Somewhere on the outskirts of a mid-sized American city, behind a fence of black steel and cameras with no visible brand markings, sits a building of tremendous and deliberate ordinaries. It has no windows. Its parking lot is half-empty. A low mechanical hum radiates through its cinder-block walls — the sound of ten thousand servers breathing in unison, drawing power and expelling heat in an endless industrial metabolism. Precision cooling systems push chilled air through raised floors at regulated temperatures. Indicator lights blink in rhythmic patterns across rack after rack of hardware, each unit quietly processing what the modern world has decided to call “the cloud.” The air smells faintly of electricity. Nobody who does not need to be there ever is.
This is a data center. There are thousands of them scattered across the planet, from the suburbs of Northern Virginia — which alone handles an estimated 70 percent of global internet traffic exchange — to rural Oregon, to the outskirts of Dublin, to the industrial fringes of Singapore and Shanghai. Together they form the nervous system of modern civilization: the invisible backbone through which photographs are stored, financial transactions are cleared, social media posts are routed, and the streaming of films is made possible. They are, by virtually every official account, neutral utilities — the digital equivalent of water towers or electrical substations, serving the public interest without agenda or intent.
That account is not exactly wrong. But it is radically incomplete. Because beneath the mundane reality of cloud storage and content delivery lies a deeper architecture — one of surveillance, behavioral modeling, geopolitical weaponry, and monopolistic control — that has no real precedent in human history. Every WiFi signal, every connected device, every digital interaction feeds an ever-expanding network that quietly maps the movements, habits, purchasing behaviors, political sympathies, and intimate lives of billions of people. And the physical infrastructure enabling all of it — those vast, windowless buildings and their blinking lights — sits at the center of a power structure so entrenched, so profitable, and so deeply embedded in both government and corporate interest, that most of the public has never been invited to look directly at it.
This report invites you to look.
SECTION I: THE COVER STORY — WHAT WE’RE TOLD
The official narrative about data centers is not a lie — it is a carefully curated partial truth, polished to a consumer-friendly shine. Amazon Web Services, Google Cloud, and Microsoft Azure together spend billions each year communicating a version of reality in which data centers are benevolent infrastructure: the place your vacation photos live, the system that runs your company’s email, the engine behind your favorite streaming service. And this is all, in a technical sense, accurate. Data centers do store photos. They do run apps. They are, genuinely, the physical substrate of the modern internet.
But this framing obscures something fundamental. It treats the infrastructure as neutral — as a passive container for digital life, rather than an active participant in it. A water tower holds water. A data center does not merely hold data. It processes it, analyzes it, routes it, sells access to it, and — as over a decade of documented evidence now confirms — shares it, under specific legal circumstances, with government intelligence agencies. The water tower does not know who you are. The data center almost certainly does.
The cover story also omits scale. When the public thinks of “the cloud,” it imagines something ambient and ethereal — a kind of digital atmosphere. The reality is profoundly physical. The International Energy Agency estimated that data centers consumed approximately 415 terawatt-hours of electricity globally in 2024, roughly 1.5 percent of all electricity used on Earth. By 2030, that figure is projected to nearly double, rising to approximately 945 TWh — representing close to 3 percent of total global consumption, driven in large part by the explosive energy demands of artificial intelligence workloads. These are not incidental utilities. They are among the largest, fastest-growing, and most strategically significant infrastructure assets on the planet.
|
By 2030: Global data center electricity consumption is projected to reach 945 TWh — nearly double 2024 levels — according to the International Energy Agency. AI-focused facilities are expected to triple their power draw within the same period. |
SECTION II: THE SURVEILLANCE ARCHITECTURE — WHAT THE DOCUMENTS REVEAL
On June 6, 2013, two of the largest newspapers — The Guardian and The Washington Post — published a series of documents that fundamentally altered the public’s understanding of digital infrastructure. The source was Edward Snowden, an NSA contractor then employed by Booz Allen Hamilton. The documents revealed, among much else, the existence of a clandestine surveillance program known as PRISM.
