission Operators, Reliability Coordinators, and Balancing Authorities to establish Interpersonal Communication capabilities with computational loads and to issue instructions or orders through voice, SCADA, or other platforms to prevent BES Emergencies.
Taken together, those four actions specify a real-time directive communication path, bidirectional telemetry, remedial action scheme participation, and shared protection and control data between a registered entity and an unregistered one. That asymmetry is the security problem, and it exists today, before any standard is written.
The CIP-002 question
CIP-002 categorizes BES Cyber Systems by the impact their misoperation would have on the reliable operation of the bulk power system within fifteen minutes. Applied to the equipment described in the Level 3 Alert, the traditional CIP-002 categorization becomes much harder to reconcile.
A computational load facility contains UPS control logic with configurable ride-through settings, protection relays capable of disconnecting the facility in cycles, load-shed automation, and on-site generation and storage operated in parallel with the grid. Following commissioning, it also carries SCADA points and, in some cases, remedial action scheme participation.
NERC is asking planners to model that equipment specifically because its behavior is consequential to grid stability on timescales far shorter than fifteen minutes. Documented events show aggregate computational load reductions on the order of a thousand megawatts in seconds.
Three scenarios are available.
Scenario one: narrow applicability. NERC registers Computational Load Entities with an applicability limited to modeling data submission, commissioning, and operational coordination. CIP is expressly excluded. This is the most likely near-term outcome and the least durable one.
Scenario two: applicability by function. Facilities with parallel-operated generation or storage, RAS participation, or direct real-time interfaces with a Transmission Operator pick up narrow obligations. This tracks how NERC has historically handled hybrid facilities, and it is where the genuinely contested cases will live.
Scenario three: convergence. If computational load flexibility becomes a resource that operators rely on to maintain frequency stability, the control systems delivering that flexibility become reliability-relevant cyber assets from a reliability perspective. NERC's own CIP Roadmap points toward a framework that follows operational reality rather than legacy asset categories.
The 2027 phase of Project 2026-02 is where this gets decided, and FERC's July directive will shape what that phase is permitted to consider.
Workload becomes a regulated attribute
Here is the development that should reach every AI governance function, and that has not.
Essential Action 1 requires collection of facility use information, specifically whether the facility performs traditional compute and storage, AI training, inference, or cryptocurrency mining, including percentages where a facility supports multiple use cases, with separate model information potentially required for each end-use.
Essential Action 3 directs Planning Coordinators to revise their definition of "qualified change," the trigger for re-studying local protection and stability limits, to include repurposing of computational load for a significantly different application. The Alert's own example is converting a data warehouse or crypto mining facility into an AI training facility.
Read that plainly. A decision to retask compute capacity from inference to training becomes an event that triggers a transmission planning study. Workload composition becomes a modeling input. Workload change becomes a regulated change.
No enterprise AI governance framework in current use contemplates this. NIST's AI Risk Management Framework, model risk management practice, and the compliance architectures built around them all treat the physical substrate as an infrastructure concern several layers below the governance boundary.
Where a model trains, on what schedule, and at what ramp rate has been a capacity planning question. It is becoming a question with an external regulator attached, and the regulator has statutory authority over reliable operation of the grid.
The practical consequences follow quickly. Grid operators will hold authority to issue instructions to computational load entities to prevent BES Emergencies, and NERC's prior Level 2 Alert recommended that those entities comply.
A training run is therefore interruptible by an entity that is not a party to any commercial agreement with the model owner. Capacity commitments, service level agreements, and training continuity plans written without that assumption are incomplete.
Organizations that treat AI infrastructure governance and grid compliance as separate disciplines will discover they are becoming one discipline. AI governance and grid governance are beginning to regulate the same operational reality from opposite directions.
The adversary's view
One further consequence deserves stating plainly. The Essential Actions are building a control and communication interface into facilities capable of removing a gigawatt of load from the system in seconds. The security question is not only whether that load behaves correctly. It is who else can make it behave.
A data center control plane that can shed load at scale, on command, on second timescales, has the same reliability significance as a large generator's controls.
The systems that govern it, the building management systems, the UPS controllers, the workload orchestration layer, and the emerging grid communication path, were not designed against a threat model in which grid frequency is the target. They were designed against a threat model in which customer data and service availability are the targets.
Those are different problems, and the security architecture that solves one does not automatically solve the other.
That gap is the strongest argument for bringing computational load control systems inside a CIP-equivalent regime rather than leaving them to contract. Contracts allocate liability after an event. Standards impose controls before one.
The next ninety days, and the bottom line
Registered entities: file the Level 3 Alert response. Failure to acknowledge and report is a Rules of Procedure Rule 810 obligation independent of the Alert's non-penalty framing, and the Alert is explicit that it does not excuse any failure that separately violates an approved Reliability Standard.
The Alert cross-references FAC-001-4, FAC-002-4, TPL-001, PRC-002, and PRC-028. Responses are due August 3. NERC aggregates them and provides an anonymized report to FERC under Rule 810, and those responses will inform the standards that follow. The filing is the evidentiary record for a rulemaking FERC is scoping in parallel.
Note the scope. The Alert reaches entities that have no computational load in their territory today, if they could feasibly receive an interconnection request within two years.
Large load operators and hyperscalers: engage Project 2026-02 while registry criteria are still being drafted. The criteria define the population, the population defines the applicability fight, and organizations that wait until a standard is balloted will be negotiating their obligations after the boundary has been drawn around them.
Security and AI governance leadership: treat these as one file. The operational interface being built into computational load facilities is a security interface, and the workload decisions your AI governance function makes are becoming reliability-regulated events. Neither organization currently owns the other half of the problem.
The reliability framework has always expanded through registration. FERC's July action may represent the point at which a federal regulator begins the process that could ultimately create a new registered entity class covering the fastest-growing category of electrical load in North America.
The modeling requirements are the visible part of this proceeding. The registry criteria, and the security obligations that follow registration, are the consequential part.
Originally published on LinkedIn Pulse on July 15, 2026.