Weekly AI Governance Brief: 21–27 September 2026

Share

Bringing you the latest developments in the AI Governance world.

EU opens regulatory process around the environmental performance of data centres

On 21 September, the European Commission proposed a common EU rating scheme for the sustainability of data centres and simultaneously opened a public consultation on possible minimum performance standards.

The rating scheme is intended to make the energy and water performance of data centres more transparent and comparable. It sits within the framework established by the Energy Efficiency Directive, which already requires reporting on the energy performance of data centres with significant energy consumption.

The Commission also launched a 12-week consultation and call for evidence on potential minimum performance standards. Feedback is open until 14 December, with a legislative proposal planned for the second quarter of 2027.

The initiative is explicitly connected to Europe's growing computing requirements. The Commission states that expanding data-centre capacity is important for technological sovereignty and AI development, while acknowledging the associated pressures on electricity systems, water resources and carbon emissions.

The rating scheme is intended to improve transparency around those impacts. The separate consultation goes further by examining whether minimum performance requirements should become part of the EU framework.

Why this matters

The development broadens the regulatory perimeter surrounding AI infrastructure.

AI governance is often centred on models, applications and organisations deploying them. Large-scale AI systems, however, also depend on substantial physical computing infrastructure. The Commission's initiative begins to place more structured sustainability requirements around that layer of the AI ecosystem.

For organisations operating or procuring computing infrastructure, the immediate significance is transparency. The longer-term regulatory question is whether the EU moves from reporting and comparative ratings toward mandatory efficiency requirements.

The consultation is therefore the more consequential part of the package from a governance perspective. It begins the formal preparatory process for legislation expected in 2027 rather than imposing new minimum standards immediately.

US appeals court upholds Pentagon supply-chain designation of Anthropic

On 25 September, the U.S. Court of Appeals for the District of Columbia Circuit issued its judgment in Anthropic PBC v. United States Department of War, consolidated cases Nos. 26-1049 and 26-1162.

The dispute concerned the Department's decision to designate Anthropic as a supply-chain risk under the Federal Acquisition Supply Chain Security Act.

The disagreement originated in negotiations over government use of Claude. The Department sought contractual permission to deploy the model for “all lawful uses,” while Anthropic maintained restrictions concerning lethal autonomous warfare and mass surveillance of Americans.

The Department subsequently concluded that the restrictions created a national-security supply-chain risk. Anthropic challenged that determination.

In a 2–1 judgment, the D.C. Circuit rejected the challenge. The majority concluded that the Department had sufficient support for determining that continued integration of Claude into its systems, whether directly or through contractors, presented a risk covered by the relevant statute.

The court's decision concerns a distinct statutory designation from the government measures considered in separate California litigation involving Anthropic. The D.C. Circuit addressed the supply-chain determination made under the federal acquisition statute before it.

Why this matters

The judgment addresses a governance question that is becoming increasingly important as governments integrate frontier AI into sensitive systems: who ultimately determines acceptable restrictions on the use of privately developed models?

AI providers may impose contractual or technical controls intended to prevent specified uses. Government customers, particularly in defence and national-security environments, may consider those same restrictions incompatible with operational requirements.

The D.C. Circuit's judgment confirms that, under the statutory framework considered in this case, supplier-imposed limitations can form part of a government supply-chain risk assessment.

The decision therefore connects private AI safety governance with public procurement and national-security authority. Model policies do not operate independently of the institutional environment in which an AI system is deployed.

UK and US establish new defence AI and autonomy partnership

On 22 September, the UK government announced its collaboration with the United States on a new bilateral AI and Autonomy partnership.

The initiative brings together the UK's Ministry of Defence Rapid AI Delivery Taskforce and the U.S. Department of War Chief Digital and Artificial Intelligence Office. Their work will focus on accelerating development of AI and autonomous capabilities that the governments describe as trusted and interoperable.

The partnership is linked specifically to defence and protection of critical national infrastructure, including maritime and airspace security.

The initiative also sits alongside existing cooperation on autonomous defence technology. The UK government identified work under AUKUS on undersea autonomous capabilities as an existing area of technological collaboration upon which the new partnership can build.

The announcement does not create general AI compliance obligations for companies. Its significance instead lies in establishing an institutional mechanism through which two governments intend to coordinate development and deployment of AI in high-security environments.

Why this matters

Military and national-security AI creates governance requirements that differ from many commercial deployments. Interoperability, assurance and control over system behaviour must operate across institutional and national boundaries.

The UK-US partnership makes those issues part of a formal bilateral development process.

It also demonstrates that international AI governance is increasingly occurring through operational partnerships rather than solely through treaties, standards or general regulatory frameworks. In this case, governance is embedded directly into how governments intend to develop and integrate AI capabilities.

Looking ahead

The developments of 21–27 September illustrate the widening scope of AI governance.

The European Commission's data-centre initiative moves regulatory attention further down the AI supply chain toward the physical infrastructure required to support increasing compute demand. The D.C. Circuit judgment addresses the opposite end of that chain: the conditions under which governments can procure and use frontier AI systems when supplier restrictions conflict with national-security requirements.

The UK-US partnership adds an institutional dimension, showing how governments are establishing mechanisms for jointly developing and assuring AI capabilities in security-sensitive environments.

Taken together, the week's developments show AI governance operating increasingly through adjacent regulatory systems. Energy regulation, public procurement and defence cooperation are becoming part of the institutional environment governing how advanced AI can be developed and deployed.

Sources

European Commission data-centre energy performance and common rating scheme: energy.ec.europa.eu

European Commission consultation on minimum performance standards for data centres: energy.ec.europa.eu

U.S. Court of Appeals for the D.C. Circuit judgment in Anthropic PBC v. United States Department of War: media.cadc.uscourts.gov

UK Government announcement of UK-US AI and Autonomy partnership: gov.uk

Read more