PRISM, which had been operating since 2007 under the authority of the USA Patriot Act and later the FISA Amendments Act of 2008, allowed the National Security Agency to collect stored internet communications — including the contents of emails, file transfers, live chats, and search histories — directly from the systems of America’s largest technology companies. The leaked briefing materials identified the participating firms in chilling specificity: Microsoft (2007), Yahoo (2008), Google (2009), Facebook (2009), YouTube (2010), AOL (2011), Skype (2011), and Apple (2012).
The companies, almost uniformly, denied having granted the government “direct access” to their systems — a carefully worded denial that did not contradict the substance of what had been revealed. What the briefing documents made clear was the extraordinary depth of the program’s reach. One detail, buried in the speaker’s notes of an NSA PowerPoint presentation reviewed by The Washington Post, stood out with particular force: “98 percent of PRISM production is based on Yahoo, Google, and Microsoft.” Three companies. The majority of American digital communication. A single classified program.
|
The legal architecture enabling this has only grown more expansive since Snowden’s revelations. In 2024, Congress passed the Reforming Intelligence and Securing America Act (RISAA), which reauthorized and significantly amended Section 702 of FISA. Among its most contested provisions was an expanded definition of who qualifies as an “electronic communication service provider” — language that critics warned could potentially extend NSA data demands to a far broader class of businesses: hotels, data storage facilities, equipment maintenance companies, and others whose services touch digital communications infrastructure. The surveillance net, already vast, was handed a wider casting arm. Congress also expanded the types of information the government could acquire under Section 702 to include intelligence related to international drug trafficking — a mission creep that has alarmed civil liberties advocates across the political spectrum.
The data centers, in this framework, are not passive. They are the physical sites where surveillance intersects with commerce. The servers humming behind those unmarked walls are not just storing your photographs. They are, under the right legal conditions, open windows into the lives of hundreds of millions of people.
SECTION III: THE AI ENGINE — BEHAVIORAL PROFILING AT POPULATION SCALE
If surveillance was the first great secret of data center infrastructure, artificial intelligence is rapidly becoming the second — and in many respects the more consequential of the two. Because modern data centers are not merely storing and retrieving information. They are processing it, at a scale and speed that was inconceivable even a decade ago, to build predictive models of human behavior that operate not just at the individual level, but at the level of entire populations.
Every search query submitted to a major search engine, every product purchased online, every social media post written or merely hovered over, every location signal emitted by a connected device — these are not simply logged and filed. They are fed into machine learning systems that construct increasingly granular psychological profiles of each user. These profiles encode not merely what a person has done, but what they are statistically likely to do next: what they will buy, which political message will resonate with them, when they are most anxious, what kind of content will keep them engaged longest. This is not speculation. It is the documented business model of the world’s largest technology companies, refined over two decades of iterative development.
Large language models — the engines behind generative AI systems now embedded in search engines, productivity tools, legal software, and healthcare platforms — are trained across geographically distributed data center infrastructure, drawing on datasets of almost unimaginable breadth. The model learns not from any single person’s data, but from the aggregate behavioral record of the internet as a whole: billions of interactions, compressed into statistical weights that encode the patterns of human thought and communication. The training process requires extraordinary computational resources. A single major model training run can consume enough electricity to power a small town for months.
|
What AI training requires: Geographically distributed data centers running at near-maximum capacity for weeks or months. The U.S. Department of Energy has established dedicated AI testbeds within federal data center infrastructure to develop next-generation machine learning capabilities — blurring the line between private compute and national security apparatus. |
The Department of Energy has established AI testbeds within federal data center infrastructure, explicitly developing machine learning systems for national security and scientific applications. The boundary between the private AI economy and the government surveillance apparatus is not, in practice, a bright line. It is a gradient — and it has been narrowing for years.
SECTION IV: THE GEOPOLITICAL WEAPON — DATA AS NATIONAL POWER
There is a reason that data centers now appear on the same classified strategic asset registries as power grids, military installations, and telecommunications backbone infrastructure. The ability to store, process, and control information at scale is no longer merely an economic advantage. It is a dimension of national power — as real and as consequential as the possession of aircraft carriers or nuclear deterrents.
The contest between the United States and China for data center supremacy is one of the defining geopolitical competitions of the present era. Both nations have made massive state-directed investments in compute infrastructure, driven by the understanding that control over artificial intelligence development — which requires vast computational resources housed in data centers — increasingly determines leadership in economic innovation, military capability, and intelligence operations. China’s East-to-West Computing initiative, which routes data center construction toward its western provinces, is explicitly framed as a matter of national security and economic sovereignty.
