August 21, 2026 · Issue 5 · 5 min read
Pennsylvania put AI data centers behind a local veto, and Broadcom went looking for $100 billion anyway
On Tuesday, Governor Josh Shapiro signed Executive Order 2026-05(opens in a new tab), which removes every artificial intelligence data center proposal from Pennsylvania's Permit Fast Track Program and states that data centers will not be considered for it in the future. The Department of Environmental Protection will not issue a permit until the developer has executed a legally binding consent order committing to the state's GRID requirements, attended a mandatory pre-application meeting, and secured all required local approvals first. If the township says no, the state says no. Nondisclosure agreements on these projects are no longer permissible.
The GRID terms are the part that changes the arithmetic. Developers must pay the full cost of the new generation, transmission, and distribution their project requires, without shifting that cost to Pennsylvania households and businesses. They must sign community benefit agreements, hire locally, and meet water conservation standards. What is being withdrawn is the implicit ratepayer subsidy that made some of these sites pencil out. What is being added is a local approval step with no fixed clock on it, and a transparency rule that means the terms of the next site are public before it is built rather than after.
Two days later, Broadcom was reported to be seeking more than $60 billion in debt(opens in a new tab) to finance AI chips for Anthropic and other buyers. The structure under discussion is a senior secured tranche of roughly $60 billion to $70 billion, which Broadcom would partly guarantee, plus a junior tranche near $30 billion, issued through a special purpose vehicle with Blackstone and Apollo in talks to participate. Close to $100 billion, against chips that have not shipped, for capacity that has not been sited.
Read those two together, because they point the same direction. Siting costs are rising at the state level and the buildout is being financed with borrowed money at the vendor level. Debt carries a coupon and a maturity. Equity carries neither. Capacity funded this way has to be sold at a price that services the debt on the lender's schedule, not on the schedule where an enterprise finishes proving out its pilots. Any three-year plan that assumes inference prices keep falling on their own is forecasting against a capital structure that now requires the opposite.
Two of the month's sharpest security stories sat in that same layer. CISA gave federal civilian agencies three days to patch a 9.4-severity flaw in Ray, the framework that schedules distributed training jobs, and researchers documented a four-day intrusion campaign in Taiwan run by agents built on freely available open source frameworks. Neither was a model failure. Both were failures in the plumbing that most AI risk registers cover with a single line.
Researched and drafted by an automated workflow, then reviewed and edited by a human editor before publication. Every source is linked. See how we use AI here.
Pennsylvania is one state, and a single executive order can be undone by the next governor. The reason to read it anyway is that it is the first version of a template, and templates travel. Every provision in it answers a complaint that has already been raised in a dozen other states: who pays for the substation, who decides, and why the terms are secret.
So the question for whoever owns the AI capacity plan is not whether Pennsylvania matters. It is which of the sites in the current forecast sit in jurisdictions where a local board now has an effective veto, and what the plan does if two of them slip by eighteen months.
The question for the CISO is smaller and more immediate. Ray is probably running somewhere in the estate, installed by a data science team rather than by platform engineering, and the patch deadline that applied to federal agencies has already passed.
Also worth knowing
- Pennsylvania pulls every AI data center out of its fast track permit program(opens in a new tab)
Commonwealth of Pennsylvania
Executive Order 2026-05 conditions state permit review on a binding consent order, full cost recovery for new power, and prior local approval. It also bars nondisclosure agreements on these projects.
- CISA gave federal agencies three days to patch a critical flaw in the Ray AI framework(opens in a new tab)
The Hacker News
CVE-2025-62593 rates 9.4 and allows remote code execution against Ray dashboards through DNS rebinding. Ray schedules training jobs, so the exposure is the ML platform rather than any model.
- Near-autonomous AI agents ran a four-day campaign against Taiwan's nuclear safety agency(opens in a new tab)
The Register
Twelve waves compromised 85 government accounts and took more than 2,500 personnel records, run on open source Hermes and OpenClaw agents. That tooling is commodity and already in other hands.
- Broadcom seeks more than $60 billion in debt to finance AI chips for Anthropic(opens in a new tab)
Reuters
A senior secured tranche of $60 billion to $70 billion plus a junior tranche near $30 billion, through a special purpose vehicle with Blackstone and Apollo. Compute capacity now carries a coupon.