All writing
14 min read

Australia's $150 billion compute build-out: a CTO procurement playbook for FY26/27

Australia is on track for six gigawatts of AI data centre capacity by 2030. Here is how CTOs should reshape procurement, residency and vendor risk before FY26/27 lands.

KP
Managing Director and co-founder

Something quiet has happened while most Australian boards were still arguing about generative AI pilots. The country now has a credible line of sight to roughly six gigawatts of data centre capacity by 2030, on the order of four times the operational base at the start of 2025, at an aggregate price tag CommBank pegged in early August at about A$150 billion. That figure is not a forecast for a distant decade. It is the sum of pipeline that is already announced, permitted or under construction. It has already been priced into the plans of the largest AI vendors and the largest Australian banks, and it is starting to price into the terms enterprises will get on their next AI infrastructure contract.

The technology press has covered the individual announcements. The NEXTDC and OpenAI memorandum for a hyperscale campus at Eastern Creek. The Firmus and Nvidia Melbourne AI factory. Anthropic's memorandum of understanding with the Commonwealth. Each headline is real, and each one is only a fragment of the story a CTO needs. The useful question is not whether these announcements are exciting. The useful question is what a technology leader inside an Australian scaleup, bank, insurer, health service or state agency should actually do differently in the next planning cycle because of them.

What was signed, what was announced, and why the gap matters

Read the announcements alongside CommBank's Australia's data centre boom analysis and a pattern shows up. Roughly half of the pipeline sits in New South Wales, about a quarter in Victoria, and the rest is spread across South East Queensland, Perth and one large campus in Tasmania. Most of the specialised silicon at the heart of these builds is imported. CommBank flags openly that a significant share of the headline investment leaves the country as capex on chips, cooling gear and construction machinery bought offshore. The domestic slice is real but sits mostly in land, power infrastructure, network build and skilled trades.

That distinction matters commercially. When a hyperscaler or an AI factory operator prices reserved capacity, they are pricing an asset with an FX-heavy cost stack and a construction risk profile that Australian grid, water and labour markets have never had to absorb at this pace. The gap between announced megawatts and commissioned, energised megawatts is where the FY27 pricing surprise will land. A CTO who assumes the announced 550 megawatts at Eastern Creek is going to appear as bookable capacity in the OpenAI or Microsoft pricing tables on the announced schedule is buying a planning assumption, not a supply commitment.

Firmus is the clearest example of the shape of the new build. Its multi-year Nvidia deal, reported by IT Brief in March, commits 18,400 GB300 accelerators to a Melbourne site with a further 36,800-accelerator campus planned in Tasmania, funded by a US$10 billion debt facility from Blackstone. That is a fundamentally different capital structure to a hyperscaler region. It is closer to a specialised industrial project than to cloud in the sense most Australian buyers understand cloud.

The four quadrant that should replace your current vendor slide

Most enterprise AI vendor slides still look like a two-by-two of hyperscalers with a footnote about a sovereign option. That map no longer describes the buying decision. A more useful frame has four axes that a CTO needs to weight per workload before assigning it to a provider.

The first axis is regulatory sensitivity. Is the workload touching personal information subject to the Privacy Act, or operating inside an APRA regulated entity where the model or the vendor could be a material service provider under CPS 230? If so, contracting freedom is narrower than the marketing pages suggest. The second axis is latency tolerance. Training and batch inference sit comfortably in Tasmania or Perth. Real time inference for a payments or trading path does not. The third axis is horizon. A three-year commitment to reserved capacity on a factory that has not yet energised its first megawatt is a very different risk profile to burst usage on a hyperscaler region already at scale. The fourth axis is currency exposure. AUD priced contracts on assets funded in USD debt at USD chip prices carry a hidden pricing lever that is only starting to show up in enterprise renewals.

Run each significant AI workload through those four axes and the placement question becomes obvious. Some workloads belong on hyperscaler AU regions today because the regulatory and latency requirements leave no other choice. Some belong on reserved capacity at a sovereign factory because the horizon and cost profile favour it. Some can sit offshore for training and come home for inference. The mistake to avoid is the single vendor default that many enterprises still carry from their pre-AI cloud contracts.

The compliance overlay competitors are quietly skipping

There are two regulatory clocks that shape this decision, and both are close enough to change vendor selection this quarter.

The first is the OAIC's automated decision making transparency regime. The disclosure obligations under the amended Privacy Act take effect from 10 December 2026. Any Australian organisation using automated decisions with a legal or similarly significant effect on an individual will need to make a public statement about the kinds of decisions and the kinds of personal information involved. That obligation does not sit on the AI vendor. It sits on the deploying organisation. If your vendor cannot describe the data flows and the decision logic in language you can put in front of an OAIC officer, your compliance risk does not disappear when you sign the contract. It concentrates.

The second is APRA's CPS 230 material service provider regime, which is now the primary framework any APRA regulated entity applies when selecting an AI infrastructure partner. The standard forces boards to identify which providers underpin critical operations, to test the concentration of those dependencies, and to maintain plans for the failure or exit of a material provider. The Anthropic Australia MOU and the Commonwealth's broader engagement through the AI Safety Forum sit inside that regulator overlay, not outside it. Ministers can sign memoranda. APRA still expects the operational risk case to be documented, tested and refreshed.

Put those two clocks together and vendor selection is no longer a procurement exercise the CIO can delegate to sourcing. It is a board level question with regulatory paper attached.