Within the United States, the geographic concentration of this infrastructure has become its own strategic vulnerability. Northern Virginia — a single cluster of counties proximate to Washington, D.C. and the CIA’s Langley headquarters — handles nearly 15 percent of the world’s entire hyperscale data center capacity, according to Synergy Research Group analysis. This single region accounts for more hyperscale capacity than any other location on Earth, including Beijing. The top five U.S. data center clusters — Northern Virginia, Texas, Georgia, Oregon, and Iowa — together account for the majority of the nation’s compute capacity. This concentration creates obvious single points of failure, whether from physical disruption, cyberattack, or extreme weather events increasingly likely in a period of climate instability.
|
The United States government has responded to this reality with a combination of investment and classification. Data center infrastructure has been formally designated as critical national infrastructure. Federal agencies are among the largest consumers of data center capacity in the world. And the line between what is “private” hyperscale compute and what is de facto national security infrastructure has become, in practice, nearly impossible to draw.

SECTION V: THE CORPORATE MONOPOLY — WHO REALLY CONTROLS THE FLOW
Four companies — Amazon Web Services, Microsoft Azure, Google Cloud, and Meta — operate nearly 500 self-built data center facilities across the United States alone, with an additional 530-plus buildings announced or under active construction. Together, AWS, Azure, and Google Cloud account for approximately 60 percent of all global hyperscale capacity. This is not a competitive market in any meaningful traditional sense. It is an oligopoly — a small number of private entities exercising control over the infrastructure through which the majority of human digital activity flows.
The consequences of this concentration extend far beyond technology. These companies monetize the behavioral data that flows through their infrastructure in ways that now penetrate virtually every sector of modern economic and political life. Advertising targeting, built on granular behavioral profiles, generates hundreds of billions of dollars annually. Financial modeling firms purchase behavioral data to build predictive risk models. Political campaigns use micro-targeting systems built on the same data pipelines to identify and manipulate persuadable voters. Corporate intelligence operations purchase behavioral analytics to monitor competitors, track consumer sentiment, and identify regulatory risks.
What is rarely discussed is the extent to which this private power infrastructure has been built, in part, with public money. State and local governments across the United States have extended extraordinary incentives to data center operators — including tax abatements, discounted land, subsidized energy rates, and accelerated permitting — in exchange for facilities that create relatively few local jobs while generating enormous profits captured almost entirely by distant shareholders. Virginia, the world’s data center capital, has provided hundreds of millions of dollars in tax exemptions on data center equipment purchases. The taxpayer, in effect, helps fund the construction of the infrastructure that monitors them.
SECTION VI: THE ENVIRONMENTAL LEVERAGE — ENERGY AND WATER AS POWER
The environmental footprint of data center infrastructure is, in itself, a form of power. The International Energy Agency confirmed that data centers consumed 415 TWh of electricity in 2024 — approximately 1.5 percent of all global electricity consumption — with AI-driven growth pushing that figure sharply upward. Electricity demand from data centers surged by 17 percent in 2025 alone, vastly outpacing the 3 percent growth in overall global electricity demand. By 2028, AI data center energy draw is projected to rise as much as fourteen-fold compared to current levels, potentially accounting for 12 percent of total U.S. electricity consumption.
This energy demand is already reshaping local power markets in ways that directly affect ordinary consumers. In Virginia — where Dominion Energy has repeatedly warned regulators that data center electricity demand is growing faster than almost any previous industrial expansion in state history — electricity prices have risen at rates significantly above general inflation. The $1 trillion in combined AI infrastructure capital expenditure projected for 2026 by the major hyperscalers represents a resource extraction event with consequences that ripple through supply chains, local energy markets, and household utility bills.
