A lineman in safety gear and a red helmet works on a power pole and its lines, standing in for the grid constraints that set the week's data center limits. Photo by Антон Дмитриев on Unsplash. Source: https://unsplash.com/photos/a-man-in-safety-gear-working-on-a-power-pole-ZGY5Pp8Xxaw (Unsplash License).

Executive Summary

Four limits tightened inside seven days, and every one of them had been filed as solved. Texas barred its environmental regulator from approving new data center permits after developers filed 445.8 gigawatts of interconnection requests against a grid whose record peak is 85,508 megawatts, with just 5.9 gigawatts drawing power. Alibaba Cloud answered with a 20 gigawatt target for 2032 and no funded capital figure attached to it.

The money moved too. OpenAI and Anthropic cut inference prices on one night, and cached input now prices at a tenth of the uncached rate, so the bill follows prompt shape rather than model choice. The defensive layer failed twice as well. Arista’s July fix for VeloCloud sits inside the range vulnerable to its September zero day, so operators who patched on schedule were exposed twice in three months. This was the week the AI infrastructure buildout met its price list.

The biggest moves this week were not launches. They were limits, prices, and a patch that did not hold.

Diagram of the four limits that moved in the week of 19 to 25 September 2026. Grid, Texas stopped approving permits after 445.8 GW of interconnection requests landed against an 85.5 GW record peak. Capacity, Alibaba targets 20 GW of data center capacity by 2032 with no capital figure attached. Price, two labs halved token prices in one night and cached input sits at a tenth of the rate. Trust, Arista’s July fix sits inside the September zero day range.
Four limits platform teams had filed as sold, and all four moved inside one week.

The grid set this week’s ceiling, not the chip

Texas closed its last open door on 21 September. Governor Greg Abbott ordered the state environmental regulator to approve nothing until ERCOT and the Texas Water Development Board finish audits of the queue. The order formalised an August pause on new interconnections.

The queue explains the pause. ERCOT counted 445.8 gigawatts of large load applications through 2033. Of that, 321 gigawatts had no study submitted, and only 22 gigawatts had met the requirements. ERCOT had observed 5.9 gigawatts energized, against a system peak of 85,508 megawatts. A queue entry buys a place in line, not a substation. We worked through the funnel and the schedule risk.

Alibaba answered with a number of a different kind. Its T-Head unit unveiled the Zhenwu V900 accelerator, in production early next year. The chip is the smaller story. Alibaba Cloud now targets more than 20 gigawatts of global data center capacity by 2032, against a three year commitment of 380 billion yuan and no capital figure attached. Chief executive Eddie Wu named supply as the constraint, saying the AI data center shortage limits how fast the company can scale. We read the target against the chip roadmap.

The bill moved to the cache, and the shortlist moved with it

Two labs repriced inference on the same night. OpenAI took GPT-6 Sol to 2 dollars per million input tokens and 10 dollars per million output, with cached input at 20 cents, and GPT-6 Luna to 10 cents and 50 cents. Anthropic shipped Claude Opus 5.5 at 4 dollars and 20 dollars, with cache reads down to 20 cents.

The headline rate stopped deciding the money. Cached input prices at a tenth of the uncached rate, so a prefix that repeats is cheap and one that does not is recomputed on every call. Artificial Analysis measured the change in cost per task, and found GPT-6 Sol at maximum effort runs its index for 1.06 dollars against 1.99 dollars for its predecessor. We broke down where the bill moved.

Cost decided a second market in the same window. Gartner published its 2026 Magic Quadrant for Server Virtualization Platforms on 14 September, and the grid reads as a shortlist rather than a verdict. Gartner projects that by 2028 cost concerns will push 70 percent of enterprise VMware customers to move half their virtual workloads elsewhere. We read the grid as a VMware exit shortlist.

Two exploited flaws showed that a patch is not a repair

Arista is telling customers to patch a VeloCloud Orchestrator flaw rated 10.0. The builds that closed its July zero day fall inside the vulnerable range for this one. The September flaw, CVE-2026-93952, is an authentication bypass affecting 5.2.0 through 5.2.3.15. Arista fixed July’s flaw at 5.2.3.14, so the builds carrying that fix are patched against July and open to September. Patching on schedule exposed operators twice in three months on one appliance.

The advisory also assumes something only a specialist would catch. Arista says exposure requires access to the public portion of the edge authentication certificate. A public key is not secret by design, so the certificate is not the mechanism. The code mishandling input is. Because the indicators are a hidden script and a service that restarts at boot, a hotfix closes the door without evicting anyone inside. We worked through the version matrix.

The FBI made the same point from another direction. ShinyHunters told BleepingComputer it took two to three terabytes from fbijobs.gov, with names, home addresses and family details. The Bureau has confirmed only that it is investigating unauthorized activity, so treat the scale as a claim. The lesson survives either version. A PeopleSoft zero day cannot be patched before it is disclosed, so no patch decided that outcome. What decided it was what the system could reach and how much could leave unnoticed. We separated the confirmed from the claimed.

Both stories land on one rule. Remediation starts with understanding what a system can reach, and it starts before the upgrade, not after it.

Related reading. Our look at NVIDIA open sourcing the cluster map schedulers never had, why confidential AI has to attest the hardware, and why multi-AZ was never a backup.

By Ivan Tarin

Ivan Tarin is a Principal Product Marketing Manager at SUSE, where he owns go-to-market strategy and positioning for a seven-product cloud-native portfolio spanning Kubernetes, virtualization, storage, security, and observability. A former full-stack developer who shipped production code for enterprise and public-sector clients including U.S. national laboratories, Ivan translates complex infrastructure and AI technology into messaging that lands with developers, platform teams, and enterprise buyers. He has presented at KubeCon, SUSECON, and AWS Developer Week, and is currently pursuing an MS in Artificial Intelligence at the University of Colorado Boulder.

Leave a Reply

Your email address will not be published. Required fields are marked *

Get the next one before it is old news

Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.