Category: Uncategorized

  • The Accounting Ambiguities In Microsoft’s Data Center Manifesto

    All Jobs Do NOT Generate Equal Value!

    On January 13, 2026, Microsoft published a data center manifesto called Building Community-First AI Infrastructure. The document described five commitments that purportedly expressed an intention to “be a good neighbor” and adhere to a “sense of civic responsibility.

    The manifesto certainly didn’t deter the current bipartisan backlash against the data center industry. On August 23, 2026, Texas Governor Greg Abbott explained that he reversed his initial support of the industry because “they basically dug their own grave … and that’s why they got the backlash they deserve.”

    His position is very similar to that expressed by Pennsylvania Governor Josh Shapiro. On August 18, 2026, he explained his own reversal of initial support by noting that many data center developers “have no regard for local communities” and take action by “being aggressive with township officials, bullying our neighbors, and refusing to listen to the people …”

    Why didn’t Microsoft’s manifesto deter such angry reactions? One reason may be that each of its five commitments included at least one significant accounting ambiguity that damaged the credibility of the entire document. For instance:

    The first commitment promised that the firm would “pay our way to ensure our data centers don’t increase your electricity prices.” The descriptive detail, though, only went so far as to promise to pay “the costs of adding and using the electricity infrastructure needed for the data centers.”

    A good accountant, however, would note that there are different ways to calculate such costs. The cost of adding capacity to existing power plants, for instance, is usually much different than the cost of building new power plants from scratch. Although Microsoft has opted for different approaches (to adding capacity) for its various projects, it did not refer to its experience (and its complex historical data) in its manifesto.

    The second commitment promised that the firm would “minimize our water use and replenish more of your water than we use.” By definition, though, even a 100% closed water system with 100% recycled water would need to produce new water from scratch (or transport water from elsewhere) to literally return “more” (than what it uses) to the water supply. Microsoft did not promise to do so for each project.

    So what did Microsoft mean by its second commitment? The firm suggested a number of activities for generating new water, including the repair of water system leaks and the restoration of wetlands. It is implausible, though, to assume that a sufficient amount of such improvements could be found in close proximity to each data center to ensure that its Ratio of Water Replenished to Water Used exceeds 1.0.

    The final three commitments promised to create jobs, add to the local tax base, and invest in AI training and nonprofits. However, the firm did not commit to any specific quantitative targets in any of the three areas. In addition, certain descriptive details appeared to be ambiguous about the economic impacts of promised outcomes.

    Consider, for instance, the firm’s promise to create jobs. On June 17, 2026, Morgan Stanley reported that the AI data center “jobs story is real, but front-loaded.” It quoted a Virginia report that “a 250,000 square foot data center can support more than 1,500 workers during the construction phrase … (but such) data centers employ only 50 full-time workers once operational.” It also quoted Illinois and Oklahoma reports that estimated even smaller respective operational work forces of 20 workers and 10 workers per data center.

    Admittedly, all jobs create some level of economic activity. A good accountant, though, would note a vast difference in value between a project with 1,500 permanent workers versus one with 1,500 temporary workers (albeit with a few dozen additional permanent workers). Microsoft did not address such concerns when it promised to “create jobs” in its manifesto.

    To be sure, none of Microsoft’s five commitments are individually harmful to communities. In the aggregate, they would undoubtedly add some level of positive value to any community. The accounting ambiguities that are included in each commitment, though, may explain why the manifesto was unable to deter the current bipartisan backlash against data center organizations.

  • How To Distinguish The Good Data Center Operators From The Bad

    Who are the good operators? Who are the bad?

    Tired of partisan political conflicts? You may be pleasantly surprised to learn that a strong bipartisan consensus has emerged about a critical new industry sector. Politicians on both ends of the political spectrum now agree that government agencies should exert more regulatory control regarding data centers.

    When a Republican politician like Florida Governor Ron DeSantis and a Democratic one like New York Governor Kathy Hochul agree on any fundamental principle, it may be safe to assume that significant new legislation is likely to follow. In the case of data centers, such regulations will focus on distinguishing the good data center operators from the bad.

    Fortunately, we do not need to wait for legislative bills to become law to achieve this goal. Right now, an effective approach for assessing data center organizational performance is the completion of the following three steps:

    1. Review the organization’s annual sustainability report for energy use, water use, and other relevant data. Facebook’s corporate parent Meta, for instance, published an Environmental Data Index with its 2025 Sustainability Report. It presented electricity consumption metrics on Sheet F and water withdrawal, consumption, discharge, and stewardship metrics on Sheets I, J, K, and L.
    2. Review the professional accounting standards that were utilized to define the metrics in the organization’s report. On Sheet B of Meta’s Environment Data Index, for example, the firm stated that it employed the standards of the Global Reporting Initiative (GRI), the UN Global Compact, and the Sustainability Accounting Standards Board (SASB). All of these organizations post their standards online for free download by the public.
    3. Review the independent accountant’s review report on the data. Ernst & Young LLP, for instance, reported on the results of its review procedures regarding Meta’s energy consumption, water consumption, and other metrics.

    Indeed, a massive amount of data is already available to assess the performance of our massive new data centers. Hopefully, the accessibility of this information will support the current bipartisan consensus and extend it into an enduring tradition of collaborative governance.

  • Why You Now Must Fear A Cyberattack By Your Own AI LLM Application

    OpenAI now acknowledges that its LLMs have “gone rouge” and hacked into other applications.

    Imagine, for a moment, that you pick up your phone and discover a technology nightmare. Indeed, imagine that your AI LLM is breaking through the walls of its mobile consumer app and is maliciously attacking your other mobile applications. You’d be terrified, wouldn’t you?

    Two days ago, this scenario was simply a theoretical possibility. Yesterday, though, an OpenAI news release revealed that we now must fear such attacks.

    OpenAI, the owner of the ChatGPT LLM, acknowledged that a combination of its AI models had obtained open internet access and had hacked into the data systems of a vendor. Even worse, the purpose of the hack was “to gain access to secret information that it could use to cheat” a legitimate cybersecurity evaluation process.

    OpenAI previously placed these AI models in a “sandboxed testing environment,” i.e. an electronic location that was surrounded with virtual walls that should have blocked the path to open internet access. Unfortunately, the rogue models hacked their way around the sandbox walls before they hacked into the vendor’s data systems.

    Given that a collection of OpenAI’s AI models successfully “cheated” by breaking through two different sets of cybersecurity walls, it may indeed be time for you to fear a similar attack by your cell phone’s AI LLM application. What can you do to protect yourself against such a risk?

    You are likely already familiar with the standard recommendations regarding protective activities. For instance, you should always use the current version of your device’s operating system. Likewise, you should always use the current versions of your cell phone applications. In addition, instead of passwords, you should consider using PassKeys or Dual (or Two-Factor) authentication methods to access your mobile service applications.

    If you continue to be worried after implementing these steps, you might consider removing sensitive personal information from your phone. Alternatively, if you must maintain such information on your device, you might consider removing the LLM app instead. Most LLM services allow you to avoid using their apps by logging into their systems through web browsers.

    The most important protection, though, might be to simply remain aware of the possibility that your own AI LLM application — or any set of software code, for that matter — can be employed to hack into your proprietary electronic data. As long as you remain alert to that possibility, you will be better prepared to manage this particular risk.

    Regrettably, such activities cannot entirely eliminate the underlying concern. Nevertheless, as LLMs become more embedded in the fabric of your technologies, you’ll have no choice but to dedicate more time and resources to strengthening your relevant protective controls.