Water consumption is the other environmental lever seldom discussed in the context of data center power. Cooling is the single largest non-computational energy use in major facilities. In 2025, roughly 30 percent of data center electricity consumption — more than the total annual power consumption of Sweden — went exclusively to cooling. Google alone consumed approximately 31 billion liters of water across its global data centers in 2024. The siting of data centers near high-voltage transmission lines and abundant water sources is not merely logistical convenience. It represents a structural claim on critical natural resources — one that, as these facilities scale dramatically in the AI era, will increasingly place them in tension with agricultural, municipal, and ecological water demands.
|
Water consumed by Google’s global data centers in 2024: 31 billion liters — enough to fill more than 12,000 Olympic swimming pools. The figure is rising with every new GPU cluster commissioned for AI training. |
SECTION VII: THE BOTTOM LINE — CENTRALIZED DATA IS CENTRALIZED POWER
Step back from the individual revelations — the PRISM slides, the FISA amendments, the energy statistics, the market concentration figures — and a coherent architecture becomes visible. The internet, as it has actually been built, is not a distributed network of equals. It is a profoundly centralized system, in which the data generated by billions of people flows upward into a small number of physical facilities controlled by a small number of institutions, subject to a legal framework that is deliberately elastic, operating under economic incentives that are fundamentally misaligned with the interests of the people whose data they hold.
This architecture was not inevitable. The early internet was, genuinely, more distributed — a network designed, famously, to route around damage, to have no single point of control. What transformed it into its current form was a combination of economic gravity, deliberate policy choices, and the network effects that reward consolidation in digital markets. The result is a world in which the most intimate records of human life — our communications, our movements, our desires, our fears, our political beliefs, our medical conditions, our financial anxieties — are concentrated in facilities operated by four American technology companies and accessible, under defined legal conditions, to government intelligence agencies.
The word “cloud” was always a marketing decision. The data does not float. It sits, in specific buildings, on specific servers, in specific counties, subject to specific laws and specific business interests. Understanding that is not paranoia. It is geography.
|
Layer of the System |
What It Really Is |
|
Cloud Storage |
The cover story sold to the public — a consumer-friendly abstraction that conceals the full scope of what data centers do and who they serve |
|
Surveillance Collection |
Government-accessible intelligence pipelines — legally mandated under FISA Section 702 and expanded by RISAA in 2024, channeling communications data to NSA and FBI |
|
AI Training Engines |
Behavioral profiling at population scale — building predictive psychological models of individuals and entire populations from decades of accumulated interaction data |
|
National Security Assets |
Classified critical infrastructure — designated at the same strategic level as power grids and military installations, at the center of the U.S.–China geopolitical competition |
|
Economic Power Tools |
Corporate monopolies over information flow — four companies controlling ~60% of global hyperscale capacity, monetizing behavioral data across advertising, finance, and politics |
|
Environmental Leverage |
Structural claims over energy and water — consuming 1.5% of global electricity and tens of billions of liters of water annually, with resource demands accelerating sharply |
SECTION VIII: THE FUSION CENTER CONNECTION — WHERE DATA BECOMES ACTION
Data centers and fusion centers are two halves of the same surveillance machine. They are rarely discussed together — and that separation, whether by design or institutional convenience, is itself instructive. The data center is the storage and processing layer: the vast, humming infrastructure in which the raw material of modern surveillance is collected, organized, and held. The fusion center is the analysis and action layer: the point at which that raw material is transformed into intelligence products, correlated with other datasets, and handed off to law enforcement and federal agencies for real-world use. Together, they form a seamless pipeline stretching from the WiFi router in your kitchen to the agent at the door.
Understanding this connection requires holding two realities simultaneously. The first is legal: at every step of the pipeline, the data moves through mechanisms that have been authorized by statute, blessed by courts, or insulated by administrative policy. The second is practical: the cumulative effect of these individually legal steps is a system of population-level surveillance whose scope would have been unrecognizable — and almost certainly impermissible — to the drafters of the Fourth Amendment. The machine does not need to break the law. It was built to operate inside it.
What Is a Fusion Center?
Fusion centers were created in the immediate aftermath of the September 11 attacks, authorized under the USA PATRIOT Act and formally institutionalized by the Implementing Recommendations of the 9/11 Commission Act of 2007. Fusion centers were designed to be the connective tissue — the institutional mechanism through which information could flow freely between federal, state, local, tribal, and private sector partners.
