Building AI Data Centres: What's in it for Australia and for AI safety?
7 July 2026 · 2:00 pm–2:25 pm · Refectory
Australia is being discussed as a place to build AI data centres — the infrastructure that trains and runs frontier AI. This talk explores what Australia could gain from hosting AI infrastructure, how it could contribute to the broader goal of AI going well, and some of the difficult questions along the way.
Recording
Audience Q&A
Ask a question or upvote others.
Loading questions…
Transcript
Emily Grundy
You've probably heard quite a lot about the prospect of Australia building AI data centres. This is the physical infrastructure that allows AI to be trained and to run. You may have seen the headline economic figures, the billions of dollars of deals with companies like Amazon, Microsoft, OpenAI. You may have also heard a lot of the pushback against Australia building these data centres. The concerns around environment, water, and community impacts. What I'm going to talk about today is the potential benefits of Australia building AI data centres, and how we can extract the most from those deals.
So I'll flag up front that this is contested territory. There are serious concerns around building this infrastructure. And I just say that if you've come in feeling a bit tense about this idea, you don't have to agree that the potential benefits are worth it. But I think it's at least worth understanding what they might be so you can then weigh that up against the downsides. So this talk I'm going to cover the idea of having a place on the AI value chain and why that matters, how hosting AI infrastructure
that having the physical data centres here could be that for Australia, and what Australia could actually do with it. This is all very high level and a bit simplified, so also just keep that in mind. Before I get into it, I'll also flag a couple of sections as it relates to the International AI Safety Report including systemic risks. The idea of trying to reduce concentration of power and risk management (so Australia having more ability to have oversight over these risks and be able to address them).
So let's start with the idea that AI is not normal technology. I think AI is on track to fundamentally reshape the economy, national security, distribution of power and broadly how we live our lives. I think probably a lot of other people have spoken about this today, so I won't harp on too much, but just a few facts to ground it. We now have models that can outperform teams of expert biologists at various tasks, we have models that can identify thousands of security vulnerabilities in major open-source software, and we have models that are writing most of their own code.
We also see that the investment going into this is pretty enormous. This year alone, I think it was over 650 billion USD. So it's not entirely clear where this leads. But I think when a technology is this consequential, two questions become quite important. One is who gets to use it, and the other is who gets a say in how it's developed. So how does a country like Australia get a say? One answer is by having a greater place in the AI value chain. So this gives others reason to protect your interests.
If you play it right and it gives you something that you can negotiate with. Also the idea of things happening within your jurisdiction: they fall under your laws regarding AI. Maybe having more of a place in the AI value chain could mean you have more of a say in how AI develops and how its risks are managed. It could also mean that you are spreading that power across more countries. So what could Australia's place on the AI value chain be? Obviously here I'm going to say potentially it's having the physical infrastructure located here.
Not all of it, but perhaps a decent portion. So the key point here is that AI developers are looking for places to build this infrastructure beyond the US. There are a few reasons for this. One is that there's increasing demand for their models, so they just need increasing infrastructure to be serving those models to users. They're also coming up against energy bottlenecks in the US. There's political backlash. There's also perhaps reasons to not want all of their compute concentrated in very few jurisdictions. So developers are looking for places to build, and Australia seems like quite an attractive destination.
You've probably heard, like I said before, the investment going into this, I think in 2024, Australia was the second largest destination for data centre investment, just behind the US. So we have a few things that a big buildout needs: we have land, we have renewable energy at scale, and we also have stable government that makes companies more comfortable investing billions of dollars into putting important infrastructure here. Not every country has all of these traits. I'll add here that it's not like we just want to attract all data centres, there is this idea that not all data centres will provide equal value.
So very broadly, you could split this into two. And here again I'm speaking about these frontier AI models. So we have inference data centres. Inference data centres run existing models and they serve them to users so they can be spread out across many sites and so lots of countries might host this infrastructure. On the other hand, you have data centres that enable AI models to be trained. So this involves building the actual models themselves. Training data centres involve large concentrated clusters of chips and a lot of power.
You want these chips to work together as one system, so they need to be relatively close (perhaps not the exact same site, but within the region at the moment). It's far less spread out than inference. And because building that kind of concentration is hard, fewer countries will do this. It's an argument, therefore, that if Australia is able to host AI training, perhaps that would be quite valuable and perhaps more valuable than Australia hosting inference. The analogy my colleague Greg Sadler uses is like petrol stations. He says that inference is like a petrol station: you need lots of them and they need to be spread out (ideally maybe close to users).
