Issue 6 Q2 2026
FEATURING
Energy transition in the age of global disruption
Rebecca Armstrong Partner, London
Introduction It is my pleasure to introduce the second edition of Risk Quarterly, a publication designed to provide insights on the ever-changing risk landscape and its implications for business. Risk Quarterly draws insights from our annual Corporate risk radar report, featuring perspectives from Clyde & Co lawyers globally on the key risk areas that are top priorities for C-suite executives, in-house legal teams, and claims departments. With 71% of businesses using genAI in at least one business function, this edition reframes the AI conversation by exploring a less discussed but critical perspective: the risks of not adopting AI, using it as a cornerstone of any future-proofed strategy. We also explore the transformation of HR through AI. Also in this issue, we look at the insurance risks of green technologies, the latest developments in cyber risk, the rise and cost of obesity drug use and the global impact of shifting tariffs. At Clyde & Co, we believe that nobody handles risk like we do, bringing to life the legal expertise we have managing emerging risk and handling new commercial complexities borne out of nearly a century operating at the heart of global commerce. We hope you find real value in this edition. If there are topics or themes you would like to see covered in future editions, please let us know at riskquarterly@clydeco.com.
Introduction I am pleased to introduce the sixth edition of Risk Quarterly, our global publication focused on the strategic risks shaping your business in an increasingly interconnected and resource-constrained world. This edition explores how geopolitical disruption, the energy transition, digital infrastructure and emerging technologies are reshaping the global risk landscape. Against a backdrop of geopolitical instability, shifting regulation and increasing pressure on energy security, organisations must balance decarbonisation with resilience, affordability and long-term competitiveness. At the same time, rapid digital expansion is creating new dependencies between energy systems, infrastructure capacity and emerging technologies.
Recent disruption across key energy corridors has reinforced the importance of energy security, resilient supply chains and diversified investment strategies, accelerating changes that were already underway. From the evolving energy transition and the renewed role of nuclear power, to the risks and opportunities associated with next generation technologies such as small modular reactors, we explore how organisations are navigating competing priorities around energy security, investment and decarbonisation. We also examine grid access and connections reform, alongside the practical realities of delivering large-scale oil and gas projects, including the limitations of contractual protections such as suspension rights and liquidated damages. Insights from our latest Corporate Risk Radar add context on how organisations are prioritising these challenges and where we are seeing risk shift. A central theme of this issue is the rise of data centres as critical infrastructure. As artificial intelligence (“AI”) drives significant demand for power and processing capability, we explore the tension between energy use and sustainability goals, alongside insurance and valuation considerations, operational resilience, and growing competition for grid capacity. We also consider how project models are evolving, including disaggregated procurement, and what that means for delivery risk. For other sectors, we examine how technological and systemic pressures are reshaping risk. This includes the impact of AI on maritime workforces, disruption across aviation supply chains, and the regulatory challenges emerging as the commercial space sector expands. We also consider a range of emerging risks, from next generation nuclear and the implications for insurance, to the growing impact of social media related harms, developments in cyber risk and operational resilience, and outlooks for insurance market growth. Across these topics, one point stands out: today's risks are increasingly interconnected across geopolitics, energy systems, physical infrastructure, digital technologies and regulation. Events in one region or sector can rapidly reshape markets, supply chains and investment decisions elsewhere. Understanding and managing these interdependencies will define how successfully organisations navigate uncertainty and build long-term resilience. We hope you find this edition useful and thought-provoking. Thank you to all our contributors. If there are topics you would like to see explored in future issues, please contact us at riskquarterly@clydeco.com.
Scroll down
Energy transition
By CHRISTOF RÜHL
Senior Research Scholar, Columbia University
For businesses, this is not a matter of ideology. Rather, they must keep abreast of the complex risks flowing from an energy transition entangled in national security concerns, strategic competition, and stressed supply chains.”
Energy Transition and Energy Security
QUOTE
Click photo to find out more
Energy Institute. (2025, June). Statistical Review of World Energy 2025. Energy Institute.https://www.energyinst.org/statistical-review Cavina, T., Moavero Milanesi, L., Samandari, H., Tai, H., & Winter, R. (2023, August 8). Five Key Action Areas to Put Europe’s Energy Transition on a More Orderly Path. McKinsey & Company.https://www.mckinsey.com/capabilities/sustainability/our-insights/five-key-action-areas-to-put-europes-energy-transition-on-a-more-orderly-path Intergovernmental Panel on Climate Change (IPCC). (2018, October 8). Global Warming of 1.5°C: An IPCC Special Report. IPCC. https://www.ipcc.ch/sr15/ Net Zero Tracker. (2025, September 22). Net Zero Stocktake 2025: Assessing the Status and Trends of Net Zero Target Setting. Net Zero Tracker.https://zerotracker.net/analysis/net-zero-stocktake-2025
Reference list
MEET THE AUTHORS
Christof Rühl Senior Research Scholar, Columbia University
in the age of global disruption
Introduction
To some extent, this faltering momentum is the result of economic and technological obstacles. But the world has also become a much more volatile place. Energy markets have been at the epicentre of recent disruptions: wars, sanctions and the weaponisation of energy are reshaping the political and economic environment in which the transition unfolds.
“For businesses, this is not a matter of ideology. Rather, they must keep abreast of the complex risks flowing from an energy transition entangled in national security concerns, strategic competition, and stressed supply chains.” They need to understand how to keep their plans resilient in a disruptive world.
Strategy
The energy transition is no longer unfolding in the relatively benign global environment in which many commitments were made. Political support is waning. Big players such as Europe, the US, or China are following very different pathways, and fragmentation is growing.
To some extent, today’s uncertainty is the consequence of a simple narrative encountering hard economic and technological constraints, as the transition got underway.
The modern energy transition is not comparable to historical transitions. The replacement of wood by coal as the world’s largest fuel in the 19th century, and that of coal by oil in the 1960s, was driven by economic incentives. The new fuels had superior properties and were cost-competitive. They could replace their predecessors and usher in huge secondary waves of progress: the Industrial Revolution for coal and individual transport, plastics, or fertilisers in the case of oil.
Over the long term, the new fuels became energy additions, rather than substitutes. Aggregate energy demand continued to rise – and so did the consumption of every single primary fuel since we have records.
AI is often described as a “force multiplier”3 – meaning that early adopters can make progress faster and faster as AI augments their capabilities, leaving the rest falling further behind. This applies to every industry, not just ‘high-tech’ sectors. For example:
Bullet 1
Bullet 2
Bullet 3
H3 18 Teal. Body Normal 18/22 18/24
H2 18 semi-bold
Unlike previous transitions, the modern transition is not driven by a near-term performance advantage. Clean fuels are introduced as a safeguard against the risk of global warming.
Perhaps as a result, the basic narrative of the modern energy transition has always been one of substitution: global warming is caused by the accumulation of greenhouse gases (GHGs) in the atmosphere; fossil fuel consumption is the prime source of greenhouse gas emissions; fossil fuels therefore need to be replaced by clean fuels to the extent possible.
Where modern renewables can compete, and effectively so, is in power generation. Electricity can be produced from any primary fuel, fossil or not. As a result, the spending on clean energy investment is heavily concentrated in power generation. About 85% of modern renewable energy is deployed in power generation, of which ca. 90% is from wind and solar (1).
But it is not always possible. Non-fossil fuels – modern renewables such as wind, solar or geothermal, plus hydropower and nuclear energy – are sometimes unable to replace incumbent fossil fuels directly, including in large applications such as transport, industrial feedstock, or space heating.
With power generation from wind or solar not causing (direct) greenhouse gas emissions, a simple strategy was born, immortalised in the battle cry “electrify everything”: electrification would be the prime vehicle to replace fossil fuels across the global economy, including the segments where substitution is not yet possible.
The intermittency problem
This strategy, however, has a problem. The sun and the wind are intermittent resources that cannot be stored directly. They cannot on their own provide reliable baseload. Electricity can be stored but at the scale required, current technologies face serious limitations.
This is a technical obstacle, distinct from how cost-competitive renewable electricity has become, and unlikely to be quickly resolved by politics, regulation or investment.
Given the limits to electricity storage (and to the expansion of hydro- and nuclear power), an expansion of clean power generation requires the provision of back-up generation capacity, to prevent disruptions originating from the intermittency of renewable resources.
The fuel requirements for back-up generation encapsulate on a plant level the features we encounter when it comes to energy security more broadly. To be an effective safeguard, the feedstock needs to be available instantaneously, while being storable, and lying dormant for potentially long stretches of time.
These requirements explain why globally fossil fuels, in particular gas and coal, are the dominant feedstock to safeguard power generation from clean energy.
For companies, the consequences are not ideological but awareness of the exposure to reliability, procurement and price risk of the power supply.
Reliable estimates of back-up requirements are few and hard to come by. They will differ by location, legacy infrastructure, the structure of demand, and not least, by weather patterns. McKinsey (2) estimates the average back-up requirement for the EU at 50%, meaning half of Europe’s wind and solar output needs to be matched by back-up generation, available and fully deployable at any time.
Now, Europe is growing only slowly. It has a dense network of legacy infrastructure, of plants and grids which can be repurposed once their primary function has been outgrown by new wind or solar power parks. For regions with higher economic and power demand growth, less sophisticated legacy infrastructure, or more extreme weather patterns – this list includes most low- and middle-income economies – the back-up requirement will be higher.
The need to safeguard the power supply is one of the prime reasons for the multi-speed transition we observe across countries and regions.
The big economic problem of the substitution narrative thus starts with the implications of intermittency. It makes the transition more expensive and the new infrastructure more complicated to build, manage and regulate – even before considering the wisdom (and the efficiency) of electrifying other energy-consuming activities.
Intermittency is not only a hard technological constraint. It has knock-on effects on the governance of energy networks. Physical back-up requirements snowball the need for generation equipment and grid infrastructure optimised for new demand dynamics. In parallel, to reap the decarbonisation benefits of electrification, appliances all across the economy need to be shifted from fossil fuels to electricity.
It is easy to see how giant an undertaking this is. Where economic incentives are insufficient, it cannot simply be “left to the market”. It will absorb sophisticated administrative and managerial capacity, and shift regulatory and governance structures and consume supervisory resources.
These requirements are not simply “costly” in financial terms. On many occasions, bureaucratic and technical skills have to be drawn from elsewhere in the economy, at a time when new legal uncertainty, regulatory discretion and compliance risk are introduced. The resulting bottlenecks constitute an implementation risk in rich and poor countries alike, which cannot easily be mitigated.
We are witnessing the political and commercial backlash, at different speeds in different countries. For business, this backlash is less about an abstract political debate than about the threat of volatility in economic and energy policy, ranging from changes in permitting rules, disclosure standards and subsidy regimes to tariffs and industrial policy.
Examples of changes in energy and economic policy in response to a difficult transition come from all sides. The rollback of legislative and financial support for the transition under the current US administration is one example. The massive rollout of electrification in China, motivated by concerns over energy security and the prospect of export leadership in clean energy appliances more than by climate change, is another.
From a board perspective, the issue is not whether the transition continues but whether transition plans will remain resilient or need to change in response to weaker policy support, higher capital costs and more volatile energy prices.
Global primary energy consumption continues to grow, marking another record last year – since 1988, when the Intergovernmental Panel on Climate Change (IPCC) was established, it has fallen only after the financial crisis (in 2009) and the pandemic (in 2020).
Mission creep?
For the state of the energy transition, however, the composition of primary energy matters more. It is still dominated by fossil fuels. Last year, 87% of total primary energy was comprised of oil (34%), coal (28%) and natural gas (25%). In 1988, it was 91%.
Over almost 40 years, the share of modern renewables grew from less than 1% to almost 6%, a gain of 5.3 percentage points. The shares of hydroelectricity (3%) and nuclear (5%), in contrast, have barely moved. At least the pace of change is accelerating now, however: one-third of this gain happened after 2020.
It is, on balance, a sobering message, considering the effort and global goodwill that has been spent – as well as the problems ahead that have become apparent.
And yet, it was not the impassionate language of energy statistics alone that triggered the recent public reassessment of support for the transition. Economic warfare and the weaponisation of energy brought home the unpleasant arithmetic behind the statistics.
Economic warfare is defined as using economic means to achieve political ends. In practice, it almost always comes down to disrupting the free flow of capital, labour and goods to harm an adversary’s economy. Instruments range from tariffs and sanctions to unilateral boycotts enforced by military means. There is no neat catalogue. Needless to say, economic warfare is not necessarily beholden to established rules of engagement or arbitration. Part of its collateral damage is the layer of uncertainty it inflicts on third parties.
The weaponisation of energy
Fossil fuels are inevitably at the centre of economic warfare. They are strategic. Their supply is geographically concentrated, they are hard to substitute and if disrupted, can cause enormous damage.
The war between Russia and Ukraine illustrates the consequences. Economic sanctions had played an important part in the run-up to Russia’s invasion in
February 2022. Energy sanctions entered the picture gradually during 2022, as Russia started to curtail its natural gas supplies to Europe.
For energy markets, this is a battle of giants. Russia (still!) is the world’s largest exporter of commodities as well as fossil fuels. About 12% of oil crossing an international border comes from Russia. The G7, on the other hand, produces more than half of the world’s GDP. It is easy to see why this created a problem for sanctioning Russian oil. The harm of sanctions was not asymmetric: the G7 itself was vulnerable to higher oil prices resulting from the export restrictions it imposed on Russia.
Before the war, the EU had received almost half of its natural gas imports from Russia – it was dependent on Russia’s imports as an important source of heating and of power generation.
Russia’s invasion changed the European energy debate overnight. Before, the energy transition was the prime concern. After, when Russia gradually cut Europe’s access to pipeline imports, energy security moved into the top spot. Suddenly, the prime focus of energy policy had shifted to the question of how to keep the lights and heating on, by securing sufficient supplies of oil, gas and coal – the very fuels that were meant to be eradicated by a successful transition to clean fuels.
infrastructure for liquefied natural gas (LNG), terminals and regasification facilities, at breakneck speed and by securing LNG imports from around the world. It became clear, however, that renewables could not be asked to step up. With capacity fixed in the short term, utilisation depended on the weather. Clean energy could not be commanded to ramp up production in a time of need (in actual fact, the weather was benign, and with hydro and nuclear fully utilised, coal played the swing producer).