There are currently 80 fusion centers operating across the United States — one in nearly every state and in most major urban areas. They are funded, technically supported, and partially staffed by the Department of Homeland Security, which describes them as the hub of the two-way intelligence and information flow between the federal government and its State, Local, Tribal, Territorial, and private sector partners. Each center receives federal grants, access to classified databases, and in many cases embedded DHS and FBI personnel. They are, in institutional terms, the domestic intelligence network that the United States officially does not have.
The Physical Infrastructure Link
Fusion centers do not operate in isolation from data center infrastructure — they depend on it entirely. They do not maintain significant local data storage. Instead, they pull from and push to a network of commercial and government data centers that host the intelligence-sharing platforms on which the entire fusion center ecosystem runs. The primary data-sharing backbone of the network is the Homeland Security Information Network-Intelligence (HSIN-Intel) platform — a classified and sensitive-but-unclassified information-sharing environment hosted on federal cloud infrastructure, contracted to and operated through government and commercial data center facilities. Every intelligence product generated by a fusion center — every Suspicious Activity Report, every threat assessment, every bulletin distributed to law enforcement partners — flows through that infrastructure. The data center is not incidental to the fusion center’s function. It is the circulatory system through which the fusion center’s intelligence moves.
Fusion Centers Formally Purchase Commercial Data
This is the critical link that most public discussions of surveillance consistently miss. Fusion centers are not limited to government-generated intelligence. They are explicitly authorized — and in DHS guidance, actively encouraged — to integrate private sector data through Memoranda of Understanding and non-disclosure agreements with commercial entities. This means they legally purchase and access data that lives in commercial data centers operated by the same companies that power the consumer internet. The categories of commercially acquired data flowing into fusion centers include: social media monitoring platforms that aggregate and analyze public and semi-public posts at scale; Automated License Plate Reader (ALPR) databases — including Flock Safety’s TALON network, which shares plate-reader data across virtually all subscribing law enforcement agencies nationally; commercial data brokers that aggregate location history, financial patterns, and behavioral profiles assembled from app data, loyalty programs, and retail tracking; facial recognition databases cross-referenced against billions of stored images from social media, government ID systems, and security camera networks; and IoT sensor data drawn from smart devices, municipal traffic monitoring systems, and acoustic gunshot-detection infrastructure embedded in urban environments.
Every one of these data streams originates in, or flows through, commercial data center infrastructure before it reaches a fusion center analyst’s screen. The legal mechanisms enabling this access to vary — some data is purchased outright; some is shared under cooperative agreements; some flows through automated feeds — but the commercial data center is, in every case, the origin point. The distinction between “private” data and “government” intelligence, at this layer of the architecture, has ceased to be operationally meaningful.
Real-Time Crime Centers — The Live Bridge
Between the data center and the fusion center sits another layer of infrastructure that has proliferated with remarkable speed and remarkably little public debate: the Real-Time Crime Center (RTCC). RTCCs are the live operational bridge — facilities, typically operated by municipal police departments, that aggregate surveillance streams in real time and route processed intelligence upward to fusion centers and, through them, to federal agencies. A functioning RTCC pulls live CCTV feeds from municipal camera networks, ALPR data updated by the second, gunshot-detection alerts from acoustic sensor arrays, active 911 call data, and body camera footage from officers in the field. Critically, they also pull from private camera networks — registered by businesses, schools, homeowners, and residential associations — without requiring individual warrants, typically under voluntary sharing agreements that residents are rarely aware they have entered into.
The commercial platforms powering this infrastructure are a small and increasingly consolidated set of vendors. Palantir Gotham provides data integration and analytical tooling used by dozens of major municipal and federal agencies. Fusus — acquired by Axon, the body camera manufacturer, in 2024 — operates a camera-registration and live-feed platform deployed across hundreds of jurisdictions. Flock Safety’s FlockOS operates the largest private ALPR network in the country, with data retention and sharing policies that route plate reads to any subscribing law enforcement agency regardless of geographic jurisdiction. Motorola Command Central provides integrated dispatch and intelligence platforms to police departments across the country. Every one of these platforms stores and processes its data in commercial cloud data centers — the same infrastructure that hosts your email, your streaming service, and your cloud-synced photographs.
