Data Center Fire Exposes Accountability Gap in Anthropic and Google's Supply Chain
What happened
Investigative reporting by Ars Technica, published September 7 2026, examined The complex corporate web behind a $3.2 billion AI data center following a fire at the Lake Mariner facility in New York. The facility involves at least four distinct corporate entities: TeraWulf as the site owner, Fluidstack as the operator, Google as an anchor customer, and Anthropic as a downstream compute consumer. Investigators found that fire safety infrastructure at the site was materially deficient, including missing alarms, absent suppression systems, and safety documents that were not readily accessible to emergency personnel. None of the four entities had clearly documented responsibility for those conditions. Anthropic had made public commitments regarding ratepayer cost impacts and clean energy use tied to its compute consumption, but the reporting found no verification mechanism confirming those commitments applied to or were enforceable at this third-party leased site.
Why it matters
- ·Physical AI infrastructure is now a supply chain governance surface: when a data center fire injures workers or triggers regulatory scrutiny, the frontier AI company whose compute runs there may face reputational, legal, and regulatory exposure even if it has no operational control over the site.
- ·Voluntary commitments made about leased third-party infrastructure, such as Anthropic's ratepayer and clean energy representations, carry ESG and investor disclosure risk if they cannot be verified or enforced, particularly as regulators increase scrutiny of AI-related sustainability claims.
- ·The diffuse accountability structure revealed at Lake Mariner, where no single entity among four corporate layers owned safety compliance, is a textbook third-party concentration risk that standard vendor due diligence frameworks rarely extend to physical compute infrastructure.
Governance controls affected
What to do now
- ☐Map your organization's AI compute dependencies at least two tiers deep, identifying whether the data centers your AI vendors use are owner-operated or subcontracted to third parties.
- ☐Review any public or investor-facing AI sustainability, safety, or ratepayer commitments your organization has made and confirm whether contractual verification mechanisms exist at each facility tier covered by those commitments.
- ☐Extend your vendor due diligence questionnaires to require frontier AI providers and compute vendors to disclose the identity and safety certification status of their upstream data center operators.
- ☐Assign explicit ownership of physical AI infrastructure risk within your third-party risk management program, distinguishing between software-layer vendor risk and compute-layer facility risk.
- ☐Request evidence of fire safety compliance and environmental certifications directly from compute facility operators named in your AI vendor agreements, not solely from the vendor with whom you have a contract.
What to watch next
Regulators in New York and at the federal level are increasingly scrutinizing AI data center permitting, environmental impact, and worker safety, a trend the EPA rule change on public participation in AI data center permitting has already brought into focus. Compliance teams should monitor whether state attorneys general or OSHA use the Lake Mariner incident to assert jurisdiction over AI infrastructure safety, which could create new disclosure or corrective-action obligations for compute customers, not just operators. The incident also increases the likelihood that investor ESG disclosure frameworks will begin requiring companies to document the governance structure of their physical AI supply chains, not just their software vendors.
Stay ahead of stories like this
Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.