In this way, Russia’s share in total EU gas imports fell from ca 45% in 2021 gradually to ca 12% in 2025, while total gas imports declined by only 14%. There was luck in coming through this energy crisis unscathed (the weather!), as well as skilful policies – in particular, allowing the price mechanism to do its work: Natural gas prices reached levels never seen before, helping to attract LNG imports. Instead of imposing price caps, EU member states chose to support consumers with transfer payments.
Both sides then disrupted energy flows for military and political concessions – Russia its pipeline gas deliveries to Europe, and the G7 Russia’s oil (and later gas) exports. For business, this meant an immediate elevation of geopolitical risk, in the first instance affecting energy trade, but on a scale hitherto unknown: price volatility, sanctions exposure and related contract risk, procurement stress and, for insurers and shippers, a whole new layer of physical risk to their assets.
Russia faced better prospects in her campaign to curtail natural gas exports to Europe.
In the event, the European Union managed to secure alternative supplies, by permitting and building import
The price Mechanism: Redirecting Natural Gas Trade
More important for our purposes are two inescapable conclusions: Fossil fuels have properties which, for the time being, make them indispensable when energy security is at stake: they are easily divisible, storable and transportable. This feature, together with their global availability, ensured the badly needed alternative supplies. Second, they are not exposed to intermittency. Europe’s system turned out to be vulnerable despite ca 35% of its power supply generated “at home”, by modern renewables – because this share could not be varied by discretionary supply management. In times of need, it was not a reliable alternative.
The world of geopolitics around us continues to fragment, incidences of economic warfare continue to rise, and rules continue to change. The next crisis for global energy markets came, almost to the day, four years later: the closure of the Strait of Hormuz. Again, the world was at risk of a serious disruption of energy supplies, potentially larger than the disruptions four years earlier. This time, however, it was a disruption of fossil fuel trade.
Consumers, companies all along the affected global supply chains, and governments had to learn a hard lesson: Fossil or renewable, no segment of global energy supplies seemed immune from disruption. Energy security (or lack thereof) had advanced to a material risk for the entire supply chain.
Was this proof of the need to rely on domestic supplies, on power from renewables and subsequent electrification, to protect the system from the vulnerabilities of open trade? The argument surfaced but it didn’t last – because it ignored the intermittency lesson.
It is unlikely that the debate will shift back to where it was before Russia started its war. The world has become less predictable, risks have increased all around us, and energy markets reflect the need for improved risk assessment and contingency planning.
From an economic or technological perspective, we will need both fossil and renewable energy for some time to come. Adding energy security to this equation reinforces the conclusion. “It is hard to envisage an energy transition without energy security. For the time being, it is even harder to envisage energy security without fossil fuels.” We need both to advance the transition.
From a practical perspective, the question for companies becomes how to operate in a mixed system which is vulnerable in all of its components, while preserving security, affordability and at the same time, credible transition claims.
There is a need for expectations to adjust further. The Paris Agreement specifies the need to keep temperature rises due to global warming well below 2°C above pre-industrial levels, with efforts to pursue 1.5°C. It was adopted by 195 governments in 2015; the US has opted out.
The Net Zero Promise
The IPCC, the UN’s scientific assessment body, specifies emissions pathways to reach these targets (but not the policies to reach them). To reach the 1.5°C target requires reducing all GHG emissions globally by more than 40% by 2030 (from 2019 levels), and more than 80% by 2050. To stay below 2°C is less arduous but still implies a reduction of more than 20% by 2030 and more than 60% by 2050.
Current policies and delivery pathways indicate a fair probability that these macro-targets will be breached. An official announcement to this effect and the likely fragmented, and possibly extreme, reactions triggered
by it will increase political and regulatory uncertainty in energy policy even further. It will contribute to the rising regional dispersion of measures and policies in support of the transition and will have the potential to affect the business environment beyond energy.
As has been discussed, the modern energy transition was not triggered by economic incentives, but by a change in global preferences. Governments and international institutions therefore have an important coordinating role to play. When opinions evolve on a grand scale, however, many businesses and individuals will feel the need to do more to support their cause than just delegating it to government.
The most popular way to pledge support to the energy transition and its targets for companies and other institutions is the pledge to achieve a net-zero emissions target at a certain point in time. These pledges gained momentum after a special report by the
IPCC in 2018 (3) and started to proliferate across different sectors in many countries after the UN-backed Race to Zero campaign in 2020. Crucially, net-zero pledges have found widespread support in the private sector, in particular in large companies in high-income economies. They are typically clustered around the year 2050 as the date for delivery.
Today, about 140 national governments have net-zero pledges in place, covering 74% of global GHG emissions and 77% of global GDP. In 2025, around 63% of the Forbes Global 2000 companies had targets in place, representing 70% of the revenues of this index (4). Statistics on small and medium-sized companies are patchy, but estimates suggest a number in the low 10,000s globally – a large number but a lower participation than for large multinational companies.
Companies that have pledged net-zero targets face a difficult situation as the energy transition is slowing down, although this is happening by no fault of their own. Changes in tools, support systems, and even in macro-targets affect their operating environment and may make it harder to deliver business targets.
The impact does not stop at rule changes and regulatory uncertainty. “Companies have publicly pledged to deliver emissions cuts. They have invested reputational and often real capital in a target which may slip out of reach.” Credibility, reputation and in some instances the threat of litigation are at stake.
One pressure valve is the offset market: Companies that see their targets slip may seek to balance their residual GHG emissions by financing emissions reductions elsewhere. Companies that, in the face of moderating ambitions outside their reach, want to increase their efforts may do so by investing in emissions reductions somewhere else. A market for trading GHG credits would have this potential.
Companies have publicly pledged to deliver emissions cuts. They have invested reputational and often real capital in a target which may slip out of reach."
Commodity, Energy, and Manufacturing Prices
A Global Market for Offsets
The idea of an offset is simple: a reduction of emissions which would not have occurred otherwise is rewarded with an emissions credit. The credit can be sold to someone who causes emissions they cannot afford to cut. By buying and retiring the credit, an equivalent volume of pollutants is “offset”.
The theory makes sense. Making credits tradeable will attract investment into projects where emissions can be reduced most easily and cheaply. The practical implementation, however, has been rocky.
To date, emissions credits or offsets are traded in two very different environments.
The first segment comprises compliance markets. These are well-established, regulated and often sizeable markets, typically designed to price and trade emission rights (usually for CO₂ ) which, in some instances, accommodate trading of emissions credits. They are supervised by government authorities and operate on a par with other financial markets, to the same standards of transparency and fungibility.
And then there are voluntary markets to trade emissions credits. Voluntary markets are not centrally regulated and are typically not used to satisfy a statutory emissions obligation. To date, these markets are fragmented. Integration, global standards and centralised oversight are absent. The law of one price which characterises competitive markets is largely absent as well: An extraordinary price dispersion signals inefficiencies and legal and reputational vulnerabilities associated with these markets. Voluntary trading of GHG credits can create substantial legal exposure when used to support public claims.
Today, the recorded turnover for emissions credits is tiny. Estimates put the value of the retired credits last year at less than USD 2 billion – a tiny fraction by any measure, representing only about 0.5% of global CO₂ emissions.
Why has a sizeable market for offsets not emerged yet?
Consistent implementation requires definitional clarity. If global warming is caused by the accumulated volume of greenhouse gases in the atmosphere, credits can be issued against the removal of pollutants (e.g., by carbon capture technologies or by establishing or maintaining carbon sinks like swamps or forests), or against reducing the inflow of new pollutants (e.g., by feedstock substitution or the switch to electric vehicles). In both instances, permanence and leakage need to be considered.
Implementation also suffers from incentive problems, and a checkered historical record. Additionality, verification and accounting rules (including the relationship between private claims and host-country accounting) are central to an expansion of the market for offsets.
These are not insurmountable roadblocks.
Energy markets are huge and the problems with the energy transition are real. Many companies with net zero pledges at risk will investigate offsets before withdrawing the pledge. However, at the moment, contracting in these markets comes with reputational and litigation risk.
A larger market for offsets could also provide a spur to the supply side, by attracting private capital into projects which would advance clean technologies, in a competitive way, and by providing finance, entrepreneurship and innovation. That is exactly the private impetus the transition needs.
At this point in time, attempts at better regulation and standardisation are tentative and not centrally coordinated. The emerging architecture includes reports on integrity and claims, the publication of good business practices, and attempts at operationalising the carbon market rules in the Paris Agreement. These are partial measures, with patchy implementation at an early stage.
Failure to establish a credible market architecture, around standards, disclosure and enforcement, would leave options along the road to a successful energy transition unexploited. Rapid growth without better regulation would amplify risks to participants and may escalate to become a systemic threat to the idea of tradeable emissions credits.
Establishing a safe and sound market for the trading of emissions credits, on the other hand, could become a bridge between the need to spur competitive investment into clean energy technologies and the need to improve the removal of pollutants in the atmosphere – two underexposed components from the current transition narrative. To achieve this, markets need to expand and become an accepted part of the global financial architecture.
Conclusion
“The overall lesson for companies is to approach the energy transition with an open mind, but to stress-test KPIs and next steps.” In a world in which discretion continues to interfere with global rules, and economic warfare with diplomacy, energy markets will remain on the front line.
Procurement and supply chain reliance; sanctions exposure and financing plans; and offset reliance and climate claims across diverging regional settings will remain important areas for review, monitoring and stress-testing.
It is hard to envisage an energy transition without energy security. For the time being, it is even harder to envisage energy security without fossil fuels
The overall lesson for companies is to approach the energy transition with an open mind, but to stress-test KPIs and next steps.
expensive and exposed to familiar regulatory and supply chain risks. For clients, whether investors, offtakers, or industrial hosts, this creates a familiar tension between early-mover advantage and first-of-a-kind risk.
The contrast is deliberate. Large-scale nuclear is intended to anchor national supply, while SMRs provide a more flexible solution for industrial decarbonisation and regional deployment. For businesses operating in Poland, particularly in energy-intensive sectors, this creates new strategic options. Engagement is no longer limited to purchasing grid electricity; it may include project participation, long-term power purchase agreements, or hosting generation assets.
Decarbonisation pressures are intensifying. As policy frameworks move from ambition to enforcement, the need for firm, low-carbon power is becoming more visible. While renewable deployment has scaled rapidly, intermittency challenges persist. Nuclear, by contrast, provides predictable baseload generation, which is a valuable attribute in complex power systems.
Energy security concerns have hardened as recent disruptions have exposed structural vulnerabilities in supply chains and fuel dependencies. This has prompted governments and businesses alike to seek more domestically anchored solutions and reassess nuclear through this lens. At the same time, demand is evolving, with electrification extending beyond transport and households into industrial processes, hydrogen production and AI-driven data infrastructure. For large energy consumers, reliability is increasingly as critical as price.
Against this backdrop, small modular reactors (SMRs) and micro modular reactors (MMRs) have emerged as a focal point of innovation. Their appeal lies in smaller, standardised units that can be factory-manufactured, deployed flexibly and financed with lower upfront exposure than traditional plants. From an industrial and defence perspective, the applications are significant. SMRs and MMRs could be co-located with energy-intensive facilities, replace retiring coal units using existing grid connections, or supply dedicated clean power and heat to industrial clusters.
In parallel, MMRs in particular are attracting military interest, given their potential to provide resilient, off-grid power for forward bases and support energy-intensive technologies such as advanced communications and high-performance computing. This combination of flexibility, mobility and reliability underpins their growing attractiveness.
However, the commercial case remains uncertain. No SMR or MMR design has yet achieved sustained, large-scale deployment in Western markets. Cost advantages depend on future serial production, a “build many” model that is still unproven. Early projects are
Poland offers a clear example of how this nuclear resurgence is being operationalised, including its inherent trade-offs. The country’s coal dependency makes decarbonisation both urgent and politically sensitive, while energy independence remains a key priority. Nuclear is therefore positioned not as a complement, but as a cornerstone of the future system.
On one side is a flagship large-scale plant on the Baltic coast, based on established reactor technology. This reflects a conventional model of high capacity, proven design and strong state backing. It represents the more bankable end of the spectrum, albeit with known risks around construction complexity, timelines and cost overruns. On the other side, Poland is advancing an SMR programme in partnership with industrial players. This pathway is more decentralised and commercially oriented, aiming to integrate nuclear directly into industrial energy consumption.
Alongside these technical and strategic considerations, financing and regulatory frameworks will be critical in determining the pace and scale of deployment. Nuclear projects, particularly first-of-a-kind SMRs, require significant upfront capital and long development timelines, which can deter private investment without policy support. Mechanisms such as regulated asset base models, long-term pricing arrangements, and state-backed guarantees are likely to play an important role in allocating risk between public and private stakeholders. For businesses considering participation, understanding how these frameworks evolve will be key to assessing bankability and long-term commercial viability.
The answer will vary by market. In countries such as Poland, where emissions intensity is high and energy security concerns are acute, the strategic case for nuclear is particularly strong. The pursuit of both large-scale and modular pathways reflects a balance of urgency and pragmatism.
The key is to view nuclear not as a binary choice, but as a portfolio of opportunities with distinct risk-return profiles. Early engagement, through partnerships, supply chains or offtake agreements, may offer strategic advantage, but requires careful navigation of regulatory, commercial and technological uncertainty.
Nuclear energy and the energy transition:
A new strategic equation for businesses
uclear energy is re-entering boardroom discussions as a potential enabler of the energy transition. The shift is increasingly practical
rather than ideological. The question is no longer whether nuclear has a role, but what type, on what terms, and with what risk profile.
N
More information on our Energy & Natural Resources team
Further complexity arises from NESO’s stated position that the newly formed queue is final. This approach, though perhaps stemming from a desire to provide certainty, is undoubtedly far too rigid. Such inflexibility fails to account for the complex histories of many projects, the differing needs across Great Britain, and the possibility of errors in the G2tWQ process – whether on the part of applicants or NESO itself.
