Procedure, not judgement
Uptime attributes 85% of human-error outages to staff not following procedures, or to flaws in the procedures themselves. The failure is in the method, not the operator.
The report has spent ten markets on land, power and capital. This is the layer underneath all of them: the discipline that decides whether a finished building will actually carry a live load. Louis Charlton, Group CEO of GCV Group, on where risk is created, the seams where it accumulates, and why the commissioning crunch will not be solved by hiring.
A building can be finished and still not work.
Every chapter in this report ends at the same place: a site with land, a grid connection and a financing package. What none of them examine is the discipline that stands between a completed building and a working one. That discipline is lifecycle assurance, and the industry has historically treated it as a service bolted on at the end rather than a thread running through the whole build. Louis Charlton, who founded Global Commissioning and now leads GCV Group, puts the distinction in six words: complete and proven are not the same thing. Complete is a construction status. Proven is an assurance status, and only one of them tells you the facility will do what it was designed to do when it is carrying real load.
The structural problem is a mismatch of position. Almost all of the risk in one of these facilities is created on the left of the timeline, at concept and design, in decisions about how power is distributed, whether energisation can be staged, whether the building can be tested at partial load and re-verified in five years without being pulled apart. By the time a spade is in the ground, that ceiling is largely fixed. But in the conventional model the commissioning authority is appointed after the design is finished. The risk sits at one end of the line and the people whose job is to catch it stand at the other. Charlton calls the usual arrangement what it is: a closeout with an earlier start date.
That gap is widening because the buildings changed faster than the method for proving them. Grid connection timelines running to five or seven years against an eighteen-month capacity requirement have pushed operators to bring power infrastructure inside the fence, which turns high voltage from somebody else’s asset into a strategic one. Rack densities above 200kW have made liquid cooling unavoidable, and introduced failure modes that cannot be fully proven until real compute is running. Phased delivery means live systems and open construction now share a site. Each of those pushes the assurance boundary outward, upstream into the energy chain and downstream into live operation, while shrinking the room to get it wrong. This chapter follows that line from the first design decision to the fifteenth year of operation, and marks the points where a planner, an investor or an operator should ask for proof.
Asked to set out the lifecycle in a single diagram, Charlton described one horizontal line and a structural mismatch along it. Almost all of the risk is created at the far left, in design decisions taken before anyone is on site. In the conventional model the people whose job is to catch it are appointed at the far right. Between them sit the seams, and it is at the joins rather than inside the phases that risk actually accumulates. Switch the model below, then select any stage or hand-off.
Diagram constructed by Entelligencia from the contributor’s description of the lifecycle. Quoted passages are reproduced from his written submission. Stage and hand-off framing is editorial.
How a delivery model built for a simpler building ran out of road: grid queues, power crossing the fence, high voltage as an operator discipline, density beyond air, and a verification gap that only closes once the accelerators are running. Seven chapters. Scroll to begin.
A data centre was a shell with power, cooling and a fence. The systems were well understood, the sequences were familiar, and a programme could afford to leave verification until the end because there was slack at the back to absorb it. The method the industry still uses was designed for that building.
Grid capacity stopped being a procurement line and became the binding constraint. Across the markets in this report, waits now run to five or seven years while operators need hundreds of megawatts inside eighteen months. That single mismatch is what set everything that follows in motion.
If the utility cannot deliver on the timescale, the operator builds it. Private substations, behind-the-meter generation, storage. The moment that happens the boundary of the project moves outward, and high-voltage infrastructure that used to sit outside the fence becomes something the operator owns, operates and has to prove.
Different competence, different regulatory exposure, different consequence of error. Protection coordination, arc-flash study, switching discipline and authorised-person regimes are not scaled-up versions of ordinary electrical commissioning. And the consequence of getting a protection scheme wrong does not stay inside the building.
Liquid cooling stopped being an option and became a requirement, bringing failure modes a conventional facility never had: leak detection, coolant chemistry, pressure regulation, flow balancing, thermal expansion across hundreds of quick-disconnect couplings. None of it is caught by visual inspection or standard functional testing.
A loop can be pressure-tested and flow-balanced in isolation, pass every pre-load test, and still behave differently once real compute is on it. That is a verification gap conventional infrastructure does not have, and it sits precisely where the schedule has the least room left.
