Moms Across America

The Federal Data Center Regulations Are Expiring On September 30–WHAT HAPPENS NEXT?

Sara Villani·

On September 30, America’s main law governing federal data centers is set to expire, with no clear replacement or extension in sight. The timing is difficult to ignore, as the United States is being pushed, largely by executive order, through what may be its largest infrastructure buildout since the construction of the railroad system.

We are all witnessing, in real time, trillions of dollars being poured into thousands of massive data center campuses, along with the power plants, pipelines, and transmission systems needed to sustain them. Even as public opposition grows, these projects continue to advance at warp speed–while concerns about human health, water use and quality, noise and air pollution, livestock, wildlife, plant life, extreme heat, and land use, rising energy costs, and tax breaks appear to be falling on deaf ears.

And now, the existing standards for federal data centers are being allowed to expire, while the private facilities driving the buildout have still not been made subject to comparable standards at all.

Surely this is all just an innocent mistake, and not a coordinated play to make private data center expansion a federal imperative while ensuring the industry remains free from comprehensive regulatory oversight...

What we do know for sure is this: In the precise moment when federal oversight should be expanding, Washington is instead preparing to allow one of the country’s only data center safeguards to vanish.

What the Act Actually Does

The Federal Data Center Enhancement Act of 2023 (FDCEA) was enacted through the FY2024 National Defense Authorization Act. It built upon more than a decade of federal consolidation efforts, including the Federal Data Center Optimization Initiative, which collectively closed more than 6,000 facilities and generated an estimated $5.8 billion in savings and avoided costs. The FDCEA shifted the focus from simply closing inefficient facilities to establishing how the government’s remaining and newly acquired data centers should be secured, monitored, and operated.

The resulting minimum requirements addressed sustainable energy, uptime, backup power, physical security, and public reporting. The U.S. Office of Management and Budget’s (OMB) implementing guidance, Memorandum M-25-03, went further by requiring agencies to monitor electricity consumption, consider the cost and scarcity of energy and water, arrange professional efficiency assessments, and report their compliance.

This was never a sweeping data center regulatory framework, as it did not regulate most private hyperscale facilities or protect the communities being asked to host them. But that is an argument for expanding these laws, not allowing them to disappear. At minimum, the FDCEA established that data centers serving the federal government should not be built or operated without clear and enforceable standards, centralized oversight, and corporate accountability. Yet here we are.

What Is Disappearing

Federal cybersecurity, environmental, and procurement laws will not suddenly disappear next month. What will disappear is the only uniform, data center-specific framework requiring covered federal agencies to follow the same operating standards, evaluate energy and water consumption, and publicly report their compliance. That matters because without a common baseline and public reporting requirement, agencies can make inconsistent decisions, environmental and resource impacts become harder to track, and Congress and the public lose a clear way to hold the government accountable.

OMB’s own guidance acknowledged that the federal government’s growing use of artificial intelligence would increase demand for the high-performance computing provided by data centers. And put simply, the Trump administration is preparing to abandon this framework as its reliance on these facilities continues to grow.

A Federal Contract Does Not Make a Federal Data Center

An even deeper systemic problem is that the FDCEA never reached most of the private industry driving the current buildout. Its requirements applied to data centers operated by federal agencies and certain contractor-operated facilities acting on an agency’s behalf. Most privately owned commercial data centers remained outside its reach.

Exactly how many facilities fall on either side of that line is difficult to determine. There is no credible, up-to-date national dataset that cleanly distinguishes between “federal” and “private” data centers. Government inventories generally count federally owned or operated facilities, while industry reports track commercial data centers. Those categories can overlap when private contractors operate facilities for federal agencies. What the available figures make clear, however, is that the vast majority of U.S. data centers are privately or commercially operated.

OMB’s guidance demonstrates why that distinction matters. It states that the federal requirements generally do not apply to private data centers whose only government connection is providing commercial cloud services or products to a broad range of customers. A company can therefore hold enormous federal contracts and provide infrastructure essential to federal operations without its privately owned data centers becoming subject to federal data center standards.

Under the current patchwork of laws, the federal government can rely on private hyperscale infrastructure, accelerate its construction, and characterize it as a national security asset without requiring it to meet the standards imposed on the government’s own facilities.

That is not a coherent national policy. It is forced public reliance without corporate or government accountability.

Policy By Fait Accompli

The data center boom is not something Washington merely failed to regulate, but a coordinated playbook that involves advancing an agenda through executive action instead of comprehensive legislation and due process through the invocation of national security, suspension of ordinary safeguards, and leaving affected communities fighting to stop construction after the machinery has already arrived.

