More than 3 GW of data center load left the PJM system on July 22, 2026, after a single transmission fault. The North American Electric Reliability Corporation (NERC) investigated the same failure mode in 2024 and found that utility equipment shed none of it. Customer-side protection did all of it. Those settings are about to become a filed obligation, and the fleet that absorbs the swing has a stake in how they get written.
I design electrical power systems for data centers. This is an argument the data center industry should make for itself, rather than receive from a standards drafting team.
An electrical room rarely announces a bad day. There is often no bang and no smoke. A static switch operates in a fraction of a cycle, an uninterruptible power supply (UPS) begins supplying load from battery, a generator-start signal goes out, and the facility keeps computing without dropping a transaction. Inside the building, that is a clean success. The equipment did exactly what it was set to do.
On July 22, 2026, thousands of those small successes happened at once. Dominion says a transmission line in Ashburn, Virginia, faulted and automatically went out of service, and data centers across the region transferred to backup power. More than 3 GW of load left the PJM Interconnection system, about 3% of demand at the time, according to PJM figures reported by Reuters. PJM reported a measurable frequency change and no reliability impact to the bulk power system. The grid absorbed it. It should not have had to.
For anyone who operates generation, that is what an uncoordinated protection scheme looks like from the outside: a multi-gigawatt instantaneous load rejection that your units, not the data center’s, have to answer. Governors respond, frequency rises, machines already at minimum load have nowhere left to go, voltage climbs on a suddenly lightly loaded network, and someone starts switching shunt capacitor banks out of service to hold it down. None of that shows up in a data center’s own event log as a problem, which is precisely why it has taken the data center industry this long to treat it as one.
The 2024 Precedent
What makes this an engineering story rather than a news cycle is that the same failure mode happened two years earlier, on a smaller scale, and NERC investigated that one and published what it found. On the evening of July 10, 2024, a lightning arrester failed on a 230-kV line in the Eastern Interconnection, producing a permanent fault that eventually locked the line out. Automatic reclosing was configured for three attempts staggered at each end, so the system saw six successive faults in an 82-second window. All six were detected and cleared properly. The shortest lasted 42 milliseconds and the longest 66. Voltage in the affected area dipped to between 0.25 and 0.40 per unit.
In that 2024 event, about 1.5 GW of load disappeared, and NERC determined it was exclusively data-center-type load. None of it was disconnected by utility equipment. All of it went off on customer-side protection and controls, which is to say, on customer equipment, per customer settings. Frequency rose to 60.047 Hz and took four minutes to settle. Voltage climbed to 1.07 per unit, and operators had to remove shunt capacitor banks to bring it down.
Then the part of NERC’s 2024 review worth reading twice. Most of the sustained loss, roughly 1.26 GW, did not drop on the initial fault. It dropped on the third voltage depression and did not return for hours. NERC attributes that to an interaction between the line’s reclosing sequence and a scheme inside the data centers that counts voltage disturbances, typically tripping after three within one minute and then holding the facility on backup until someone manually reconnects it.
So, in 2024, a counting relay on the customer side, with no awareness of standard utility reclosing practice, latched a gigawatt of load off the grid for hours. That is not equipment being too sensitive. That is two protection schemes that were never coordinated with each other, the oldest failure mode in protection engineering and the one it is trained to prevent. Restoration is just as uncoordinated: static UPS systems return quickly once voltage recovers, while diesel rotary systems typically have to be transferred back by hand.
A Protection System That Happens to Compute
This is what the data center industry has not internalized. On paper, a data center is a load. In physics, in the milliseconds after a fault, it is a fleet of protection devices: static transfer switches, UPS logic, breaker trip units, generator controls, thousands per campus, each measuring voltage continuously and each holding a setting that decides when to separate from the source. That is not a load. That is a protection system that happens to compute.
And it was built the way no protection engineer would accept. Coordination is the first thing a protection engineer is taught: grade devices in time and reach so the device closest to the fault operates first and everything upstream holds, define zones, accept a few cycles of delay upstream so the whole system does not clear at once. Thousands of near-identical elements in parallel, with no grading between them and no coordinated restoration, would not survive a design review. That is a fair description of the regional posture today.
None of it was carelessness, and no individual setting was wrong. Data center protection philosophy was written to defend the load in an era when the sector was too small for the grid to notice. A UPS transfers on a sag because the reason it exists is to not ask questions. Thresholds are conservative because a transfer to battery costs nothing and a dropped rack costs everything. Then the sector industrialized, copying reference designs from campus to campus, and correlated design produced correlated tripping.
The record now shows a pattern rather than an incident. NERC’s 2026 State of Reliability report counts two data center customer-initiated load reductions of greater than 1 GW during 2025 alone, with many more above 0.1 GW, and notes that the Electric Reliability Council of Texas’ (ERCOT’s) tally of these events has climbed since 2023 with no sign of improvement. NERC’s conclusion is that as facilities grow and cluster, the events get bigger and start to threaten frequency and voltage stability. Anyone expecting this to resolve itself should note that inverter-based resources followed the same trajectory, through voluntary guidance and reliability guidelines, and ended up under mandatory standards.