What the sovereign factory operators actually promise

The Firmus and NEXTDC pitch to Australian enterprise buyers is that data trained on their infrastructure stays inside Australian jurisdiction, at Australian latency, with Australian construction and Australian operating staff. That is a real value proposition, and for a workload that touches OAIC-regulated personal information or APRA-classified material services, it is often the only defensible answer.

It is also worth reading carefully. Residency is a physical claim about where a workload runs. It is not automatically a claim about who has legal reach into the operator. Ownership structures, funding sources and the location of parent entities all shape the surface area an Australian buyer inherits. Ask the operator directly. Ask where the operator's parent is incorporated. Ask where the equipment vendor's support contracts are governed. Ask how a subpoena from a foreign jurisdiction would be handled. The good operators have clean answers ready. The ones that do not are worth a second look.

NEXTDC's positioning at Eastern Creek, as covered by Data Centre Magazine, is explicit that the S7 campus is designed for government, defence, finance, research and enterprise. That framing is helpful because it tells buyers what kind of contract negotiation they are entering. It is not a commodity cloud region. It is a specialised industrial asset with a specific customer base and a specific compliance posture. Price and terms should reflect that on both sides.

Three procurement moves to make before FY26/27 planning locks

There are three moves that a technology leader can make now that will save the organisation a poor commitment when the FY27 renewal cycle hits.

The first move is to renegotiate residency clauses on every current AI vendor contract. Most residency language written before mid-2025 was drafted for a world where the only serious answer was a hyperscaler region and the operator's word. That is no longer the state of the market. Rewrite the clause to specify the physical facility, the operator, the parent structure, and the notice period required for any change. If the vendor cannot commit to that specificity, price the ambiguity into the term.

The second move is to require material service provider status commitments in writing for any provider whose service could plausibly meet the CPS 230 threshold. This is not a request for legal comfort. It is a request for the operational disclosures, the exit plan support, and the audit access that CPS 230 assumes. A provider that treats this as a routine ask is one you can build on. A provider that pushes back is a provider whose commercial team has not caught up with what Australian regulated buyers now need.

The third move is to price a twelve month slip into any pipeline capacity that is not already energised. The build risk on grid connections, water permits and specialised trades is real. Every experienced operator in the room knows it. Contracts written with a hard cutover on an announced date, without a fallback path for slipping delivery, are contracts that transfer construction risk onto the customer. Do not sign them.

Where this leaves Australian SaaS founders

The sovereign compute build-out reshapes the enterprise sales pitch for every Australian SaaS company selling into regulated buyers. Enterprise procurement teams inside banks, insurers, health providers, state agencies and universities are now asking their SaaS vendors the same questions they are asking their AI infrastructure vendors. Where does the workload run. Who is the operator. What is the residency posture. What is the plan if the underlying provider changes hands or fails.

A SaaS company with a clean, specific answer to those questions is now competitive with a much larger US incumbent that cannot provide the same specificity. A SaaS company that has been vague about its infrastructure choices is starting to lose deals it would have won a year ago. This is the sales cycle reality of the CPS 230 and OAIC clocks meeting the sovereign compute build in the same twelve month window.

Wai works with Australian technology teams building products into this environment. ARC, the authority and AI-visibility infrastructure Wai operates, is designed for organisations that want to be found and cited as the answer inside AI systems on exactly these procurement questions. Buyers now use answer engines to shortlist vendors. The vendors that have written the clearest, most sourced answer on residency, on CPS 230 alignment, on OAIC disclosure and on operator transparency are the vendors that appear in the shortlist.

FAQ

Should Australian enterprises reserve capacity on NEXTDC or Firmus AI factories now?

For workloads where regulatory sensitivity or Australian residency is a hard requirement, reserved capacity on a sovereign operator is often the strongest answer. For everything else, keep the flexibility of hyperscaler pay-as-you-go until the pipeline capacity is energised and priced against production benchmarks.

How do APRA CPS 230 and OAIC ADM rules change AI vendor selection in Australia?

They move vendor selection from a sourcing decision to a board level operational risk decision. CPS 230 requires regulated entities to identify, test and maintain plans for material service providers. OAIC ADM rules require the deploying organisation to publicly describe automated decisions from 10 December 2026. Both obligations demand vendor disclosures that AI providers are still learning to produce.

What happens if Australia's AI data centre pipeline slips?

Some slippage is close to certain. Grid connections, water permits and specialised construction labour are the binding constraints CommBank flags. Enterprises with contracts written to a hard commissioning date without a fallback path will absorb the delay. Enterprises that price a twelve month slip into their planning will not.

What data residency claims can Australian SaaS make in 2026?

Physical residency claims are stronger than they have ever been given the domestic build-out. Legal residency and operator jurisdiction are more nuanced. The credible SaaS story specifies the facility, the operator, the parent structure, and the process for any change, and does not overstate the legal reach of physical location alone.

How much of Australia's AI infrastructure spend flows offshore?

A significant share, per CommBank's analysis, because the specialised silicon, cooling equipment and large scale construction machinery are almost entirely imported. The domestic slice is concentrated in land, power infrastructure, network build, integration and operations.

Sources

Keep reading

More writing.

A few more pieces along the same thread. See the full index for everything.

Subscribe

One short note, as it happens.

The writing above, delivered to your inbox when we publish it. No other emails, no tracking pixels, and you can leave in a click.