Whereas training is like the refinery: it's large, concentrated and there are only a handful. I'll flag there is some pushback to this idea that training could be more important. I've heard some people say that if you host a large enough share of global inference compute then perhaps you'll be an important player, regardless of whether you host training or not. I think my best guess for now is that hosting training will be rarer. Fewer countries will do this, and there are fewer reasons why inference compute needs to be concentrated in one region.
So perhaps it's just harder to be a large player in the inference game. I will stop here to once again flag and emphasise there are real downsides to data centres. These facilities use a lot of energy so if that's not cleanly sourced you can have various environmental impacts and it can add to emissions. If there aren't sufficient conditions in place you can also have noise concerns from the community. And concerns about power prices increasing. Also, if we're talking about training, then at the moment it seems like training models, training frontier AI models in Australia is not viable.
So if you want to enable that, then you have to think about what kind of reforms might be possible. And that has a whole bunch of issues, in itself. So each one of these is a massive issue that I am not getting into today. What I will say is that earlier this year, the government released its expectations of datacentre operators, and that covered at least the first two of these and some other things. Broadly, I think these expectations are on the right track. At the moment, it seems like they're largely voluntary, which I think is not a great thing.
I think we need to be enforcing them. But I do think they're on the right track. I think one thing worth considering when considering the downsides of data centres is that at the moment, it seems like compute is constrained. So the AI chips that you need to train and run these models is limited. What that means when you're thinking about data centres is that potentially an extra data centre in Australia is not an extra one globally. It could be more likely that it's displacing ones that could have been built elsewhere.
So what this means is that if you're building them in Australia, where maybe we have a stronger commitment to renewable energy or higher standards, perhaps that could be better overall. I think this involves thinking about the counterfactual of where otherwise would these data centres actually be built. So that's quite difficult to do. But I do think it's something worth considering. So moving on to what can we actually do if we have data centres here? I think it's all very well and good to say they could get us a place in the AI value chain, but what are we actually going to do with that?
I think one of the most important things that we could be trying to get if we had more leverage, is securing access to frontier AI models. I don't think it will come as a surprise to people when they hear that Australia is not guaranteed access to these models. I feel like if this was two months ago maybe this would be harder to convince people of. We've seen this play out over the past couple of months. We saw it with Mythos, which was deemed so dangerous it could not be released publicly and was released to a select group of organisations that were mostly US based.
The Australian government was not on that list. Saw it again with Fable, which was released publicly for three days before there was a US export directive rescinding that first for foreign nationals (and then for everyone basically). We're seeing it again with OpenAI's 5.6 models, which again, have been rolled out just to a trusted select group of users. So there were a few reasons to expect this to continue to be a problem. One is that, as I said before, compute is limited. It takes a lot of compute to serve these models to users.
Companies or countries may decide that Australia is not a top priority when it comes to that. They may decide to direct the compute elsewhere. Another point is security risks. These models, as we've seen, have some concerns. And so maybe it is right to limit these to a select group of trusted actors. I think that is correct. Whether or not there should be non-US based governments and organisations on that list, I think perhaps goes without saying. And then the third is just in terms of strategic interests, being able to grant or withhold access to these models is a very valuable thing to have.
So my point here is that access is not secure and that that does matter. So we need access to the best. So here I draw a lot on Anton Leicht's work. He'll be speaking tomorrow. I very much recommend reading his work. He talks about how it's not enough to have good AI. You can't afford to fall behind on the best. I think security is a very clear case here. If you think about Mythos, that again, was so good at finding software vulnerabilities it wasn't able to be released publicly.
That kind of capability cuts both ways. The classic dual-use risk. So whoever has access to that kind of capability could be able to find vulnerabilities in systems of national significance. So Medicare or the power grid. If it's a bad actor that has that capability, perhaps they can exploit those vulnerabilities. If it's a good actor, maybe they can find and patch them. I think the same goes not just for cyber capabilities, but also something like biological capabilities. You want the people who are designing vaccines and improving gene synthesis screening to have access to the same, if not more powerful, models than the people who are trying to build biological weapons.
I think the same also goes for the economy and research. If you have citizens and startups and researchers and universities that are using less capable models, and it seems likely that they would just be outcompeted by those who are using more capable models. An important thing to note here is that I'm not saying everyone should have access to every model. I think that would be a disaster if everyone had access to Mythos. What I am saying is that Australia could use leverage to secure different levels of access.
So you can split these into three tiers. Again, drawing on Anton's work. One is commercial access. So trying to ensure that the Australian commercial market has access to the same models that the US commercial market has access to. I don't think this is guaranteed. I think we saw this vaguely with Fable, where it was an export directive that was issued. I think there's reason to believe if you can improve your, know-your-customer requirements or be able to verify whether someone is a US national or not, perhaps this could be more of an issue.
