The race to build artificial-intelligence infrastructure has been organized around a deceptively simple question: where are the available megawatts? Developers have searched for generation, transmission headroom, substations, natural gas, water, land and permitting pathways. Executive Order 14420 adds another question that may prove just as consequential: can the equipment required to deliver those megawatts be legally procured, securely operated and reliably serviced?
President Donald Trump signed the order on August 26, declaring a national emergency over foreign involvement in equipment used by the U.S. bulk-power system. It authorizes the Department of Energy to prohibit the acquisition, importation, transfer or installation of foreign-produced equipment associated with entities determined to present unacceptable national-security, cybersecurity or supply-disruption risks. The order covers not only transformers, generators and circuit breakers, but also grid-connected inverters, battery energy storage systems, protective relays, backup generators, industrial controls, firmware, software, maintenance services and remote-access capabilities.1
The security rationale is credible. The implementation risk is equally real. If DOE develops a technically grounded, risk-tiered system supported by domestic manufacturing and trusted allied supply chains, the order could close material vulnerabilities. If it relies primarily on country of origin, it could deepen equipment shortages, increase market concentration and delay the grid expansion needed to support the AI buildout.
What the Order Actually Changes
Executive Order 14420 is not an immediate prohibition on all imported grid equipment. A covered transaction must involve foreign-produced equipment or an associated component, service or digital capability connected to a “Covered Foreign Entity,” and DOE must determine that the transaction creates an undue or unacceptable risk. China is among the jurisdictions captured through the order’s incorporation of U.S. arms-embargo and sanctions policies, although DOE may designate additional governments, companies or persons.2
The Secretary of Energy can license otherwise prohibited transactions, negotiate mitigation measures and establish a list of prequalified equipment and vendors. DOE must publish implementing rules within 120 days, placing the initial deadline around December 24, 2026. Until those rules define the affected countries, companies, products and transaction classes, the legal perimeter will remain uncertain.
The commercial effects begin before the rules are complete. Transactions initiated after August 26 may eventually be subject to prohibition, while equipment installed before the order can be identified, isolated, monitored, secured, disconnected, replaced or removed. DOE must consider reliability, safety, replacement availability and continuity of service before ordering removal, but utilities and developers cannot assume that installed equipment is permanently grandfathered.
This is a more expansive successor to Executive Order 13920, issued during the first Trump administration in May 2020.3 The implementing action under that order was ultimately limited to selected Chinese equipment serving critical defense facilities and was revoked in April 2021.4 The new order covers a wider set of technologies, explicitly reaches software and lifecycle services, and gives DOE clearer authority to address equipment already in operation.
Two Risks Hidden Inside One Policy
The order combines two distinct national-security problems. The first is control risk: the possibility that a foreign government or affiliated vendor could exploit hardware, firmware, software or remote access to manipulate equipment. The second is continuity risk: the possibility that geopolitical conflict, sanctions, export controls or industrial concentration could interrupt the supply of equipment, replacement components or maintenance services.
Those risks require different responses. Control risk is reduced through product testing, signed firmware, access restrictions, network segmentation, credential management, software bills of materials, independent monitoring and the elimination of unnecessary vendor connections. Continuity risk is reduced through diversified sourcing, interchangeable designs, domestic and allied manufacturing, strategic inventories, repair capacity and long-term procurement commitments.
A blanket equipment restriction can address one risk while worsening the other. Removing a vendor with dangerous remote-control capabilities may reduce control risk. Removing multiple suppliers before substitutes are available may increase continuity risk by reducing spare-equipment availability and lengthening restoration and construction schedules.
The distinction matters because the order invokes AI and data-center growth as evidence that the threat has become more acute. Load growth increases the economic consequences of a major grid disruption, but it does not necessarily increase the probability that any individual transformer or control system has been compromised. AI infrastructure changes the consequence side of the risk equation more directly than the vulnerability side.
That distinction should influence implementation. Equipment serving a nationally significant transmission corridor, nuclear facility, military installation or multi-gigawatt data-center cluster presents a different consequence profile from similar equipment at a smaller and more isolated facility. A serious regime would account for system consequence, digital controllability and substitutability rather than treating every product within a broad category as equivalent.
Why Origin Alone Is Not Enough
The order uses foreign production and foreign control as thresholds for federal action, but neither is a complete measure of security. A product assembled in the United States may still contain foreign control boards, communications modules, code libraries, firmware, cloud services or administrative dependencies. Domestic assembly does not establish who controls the product after installation.
The reverse is also true. Equipment manufactured by a trusted allied company under transparent security and servicing practices may present less operational risk than domestically assembled equipment with opaque software and persistent vendor access. The relevant question is not simply where the enclosure was built, but who can alter the device, reach it remotely, withhold essential services or prevent its owner from operating it independently.
The order partly recognizes this problem by including software, firmware, maintenance services and remote access. Its domestic-manufacturing provisions nevertheless risk turning a complex engineering assessment into a politically convenient country-of-origin test. That would be easier to administer, but it would not necessarily identify the most consequential vulnerabilities.