The drivers of reform
It is easy to criticise the current position. Yet the reality is that NESO and its delivery partners had little choice but to bring about radical change in response to a system that was no longer functioning effectively. The question, therefore, is not whether reform was necessary, but how it can be delivered as seamlessly as possible.
The current position and evolving challenges
Connections reform:
In Great Britain, the National Energy System Operator (NESO) and its delivery partners are now implementing long awaited reforms to the electricity grid connections regime.
In the years preceding these reforms, an outdated process operating on a first-come, first-served basis had led to a state of effective gridlock in the connections queue. So-called ‘zombie projects’ occupied positions in the queue without progressing, leaving viable schemes waiting years for connection.
The need for reform was clear. A more efficient grid connections regime was required to reduce delays and unlock investment. This was particularly vital in the context of the UK’s energy transition and the Clean Power 2030 Action Plan.
Against this background, and after years of consultation, NESO and Ofgem took the decision to fundamentally restructure the connections queue. In 2025, NESO carried out the ‘Gate 2 to Whole Queue’ (G2tWQ) exercise, under which all existing projects were required to reapply for connection dates.
The outcome of the G2tWQ process was published by NESO in December 2025, following an application process which was beset with delays and technical issues.
Reform meets reality
Since then, uncertainty has persisted as the implementation of the reforms continues. The timelines set by NESO have proved fluid, with key milestones subject to revision. Meanwhile, there remains ambiguity as to how the G2tWQ criteria have been interpreted and applied in practice.
Under the reformed system, projects that have secured a Gate 2 offer are expected to connect in 2026-2030 (Phase 1) or 2031-2035 (Phase 2). Projects that fall within Gate 1 must now wait for the next application window, the dates of which are currently unknown, amend to although application windows are intended to be held annually.
Many projects are yet to receive updated offers at all, and uncertainty persists even among Gate 2 offer holders as to the timing of their connections, with corresponding implications for project viability.
A further issue has arisen from the treatment of ‘Protected Projects’ which were, in principle, guaranteed to retain their existing connection dates and points of connection. In reality, however, NESO has acknowledged that it will not be able to deliver on this commitment, and that well over half of projects in this category would not receive offers reflecting their existing entitlements.1
The implications of this sustained uncertainty are material. Developers and investors are approaching key milestones and investment decisions without reliable visibility as to connection timelines. There is a risk of precisely the outcome the reforms were intended to avoid: ‘shovel-ready’ projects which ought to have been prioritised are instead threatened by an environment of widespread instability.
What success will require
First, reform of this magnitude requires substantial resource. NESO has undertaken a genuinely transformative exercise, and one that demands funding commensurate with its scale. Without adequate resourcing, the risk is not merely delay but broader disruption, accompanied by a loss of confidence across the market.
Second, transparency and predictability are equally critical. Market participants must be able to understand, and rely upon both the framework within which decisions are taken and the timelines by which they are delivered. Information provided by those responsible for reform should be accessible, clear and
consistent. While the provision of extensive guidance is understandable, there is a risk that excessive volume may overwhelm users and obscure the information that matters most.
Where ambition, resourcing, and clarity are successfully aligned, the GB grid reforms, and others like them, have the potential to act as a catalyst for the energy transition. The lessons are clear; the challenge now lies in ensuring they are applied in practice.
Refrence will be provided
MEET THE AUTHOR
Helena Dodds Junior Associate, Guildford
Liquidated damages (LDs) are intended to create financial certainty for parties in cases where there is a delay to the agreed commencement, operation or completion dates, or where underperformance is caused by design or technical faults impacting output, efficiency or reliability guarantees. Pre-agreed rates of compensation are incorporated into contracts in advance, effectively putting a price on failure. Such clauses are vital because even minor delays or poor performance can have major cost implications. Their effectiveness depends both on the way they are drafted, and the choice of governing law and dispute resolution framework (since LDs are not treated uniformly across jurisdictions).
Suspension rights are designed to help manage situations where a force majeure event (i.e. an extraordinary, unforeseeable event that prevents a party from performing their contractual obligations) or a material breach of contract has occurred, and where contract termination or variation are not appropriate. They can also be triggered simply on the grounds of convenience (i.e. at the will of a party) even where there has been no fault.
Each contract should have its own defined framework to provide clarity over what triggers suspension, who can trigger it, the cost of suspension, duration and notice requirements, obligations during the period and the way forward afterwards.
Carefully considering liquidated damages provisions and suspension rights is essential in every complex, high-value oil and gas contract to allocate risk and provide legal certainty and/or financial redress. However, it’s important for parties to consider the operational impact that these clauses may have on project delivery.
As the name suggests, suspension rights can disrupt project momentum and, in doing so, contribute to further delay. It’s important to be aware that suspension freezes the obligations of the suspended parties, but may not necessarily freeze the entire project. Prolonged delays could have profound adverse impacts on the wider project (and have a knock-on effect on other projects being undertaken by the parties concerned), and even short spells of downtime could prove painful.
Spotlight on risk allocation: what are liquidated damages and suspension rights?
Liquidated damages should not be the only remedy available (as is often expressly the case). These provisions should be backed up with other contractual measures that ensure failures are actively addressed. These measures could include performance correction obligations, step-in rights, escalation procedures or termination rights once the damages cap is reached. Contracts should be drafted in such a way that these supplemental mechanisms can apply alongside LDs without inadvertently being undermined or excluded.
Since suspension can be triggered at will, even if no fault or major event has occurred, and because the right to do so is generally only afforded to one party (usually the employer), it’s vital to negotiate safeguards such as time limits and cost recovery mechanisms into the contract. It may be possible to mitigate any adverse impacts from suspension by allowing for options such as standby compensation or time relief, however these must be carefully thought through. For example, pre-agreed standby rates generally only cover the cost of inactivity during the suspension period, but not the costs of restarting the work which can be significant.
In the current uncertain and turbulent geopolitical environment, the challenges involved in getting major oil & gas projects off the ground, and operating them over the long term in line with agreed contractual obligations including performance levels and guarantees, are increasing. Both liquidated damages and suspension rights are powerful tools to deploy from a legal and financial perspective to mitigate risk, but they may not be enough to rectify delivery and performance issues on their own: they must be deployed as part of a wider risk allocation and contractual protection framework.
Being heavily reliant on global supply chains and framed within rigid timescales, oil and gas projects have always been susceptible to volatile, unpredictable (and often uncontrollable) external factors that could cause delays, default or impaired performance. Today’s tensions in the Middle East have amplified the risks, with projects now increasingly being delayed by disruption to key transport routes, resulting in already tight delivery schedules quickly becoming fragile, costs mounting and more disputes arising.
In these situations, given the complex and highly capital-intensive nature of projects, and because they are typically contract-driven, it’s only natural for parties to seek to trigger the liquidated damages provisions and/or suspension rights in their contracts as a remedy. But while these clauses are vital components of any engineering, procurement and construction (EPC) contract, they can have their limitations, and enforcing them often has a significant operational impact on projects.
Other ways to address operational risk
MEET THE AUTHORs
Bryan Wilson Senior Overseas Manager, Abu Dhabi
Marc Penman Senior Associate, Abu Dhabi
Dealing with delays, default and underperformance in oil & gas projects
iquidated damages and suspension rights are critical components of EPC contracts, but triggering them can have
significant operational impacts and remedies may be limited.
L
Understanding the operational impact
Liquidated damages essentially only provide for financial remedies, but nothing more (and it’s worth noting that damages are often capped). Therefore, these provisions have limited use as a lever to force operational improvements. Although the innocent party may receive compensation should there be a delay or underperformance, liquidated damages (in isolation) do not impose any obligations on the party at fault to accelerate delivery to make up for lost time or rectify problems affecting performance promptly.
Bartlomiej Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse tincidunt purus et consequat ultrices. Mauris convallis vestibulum est, ut ultricies ante porta ac. Ut faucibus ante sed varius posuere. Mauris posuere et enim ut posuere. Proin mattis porta rhoncus. Integer suscipit lorem eget magna laoreet, in eleifend erat mollis. Morbi a lorem neque.
n 2026, businesses are operating in a climate of constantly elevated risk, where the volume of threats they face
The evolving risk landscape through the lens of leading decision-makers
Corporate Risk Radar
Click photos to find out more
Navigating risk without respite as threats intensify and converge
Click here todownload the report
I
keeps increasing, and their nature is ever-changing. Amid geopolitical instability, economic volatility, technological disruption and regulatory pressure, organisations must become resilient to a wide range of very real hazards.
Perceptions of risk jump sharply across all categories
What's more, these risks are converging. Single events are now triggering operational, regulatory and reputational risks simultaneously. As a result, managing interconnected risk has become central to strategic decision-making. The business leaders we surveyed for this year’s Corporate Risk Radar report, including senior decision-makers from some of the world’s largest companies, are well aware of the challenges, and largely confident in their response. After several years of “polycrisis”, they are no longer waiting for conditions to stabilise, and have accepted that heightened risk is now a permanent condition of leadership. However, threats are intensifying at an alarming pace.
This year's findings are particularly striking because they point to a step-change in risk intensity and complexity. Perceptions of risk among C-suite executives, board members and general counsel (GCs) have increased sharply in the past year across all categories. When asked about key risks they face in the next 12 months, technological risks have seen the biggest jump, almost doubling year on year. 86% of leaders now rate technological risk as the highest risk area, alongside operational challenges and closely followed by increased regulatory and compliance requirements. It's also notable (but perhaps not surprising in the current climate) that 72% now see geopolitical risk as a major concern - up from under half (49%) last year. As these risks become more intertwined, addressing them also becomes harder. Nearly six in ten leaders described the complexity of emerging risks as the biggest single barrier to managing them effectively. Encouragingly, preparedness has increased across most categories. Almost all (98%) said risk is always or frequently considered in strategic decision-making, and nearly three quarters (72%) reported that boards now proactively monitor emerging risks.
Risk to organisations
Economic and geopolitical risk weigh heavily
Organisations feel most confident where risk management depends on their own processes and internal discipline, but where outcomes depend on factors outside their direct influence, such as market conditions or geopolitical events, the sense of exposure is considerably greater. With this in mind, two findings are particularly pertinent: 59% see economic risk as the number one concern over the next two to three years, while concerns around geopolitical risk have also risen sharply. Economic shifts - and the geopolitical escalations they are closely connected to – are unpredictable and cannot always be mitigated against in conventional ways. That’s not to say business leaders aren’t trying. The prospect of interest rate rises, currency volatility and economic turbulence weigh heavily on leaders’ minds, as does the possibility that conflict escalation and/or trade restrictions and sanctions could disrupt trade routes and supply chains, and increase costs. Four in five said that geopolitical shifts, trade policy changes and evolving tariff environments are materially influencing where and how they operate globally, while half are taking proactive steps to improve supply chain resilience and diversification. Agility matters.
Factors posing the most risk to organisations
As AI moves from future concern to operational reality, the potential value creation benefits are tempered with issues around adoption, including organisations’ reliance on third-party providers, integration problems and exposure to failures in interconnected systems. Security considerations and maintaining business continuity also loom large, especially as increasingly sophisticated criminal networks and hostile state actors target cyber (and physical infrastructure) vulnerabilities. As companies accelerate AI implementation, some are still in catch-up mode as far as governance is concerned. More organisations said they are rapidly evolving their AI, data privacy and cybersecurity regulations and associated compliance requirements (76%) than have a mature artificial intelligence governance framework in place to manage it (68%). This governance gap cannot be ignored: half said weak governance over emerging technology adoption, including AI, is likely to pose a significant risk in the year ahead. No wonder the C-suite cited technology risk as a top area of focus. Balancing robust controls with the ability to seize competitive advantage is essential.
AI: GOVERNANCE GAP EMERGES AS TECHNOLOGY RISK ENTERS A NEW PHASE
In this high stakes environment, the role of the General Counsel is expanding, moving from reactive legal support to proactive strategic engagement. Eight in ten GCs said they now act as trusted advisers to the C-suite and board. Their remit is evolving fast, with the skills identified as most critical for the next generation being commercial and forward-looking: regulatory foresight and proactive risk management (62%), innovation in legal service delivery (58%), leveraging AI and emerging technologies (58%) and strategic business partnering and commercial acumen (56%).
EXPANDING EXPECTATIONS OF GCS
This year’s Corporate Risk Radar confirms that a fundamental shift in the operating environment has taken place. Where once, organisations might have faced a series of isolated challenges over time, now continuous, heightened, fast-changing risk converging from multiple interconnected fronts at once has become the new normal. Waiting for uncertainty to pass is no longer an option. Business leaders understand that they must strengthen resilience and build the capacity to respond at speed as conditions change, in the full awareness that the risks they are anticipating today may not be what materialises tomorrow. They must not only be prepared for disruption, whatever form it takes, but be ready to lead confidently through it.
Conclusion: Elevated risk is now the new normal
Important skills when hiring next generation of general counsel
Today, regulatory compliance is a moving target: requirements span diverse areas of business, rules can change rapidly and are applied inconsistently across jurisdictions. This is business-critical. More than eight in ten respondents (82%) said increasing regulatory and compliance obligations are materially influencing their organisation’s ability to invest and grow. The cost of compliance failures goes far beyond the financial – they can cause significant reputational damage, especially if there are real-world consequences, for example, from data breaches or environmental harm. However, our research found that only 14% of business leaders see regulatory risk as an area requiring the most C-suite attention – probably because compliance is delegated to dedicated, specialist technical or legal teams. While understandable, this approach can create a lack of accountability at the top and lead to a reactive, rather than proactive, response should failures occur. There are compelling arguments to say that compliance should be seen as a strategic function, rather than purely an operational one.
Increasing regulatory burden puts growth under pressure
The volume and complexity of the risks organisations must address simultaneously, makes for serious operational challenges. Tactics such as developing robust horizon scanning are now table stakes. Yet only 54% say their organisations are actively increasing investment in operational resilience, and just half have invested in business continuity and crisis response planning. The human factor should not be overlooked here. People and skills are as much a part of operational resilience as structural frameworks, processes and toolkits. Recognising this, respondents cited talent acquisition and retention as the most significant personnel risk factor (69% said so). However, they continue to grapple with changing workforce expectations around working arrangements and flexibility, and this is influencing talent management, workforce engagement and organisational performance (said 77%).
