Governors Now Set Your 2027 Compute Plan
Two states moved the AI buildout's chokepoint from chip allocation to permit queues and audit calendars, and the copycat legislation is already drafted in a third.
Diffusion is the mechanism, not any single statute
Illinois now runs the strictest AI regime in the country, and the part that matters is who is copying it. Its Artificial Intelligence Safety Measures Act goes past California's SB 53 by requiring large frontier developers to retain an outside firm to audit their safety framework, with incident reporting and whistleblower protections attached. Massachusetts is drafting amendments modeled directly on both, per a16z's policy brief. Which means the operative compliance target is not the median state but the strictest one. A compliance calendar prices in the outlier long before a conference committee sands it down.
The siting freeze has a physical corollary that already shows up in the numbers. Off-premises facilities now host 46% of enterprise workloads against 44% owned, a crossover across more than 800 operators tracked by TLDR IT, alongside protests in 42 states, moratoriums in 10, and new large-load electricity tariffs. Workloads are leaving corporate buildings at the exact moment the buildings become permit-gated. That is not a procurement line item. It is a supply chain whose delivery date is an energization date.
| Jurisdiction | Binding constraint | Bites when |
|---|---|---|
| New York | Hyperscale permit moratorium at 50MW+ capability | Now, up to 12 months |
| Illinois (compute) | All new data center incentive agreements frozen | Indefinite, since July 1 |
| Illinois (models) | Mandatory third-party safety framework audit | January 1, 2027 |
| California | 30+ pending bills, including training-data disclosure | Session closes August 31 |
| Federal (FRONTIER) | Tiered obligations plus possible state preemption | Unresolved, highest leverage |
The threshold cliff missing from most board models
Drafters have converged on revenue and user counts as the sorting mechanism. The FRONTIER Act tiers at $1B and $5B of annual revenue; the AI Labeling Act applies at 10 million users or $1.5B revenue. A reasonable skeptic would say numbers that large are somebody else's problem, and for most companies this year that is correct. It stops being correct in the year of crossing, because the cost does not scale gently into the regime. It arrives in a single step, in the year the line is crossed, which is generally the year cash is tightest. A plan that crosses $1B inside three years puts that discontinuity in the operating model now rather than in a footnote later.
Europe reversed direction while US states hardened
The EU approved its Digital Omnibus on AI, which simplifies compliance and delays high-risk deadlines, enacting by early August. China moved the other way, bringing three prescriptive rules into force in a single month. Every 2025-vintage strategy deck that treated Europe as the friction market and the US as the permissive one has the near-term sequencing backwards. The tradeoff is worth naming plainly: that reversal changes which jurisdiction a high-risk deployment enters first.
The precedent worth studying is the export-control episode
Commerce imposed a model-level directive on two named Anthropic models. Anthropic did not degrade service. It suspended access for all customers, then regained partial and eventually full access after deploying an updated safeguard. Two lessons come out of that sequence. Single-model dependency is now a continuity risk with a regulatory root cause that no standard vendor framework anticipates. And safeguard engineering demonstrably reversed a government restriction, which makes it an investment with measurable return rather than a compliance tax.
The binding constraint on AI has moved from model capability to megawatts and audit readiness, and both are now set by governors rather than Congress.
What to do
Re-underwrite every megawatt in the compute pipeline against permit and incentive risk before Q4 budget lock, with a named alternate site for each at-risk project and the model re-run at operator-pays-full-cost power pricing
Fund an audit-ready safety framework program to the Illinois standard now, with a mock third-party audit two quarters ahead of January 1, 2027
Deploy government affairs capacity into the California Appropriations window between August 3 and August 31, prioritizing the training-data documentation and child-safety private-right-of-action bills