The administration has not asked whether data centers should consume this much of our resources, it assumes they will and reorganizes federal power around making sure they can.

The data center buildout has been assembled, step by step, via executive order:

  • January 2025, Executive Order 14179: Established American “global AI dominance” as federal policy and directed agencies to revise or rescind actions considered obstacles to that goal.
  • April 2025, Executive Order 14261: Cited rising electricity demand from AI data centers as justification for expanding coal production and coal-powered infrastructure.
  • July 2025, Executive Order 14318: Made rapid data center construction a federal priority, opened federal land, and authorized an initiative offering loans, guarantees, grants, and tax incentives to qualifying projects.
  • December 2025, Executive Order 14365: Established a “minimally burdensome” national AI policy and created a Justice Department task force to challenge certain state AI laws.
  • December 2025, “Winning the 6G Race” memorandum: Directed agencies to identify federally used spectrum for possible reallocation to commercial 6G development.
  • June 2026, DOJ motion in NAACP v. xAI: In what Harvard Law identified as the first action of its kind, the Justice Department asked to intervene in and dismiss a Clean Air Act citizen suit over xAI’s data-center turbines, despite bringing no enforcement action of its own. DOJ argued that allowing the case to proceed would conflict with federal AI policy and national-security interests.
  • June 2026, Townsite Data Center approval: Authorized construction on 88.5 acres of public land near Boulder City, Nevada, explicitly citing Executive Order 14318.
  • August 2026, Executive Order 14420: Declared a national emergency over foreign-made bulk power equipment, citing growing electricity demand from data centers and AI, and authorized the Department of Energy to restrict or replace equipment deemed a security risk.

Congress Has Proposals. It Has Not Acted.

Proposed legislation shows that Congress is not devoid of solutions. The Artificial Intelligence Data Center Moratorium Act, introduced by Representative Alexandria Ocasio-Cortez with a Senate companion led by Senator Bernie Sanders, would pause new and expanded AI data centers until Congress establishes national safeguards. The bipartisan GRID Act would protect customers from data center-related electricity costs, give consumers priority on the grid, and require greater disclosure of data center electricity use. Representative Ro Khanna’s Data Center Bill of Rights calls for transparency, public impact reports, local authority, water-use disclosure, and protections against unfair tax subsidies, although it remains a nonbinding resolution.

Other proposals would fill additional gaps. Senator Dick Durbin’s Data Center Water and Energy Transparency Act would require operators to report their energy and water consumption. The AI Environmental Impacts Act would establish standardized measurements and public reporting for environmental and energy impacts. The AI Data Center Site Selection Transparency Act would require advance public notice, independent impact disclosures, and limits on nondisclosure agreements with public entities.

Congress does not have to begin from a blank canvas. These proposals outline the possible foundation for a national framework: pause construction where necessary, measure resource use, disclose impacts, protect ratepayers, and preserve local control. At minimum, it can extend the FDCEA before September 30 while developing broader protections that reach the private facilities benefiting from federal contracts, land, financing, tax incentives, and expedited permitting.

None of these proposals have become law yet, but the tools do exist. What remains missing is the political will to use them.

What Needs to Happen NOW

Congress must act before September 30, but that will not happen without public pressure. Here is what we need you to do:

  • Contact your elected officials. Call or write your U.S. Representative and Senators. Ask that they extend the FDCEA until Congress passes clear, enforceable standards covering both federal AND private data centers.
  • Demand meaningful safeguards. Any comprehensive law must protect our resources, communities, and environment through public disclosure, independent impact reviews, pollution and noise protections, decommissioning guarantees, ratepayer protections, and meaningful community consent.
  • Keep advocating locally. Until national protections exist, communities must continue pursuing moratoriums, bans, and enforceable local standards. Do not wait for Washington to act.
  • Use and share our resources. Visit Moms Across America’s Data Center Action page for research, weekly AI and data center news updates, community resources, proposed legislation, legal developments, and tools you can bring to your neighbors and elected officials.
  • Join the Data Center Action Team. We are actively seeking volunteers to research, organize, track legislation, connect with affected communities, and bring this work into more towns and states. Please email info@momsacrossamerica.org to get involved.
  • Support this work. Donate to Moms Across America to help us continue investigating these issues, developing public resources, supporting communities, and advocating for meaningful protections.

America cannot afford to build the infrastructure of its future through executive orders while allowing public protections to expire in the background. If this industry is too important to slow down, then it is far too important to leave unregulated.

Translate this page