Building operational resilience: people plus process
Click here to download the full Clyde & Co Corporate Risk Radar report 2026
Meet the AUTHORS
Jared Kangwana Partner, Nairobi
Rebecca Kelly Partner, Brisbane
Roshanak Bassiri Gharb Partner, Dubai
Marianne Anton Partner, London
Jan Spittka Partner, Düsseldorf
Sam Tate Partner & Global Head of Regulatory and Investigations, London
Tim Crockford Partner, London
As organisations increasingly enjoy AI’s benefits, they should be conscious of the sustainability, regulatory, and liability risks associated with its environmental footprint, including indirect emissions arising from data centres and supply chains. This raises an emerging question for businesses: how to balance the competitive advantages of AI with growing regulatory and sustainability expectations.
Governments are placing greater focus on corporations’ environmental impact through regulatory measures aimed at increasing transparency and allocating responsibility across the value chain, rather than placing it solely on data centre operators.
Data centres already account for around 1.5-2% of global electricity consumption, a figure projected to rise sharply as AI deployment accelerates. The International Energy Agency projects that data centre electricity use could exceed 1,000 TWh by 2030, more than doubling current levels. Global electricity use by data centres has also been increasing at roughly 12% annually since 2017, highlighting the pace of this growth. This is driven by the energy-intensive nature of generative AI systems, which require vast computational resources to train and deploy.
Data centres also consume significant volumes of water for cooling and can contribute materially to carbon emissions, particularly where electricity is sourced from fossil fuels. While these effects occur at the infrastructure level, they are largely driven by corporate demand for AI-integrated services.
In the EU, under frameworks such as the Corporate Sustainability Reporting Directive, companies are required to apply the concept of “double materiality”, requiring them to disclose not only how sustainability risks affect them financially, but how their activities impact the environment across their value chain. In practice, this means that a company’s decision to deploy AI may feed directly into its reported emissions profile, even though the underlying electricity and water consumption occurs elsewhere.
In the UK, the regulatory position is less advanced but is moving in the same direction. Existing frameworks such as Streamlined Energy and Carbon Reporting (SECR) and mandatory climate-related disclosures already require large companies to report on energy use, emissions and climate risks, although Scope 3 (value chain) emissions remain largely voluntary at present. However, the UK government is developing Sustainability Reporting Standards (UK SRS), which are expected to require more comprehensive climate disclosures, including value chain emissions, and may become mandatory for large companies in the coming years.
These frameworks focus on the impacts of activities across a company’s value chain, meaning that the environmental consequences of AI deployment should not be disregarded simply because they occur within third-party infrastructure.
Mitch Boden Trainee Solicitor, London
he rapid adoption of artificial intelligence (“AI”) is reshaping industries and driving efficiency. Organisations that fail to adopt AI at pace risk falling behind competitors. However, this technological transformation comes with a important environmental
cost. Data centres, which underpin AI systems, are becoming an increasingly significant source of electricity demand, creating friction between technological innovation and sustainability efforts.
T
Managing the hidden sustainability risks
Data Centre AI and the energy transition:
Liability and Risk Exposure
Regulatory Developments
AI’s Environmental Impact
From a risk perspective, the value chain impact of AI raises several potential heads of liability.
First, regulatory non-compliance risk may increase. Failure to meet disclosure obligations under existing
Second, companies may face “greenwashing” claims from stakeholders if public disclosures concerning sustainability or net-zero commitments are inconsistent with the environmental damage caused by AI-driven operations.
Third, while direct liability remains underdeveloped, companies may face increasing legal and reputational exposure arising from their indirect contribution to environmental harm. Third parties could seek to challenge those contributions, particularly where they undermine stated climate commitments.
It is still early days, but AI-related emissions that undermine climate targets could create a credible future risk of regulatory scrutiny, investor action or claims based on misleading disclosures.
To navigate this evolving landscape, organisations should adopt robust governance frameworks that integrate AI-related environmental considerations, including the indirect impacts associated with data centres, into their AI strategy and deployment.
Governance and Risk Mitigation Strategies
Key measures include:
Energy and emissions monitoring: Implementing systems to measure AI-related energy consumption at a granular level, enabling accurate reporting, including Scope 3 disclosures where applicable, and identification of inefficiencies.
Sustainable procurement and infrastructure: Prioritising data centre providers powered by renewable energy or designed for energy efficiency. For example, Google reports that it has signed over 170 renewable energy agreements to power its data centres and now operates some of the most energy efficient facilities
Model and system optimisation: Using smaller, task-specific AI models to reduce energy intensity.
Board-level oversight: Flagging AI-related environmental risks within governance structures, ensuring that indirect emissions are treated as part of a business’s risk management and subject to appropriate board oversight.
Although the legal landscape is still developing, early engagement will be critical.
globally, demonstrating that infrastructure choices can significantly influence the emissions associated with AI use.
AI offers significant economic and operational benefits, but its environmental footprint presents a growing challenge. The tension between innovation and sustainability is becoming a defining issue of modern times.
As regulatory frameworks tighten and ESG scrutiny intensifies, businesses must adopt a proactive approach to managing AI-related environmental risks. Ultimately, the organisations best positioned to succeed will be those that treat AI sustainability not as a compliance burden, but as an opportunity to manage their emissions effectively while remaining competitive.
and future regulations may result in fines, enforcement action, or reputational damage. This could in future include situations where companies fail to adequately account for emissions associated with outsourced digital infrastructure underpinning AI deployment.
Data Centres
Data centres have become a key part of the digital economy, and their rapid expansion is creating unique challenges for insurers. Nearly USD 3 trillion will be spent globally on data centres by 2029, according to Morgan Stanley, with McKinsey estimating capital outlays of USD 6.7 trillion by 2030.1
As such, the policies sit at the boundaries of property CAR and power CAR, and the same for operational, which can bring some challenges.
The US in particular is accelerating the construction of large-scale data centre campuses, with the supply in primary data centre markets increasing by 34% year on year to 6,922.6 megawatts (MW) in 2024, far surpassing the 26% increase in 2023. While many countries are investing heavily in the market, the US is projected to have around 40% of worldwide data-centre investment by 2030.
In many ways, the construction risk profile of a data centre is very similar to that of an office/warehouse construction project, since the highest value components (the computer hardware and Graphics Processing Units (GPUs) specifically) tend not to be covered. What makes data centres different from these established projects is the power consumption required, and in particular the need for either on-site power backup or on-site generation capacity.
Delays in securing an appropriate grid capacity, together with challenges of securing a suitable, and reliable, power supply are pushing more data centre developers towards on-site generation. The power demands of the large data centres are akin to the electricity demands of 30,000 to 60,000 homes, making the on-site power generation similar to that of a power station or commercial wind/ solar farm. Large data centres also consume up to 5 million gallons per day, equivalent to the water use of a town populated by 10,000 to 50,000
The project values are staggering. Developers are seeking loss limits of USD 10 billion for projects valued at USD 30 billion – excluding GPUs. With GPUs included, exposure could reach USD 60 billion. Construction market capacity typically caps at USD 4–4.5 billion, forcing creative placement strategies. Operational risks often fall under property markets, but significant power components may push coverage into the power/energy sector.
Navigating insurance challenges and mega-valuation
Data Centres at the core:
Valuation and capacity constraints
Coverage nuances
Growing complexity of data centre insurance
Fire is still one of the main causes of data centre losses, so fire compartmentalisation is essential to mitigate spread as well as smooth running of the HVAC systems. The high density of electrical power, sometimes several megawatts, increases the potential fire hazard caused by arcing, short circuits, smouldering fires or defective components, among other things.2 Other common loss drivers seen to date in the CAR market include concrete slab defects, water ingress, and storm damage.
On the power side of the risk profile, losses include transformer failures and power equipment breakdown. The industry faces a shortage of experienced contractors and long lead times for critical components. For example, gas turbines now have an eight-year delivery horizon, which could exacerbate future loss scenarios. Integra recently reported that Siemens has a backlog of gas turbine orders valued at EUR 131 billion and Mitsubishi has also seen an increase in demand for its turbines.3 This raises the risk of a limits loss for BI or DSU, and puts considerable stress on ICOW (Increased Cost of Working) expenses. There are similar issues, albeit not as severe, regarding the availability of diesel generators often used as a backup power supply.
The amount of investment in these projects is unprecedented. Insurers should be cognisant of the possibility of a slowdown or market correction associated with the overvaluation of assets, as some of these heavily funded projects could become less financially viable. Insurers should ensure that clauses are included in policies around cessation of works to cover for this eventuality.
Global footprint
While the US dominates the market, with ten times more installed data centre capacity than any other country, projects are proliferating worldwide. The UK has over 500 active data centres, making it the third-largest global market, with key clusters in London, Slough, Manchester, and Cardiff. Over half of the new centres within the UK are due to be in London and the Home Counties – many of which are funded by US tech giants including Google and Microsoft. Google chose the north London suburb of Waltham Cross for its data centre project which includes up to 667,000 sq ft of data centre facilities and was opened by the UK Chancellor Rachel Reeves last year. Equinix, a leading US digital infrastructure giant, is building a vast new Hertfordshire data centre campus – spanning nearly 30 football pitches. This deal paves the way for one of Europe’s largest and most advanced data centre campuses.
powered by small modular nuclear reactors (SMRs) are on the horizon, with the US expected to lead adoption in 2027, followed by the UK. Several US power providers have indicated that they are in advanced discussions to power data centres through the revival of multiple closed nuclear power facilities and the development of new nuclear projects. Just this month, the US Energy Department airlifted a small nuclear reactor from California to Utah as a demonstration of its ability to efficiently meet the energy demands of data centres. Ontario Power’s Darlington site is an example of smaller conventional nuclear projects already in play.
At the end of 2025, the UK House of Lords approved regulations allowing large data centre projects to be considered “nationally significant infrastructure projects”. This change is intended to streamline the planning process for new facilities and allow developers to more easily bypass particular planning permission, which will undoubtedly lead to a major expansion of data centres within the UK. Data centres
Data centres represent one of the most complex and high-value asset classes in today’s insurance landscape. With escalating valuations, intricate technical requirements, and evolving risk profiles, insurers and brokers must innovate to keep pace with this rapidly expanding sector while effectively managing the risks.
The enormous physical footprint of many new data centres means they are often sited in remote locations, particularly throughout the US. “Data Centre Alley,” a rural area in Northern Virginia, already represents 13% of the global data centre capacity. These data centres can be exposed to natural catastrophe risk, heightened storm frequency and severe weather events as climate change intensifies weather risks. Natural catastrophe exposure is therefore critical, particularly for sites in tornado-prone regions.
With demand soaring globally, the insurance market is responding to the challenges they raise – including capacity constraints, complex risk profiles, and evolving technical requirements.
Key risks and loss trends
Allianz Commercial. (2024, n.d.). *The data center construction boom: Emerging risk trends in the global buildout.* Allianz. https://commercial.allianz.com/content/dam/onemarketing/commercial/commercial/reports/commercial-data-center-construction-risks.pdf Ronken, L. (2021, August). *Data centres – An underestimated risk?* Gen Re. https://www.genre.com/content/dam/generalreinsuranceprogram/documents/pmint21-2-en.pdf Integra, Integrated, Issue 17
Paul Lowrie Partner, London
Ben Keatinge Legal Director, London
Alice Hodgson Senior Associate, London
Corey Greenwald Partner, New York
ata centres are rapidly becoming one of the most complex and capital-intensive asset classes in
the global economy, blending property, energy and technology risks at unprecedented scale. As valuations surge into the tens of billions and power demands rival small cities, insurers face mounting challenges around capacity, underwriting and evolving risk exposure.
D
people. In the US, it is estimated that data centres could take up as much as 12% of total power consumption by 2028, a higher demand than all manufacturing of steel, aluminium, and other high-intensity manufactured goods combined.
Similarly, conflicts and increasingly common climate change-driven natural events such as floods, heatwaves and droughts can affect the infrastructure on which data centres rely, notably power plants, electricity grid networks or water supplies for cooling equipment.
Power outages could result in significant service disruption. Meanwhile, if equipment overheats (which is a particular risk for AI servers which have an extremely high thermal load) it may require replacement, potentially resulting in prolonged downtime.
Data centres are critically important long-term assets, where regular maintenance and upgrades are vital, so they remain fit-for-purpose and efficient over their entire lifecycle. Their highly specialised equipment and components can rarely be sourced locally: they are typically procured from a global supplier base.
Implement robust business continuity and disaster recovery measures – traditional measures include, for example, establishing mirror servers and a combination of online, nearline and offline back-up data storage facilities to minimise service downtime and ensure that secure data access can continue uninterrupted in the event of a data deletion or corruption incident.
Power outages and overheating events
It is important to ensure in advance that this is permissible under the relevant data protection laws in the jurisdiction(s) concerned. Some countries require certain data (such as information held by government departments) to be kept within their borders, while regulatory requirements can differ significantly between jurisdictions. Discussions around business continuity and disaster recovery arrangements should happen at an early stage in the customer journey, and the choice of an acceptable secondary location must be carefully considered and recorded in the contract.
There are several practical steps data centre operators, contractors and suppliers can take to mitigate the impact of these diverse and complex challenges. These include:
Strategically maintain spare parts inventory – data centre operators and maintenance contractors would be well-advised to maintain a spare parts inventory in excess of their contractual obligations, and strategically consider the location of those supplies. Just-in-time inventory management for spares may be appropriate for non-business critical spares with a ready supplier market from a variety of sources; but for critical components available from a limited source, maintenance of spares in strategic, physically secure locations will limit the risk of serious downtime (and contractual penalties) in the event of a breakdown or incident.
The risk of cyber-attacks is well known, but physical threats are equally real. Earlier this year, commercial data centres became strategic military targets for the first time in modern warfare, when at least two sites in the Middle East were hit by drones in the Iran-US-Israel conflict. Previously, hostilities have involved cyberattacks on state-affiliated data centres, e.g. during the Ukraine-Russia war.2 These unprecedented, deliberate airstrikes have starkly highlighted the physical vulnerabilities to which data centres are exposed during conflicts.
