Wayne Bretherton, Halliwell

Infrastructure: Data centres are racing ahead of the rules built to insure them

Wayne Bretherton, Halliwell

September 21 2026

Data centres have become a defining infrastructure story of the AI era, particularly in the Asia Pacific region. A single hyperscale facility can now draw more than 100MW, and in Malaysia alone roughly 13GW of data centre capacity is either planned or already under development.

Behind every one of those numbers sits a construction and engineering challenge of extraordinary complexity and, for the insurance market, a risk profile that is evolving faster than the tools traditionally used to assess it.

At Halliwell, we work across the full risk lifecycle for data centre operators and their insurers, from pre-loss consulting through to claims. Pre-loss has become the sharper, faster-growing focus. The sector has not yet experienced a major, market-defining insured loss. That is not a reason for complacency, however, and the window to identify and correct design and operational risk is now.

A widening design gap

The core issue is that engineering codes and guidelines are being outpaced by how quickly the technology and demand are evolving. Standards written only a couple of years ago are already lagging behind current build requirements.

Many of the codes in use across the region do not necessarily consider the potential consequences given the layers of hazards being combined within data centres.

We’ve seen this pattern before in other sectors – in New Zealand, for instance, extreme weather has already outpaced the building materials and regulations designed around it.

Data centres risk is following the same trajectory unless the gap between functional need and code is closed early. Given this gap, it is crucial that site and technology-specific safety analyses need to be undertaken.

That gap is compounded by scarce specialist skills and stretched supply chains. Highly specialised contractor expertise is needed to build to the standard these facilities demand.

Fire safety, and the consequences of fire, for example, need to be considered on a site-specific basis. Battery fire consequences can be severe and as yet, are poorly understood.

The co-location of batteries with other fuel sources and a highly sensitive clean environment is not a trivial matter. Critical equipment is similarly short: generators of the scale now needed for the largest facilities are effectively unavailable before 2030. The same constraints apply to operations – maintenance regimes need to keep pace with technology that is still changing rapidly.

Reliability with almost no margin for error

These facilities are engineered for near-total uptime of reliability. For example, annual down time for data centres commonly being required for fault tolerant facilities is as low as around 26 minutes per year, which leaves very little room for design or construction error.

Layered on top of that is a wave of new complexity from the shift toward renewable and hybrid power. Firefighting water run-off is also now a genuine environmental consideration, with the potential to contaminate surrounding land and waterways.

Renewable energy overlays – a growing area of interest in Australia – introduce structural and environmental risks that original design briefs, and in many cases the insurance wording written against them, never

anticipated. Power and water are both under real strain, and while attention tends to gravitate to grid demand, water use for cooling is emerging as just as significant a question.

There are less high-profile, but equally significant, risks that need to be considered. Insulation degradation on copper wiring under sustained heavy load is the kind of slow, hard-to-detect issue that can build for years before it surfaces as a failure, and as an industry, we don’t yet have a clear, shared view of how to identify or price for it.

Nor do we have a clear line of sight on business interruption exposure created by procurement delays: if a design or component issue is identified, sourcing like-for-like replacement parts at scale, given current supply chain lead times, can turn a contained technical issue into an extended period of downtime.

Why the fix has to start at the brief

All of this means risk management must mature at the same pace as the build-out. The most effective lever is not more insurance capacity, but a clear, rigorous functional brief and contractor assurance process that defines acceptable risk before construction starts, and holds to it through delivery.

Underwriting is shifting accordingly: this is increasingly an engineering-led assessment rather than a purely actuarial one, simply because the claims history to support the latter does  not yet exist.

Interest from the insurance market bears this out. In recent conversations with insurers across Asia Pacific, we have seen underwriters actively seeking to understand this exposure well ahead of any loss event forcing the issue.

The operators, insurers and engineers who treat design, contractor assurance and ongoing risk management as one connected process – rather than three separate ones – will be the ones best placed to support this growth.

MORE FROM: Comment
Partner Content