The Compliance Calendar
Which is where this is heading, faster than most of the industry realizes. NERC issued a Level 3 “Essential Actions” alert on computational load on May 4, 2026, with responses due Aug. 3, 2026. ERCOT’s Nodal Operating Guide Revision Request (NOGRR) 282 ride-through requirements were approved by the Texas Public Utility Commission (PUC) on July 9, 2026, and took effect Aug. 1, 2026. And on July 16, 2026, the Federal Energy Regulatory Commission (FERC) directed NERC to file new or modified reliability standards for computational loads by Dec. 31, 2026, with registry criteria and a Phase II work plan due March 1, 2027, as shown in Figure 1.

The registry threshold is the number worth circulating. NERC’s draft criteria for a computational load entity currently cover an aggregate connected load of 20 MW or more at a single point of interconnection, at 60 kV or above, hosting 1 MW or more of computational load. That is not a hyperscale-only bar; it reaches well into colocation and enterprise sites whose operators are confident none of this applies to them. The alert also asks planners to collect facility UPS settings, models of the protective devices at the point of common coupling, reconnecting voltage and timing, and ramp rates in both directions. Those settings files are already on someone’s data request.
So, the question is not whether ride-through becomes a requirement. It is whether data centers write those settings or receive them, and the received version already exists. ERCOT’s large load stability studies white paper tells planners that where trip settings are in doubt, they should model those facilities as tripping below 0.75 per unit for 20 milliseconds or longer and not recovering for the rest of the simulation. NERC’s alert illustrates the same idea with a relay set at 0.85 per unit for 30 seconds. Those are the numbers assigned to the load in the absence of anything better, and they are penalizing by design. Both documents also say that a facility justifying its actual capability gets modeled as it truly is. That is the opportunity, and it is available now, without waiting for a standard, as shown in Figure 2.

What Riding Through Actually Costs
The cost is real, and I would not pretend otherwise. Riding through means letting a disturbance reach further into the facility than current design philosophy permits, sharing protection settings with planners, installing fault recorders and handing over the records, commissioning tests that swing voltage 10% in both directions with the compute installed and running, and implementing joint operating procedures with the transmission operator and balancing authority. Some of that is tuning, some is vendor firmware never designed to be adjusted this way, and some is a design change with a multi-year lead time. For a share of the installed base, the honest answer is that the capability is not there, and saying so in a data request is better than having it discovered in a planning study.
Coordination does not stop at the trip, either. NERC flags controlled reconnection as the next problem, because large blocks of load returning without a managed ramp are their own voltage and balancing event. From the generation side, that ramp is the difference between a load that comes back on a schedule you can dispatch against and one that arrives as a surprise while your units are still recovering from its departure. Data centers owe the grid a restore sequence, not just a trip setting.
The Alternative Is Worse
Weigh all of that against the alternative. Every gigawatt-scale event writes the political case against data centers for free, and hands every state already fighting about data center rate impact a reliability argument to stack on top of a cost argument. It also undercuts the bargain the industry is currently trying to strike. FERC has directed six grid operators to justify or reform how they integrate large loads, including service options for loads willing to curtail, and the fastest path to power now runs through that lane. You cannot credibly sell flexibility to a grid operator who has just watched you shed 3 GW without being asked.
Ride-through and flexibility are not two compliance problems. They are the same asset base, the same settings files, and the same commissioning process, pointed in two directions. Uncontrolled, that capability is a reliability event. Coordinated and contracted, it is the fast lane.
So, the data center industry should act like the protection system it already is. Grade settings against the utility practices that actually exist, starting with reclosing sequences, instead of optimizing each building in isolation. Retire counting schemes that latch a campus off the grid for hours. Test against real disturbance signatures, document the ride-through that genuinely exists, and hand the planners something better than 0.75 per unit.
There is a reciprocal ask, and it belongs to the people who run the machines and the wires. Publish the reclosing practice on the circuits feeding these campuses, because no one can grade against a sequence nobody has shown them. Ask for ride-through capability and reconnection ramp rates during interconnection studies rather than defaulting to 0.75 per unit and moving on. And treat a documented data center ride-through curve the way you would treat a generator capability curve: a verified, modeled, contractual number rather than a courtesy.
Alert responses were due Aug. 3. Show-cause responses land Aug. 17. NERC’s standards filing is due Dec. 31. This industry has now proven twice in two years that it can drop gigawatts in under a minute. The next time, it should be because a grid operator asked, and because somebody was paid for it.
—Shalin Savalia is a senior electrical engineer at Amazon Web Services, where he works on data center power systems. He is a Senior IEEE member and an active contributor to the IEEE Power and Energy Society and the IEEE Industry Applications Society. The views expressed are his own and do not necessarily reflect those of his employer.