Even in peace time, the risk of physical (not just cyber) attacks should not be underestimated. Just as hackers are adept at gaining entry to online systems, bad actors have been known to exploit vulnerabilities in on-site security protocols to force or trick their way into data centres in person to steal valuable equipment, including the servers on which valuable, sensitive data is held.
Risk mitigation strategies
Data centres:
emand for data centres is booming, with capacity expected to double over the next five years,1 as cloud
computing and artificial intelligence (AI) continue to transform the digital landscape. But as demand increases, so do the challenges – especially in today’s volatile geopolitical environment, and the potential for problems (and therefore disputes) to arise is heightened.
Supply chain disruption and skills shortages
In the current febrile geopolitical climate, international supply chains are more prone to disruption from the sudden imposition of export controls and sanctions, or logistical roadblocks such as the unexpected closure of the Strait of Hormuz. Even if it is possible to source an alternative, switching suppliers or transport routes can dramatically increase costs, extend maintenance delays and ultimately undermine service quality.
Mitigating the risk of disruption and downtime post go live
In the first of our series of articles on data centre disputes, we explored pre-project delivery issues; here we examine the risks that can occur once a data centre is live, and how to mitigate them. A range of factors can disrupt service delivery and performance, increasing the likelihood of disputes, including:
Physical (as well as cyber) security breaches
Back-up power supplies, such as generators and batteries, are also a critical component of a robust solution for equipment and services that rely entirely on energy to power and cool them.
The recent Middle East air strikes showed the importance of having the ability to provide business continuity services from other regions in case an entire country or region is affected.
Best practice, therefore, is to anticipate potential risks and address them in the contract, in particular by:
Creating back-to-back contracts, under which obligations and risks contained in the main supplier-customer contract are replicated in agreements with subcontractors to enable the flow down of SLAs and the payment of penalties.
Strengthen contractual protections – risks that may have seemed remote in previous decades may now be foreseeable, for example geopolitical risks and extreme natural climate events in many parts of the world. Is it still appropriate, therefore, to consider wars, floods and similar events as unforeseeable force majeure events capable of suspending or relieving suppliers from contractual performance? The answer might be yes in some circumstances, but suppliers and customers should always choose contractual certainty where possible.
Focusing on well-crafted force majeure clauses, so the risks that might make it impossible for contractual obligations to be performed are identified as far as possible, and the responsibility and expense for mitigating force majeure events is clearly assigned.
Ensuring robust business continuity provisions, permitting suppliers to take the measures they need to take to continue to provide service, such as sending data outside the region where necessary.
Including terms such as price escalation clauses, change of law mechanisms and enhanced partial or full suspension and termination for convenience rights as necessary, to allow parties to raise prices, address regulatory changes or even exit an agreement (e.g. to escape escalating costs) when there has been no breach of contract.
Including appropriate governing law and dispute resolution clauses to ensure issues can be resolved in a suitable forum. This may include:
evaluating where a counterparty has assets which can be enforced against and whether it is necessary to ask for project-specific insurance to be taken out, a parent company guarantee or performance bond;
a tiered approach, such as a negotiation or mediation stage for a defined period, followed by formal proceedings in court or arbitration, in order to encourage early resolution and avoid escalating costs if possible;
choosing a mature, predictable governing law and forum and considering whether any mandatory laws apply despite the choice of governing law, for example data protection laws applicable to the parties or location of the data centre;
Operating a data centre is a high-risk undertaking on which the success of businesses – and even economies – around the world rests. Some jurisdictions, such as the United Kingdom, have already categorised data centres as critical national infrastructure, placing them on an equal footing with energy and water supplies3. As data consumption and processing needs increase, and as geopolitical and climate uncertainty persists, the challenges are likely to become more complex over time. Disruption and downtime are costly for suppliers and customers alike, with consequences ranging from contractual penalties and reputational damage to, in extreme cases where termination is triggered, lost revenue and wasted investment. It is imperative for all concerned that these risks be addressed from the project inception and contract negotiation stage. With appropriate security, disaster recovery and business continuity measures and contractual risk allocations in place, it should be possible, even in uncertain times, to maintain business-as-usual.
considering whether any investment treaty exists that could provide another route for dispute resolution and recovery.
Alexandra Lester Partner, Dubai
REFRENCES
Skills shortages also loom large in areas affected by conflict or natural disasters. If geopolitical or other events prompt an exodus of talent capable of managing complex systems, it can become difficult for data centre operators to meet their obligations under their service level agreements (SLAs).
This is clearly demonstrated by recent developments in Great Britain, with the system operator carrying a long-overdue grid connection reform: a year-long process that halted M&A activity and project development industry-wide.
Of course, there are solutions to grid constraints. The classic example is connection to private wire generation and distribution systems, ones that incorporate batteries to ensure that back up power is available. While such measures may not completely avoid the need for a grid connection, they can vastly reduce the import capacity required, allowing data centres to come online sooner – by a matter of years rather than months.
Long delays due to required grid reinforcements;
Watt’s the rush?
ata centre developers are newer to the pains of obtaining grid connections. For developers of
renewable generation and battery storage systems, the fight to get connected to grid networks is a familiar battle. Grid networks around the globe are often creaking at the seams due to decades of underinvestment.
Data centre developers, alongside their advisers, should clearly be considering grid access and power purchase arrangements alongside their general equipment manufacturing lead times and construction timelines. It is key to understand the regulatory and legislative landscape in the relevant jurisdiction so that arrangements can be made within the bounds of local law. We are well placed to advise, having worked across a number of jurisdictions, particularly in relation to project development and power purchase arrangements.
Data centres plugged into the grid race!
While renewable generation projects have been attracting investment for years, the infrastructure that supports their deployment has failed to keep up. Often, this is because the monopoly infrastructure is state-owned or more stringently regulated, with the investment required to deliver planned expansions and reinforcements requiring approval from regulators or governments. This means investors are facing a host of issues in trying to connect their projects, including:
Supply chain pressures from global demand resulting in escalating costs and further delays;
Regulatory uncertainty, with many jurisdictions assessing and changing prioritisation and connection of renewables, and also treatment of batteries that require both export and import capacity.
This is the state that data centre developers have found the market in, and they are likely to face the same issues. With ever more power-hungry data centres and hyperscalers being planned to deal with the vast quantities of data that our modern world runs on, and the rise of AI which has exponentially increased that need, grid capacity and securing power is an issue that can put a spanner in the works of the best laid plans.
Tim Atwood Associate, London
One of the primary advantages of a disaggregated approach is the ability to reduce programme risk by enabling earlier procurement of critical equipment. By engaging directly with suppliers, owners can secure factory production slots and improve programme certainty in an environment where supply chain constraints are common.
Benefits of splitting the delivery route
Despite these benefits, a disaggregated contracting model removes the simplicity of a single point of responsibility, creating a network of design, supply and workmanship interfaces that must be actively managed. Where defects arise, determining the root cause can become complex and contentious.
While disaggregated procurement offers clear advantages, its success depends on robust project governance and well-structured contractual frameworks.
Where overseas procurement is involved, additional layers of complexity emerge. Data centre development is inherently global, with specialist equipment often sourced internationally. Owners must consider differing legal and regulatory frameworks, compliance standards, and governing laws across contracts. Practical considerations also expand to include shipping, customs, insurance and factory inspections.
Early coordination between delivery parties is essential, including suppliers, contractors, programmers and commissioning agents. Equipment suppliers may be engaged at an early stage to address long lead times, but should not be treated in isolation. Their specifications, delivery schedules and performance requirements must be considered within the overall project strategy.
Traditionally, developers (and their lenders) in most commercial construction projects have favoured using a single main contractor to take full responsibility for the entire design and construction of a project, under a “design and build” or “EPC” procurement model, finding comfort in having a single point of responsibility for design and workmanship issues, as well as one party responsible for logistical coordination and site access.
This sits alongside other widely reported constraints, most notably grid connection and power availability. As a result, developers are increasingly turning to on-site power generation solutions to provide primary power supplies locally, which in turn increases the amount of specialised, mission critical equipment installed on projects.
Management and mitigation
Benefits, risks and legal considerations
Legal risks and delivery challenges
The role of the owner or developer, or their appointed representatives, also expands significantly. Disaggregation requires active management of multiple direct contracts, coordination of interfaces, and alignment of scope and design integration across packages. This demands a high level of technical capability and experienced, hands-on project management.
Disaggregated procurement in data centres:
Following delivery, installation and commissioning raise further challenges. Installation by the equipment supplier may preserve technical integrity and warranties but can increase coordination complexity. Installation by the main contractor may simplify logistics but can complicate responsibility where defects arise.
During integrated testing and commissioning to achieve “Ready for Service” status, supplier involvement becomes critical. Suppliers availability needs to be secured in advance, particularly where their contractual obligations may have concluded earlier. Questions may also arise where equipment has been outside the supplier’s control for a period, leading to potential disputes over responsibility if testing issues occur.
Data centre projects are inherently complex and contract negotiations can be time-intensive. Taking a coordinated approach to procurement and contracting can reduce the risk of gaps, overlaps or inconsistencies.
Engaging experienced advisers who understand these risks can further support effective implementation, helping to mitigate challenges while maximising the benefits of a disaggregated approach.
Well-drafted contracts are critical. These should include clear role definitions, interface matrices, logistics plans, and structured communication processes. Developing contracts in parallel allows risks and responsibilities to be considered holistically and ensures consistency across the contractual framework.
Tim Atwood Partner, London
However, this is often not the case in the data centre sector. Commercial delivery pressures, sector demands, and the highly specialised nature of many elements of a data centre campus, including both computing technology and supporting infrastructure, can benefit from a more flexible and creative approach.
The rapid growth of the data centre industry has exacerbated existing pressures on supply chains, including lead times for materials and equipment, and the availability of skilled labour and technical expertise required for delivery.
These factors have led the sector to adopt, in many cases, a “disaggregated” contracting structure. Under this approach, an owner or developer directly procures certain critical equipment, removing it from the main contractor’s scope. There are different ways of implementing this, such as having the main contractor install the equipment after delivery or retaining the supplier as installer and in each case, responsibility for overall project delivery is distributed across multiple parties and contracts.
This approach can yield practical and commercial benefits, but it also introduces additional legal and operational risks. This article considers those benefits and risks, and how the latter can be managed.
Cost efficiency is another key benefit. Direct procurement removes expensive equipment from EPC or design and build contractor mark-ups. Developers with strong purchasing power may also achieve additional savings through volume discounts and standardised commercial terms.
This approach also enables owners to build familiarity with specific equipment types and performance characteristics, informing specification decisions. There is also greater opportunity to collaborate with manufacturers on bespoke solutions across projects. By promoting consistency and standardisation, owners can achieve more predictable performance, maintenance requirements and operational interfaces.
Logistics also become more complex. Multiple interfaces arise in relation to delivery, acceptance, transportation, storage and inspection. A delay or defect in one part of the supply chain can directly impact others, and these risks may ultimately sit with the owner unless clearly allocated across the contractual structure.
Close coordination between suppliers and the main contractor can help identify design clashes early and ensure alignment across the supply chain. This supports effective planning and clearer allocation of responsibilities.
A recurring challenge for employers is the difficulty in explaining how AI systems reach particular outcomes. Algorithms can be complex and opaque, making it hard to evidence decision making processes. This has become a key issue in employment litigation. Where an employer cannot explain how an AI supported decision was reached, tribunals may infer discrimination. This risk exists even where the AI tool itself is not inherently discriminatory. Recent claims involving automated facial recognition and algorithmic workforce management demonstrate the difficulty employers face when defending decisions they cannot fully explain.
Practical pointEmployers must be able to give clear, credible evidence explaining how AI tools operate and how decisions are reached. Human oversight remains critical.
AI regulation is developing at pace, but approaches differ significantly across jurisdictions.
The “black box” problem and tribunal risk
Clyde & Co works with maritime employers globally to help them harness the benefits of AI while managing risk. Drawing on our employment, regulatory and data protection expertise, we support clients to:
AI is also reshaping roles, skills and performance expectations. As tasks become automated, employers are increasingly reviewing job content, which can trigger restructures or redundancies. In the EU and the UK, this raises issues around information and consultation obligations and fair selection processes, particularly where AI informs workforce planning.
Assess whether and how AI is being used across HR functions;
AI can bring speed and efficiency to HR decision making, but it also carries a heightened risk of discrimination. It is well established now that AI is susceptible to bias, given it is trained by humans and historic data – which risks perpetuating societal disadvantage.
CV screening tools penalising references to women’s activities or women only educational institutions;
AI-DRIVEN change, restructuring and employee relations
Legal risks, real impacts and how employers should respond
rtificial intelligence is increasingly being used by maritime employers to support recruitment, workforce management
and people decision making. While AI can bring efficiency and consistency, it also presents significant legal and employee relations risks. These risks are already being tested in courts and tribunals globally.
A
A fragmented global regulatory landscape
European Union: The EU AI Act introduces a prescriptive regime focused on pre-emptive risk mitigation. CV sifting and recruitment tools are classified as “high risk” AI systems. The Act has extraterritorial reach and will apply to non-EU employers where AI affects EU based workers or candidates from August 2026.
How AI is reshaping maritime HR:
Bias and discrimination: still the biggest risk
Separately, employees are increasingly using AI chatbots to draft grievances, understand their rights and even guide their responses in meetings. There are also risks associated with managers using AI tools to assist decision making, including the creation of disclosable evidence and inadvertent disclosure of confidential information.
Practical pointEmployers should clearly define acceptable use of AI at work, update policies and ensure managers and HR teams are trained in understanding and managing the risks.
Shadia El Dardiry Legal Director, London
Examples cited in recent cases include:
Facial recognition systems performing significantly better on white male faces than on non-white or female faces;
Algorithm driven job advertising disproportionately targeting candidates based on identity rather than qualifications;
For global maritime employers operating diverse and multinational workforces, these risks are magnified. Recruitment, scheduling, promotion and access to work systems that appear neutral on their face may, in practice, place certain groups at a disadvantage, exposing employers to discrimination claims across multiple jurisdictions.
United Kingdom: There is currently no AI specific employment legislation, but existing laws such as the Equality Act 2010 and UK GDPR apply. Regulators, including the Equality and Human Rights Commission and the ICO, have identified AI as a strategic priority.
