South Africa’s surge in data-centre construction to support artificial intelligence is prompting fresh questions about national infrastructure planning, electricity and water demand, and security of the systems that run the buildings.
One project, large footprint
On 29 July 2026 a tribunal cleared Equinix to proceed with two new data centres in Cape Town’s King Air Industria precinct. Once finished, those facilities are expected to draw close to 170MW of power — a figure that sits almost level with the roughly 189MW currently used by Teraco across all its South African campuses, according to reporting on the approvals.
South Africa now hosts more than 50 operational data centres and has close to R50 billion committed to new capacity over the next three years, with most investment concentrated around Johannesburg and Cape Town. The expansion is being justified largely by demand for AI compute and cloud services.
| Item | Reported figure |
|---|---|
| Equinix Cape Town build expected draw | 170MW |
| Teraco combined draw across campuses | 189MW |
| Operating data centres in South Africa | 50+ |
| Committed new capacity (next 3 years) | R50 billion |
Beyond fences: the non-physical risks
Public debate around data-centre projects typically focuses on three issues: water consumption, power draw and local job creation. Less attention has been paid to the operational and cybersecurity risks inside those buildings.
The World Economic Forum has urged that AI infrastructure be treated as critical infrastructure on par with power stations and ports. The argument is not purely hypothetical: in March, reported attacks on commercial hyperscale cloud facilities in the Gulf region damaged physical infrastructure and disrupted services — an example where data-centre operations became a target during modern conflict.
"It is time to start treating AI infrastructure as critical infrastructure." — World Economic Forum
That insight matters locally because the most damaging attacks on a data centre may not require heavy weaponry or breaching fences. Poorly patched control systems, compromised cooling-management interfaces or exposed operational technology can be exploited remotely to disable cooling or power circuits — causing outages or equipment damage without a physical breach.
- Power systems: Massive continuous demand strains grid planning and raises questions about prioritisation during load-shedding.
- Water and cooling: Large cooling plants use substantial water or energy-intensive alternatives; municipalities must account for this demand.
- Operational security: Control systems for cooling and power are part of the attack surface and need industrial-grade cybersecurity.
Policy and planning gaps
South Africa is not at war, but the physical shape of modern data centres — concrete buildings full of servers, backup generators and cooling plants — mirrors facilities that were targeted abroad. That similarity underlines the need for clear policy: how will national planning balance private investment, grid stability and water resources while also protecting critical digital services?
Current approvals and investments are driven by private operators and global cloud demand. Yet the consequences — strain on the grid, municipal water supplies, and heightened cyber-physical risk — fall partly on public institutions and citizens. Integrating data-centre development into national critical-infrastructure frameworks would make mitigation measures, contingency planning and information-sharing more systematic.
For ordinary South Africans, the question is practical. Where will the power and water for these facilities come from during persistent load-shedding? Who is accountable if an operational-control compromise triggers outages that affect banks, hospitals or emergency services hosted in the cloud? These are not fringe issues: they are central to how a digital economy functions.
As the rush to host AI compute continues, the conversation must move from approvals for individual campuses to a national conversation on resilience, regulation and security. Policymakers, power utilities, municipalities, operators and cybersecurity professionals will need to coordinate to ensure that the infrastructure underpinning AI does not become a hidden vulnerability for the country.
Technology choices and regulatory decisions taken now will shape how robust South Africa’s AI ecosystem is — and whether it becomes an asset that strengthens the economy, or a concentrated risk that complicates already strained public services.