The Documented Abuses
“The National Network of Fusion Centers is the hub of much of the two-way intelligence and information flow between the federal government and our State, Local, Tribal and Territorial and private sector partners.” — Department of Homeland Security, Official Fusion Center Program Description
The concern with this architecture is not theoretical. It has a documented record of misuse that runs from the program’s earliest years through the present. In the years following September 11, fusion centers were used to conduct systematic surveillance of Muslim American communities — mapping mosques, monitoring community organizations, and building intelligence files on individuals who had committed no crime and were suspected of none. A 2012 bipartisan Senate investigation found that many fusion center intelligence reports were “irrelevant, useless or inappropriate” and that the program had repeatedly violated the civil liberties of American citizens.
During the protests following the murder of George Floyd in 2020, fusion centers across the country classified constitutionally protected assembly and speech as terrorism indicators, routing intelligence about protesters to federal agencies. The American Civil Liberties Union filed a FOIA lawsuit in July 2024 seeking records on how fusion centers and Joint Terrorism Task Forces (JTTFs) monitored protesters and communities of color and followed with a federal court lawsuit in February 2025 after the government failed to produce responsive documents. Particularly troubling is the documented fact that local sanctuary policies — adopted by cities and counties to limit cooperation with federal immigration enforcement — provide no protection against ALPR data, facial recognition results, and camera footage flowing to federal agencies through fusion center channels. The data moves regardless of local policy. The pipeline does not respect municipal boundaries.
The Complete Surveillance Pipeline
Assembled in sequence, the architecture looks like this — and it is worth sitting with the full picture, rather than examining any single component of it in isolation:
YOUR DIGITAL ACTIVITY → Commercial Data Centers (Google, AWS, Microsoft, Meta) → NSA / PRISM Collection Points (FISA Section 702, CLOUD Act, RISAA 2024) → Real-Time Crime Centers (Palantir, Fusus, Flock Safety, Motorola) → Fusion Centers — 80 Nationwide (DHS-funded analysis and correlation hubs) → FBI / ICE / DEA / Military Intelligence (Federal action layer) → REAL-WORLD CONSEQUENCES (Arrests, deportations, watchlists, no-fly lists, targeted disruption)
The architecture was not accidental. It was designed — through decades of incremental legal construction, technology procurement, and interagency agreement — so that no single law would need to be broken at any step. The data flows legally from commercial infrastructure to government intelligence to law enforcement action. Each handoff is covered by statute, regulation, or policy. What none of them are required to explain, and what is almost never examined in aggregate, is what the full chain produces: a surveillance apparatus of extraordinary reach, operating on the daily lives of the American public, with no single point of accountability and no obvious off switch.
What does an individual do with this knowledge? The honest answer is: not enough — and also, more than nothing. Awareness of the architecture is not a solution. But it is a precondition for one. The systems described in this report were built incrementally, through thousands of small decisions made by legislators, executives, engineers, and investors — most of whom never paused to ask what kind of world they were assembling. They can, in principle, be reformed through the same iterative process. Through legislative oversight that is genuinely adversarial to surveillance overreach. Through antitrust enforcement that takes information concentration as seriously as price-fixing. Through data minimization requirements that make behavioral profiling economically unviable. Through public investment in distributed infrastructure that does not route all human communication through a handful of private chokepoints. None of this is easy. All of it begins with the same first step: refusing to accept the cover story. The servers are not neutral. The cloud is not a cloud. And the most consequential infrastructure ever built was never really built for you.
Sources & References:
International Energy Agency, Energy and AI (2025); IEA Press Release, April 2026; NSA PRISM Program documentation via The Washington Post / The Guardian (2013); Congressional Research Service, FISA Section 702 and the 2024 Reforming Intelligence and Securing America Act (R48592, July 2025); Synergy Research Group Hyperscale Datacenter Analysis (2024); Aterio U.S. Hyperscaler Buildout Dataset (2025); 24/7 Wall St., AI Infrastructure Energy Cost Analysis (May 2026); New Atlas, University of Illinois Urbana-Champaign copper-plate cooling research (May 2026); Privacy International, PRISM surveillance documentation (2013); The Register, Northern Virginia Hyperscale Datacenter Capital (August 2024).
This EliteInfo report was compiled and published in May 2026. All statistics reflect the most current publicly available data at time of publication.