United States: Regulation is developing at state level, with some jurisdictions imposing obligations around bias audits, transparency and notification.
Practical pointMaritime employers with cross border workforces should assume that AI compliance is a global issue and avoid relying on a single jurisdiction approach.
How Clyde & Co can help maritime employers
Conduct legally privileged bias and discrimination risk assessments;
Implement appropriate human oversight and decision-making safeguards;
Navigate international AI regulation;
Update AI, grievance and data retention policies;
Manage restructures and workforce change driven by automation;
Train HR teams and managers on the use of AI.
As AI becomes embedded in maritime operations, proactive governance and informed HR strategy will be critical. We look forward to exploring these issues further during the panel discussion.
Recent comments from OEMs, together with shifts in momentum in the delivery programmes, suggest that the OEMs are now in much better control of their supply chains and delivery schedules. Aircraft manufacturers are now signalling a decisive shift: delays are over, and they intend to deliver aircraft on or even ahead of schedule. More strikingly, OEMs are asserting their contractual rights to deliver, irrespective of airline readiness. In essence, OEMs can generally either force delivery of aircraft on the scheduled delivery date or charge punitive penalties for failure to take delivery. This represents an intriguing flip of the magnetic poles of contractual risk and liability.
Most aircraft OEM purchase agreements will allocate the vast majority of risk to the purchaser. It is simplistic to see this as inherently unfair, because there is a complex hinterland of cost and pricing that allows this model to work in making aircraft affordable. However, the current situation does allow for some degree of irony.
In the recent past, all the focus has been on delays by the OEMs, relying on heavily weighted contracts and often slightly nebulous explanations about supply chain issues. Many airlines, with some force of argument, pushed back on these issues. Now, if the OEM is ready to deliver and the airline is not ready to take delivery due to issues in its own supply chain, then those arguments are, in general terms, reversed.
With OEMs pushing punctuality, airlines must therefore ensure that their BFE supply chain is watertight. That means revisiting contracts, enforcing timelines, and escalating with suppliers where necessary. The cost of complacency is no longer theoretical – it’s contractual and a financial imperative.
The shift: OEMs reclaim control
Examples of problematic provisions include:
Delays in BFE delivery can stall aircraft EIS even if the airframe arrives on time, particularly noting the challenge of flying passengers without seats. Every day that an aircraft sits idle represents lost revenue, schedule delays and potentially the extended use of less environmentally friendly aircraft. If penalties for late delivery are added to those costs, the effect can be debilitating for the airline.
Broad force majeure clauses that excuse suppliers in case of delays in performance;
Material but manageable delays before COVID-19 became systemic during the pandemic, as production halted not only at the Original Equipment Manufacturers (OEMs) themselves, but in their supply chain.
Aircraft delivery delays are not without consequence. Uncertainty in the Entry into Service (EIS) dates for aircraft can cause schedule changes, delays to new
Managing the shift
In those circumstances, it is easy to see the irony, and both the force and the farce of those inverted positions.
Aircraft delivery delays: An imbalance of power
The long-COVID shadow
This shift reverberates beyond operational planning. Many airline-supplier agreements contain restrictive provisions on liability and recovery, for example limitation clauses or liquidated damages. If a late BFE delivery delays an aircraft, the airline may find itself squeezed between an uncompromising OEM and a supplier contract that offers little recourse. Complications can arise if there is any ambiguity in
In some cases, Boeing customers are seeing signs of improved delivery whereas for Airbus the ongoing supply chain issues and engine constraints the risk of delays remains prominent.
Recent developments suggest that the poles may be switching in an uneven way for the leading OEMs, with different implications depending on fleet exposure.
While these dynamics continue to evolve, they underline that the practical and contractual implications of delivery disruption are not uniform across fleets and programmes.
Airlines therefore need to be careful on the terms they enter into for BFE and would be well advised to review their BFE contracts and engage robustly with their suppliers to deliver on time.
There are a number of ways in which an airline can find itself unable to take delivery of an aircraft on its scheduled delivery date, such as issues with finance or regulatory problems. However, the current focus seems to be on Buyer-Furnished Equipment (BFE). BFE comprises the components (such as seats, galleys, in-flight entertainment systems and others) that airlines source directly and deliver to the OEM for installation on the aircraft prior to the scheduled delivery date.
For much of the past decade, airlines have been locked in a frustrating and deepening cycle of delayed new aircraft deliveries
Airframe OEMs (Airbus and Boeing primarily) invoked restrictive contract provisions to shield themselves from liability with the result that airlines bore the brunt, absorbing losses, missing growth opportunities, and recalibrating fleet plans in an environment where delay and uncertainty were normalised. In combination with recent new technology engine performance issues, this has been a period in which a bright light has been shone upon the stark imbalance of contractual protections for airlines in OEM contracts.
routes and may force airlines to retain older, inefficient aircraft in their fleet or to have to lease in extra capacity. It can also create difficulties or extra costs with finance and lead to extended periods during which airlines are deprived of funds paid towards delivery of aircraft that they have not received. Many airlines have found themselves ostensibly unprotected from these associated losses (though many explored and agreed commercial solutions with the OEMs).
Even after the pandemic subsided, delays persisted and, in many cases, worsened. In the immediate aftermath of lockdowns, a mix of airlines either sought delivery of aircraft or looked for ways to defer or cancel orders. The heavy order books that had predated COVID exacerbated a bloated and unwieldy delivery programme that increased the difficulties associated with on-going manufacturing delays.
These delays were largely attributed to “supply chain” issues which were mostly unspecified and even more rarely justified with evidence. This created a market expectation that delivery dates were aspirational rather than absolute. In some cases, this appears to have cultured a commercial lethargy that spread to other links in the supply chain feeding the airlines.
Ambiguities in delivery specifications or regulatory compliance that give suppliers opportunities to delay or obfuscate their obligations;
Weak delivery obligations that allow for only “reasonable endeavours” or “estimated delivery dates” for compliance;
Liquidated damages clauses that restrict available compensation on delay or failure to deliver that do not mirror the airline’s obligations to the OEM.
agreed delivery schedules for BFE or where the supplier gets involved in discussions with the OEMs about the delivery timetable. All of this can cause quickly escalating losses for an airline.
Audit existing contractsReview BFE agreements for delivery obligations, remedies, and liability caps. Identify gaps that could leave you exposed. Set those obligations against those in the OEM contracts and seek suitable indemnities with regard to potential exposure to the OEMs.
The BFE bottleneck
There are some actions airlines can take to minimise their legal risk:
Engage suppliers earlyCommunicate the new reality: OEMs are enforcing timelines. Suppliers must align or risk damaging relationships. Put pressure on the suppliers to perform and to prioritise your deliveries. In a market where demand exceeds supply, there will be a process of commercial prioritisation by the suppliers.
Negotiate proactivelyWhere possible, strengthen contractual protections in all areas of potential exposure, and for new contracts try to align them as closely as possible to any commitments made to the OEMs.
Be prepared, in extreme situations, to take the risk to terminate a supplier agreement and seek more reliable and favourable terms elsewhere. The damages risk of doing so could well be lower than the effects of an extended delay. Clearly, the earlier this process is assessed and implemented, the more likely it is to be effective.
Integrate delivery planningTreat BFE readiness as a critical path item, not a parallel process. Build contingency buffers and monitor milestones rigorously.
What should airlines do now?
Parties that adapt quickly will be better able to protect revenue, preserve flexibility, and maintain credibility with OEMs. Those that don’t risk being caught in a perfect storm of operational disruption and financial liability.
Tim Fox Legal Director
Aron Dindol Senior Knowledge Lawyer
Several foundational issues in international space law remain unsettled. There is still no agreed definition of where airspace ends and outer space begins. The application of the “non appropriation” principle to commercial resource extraction remains ambiguous. And responsibility and liability at an international level continue to sit with states, even as activity becomes increasingly private and multinational.
Alongside these structural questions sit urgent practical challenges. Space debris has become a systemic risk, driven by congestion, collisions and uncontrolled re-entries, yet remains governed largely by voluntary standards rather than binding law. Dispute resolution mechanisms under the treaties are limited and untested, offering little comfort as commercial stakes rise.
New initiatives such as the Artemis Accords illustrate both the growing appetite for space governance, even among states without major space programmes, and the absence of universal consensus. They reflect a pragmatic, coalition-based approach but also underline the fragmentation of the current legal landscape.
Because international law operates at a state-to-state level, practical risks, particularly for cross-border, joint or sea-based launches, are managed through contracts and insurance. For insurers, this makes licensing structures, indemnity frameworks and operational controls critical to risk assessment.
Structural questions still unresolved
The Artemis Accords reflect a pragmatic middle ground. They reaffirm the ban on territorial ownership but take the position that extracting and using space resources does not amount to sovereignty. They also promote concepts such as “safety zones” to avoid harmful interference, relying on non-binding norms rather than new treaties.
waivers and financial responsibility limits. Operators must also register space objects, determining which state has jurisdiction and control.
What was once the preserve of states and scientific missions is now shaped by commercial launches, private satellites, tourism ventures and the renewed push for sustained human activity beyond Earth, as seen in NASA’s Artemis II mission which paves the way for future missions to return humans to the Moon. The question facing policymakers, insurers and operators alike is whether space law, largely built for a very different era, is still fit for purpose.
Looking ahead
At a high level, the existing framework still functions. The deeper question is whether a system designed for state driven activity can effectively regulate an industry dominated by private actors, commercial competition and global supply chains.
Regulating risk in an era of commercial expansion
Space law is clear on one point: no state can own the Moon or other celestial bodies. The Outer Space Treaty prohibits claims of sovereignty or territorial ownership. What it does not clearly address is whether minerals or resources extracted from space can be owned once removed.
Governments are not starting from zero. In the UK, space has long been identified as a strategic growth sector, and regulatory reform is already underway. The critical issue now is delivery: regulatory certainty, coordinated oversight and targeted support that allows companies to scale.
As space becomes more commercial, contested and congested, the law will increasingly be tested as a tool for managing risk rather than enabling ambition. Whether it can rise to that challenge, without losing the cooperative principles that underpin it, will shape the next phase of the space economy.
For operators, launching a rocket involves navigating a complex mix of international law, domestic regulation and detailed commercial arrangements.
As space activity accelerates and diversifies, the legal framework governing it is under growing strain.
Modern space law rests on a small group of United Nations treaties agreed between 1967 and 1979, particularly the Outer Space Treaty. These instruments established high level principles designed for a Cold War context, where space activity was state led and geopolitical rather than commercial in nature.
Those principles remain important. They prohibit national sovereignty claims over celestial bodies, commit states to peaceful use, and place responsibility for space activity firmly at state level. But they were arguably not designed to regulate today’s reality of commercial launches, mega constellations of satellites, space tourism or competing plans to exploit extraterrestrial resources.
As a result, the core legal framework operates at a very general level and is increasingly misaligned with how space is actually being used. Regulation has shifted towards non-binding “soft law” guidance, such as sustainability and debris mitigation standards, and fragmented national regimes. This creates legal uncertainty, regulatory competition and gaps in oversight at precisely the moment when risk in orbit is intensifying.
The result is a patchwork approach: land ownership in space remains prohibited, while ownership of extracted resources is increasingly shaped by soft law and state practice rather than settled international rules.
international level, most notably through the Moon Agreement, failed to gain widespread support. In the absence of global consensus, some states have adopted national laws recognising private rights over extracted resources, while others argue that this risks undermining the collective nature of space.
Similarly, when things go wrong in space, international law places liability on states. Launching states face absolute liability for damage on Earth and fault-based liability for damage in space. The practical question is how effectively that risk is transferred to operators through insurance and indemnities – and whether existing arrangements are adequate as collision risk and congestion increase.
Who owns space and its resources?
Space debris is widely recognised as a growing environmental and operational threat, yet there is no binding international regime that directly regulates its creation or removal. Existing treaties say little about debris, leaving governance largely to voluntary guidelines.
For insurers and risk managers, debris, re-entries and satellite interference now sit at the intersection of environmental, operational and reputational risk.
The UK took a major step forward with the Space Industry Act 2018, which finally provided a clear legal basis for domestic launches. If the UK is to compete with established launch states, the challenge now is not more law, but better application.
Streamlined licensing, a more risk-based approach to liability and insurance, and clearer regulatory guidance could significantly reduce cost and uncertainty for operators. The balance between safety, international obligations and commercial competitiveness will be critical.
This debate is sharpened by developments in the EU, which is moving towards a harmonised EU Space Law covering areas such as supervision, cybersecurity and sustainability. That creates both competitive pressure and an opportunity for the UK to differentiate itself through a more agile, commercially responsive framework.
Debris, damage and accountability
Kevin Sutherland Partner and Chair of the Global Aviation Practice Group, San Francisco
Gabriella Mifsud Associate, London
Space law at a crossroads:
A framework built for another time
Under the Outer Space Treaty, states are responsible for all space activities carried out by their nationals. Launch providers must therefore obtain government authorisation and accept ongoing state supervision. Liability is central. Under the Liability Convention, a launching state is strictly liable for damage caused on Earth, even where a launch is conducted by a private company.
States manage this exposure by pushing risk back onto operators through licensing conditions. These typically include mandatory insurance, indemnities, cross
Launching rockets: law, liability and insurance
That ambiguity has become commercially significant as lunar and asteroid mining moves from theory to planning. Attempts to regulate this collectively at an
The UK’s position: opportunity through refinement
There’s a growing American appetite for nuclear amid growing electricity demand from AI and data centres. Several states are now revisiting their long standing nuclear policies.
Data centres are driving demand, proposals from tech giants, including direct power purchase agreements tied to nuclear plants, have catalysed renewed attention on both legacy reactors and new technologies.
State-by-state inconsistencies persist with, whilst many states maintain nuclear moratoria even as they pursue aggressive clean-energy targets, prompting legislative moves to carve out exceptions for advanced reactors.
The United States: A renewed nuclear landscape
Notable features of the Dutch strategy include:
Although Poland remains a first of a kind jurisdiction with no prior commercial nuclear experience, its structured, conservative regulatory approach and strong alignment with Western partners provide meaningful stability for insurers and investors.