FERC and NERC already operate mandatory supply-chain risk-management standards for covered bulk-electric-system cyber assets.5 Those standards do not capture every device or large-load facility implicated by the present buildout, but they provide an institutional foundation. DOE should build on that framework rather than creating a separate vendor regime with different definitions, evidence standards and mitigation requirements.
The Collision with Equipment Scarcity
The order arrives during the most difficult grid-equipment market in decades. DOE reported in August that lead times for critical equipment can exceed two years and that prices for some transformers have increased four- to ninefold over the past five years. The department has announced a program of up to $375 million to expand domestic production, encourage equipment standardization and reduce reliance on imports, but manufacturing capacity cannot be created on a 120-day regulatory schedule.6
The Government Accountability Office has identified long manufacturing lead times, limited capacity, labor and material shortages, transportation constraints and excessive customization as major threats to transformer resilience. As of May 2026, GAO’s recommendation that DOE establish an actionable transformer supply-chain plan remained open.7 The federal government is therefore imposing a new security screen before it has resolved the underlying availability problem.
This creates a stock-and-flow conflict. Restrictions on new transactions affect the flow of equipment into the system, while potential replacement orders create additional demand from the installed stock. If existing equipment must compete with new substations and power plants for the same limited pool of approved replacements, remediation could displace expansion rather than accompany it.
The federal AI strategy points in the opposite direction. A July 2025 executive order sought to accelerate large data-center projects and specifically identified transmission lines, substations, transformers, switchgear, gas turbines and backup power systems as components upon which those projects depend.8 Federal policy is simultaneously trying to accelerate construction and tighten access to the equipment required for construction.
Those objectives are not inherently incompatible, but they must be modeled together. Restricting insecure equipment while expanding secure production could improve long-term resilience. Restricting equipment faster than secure supply can respond will produce higher costs, longer energization schedules and greater competition for a smaller set of vendors.
Data Centers Cannot Escape Through the Meter
The order formally applies to the bulk-power system, defined to include transmission facilities operating at 69 kilovolts or above while excluding local distribution. Many hyperscale campuses connect at transmission voltage or require new substations, switchyards and protective equipment within that perimeter. Even where the data center itself is not directly regulated, the utility facilities required to serve it may be.
Developers may therefore bear costs associated with equipment they neither select nor own. Utilities generally procure the transformers, breakers, relays and controls used for interconnection, but network-upgrade costs and schedule consequences can be assigned to the connecting customer. A utility decision to disqualify a vendor, repeat a solicitation or redesign a substation can delay a data center without changing the project’s nominal interconnection position.
Behind-the-meter generation does not remove the exposure. A campus powered by gas turbines, fuel cells, batteries or a microgrid still requires transformers, switchgear, inverters, controls, backup systems and replacement components. The order expressly includes several of those categories, making equipment provenance relevant to the very configurations being promoted as alternatives to delayed utility service.
The market response will be uneven. Hyperscalers can reserve manufacturing capacity, conduct detailed supplier audits, negotiate cybersecurity requirements and finance equipment years before energization. Independent developers, merchant generators, storage companies and smaller utilities have less purchasing leverage and less ability to absorb redesign or delay.
A prequalified-vendor list could therefore become a new concentration point. Regulatory approval would increase demand for a limited number of manufacturers, and early production slots from those companies could acquire substantial option value. Large buyers would reserve compliant capacity earlier, leaving smaller market participants to accept longer schedules or greater regulatory uncertainty.
From Available Megawatts to Secure Megawatts
The order should be treated as a constraint on deliverable capacity rather than as a generic cybersecurity flag. The relevant quantity is the secure megawatt: the amount of load that can be physically delivered by a given date using equipment that is available, qualified and serviceable under the applicable security regime. At any point in time, secure capacity is bounded by the lowest of five quantities: network-ready capacity, firm supply capacity, site-ready load, compliant equipment capacity and regulatory clearance. More generation or transmission headroom does not increase the secure megawatt if qualified transformers or control systems remain the binding constraint.
The same logic applies to timing. A project’s secure energization date is the latest of its network-completion date, power-supply date, site-readiness date, compliant-equipment delivery date and regulatory-clearance date. This makes the equipment issue analytically comparable to permitting, interconnection and construction rather than leaving it in a separate cybersecurity discussion.
That treatment reveals how a national rule can produce geographically uneven effects. Utilities use different equipment specifications, approved-vendor lists, procurement practices and substation designs. Corridors also differ in their dependence on new transmission, imported inverters, battery systems, gas turbines and behind-the-meter configurations. A national restriction will therefore propagate through regional project pipelines in different ways.
The Cost-Causation Problem
The order does not determine who will pay for compliance. That omission will become important as utilities identify equipment requiring additional monitoring, isolation, replacement or procurement changes. Costs could be assigned to individual connecting customers, included in network-upgrade charges, recovered through utility rates or absorbed by equipment vendors, depending on ownership, tariff structure and the timing of the federal determination.