Every step above pushed the assurance boundary outward, upstream into the energy chain and downstream into live operation, while removing the slack the old sequence depended on. The industry still largely buys verification as a service near the end. Charlton’s argument is that it has to be drawn as a line under the whole thing instead.









The four-tier taxonomy grades claims about the world; most of this board is professional judgement from a practitioner, so it is marked Testimony rather than graded. Where the report’s own research corroborates a finding it is also marked Verified. Charlton declined to give incident-level accounts, so the patterns are categories he says recur rather than identified projects. Quoted passages are reproduced from his written submission.
Charlton would not describe identified projects, and said the telling failures are quiet ones. The published record supports the category without needing his cases: the dominant cause of data-centre outages is not equipment, it is procedure, and the cost of it is rising faster than the frequency.
Uptime attributes 85% of human-error outages to staff not following procedures, or to flaws in the procedures themselves. The failure is in the method, not the operator.
The share of human-error outages caused by failure to follow procedures rose ten points between the 2024 and 2025 analyses.
Across a quarter century of tracking, Uptime estimates human error plays a role in two-thirds to four-fifths of all outages. Power remains the largest single technical cause.
Outages costing more than one hundred thousand dollars rose from 39% to over 60% of the total in three years. Those above a million rose from 11% to 15%.
Swiss Re projects data-centre-linked premiums to more than double by 2030, and describes a sector scaling faster than prescriptive regulation exists to govern it.
Uptime has issued over 4,300 Tier awards across design, constructed facility and operations. All three are voluntary and commercial, and the operational tier expires.
Uptime Institute Annual Outage Analysis (2022, 2024, 2025) and 25-year commentary; Swiss Re Institute sigma 07/2026. A widely repeated figure holds that 79% of outages involve components not directly tested at commissioning; it is attributed to Uptime in the commissioning-vendor literature but is not traceable to a published Uptime report, so it is not used here.
Charlton’s comparison is that aviation, nuclear, oil and gas and pharmaceuticals settled this question decades ago, and his own commissioning career was in oil and gas, so it is not an analogy borrowed from outside. Each of those regimes has a place as well as a date. They are plotted here where they were written. Select any node.
One hundred and sixty-seven men died on Piper Alpha in July 1988. Lord Cullen’s inquiry produced 106 recommendations and moved offshore safety oversight to the HSE. The regime that emerged requires an Independent Competent Person to verify that safety and environmentally-critical elements remain in good repair, and Regulation 13(1) requires that scheme to be reviewed throughout the lifecycle of the installation. The duty sits with the operator.
In every regime above, independent verification is mandatory, runs through the operating life rather than ending at handover, and the duty is carried by the operator. No equivalent exists for data centres. What does exist is set out next.
A data centre is not unregulated. Six instruments reach it, and between them they cover energy, construction safety, live electrical working, resilience and independent testing for those who buy it. Each is set out here claim by claim, graded against the record. Select a tab to bring an instrument forward, an underlined claim to read the analysis, or filter by grade.
Read together these instruments verify energy, safety and resilience. Independent proof that the facility performs as designed under load appears in exactly one of them, and it is voluntary, commercial and point in time. None carries the feature every regime on the map above shares: a mandatory duty on the operator to keep proving the asset across its working life.

“The line I keep coming back to is that complete and proven are not the same thing.”
“Complete is a construction status. Proven is an assurance status, and only one of them tells you the building will do what it was designed to do when it’s carrying a live load. As an industry we’ve been comfortable using those words interchangeably, and the gap between them is where the risk sits.”
“You control risk where it is created, you keep control of it across every seam, and you don’t let go of it at handover, because the asset carries on running for fifteen or twenty years after the project team has gone home. The old model draws that line as a dot at the end. The reality of what’s being built now needs it drawn across the whole page.”
“Anyone can be independent when it’s easy. Our clients aren’t paying us to agree with them on the good days. They’re paying us to be the one party in the room who will still tell them the truth on the bad ones.”
Contributed to The Next Hotspot via the Entelligencia briefing survey, attributed by name with firm and title at the contributor’s request. Passages reproduced from his written submission. Framing, data and editorial selection are Entelligencia’s.
Description.
Mind the Gap is a Sociogencia case inside The Next Hotspot, an interactive read on where the world actually builds AI infrastructure. The full edition is live, and the remaining drops are dated below.
Where the build actually happens, and what is in the way.