In a recent insurance webinar on emerging risks, speakers from across our international network explored how next generation nuclear technologies, including small modular reactors (SMRs), are beginning to reshape policy, regulation, infrastructure and insurability across key markets.
Global trends, risks and opportunities for Insurers
France enters the next gen nuclear era from a position of longstanding nuclear maturity. With one of the world’s largest operating fleets and deeply embedded nuclear expertise, the French strategy focuses on:
Poland is transforming into one of Europe’s most ambitious nuclear newcomers. Faced with the decline of coal and the need for energy security, Poland is pursuing a dual track of large-scale reactors alongside industrial SMRs.
The push toward next generation nuclear is unfolding against a backdrop of volatile global energy prices, heightened energy security concerns and mounting pressure to decarbonise. Traditional fossil fuel markets have proven vulnerable to geopolitical disruption, prompting jurisdictions worldwide to revisit nuclear energy not only as a low carbon solution but as a source of stable, dispatchable baseload power.
Across the United States, Europe and emerging nuclear jurisdictions, interest in new nuclear technologies is accelerating, not only in large-scale reactors but increasingly in SMRs, which promise enhanced flexibility, reduced construction risk and a more scalable deployment model.
Clear government prioritisation of repeat builds over first of a-kind risk;
The Netherlands’ two pronged approach: investing in large conventional reactors while preparing the ecosystem for SMRs as the technology matures.
24 GW of nuclear capacity by 2050, around a quarter of expected electricity demand;
The UK’s ambitious plan to revive its nuclear contribution, which has fallen sharply since the 1990s. The Civil Nuclear Roadmap to 2050 aims to deliver:
Deployment of SMRs, led by Rolls Royce following a competitive process;
Across global markets, the rise of next generation nuclear technologies is reshaping both the opportunities and the challenges facing insurers.
As nuclear development shifts from predominantly government owned models to mixed public private financing, demand is growing for new and specialised insurance solutions, including:
Completion and construction risk,
Next Generation Nuclear:
A new global energy landscape
Key developments include:
Multiple Generation III+ reactors planned, with the first large plant using AP1000 technology targeted for mid 2030s operation.
Rolling out new EPR2 reactors;
Latest insurance news and opinions to help you navigate the unknown
InsuranceEmerging Risk
s global energy systems come under intensifying pressure, from geopolitics to surging electricity demand driven
by AI, electrification and industrial growth, nuclear power is re-emerging as a central pillar of long term energy strategy.
Insurance frameworks are evolving with updates to the long standing Price Anderson Act now account for SMRs, creating proportional liability and insurance requirements more suitable for smaller-scale installations.
This evolving policy and insurance environment is positioning the US as a key driver in next gen nuclear deployment.
Poland: Building a nuclear future at speed
Significant SMR momentum, driven by major industrial players seeking to decarbonise operations.
A rapidly maturing legal and regulatory framework, aligned with IAEA standards and incorporating phased permitting, revenue stabilisation mechanisms and streamlined siting rules.
Growing geopolitical importance: Poland is positioning itself as a strategic nuclear fuel and component transit hub for Central and Eastern Europe as the EU seeks to diversify away from Russian supply chains.
FRANCE: Leveraging a mature nuclear ecosystem
Modernising existing infrastructure;
Advancing SMR and advanced reactor R&D;
Maintaining a stable, highly codified liability and insurance regime under the Paris and Brussels Conventions.
France’s well established statutory frameworks, including mandatory operator liability, strict liability rules, and specialised jurisdictions; provide a stable foundation for integrating future SMR and advanced nuclear technologies.
The Netherlands: Dual track expansion
Long-term system planning to integrate up to 14.5 GW of nuclear by 2050 (subject to cost feasibility);
A robust Paris Convention aligned insurance architecture;
The highly coordinated Dutch nuclear insurance pool, interconnected with international pools to manage aggregation risk.
For insurers, opportunities lie in pre commissioning lines (construction and erection risks) and transport insurance, alongside the eventual operational risks.
United Kingdom: Reinvigorating a declining fleet
A first SMR site at Wylfa, North Wales, announced in 2026;
A new public private partnership model, designed to attract investment while managing risk.
Challenges remain, particularly around workforce shortages, waste management, security considerations and underwriting new technologies; but the UK’s structured, government backed approach presents significant opportunities for insurers involved in project risk, construction, liability and operational lines.
Supply chain and transport cover,
Decommissioning guarantees,
Liability frameworks scaled to reactor size, particularly for SMRs.
A global shift: Opportunities and risks for insurers
These changes are driving the need for fresh insurance approaches as first of a kind projects move forward without established operational histories.
Despite variations in national policy and regulatory structures, the overall trend is clear: nuclear power is re-establishing itself as a critical pillar of energy security, decarbonisation and resilience and insurers will play a pivotal role in enabling this transition.
Click here to watch the webinar on Powering the future: Understanding insurance risks in the Next Gen Nuclear era
Click here to listen to Podcast: Insuring the Nuclear future
David Méheut Partner, Paris
Arkadiusz Krasnodębski Partner, Warsaw
Neil Beresford Partner, London
Daan van Ark Associate, Rotterdam
Konrad Krebs Senior Counsel, New Jersey
Testimony highlighting internal platform knowledge of risks, forming the basis for arguments involving intentional conduct, known loss and breaches of duty of care.
A recent U.S. coverage ruling (Delaware Superior Court, applying California law) denied Meta’s insurers a duty to defend based on findings that the underlying claims arose from intentional acts, not accidents, an early signal of potential coverage disputes insurers may face in future similar suits.
Our recent Emerging Risk webinar, From Likes to Lawsuits: Navigating the Insurance Impact of Social Media Addiction, brought together experts from multiple markets across the globe to explore how the risk landscape is shifting. Their insights reveal a rapidly accelerating challenge for insurers across casualty, cyber, tech E&O, and product liability towers.
The growing insurance implications of social media addiction
Australia’s new social media restrictions place the onus squarely on platforms, not parents, to prevent under 16s from accessing major platforms. Failure to comply may result in fines up to AUD 49.5 million, and platforms are trialling intrusive age verification technologies involving biometrics, behaviour analysis, and identity document scanning.
Public nuisance, once a relatively niche legal avenue, has re-emerged in both opioid litigation and now social media addiction claims.
The United States remains the most advanced jurisdiction for litigation related to social media addiction. Thousands of claims have been consolidated into a major Multi-District Litigation (MDL) in the Northern District of California, with additional state-based coordinated proceedings underway. These actions are driven by:
Allegations that platforms intentionally deployed addictive design features, such as infinite scroll, reward-based mechanisms mirroring slot machines, and algorithmic reinforcement loops.
France, the Netherlands and the UK are all experiencing fast-paced regulatory action.
Regulatory defence costs
These regulatory shifts increase exposure across:
Fines and penalties (where insurable)
Meanwhile, Singapore’s comprehensive online safety regime, including mandatory content moderation standards, age assurance and a forthcoming redress mechanism for online harms, all of which increase compliance risk and heighten the likelihood of claims involving psychological injury, online harassment or platform-based failures.
For insurers, these developments reinforce that digital harm regulation is globalising, creating new frontiers in liability, regulatory defence, and mental health related exposures.
The litigation landscape
School districts and municipalities are alleging that platforms have caused community wide harm by designing inherently addictive systems.
cross jurisdictions, regulators, litigators and policymakers are sharpening their focus on the harms associated
with social media use, especially among young people. While the discourse around “addiction” is evolving, one trend is clear, the insurance industry is entering a new era of digital exposure, where liability is no longer limited to data breaches or third party content, but extends deep into questions of design, behaviour, mental health, and platform responsibility.
This ruling is particularly significant. If courts increasingly frame such harms as arising from intentional conduct, coverage positions across general liability, tech E&O and cyber may constrict, prompting further litigation between insurers and policyholders.
A public nuisance revival with insurance consequences
Public nuisance claims often do not require bodily injury, complicating traditional GL policy triggers.
Insurers have historically resisted nuisance-based indemnity, creating a likely battleground in future social media litigation.
Insurers must closely scrutinise policy language, especially where bodily injury triggers, occurrence definitions, and non-accidental harm exclusions may intersect with this emerging tort strategy.
Australia: A world first ban on under 16s
Europe: Online safety, product liability and the road to strict liability
Middle East & Asia: Rapid regulatory maturity and expanding exposure
Claims alleging defective digital products
Mental health impacts attributable to online engagement
GCC countries, particularly the UAE and Saudi Arabia, are rapidly introducing child digital safety laws, stringent content regulations, mandatory influencer licensing regimes, and severe cybercrime penalties. Fines can escalate significantly where misinformation is deemed to affect public order. In the UAE, a recently approved law sets a minimum age for social media use: children under 15 are prohibited from creating or operating accounts, while those aged 15–16 will be permitted regulated access. Social media platforms have 12 months to comply with these requirements. Collectively, these evolving frameworks broaden potential liability exposure for platforms and may give rise to future claims as newly introduced civil codes mature.
Social media is just the beginning, as similar behavioural based allegations are emerging around:
Gaming platforms, where plaintiffs allege developers maximised play time and in game spending through design choices mirroring addictive techniques.
Claims from individuals, school districts, and state Attorneys General, alleging harms including depression, self-harm, anxiety, and costs associated with tackling a youth mental health crisis.
Coverage for regulatory fines under cyber or tech E&O where insurable by law
Claims relating to privacy harms arising from age verification mechanisms
This raises three crucial insurance considerations:
Litigation risk as advocacy groups and tech firms challenge the legality and proportionality of such bans
France’s upcoming under 16 ban, criminal complaints against platforms, and expanded product liability rules that explicitly encompass digital products, algorithms and psychological harm, dramatically lowering the threshold for claimants.
The Netherlands’ WAMCA framework, enabling large collective actions with significant litigation funding involvement, creating fertile ground for mass claims against platforms.
The UK’s Online Safety Act 2023, empowering Ofcom to levy fines of up to 10% of global revenue, as well as the UK Government’s recently proposed social media ban for under 16’s, which the Government hopes to pass before Christmas 2026, with the ban to be brought into force in the early part of 2027.
The next wave: Gaming and AI chatbots
AI chatbots, accused of emotional manipulation, immersive interactions, and contributing to “AI psychosis”, self-harm and, in extreme cases, violent behaviour.
These cases may expand beyond social media to any platform leveraging behaviour modifying design, creating substantial uncertainty for insurers.
The global shift towards regulating digital harms, combined with litigation accusing platforms of addictive design, marks a pivotal moment. As the boundaries between product liability, behavioural design, mental health, and digital regulation blur, so too does the traditional allocation of risk.
Click here to Read this article ‘Navigating first-instance judgments in social media disputes’ to understand how early court decisions are shaping social media risk.
Click here to listen to Podcast: Emerging Risk: Social Media Addiction
Click here to watch the webinar on Emerging Risk: Social Media Addiction
Darling Brophy Special Counsel, Brisbane
Rosehana Amin Partner, London
Kirsten Soto Senior Counsel, Los Angeles
Olivia Darlington Partner, Dubai
Zhen Guang Lam Legal Director, Singapore
Christopher Cowland Legal Director London
Deal-making by carriers held steady, while transactions involving intermediaries, particularly brokers and managing general agent (MGA) platforms, saw stronger momentum.
After a sharp downturn in global acquisitions in 2024, when deal-making hit a 16-year low prompted by global instability, has the contraction continued or has there been a recovery, and if so, where?
Insurance growth update
his year, the direction of travel when it comes to insurance M&A deal volumes has been more closely
watched than ever.
Carrier transactions hold steady, while intermediary deal-making is strong
Activity in Asia-Pacific (APAC) rebounded robustly: transaction volumes increased by 50% from 39 in 2024 to 59 in 2025, fuelled by capital availability and outbound appetite among Japanese insurers, following domestic portfolio recalibration.
2026
Global insurance M&A activity: discipline, not deal fever
2023). Discipline, not deal-fever has been the order of the day, as insurers and brokers have taken a more strategic approach to acquisitions, amid moderating interest rate pressure and improving macroeconomic stability. They have been concentrating on portfolio optimisation and geographic refocussing: targeting specific capabilities, strengthening specialisations, deepening expertise and pursuing selective cross-border expansion.
Activity around the world: APAC rebounds robustly while THE US remains busiest region
MEET THE Authors
Yvonne Lam Partner, Sydney
Peter Hodgins Partner, Dubai
Our analysis of the 2025 deal data reveals that overall activity has stabilised. Globally, 211 transactions were completed, a marginal (4%) increase from 202 the previous year (compared to a peak of 346 deals in
Behind the headline figures, there are some notable differences in activity and approach:
Among carriers, deals tended to be selective and often defensive, focused on reinforcing core market presence and targeting strategic fits, alongside streamlining portfolios, rather than ramping up scale or driving transformation.
Meanwhile, on the intermediary side, distribution and delegated underwriting models continue to attract investors because they offer robust growth opportunities with lower capital requirements than traditional balance-sheet underwriting models, driving comparatively higher transaction rates.
The United States retained its position at the top of the deal-making table, with 77 completed transactions – although this represents a 16% fall from 2024, when 92 transactions were completed. Its influence on global M&A activity remains strong, with many multinational transactions driven by US-headquartered firms.
M&A in the UK and Europe remained stable, at 57 deals last year (compared to 56 in 2024). It’s worth noting that interest in access to the Lloyd’s market appears to be returning, after some companies withdrew from the market. Meanwhile, the Middle East and Africa (MEA) region saw 15 deals, versus 17 the previous year.
Regional M&A Activity 2025
When it comes to deal values, 15 transactions exceeded the US$1 billion mark, and there were seven “mega-deals” in excess of US$5 billion. Of the latter, four were in APAC (two in Japan), and two in the US. The largest deal by far took place in Europe, with a US$10.2 billion deal in Switzerland.
Trends in mega-deals and cross-border transactions
The macroeconomic environment has created favourable conditions for cross-border acquisitions. Cross-border activity remained measured last year, at 43 transactions in total. Against this backdrop, the forward pipeline for this type of deal looks healthy, particularly among intermediaries with ambitions to build multi-territory distribution footprints.