Prospective projects will be easier to address because utilities can incorporate new requirements into interconnection agreements and procurement specifications. Existing equipment will be harder because replacement may benefit the broader system while being triggered by a national-security determination unrelated to the original prudence of the investment. Assigning those costs entirely to one customer would often be difficult to justify.
Data-center tariffs and large-load interconnection rules will eventually need to address this issue. If a customer specifies or owns the affected behind-the-meter equipment, direct cost assignment may be appropriate. If the utility owns a shared substation or replaces equipment serving multiple customers, broader allocation may better reflect cost causation.
Ignoring the allocation question will not make it disappear. It will move the issue into rate cases, interconnection disputes, contract negotiations and project financing, where uncertainty itself becomes a cost.
A Better Implementation Path
DOE should classify equipment according to system consequence, digital controllability, ownership and remote access, supply-chain concentration, replacement availability and the effectiveness of available mitigation. High-consequence equipment with persistent access controlled by an adversarial entity should face the strongest restrictions. Passive components, isolated equipment and products with independently verifiable controls should not automatically receive the same treatment.
The government should also distinguish trusted allied sourcing from strategic dependence on adversarial jurisdictions. Hardware and software bills of materials, signed firmware, controlled administrative credentials, independent logging, vulnerability disclosure, patching obligations and termination rights for remote services would provide stronger evidence of security than domestic assembly alone. Utilities should retain the practical ability to operate essential equipment if a vendor or country becomes unavailable.
Replacement requirements must be sequenced around actual manufacturing and restoration needs. Equipment presenting an active control threat may require rapid isolation or replacement, while equipment presenting primarily a future continuity risk may be addressed through monitoring, spares and phased retirement. Treating both categories as emergencies would consume scarce replacements without necessarily reducing the highest risks first.
The 69-kV boundary also requires attention. Coordinated batteries, inverters, generators and large loads connected below transmission voltage can influence bulk-system behavior even if no individual device meets the formal threshold. DOE, FERC, NERC, CISA, state regulators and utilities will need a common approach to aggregated distribution-side risk rather than a jurisdictional gap.
Conclusion
Executive Order 14420 recognizes that energy security depends on more than fuel supply and generation capacity. The electric system is also a network of manufactured devices, embedded software, service relationships and geopolitical dependencies. Ignoring those dependencies would leave a material weakness in the infrastructure supporting the AI economy.
The order can still become misguided if domestic origin substitutes for technical evidence or if restrictions advance faster than secure supply. A resilient policy must reduce adversarial control while preserving enough equipment availability to expand, maintain and restore the grid. Those are joint constraints, not competing talking points.
The AI power race is therefore entering a new phase. The next gigawatt will not go simply where land is cheap, projects are announced or electrical headroom appears available. It will go where the full corridor can procure, qualify, install and service the equipment required to turn theoretical capacity into secure megawatts.
Notes
- Donald J. Trump, “Declaring a National Emergency to Secure the United States Bulk-Power System,” Executive Order 14420, August 26, 2026, White House, https://www.whitehouse.gov/presidential-actions/2026/08/declaring-a-national-emergency-to-secure-the-united-states-bulk-power-system/. ↩
- U.S. Department of State, Directorate of Defense Trade Controls, “Country Policies,” accessed August 27, 2026, https://www.pmddtc.state.gov/ddtc_public?id=ddtc_public_portal_country_landing. ↩
- Donald J. Trump, “Securing the United States Bulk-Power System,” Executive Order 13920, May 1, 2020, Federal Register 85, no. 86 (May 4, 2020): 26595–99, https://www.federalregister.gov/documents/2020/05/04/2020-09695/securing-the-united-states-bulk-power-system. ↩
- U.S. Department of Energy, “Revocation of Prohibition Order Securing Critical Defense Facilities,” Federal Register 86, no. 76 (April 22, 2021): 21308–9, https://www.federalregister.gov/documents/2021/04/22/2021-08483/revocation-of-prohibition-order-securing-critical-defense-facilities. ↩
- Federal Energy Regulatory Commission, Supply Chain Risk Management Reliability Standards, Order No. 850, 165 FERC ¶ 61,020, Docket No. RM17-13-000, October 18, 2018, https://www.ferc.gov/media/order-no-850. ↩
- U.S. Department of Energy, Office of Electricity, “Strengthening America’s Grid Supply Chain,” August 10, 2026, https://www.energy.gov/oe/articles/strengthening-americas-grid-supply-chain. ↩
- U.S. Government Accountability Office, Electricity Grid: DOE Could Better Support Industry Efforts to Ensure Adequate Transformer Reserves, GAO-23-106180 (Washington, DC: Government Accountability Office, August 2023), updated May 2026, https://www.gao.gov/products/gao-23-106180. ↩
- Donald J. Trump, “Accelerating Federal Permitting of Data Center Infrastructure,” Executive Order 14318, July 23, 2025, White House, https://www.whitehouse.gov/presidential-actions/2025/07/accelerating-federal-permitting-of-data-center-infrastructure/. ↩