We also have restricted access programs. So this is the idea that specific critical infrastructure industry operators get access to early or more powerful AI models. So this is like what we saw with Project Glasswing. I think with that tier of access you would need to have very specific vetting and very high security. And the third tier is that the Australian government should have access to the same models that the US government has access to, including for defence and intelligence purposes. Now, how or whether you want to secure all these tiers is perhaps like a deeper conversation in itself, but I think we should at least be thinking about the different tiers of access that could be secured that are perhaps not currently secure.
Just to briefly highlight some of the benefits that Australia could negotiate. One is around oversight of AI development and having more of a say in AI development. So here there are a couple of things. One is around visibility and one is around testing. So in terms of visibility, I think there are things that we could be asking for that we're not currently asking for. One is around requiring AI developers to be more transparent about the risks that their models carry and the capability of those models.
And then the other is around requiring them to report serious incidents. And then with testing, I think it'd be very valuable if our AI Safety Institute had pre-deployment testing access to frontier models. Some of these things Australia could already require (it's not like we need to host training or have lots of inference compute here in order to require these things). But I do think that having more leverage could give us more weight, to give more weight behind the things that we're asking for. And especially if we wanted to ask for more.
So, for example, if we wanted more information about what are the models that they're training or to be notified of large training runs. Some other things that might be on the table. This includes having compute reserves for local researchers or startups. And this was also flagged in the data centre expectations the government released. There could be more control of security standards for this infrastructure. And I think there are also some more speculative things that might come of this. For example, if there's an international AI body that's set up to govern AI, and perhaps if Australia hosts a large portion
of global compute, then it has more of a reason to be involved in those conversations. I think the link between having data centres and being involved in things like this, or in international governance conversations, is slightly blurry. So I will say that's a bit more speculative. Touching briefly on how exactly Australia could secure these benefits. One option is to be directly negotiating with these companies as part of their investment. There's also attaching conditions through permitting and planning processes. And there's also just government-to-government relations. So the same way we already share intelligence and defence capabilities through Five Eyes.
We could also be pressing for frontier access. So I've outlined why we might want to have more of a place in the AI value chain and what that could get us. In terms of what we do next, if you do believe that these benefits could be worth it, I think the potential path forward here is not necessarily the default path, and it would require intentional action on two fronts. One is if you believe that having more AI infrastructure here could be good, you need to think about how to get more AI infrastructure here.
And this comes up against, again, some contentious things. Australia is an attractive destination to have this infrastructure, like I said at the beginning, but it is not the only destination. There are other places which have been put forward as the potential for a big data centre buildout, like Norway or Canada. There was a recent report that came out by the Carnegie Endowment, which said that one of the most important things for companies when choosing where to build data centres was time to power. So the time it took to make the data centre operational.
So if you believe that we should be attracting more data centres here, then perhaps streamlining permitting and construction processes is important. Again, this is contentious because if people are already worried that these processes are too rushed in Australia, then I think the question arises of “could this be faster without cutting corners?”. There's also the question of whether we would want to enable AI training here. As I flagged before, it seems like frontier AI training is currently not viable here, and if you do want to make it viable that comes up against our current copyright laws.
Again, I think that's a whole topic in itself, and I think tomorrow Jason Schultz will be speaking about copyright. So if you're interested in that, I would recommend attending his talk. One thing I am genuinely unsure about here (and I spoke to someone about this at lunch) is what portion of global compute is enough to be a significant player. And so I'm very open if anyone has any views on that. So we want to get AI infrastructure here but that is obviously not enough. So to get a whole lot of data centres here is not good unless we can actually make it a good deal.
I think the government, in addition to the current data centre expectations that it's published, needs to try and negotiate these national interest conditions. So this could cover things like securing access to frontier AI. I think the data centre expectations should be enforced. I don't think we can just rely on goodwill in this situation. And obviously, I think that we need to address the downsides, in part because I think these downsides are real and need to be addressed. But I also think if you went full throttle in doing a data centre buildout without addressing these downsides, you would get massive community backlash.
And I think that would thwart the whole thing. And we're seeing this overseas, in particular in the US and elsewhere with various data centre moratoriums. So what I've tried to do today is make the case that a place on the AI value chain is worth having, and that having physical infrastructure could be that for Australia if we attach the right conditions. This is a very murky area. But I think at the moment my best bet is that in the new world that we're stepping into Australia needs some sort of leverage: and hosting AI compute could be that (but only if the government and others