There are reasons for cautious optimism as we look ahead. 2026 has already got off to a flying start with one mega-deal completed. However, there’s always the risk that geopolitical instability could worsen, hitting confidence, or that interest rates rise, increasing the cost of capital.
Cautious optimismahead
We expect carriers to continue targeting strategic bolt-on acquisitions (rather than pursuing “growth at all costs”) to continue, and demand for intermediary consolidation to remain high, driving a gradual acceleration in deal-making rather than a cyclical surge. While the US will remain the primary source of activity, expansion across APAC looks set to continue, and parts of Africa may also become targets for those looking to penetrate new markets.
Overall, it’s reasonable to assume that market activity will be solid, even if it’s not stellar. Pent-up demand and abundant capital may drive an uptick in M&A volumes, but discipline is likely to remain a dominant theme.
Singla, A., Sukharevsky, A., Yee, L., Chui, M., & Hall, B. (2025, March 12). The state of AI: How organizations are rewiring to capture value. McKinsey. https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai (2023, June 1). Generative AI to become a $1.3 trillion market by 2032, research finds. Bloomberg Intelligence. https://www.bloomberg.com/company/press/generative-ai-to-become-a-1-3-trillion-market-by-2032-research-finds/ Ringdahl, K. (2025, April 14). Generative AI is the greatest force multiplier in agile history. Forbes. https://www.forbes.com/councils/forbestechcouncil/2025/04/14/generative-ai-is-the-greatest-force-multiplier-in-agile-history/
References to be supplied
The following analysis explores some of these vital areas, providing actionable insights for organisations.
Phishing and fraud: Cybercriminals may exploit crisis communications through government-impersonation, including campaigns mimicking the UAE Ministry of Interior and Dubai Customs.
Regional instability has catalysed a highly active and multifaceted cyber threat environment, requiring organisations to defend against both sophisticated state-sponsored attacks and opportunistic cybercrime.
Opportunistic cybercrime and ‘hacktivism’ While organisations may have their attention diverted by immediate physical risks – such as property damage, supply-chain disruptions, and inflation – non-state threat actors are likely to actively exploit this reduced cyber-vigilance. This opportunistic malicious activity manifests in several ways:
Targeted malware and social engineering: Threat actors are deploying malware specifically designed to target remote-access systems, alongside social engineering tactics that prey on anxieties surrounding evacuations, travel disruptions, and crisis responses.
Vulnerabilities in operational technology (OT) Beyond traditional IT networks, organisations should seek to secure their operational technology. Infrastructure that supports operational monitoring, including industrial monitoring systems and data sensors, represents a critical point of vulnerability. Disruption to these OT systems could lead to severe, real-world operational consequences.
Physical risks in the region directly impact digital infrastructure, making operational resilience a paramount concern.
ecent geopolitical developments in the Middle East have introduced a complex web of technology-related challenges for organisations operating within the region. To maintain business continuity and secure critical assets, companies must
holistically review their operational resilience, cyber defence mechanisms, data governance practices, and third-party contractual agreements.
R
Navigating IT risks and business continuity
Middle East operational resilience:
Operational resilience of technology infrastructure
The evolving cyber-threat landscape
Data centre and cloud infrastructure disruption The physical vulnerability of digital assets was recently highlighted when Amazon Web Services (AWS) had to temporarily shut down one of its data centres in the UAE after objects struck the facility. Such disruptions to regional cloud infrastructure can cascade into increased downtime and data latency for hosted databases, interruptions to, or failures of, Software-as-a-Service (SaaS) platforms, and severe knock-on impacts for businesses dependent on these environments.
Recognising these immense pressures, the UAE Cybersecurity Council recently introduced a temporary BCP workaround, permitting local organisations to store certain datasets offshore.
Concentration and supply-chain risks Many businesses rely heavily on a highly concentrated market of global cloud providers. If infrastructure is centralised within a single geographic region or heavily dependent on a single provider’s architecture, a localised physical outage could simultaneously cripple multiple organisations.
Organisations must therefore assess whether their critical workloads can be swiftly migrated to alternative providers or regions (again, subject to the considerations set out in Section 4 below).
Securing the remote workforce
Furthermore, organisations should map their broader technology supply-chain, recognising that instability exposes concentration risks across service providers managed service providers (MSPs), telecommunications networks, and hardware suppliers.es include:
As crisis response plans are activated, a surge in remote work introduces new security vulnerabilities. Increased exposure stems from employees utilising unsecured home networks or personal devices without a Virtual Private Network (VPN), an over-reliance on remote access systems, and a general reduction in the oversight of user behaviour.
Relocating infrastructure or shifting hosting services to safeguard operations immediately triggers complex data governance considerations.
Data residency and localisation requirements Middle Eastern jurisdictions often enforce strict data localisation requirements. Specific categories of sensitive data - such as health data, information related to critical national infrastructure (CNI), or government data - are legally required to remain within the jurisdiction where they were collected.
If local data centres face disruption, organisations must conduct rapid legal assessments to determine if their BCP measures allow for data to be transferred offshore, even temporarily.
To combat this, organisations should mandate that remote working environments maintain security controls equivalent to corporate office environments, especially concerning access to critical systems. This includes deploying appropriate endpoint security on all devices and ensuring staff are rigorously trained on secure system access protocols.
Even in the face of rapid operational disruption, companies must determine if such transfers are legally permitted, what of the mandated contractual mechanisms or safeguards would be utilised, and whether any regulatory notifications or approvals are required.
Technology disruptions often lead to contractual disputes and liability assessments.
To mitigate this, organisations must review and update their business continuity planning (BCP) to ensure adequate redundancy of hosting and database arrangements, failover capabilities both within and across geographic regions (as appropriate), and the ability to seamlessly migrate services between cloud regions (all subject to the considerations set out in Section 4 below). Where necessary, load bearing should also be geographically distributed to prevent a single point of failure.
State-linked cyber activity There is a significantly increased risk of state-linked cyber activity aimed at creating operational instability, disrupting critical services, and gathering intelligence. These highly capable threat actors typically target critical infrastructure, financial services, energy and logistics companies, cloud and data infrastructure, and government or quasi-governmental entities.
A prominent example of this is the increased activity against United Arab Emirates (UAE) entities by “Peach Sandstorm,” an Advanced Persistent Threat (APT) group with an Iranian nexus.
Hacktivist DDoS attacks: There has been a notable surge in Distributed Denial of Service (DDoS) attacks orchestrated by ‘hacktivist’ groups. Organisations must therefore remain highly vigilant to cyber threats that, while potentially not directly related to the geopolitical conflict directly, are enabled by the broader systemic disruption it causes.
Data governance and regulatory compliance
Personal data transfers Moving digital infrastructure inherently involves relocating data. If this data includes personally identifiable information, cross-border data transfer obligations under local data protection laws are triggered.
Navigating contractual and liability challenges
Reviewing technology contracts Disruptions will often trigger clauses across cloud service agreements, SaaS contracts, hosting agreements, and IT services contracts. Companies should urgently review any Service Level Agreements (SLAs), downtime provisions, limitations of liability, and the specific disaster recovery commitments made by their vendors. It is also critical to verify, where necessary, whether existing contracts legally permit temporary or permanent migration to alternative providers.
As always, the key to minimising issues is for organisations to ensure they are speaking directly and often to their technology and service providers, as keeping communication lines open will significantly reduce the risk of disputes arising.
Force majeure and ‘exceptional events’ Geopolitical developments may sometimes lead parties to invoke force majeure or “exceptional events” clauses when their contractual performance is prevented by circumstances beyond their control — such as data centre unavailability, damaged infrastructure, or non-delivery of input services.
Where provided for in the contract, organisations must strictly adhere to contractual notification procedures and mitigation requirements to successfully activate and rely on these clauses.
Delay provisions and new arrangements Even if force majeure is not successfully invoked, supply chain disruptions may trigger delay provisions where they are included in contracts, impacting implementation timelines and infrastructure deployment.
Companies should seek counsel on relief entitlements and performance extensions. Furthermore, migrating to new providers necessitates the negotiation of new hosting contracts, where organisations must prioritise cross-border data transfer obligations, stringent SLAs, and robust business continuity and disaster recovery provisions.
Managing vendor risk and enhancing business continuity
Ultimately, an organisation’s resilience is only as strong as its third-party dependencies. Organisations should extensively map their exposure to third-party technology vendors, assessing the individual resilience of their cloud and IT security solutions, hosting providers, software vendors, and hardware suppliers.
While proactive inquiries from customers are often limited, it is imperative that organisations interrogate their technology providers’ business continuity and disaster recovery plans. Companies should, where possible, secure contractual reassurances and ascertain:
how rapidly services can be restored or transferred post-incident; and
whether their suppliers have robust contingency plans for regional infrastructure disruption;
whether accessible, viable backup infrastructure exists outside the affected region, or with an alternative service provider.
Strategic questions for organisational assessment
Where is your core infrastructure hosted, and do you possess sufficient geographical redundancy?
Is your central IT infrastructure spread out enough to survive a localised disaster?
What specific regulatory constraints limit the movement of your data outside its current jurisdiction?
Do your current technology contracts grant you flexibility to migrate to alternative locations or vendors?
Can your critical suppliers meet their delivery obligations if regional hostilities escalate further?
Organisational leaders and legal counsel should evaluate their posture against the following critical questions:
Ruby Khnom Partner, Dubai
Zil Rehman Senior Associate, Dubai
Where are your teams located?
Are your teams prepared to transition to secure and legally compliant remote working arrangements?
Could operations continue unabated if a primary regional data centre or network went offline?
Have you comprehensively stress-tested the resilience of your vital cloud, network, and technology providers?
Crucially, these exercises are not designed to assess the response of IT teams. They test governance, decision-making, escalation, accountability and communication at the top of the organisation. Participants must think several moves ahead, balancing risk, compliance, ethics and stakeholder expectations, while the extortion threat evolves and confronts them.
Effective responses to extortion threats depend on multi-disciplinary support. Leaders need focused threat intelligence, experienced expert negotiators and fast, accurate legal advice so that decisions are informed, defensible and aligned with the organisation’s broader risk strategy. As in chess, leaders need to understand which pieces to deploy in response to an attack.
Across jurisdictions, the direction of travel is clear: boards and senior management are expected to understand cyber risk, oversee resilience planning, test crisis decision-making and ensure that response arrangements work in practice. Global and regional frameworks increasingly treat cyber resilience as an enterprise governance issue, not a technical compliance exercise.
The NIST Cybersecurity Framework 2.0, for example, places “Govern” at the core of cyber risk management, emphasising leadership accountability, defined roles and responsibilities, oversight, risk strategy and supply-chain governance. In the European Union, regimes such as NIS2 and DORA require senior management and boards to take active responsibility for ICT and cybersecurity risk management, incident reporting, operational resilience, third-party risk and recovery planning. Comparable expectations are reflected in sectoral regulation, corporate governance codes and regulatory guidance across many other markets.
Tabletop and simulation exercises give boards and executives a practical way to demonstrate that oversight. They show that cyber risk has been understood, rehearsed and integrated into enterprise risk management, business continuity, disclosure and crisis governance. They also allow leadership teams to test escalation paths, decision rights, reporting triggers, communication playbooks and recovery priorities before an incident.
C-SuiteCyber Chess
Governance now demands cyber readiness
Each exercise is tailored to the organisation’s sector, risk profile and regulatory environment. Scenarios can be structured to reflect applicable international, regional and sector-specific expectations, including cyber resilience, operational resilience, privacy, financial services, critical infrastructure and corporate governance requirements. Participants leave with greater confidence to confront and manage cyber risks proactively.
Clyde & Co supports clients in designing and delivering cyber tabletop and simulation exercises that are legally robust, commercially realistic and governance-focused. Drawing on our cross-border cyber, insurance, regulatory and incident response experience, we help organisations to test how leadership teams make decisions when legal, operational, financial and reputational pressures converge.
In cyber risk, preparation is not about predicting the next move - it is about being ready to respond as the game changes. In today’s fast-changing threat landscape, cyber readiness is leadership readiness.
Ransomware and cyber extortion events can halt operations, damage trust, trigger regulatory scrutiny and expose directors to personal accountability. In this environment, cyber readiness is not simply a question of technology. It is an acute test of leadership, judgement and resilience under pressure.
Cyber incidents sit at the core of business risk
Effective organisations recognise that a cyber-attack is not merely a technical failure. It is a strategic event that requires senior leaders to make rapid, high-stakes decisions: whether to shut down systems, how to engage with threat actors, when and what to disclose to regulators and stakeholders, and how to protect value while restoring operations securely. These decisions are often required within hours, with imperfect information and under intense scrutiny.
Traditional cyber readiness policies and incident response plans are necessary, but they are rarely sufficient on their own. When a real incident occurs, success depends on how well and how quickly leaders can apply those plans in practice, together and in real time.
This is where tabletop and simulation exercises come into play. Often described as “cyber wargaming”, these are non-technical, scenario-based exercises designed for boards and executive teams. Participants are guided through a realistic ransomware or cyber extortion scenario and challenged with the strategic, legal, financial and reputational decisions they would face in a live event.
From playbooks to practice
How Clyde & Co can help
Click here to view King V Code enhances principles regarding AI Governance and Cyber Risks in South Africa
Lee Astfalck Partner, Johannesburg
Christopher MacRoberts Partner, Johannesburg
Emerging Risk
Article 1
Article 2
Article 3
Article 4
Article 5
Contents
Rosehana Amin Partner
Authors
Copy Normal 18/22 or 18/24 -10 -20 -30
H1 20 BOLD ALL CAPS
Intro Semi Bold 20/30 -20
of respondents saying their organisations now use it in at least one business function, up from 33% IN 2023.
71%
A global AI survey by McKinsey found that genAI usage jumped sharply last year, with
5 key steps
employers should take when using AI in the workplace
Subscribe via:
yber threats are one of the fastest-evolving risks companies face, so staying ahead of regulatory compliance and being prepared for whatever malicious actors may have in store next is vital and challenging in equal measure.
Our podcast series is designed to enhance organisations’ visibility over key developments, upcoming issues and emerging threats, providing critical insights and analysis to help mitigate risk and improve preparedness, should a data breach or cyber attack occur.
C