Authors: Jose Bolanos MD and Philip Abraham
Artificial intelligence is becoming essential infrastructure, but the data centers supporting it are placing rapidly increasing demands on electricity, water supplies, wastewater systems and local utility capacity. Global data-center electricity consumption increased approximately 17% in 2025; the International Energy Agency now expects total data-center electricity use to double by 2030 and electricity used by AI-focused facilities to triple. These effects will be concentrated in the cities and regions where large computing campuses are built. (IEA)
Water scarcity already affects much of the world. UNESCO reports that roughly half of the global population experiences severe water scarcity during at least part of the year, while approximately one-quarter lives under extremely high water stress. AI data centers do not create the majority of global water demand, but a large facility placed in a water-stressed community can become a major local competitor for water needed by households, hospitals, agriculture and ecosystems. (UNESCO)
In the United States, data centers directly consumed approximately 66 billion liters of water in 2023, primarily for cooling. Their estimated indirect water footprint from electricity generation was almost 800 billion liters. Berkeley Lab projects that hyperscale facilities alone could consume between 60 billion and 124 billion liters annually by 2028. These national totals conceal major local differences: workload-level water consumption can vary by more than 10,000-fold depending on server efficiency, utilization, cooling technology, climate and the water intensity of the electricity supply.
The central recommendation of this paper is a Citizen-First Water Protection Standard:
Large AI data centers should be prohibited from using treated potable water for routine cooling whenever reclaimed water, stormwater, closed-loop liquid cooling, dry cooling or another technically feasible non-potable alternative is available.
This prohibition must be combined with a second requirement: the digital systems controlling municipal water, electricity, data-center cooling and emergency infrastructure must use stronger identity verification than passwords, conventional MFA and reusable bearer tokens alone. Water conservation infrastructure can still be placed at risk when an attacker steals an operator’s session, compromises remote-access credentials or issues unauthorized commands through a legitimate administrative account.
The AI water problem consists of five separate but interconnected pressures.
1.1 Direct cooling-water consumption
Open cooling towers reject heat by evaporating water. This can offer favorable energy efficiency, but the evaporated portion is no longer immediately available to the local watershed, reservoir or aquifer. Data centers also discharge “blowdown”—water removed to prevent excessive concentrations of minerals, salts and biological material within cooling equipment.
1.2 Indirect water consumption from electricity
A facility that appears to use little water onsite may still carry a substantial water footprint through the power plants generating its electricity. Thermoelectric generation may consume water for cooling, while reservoir-based hydropower can carry evaporation losses. Therefore, cities should measure both:
Site WUE: water consumed at the data center.
Source WUE: water consumed in producing its electricity.
A dry-cooled data center powered by water-intensive generation could simply transfer part of its water burden from the host city to another watershed.
1.3 Peak water capacity
Annual consumption does not reveal the entire infrastructure burden. Data-center cooling demand can peak during the same hot and dry periods when residents, agriculture and the electrical grid are under the greatest stress. Permitting must therefore evaluate maximum-day and maximum-hour demand—not merely annual averages.
1.4 Wastewater quality
Repeated cooling cycles concentrate dissolved solids. Improperly managed blowdown can overload municipal wastewater plants, damage equipment or create difficult brine-disposal requirements. The city must separate ordinary municipal sewage from concentrated industrial cooling-water waste whenever the existing treatment system was not designed to handle it. The Quincy, Washington, reuse project was developed partly because high-mineral data-center discharges were creating treatment problems for the municipal system. (US EPA)
1.5 Cyber-physical vulnerability
Modern water and electrical utilities use supervisory control and data acquisition systems, programmable logic controllers, remote terminal units, sensors and human-machine interfaces. Unauthorized access can affect pumps, valves, chemical treatment, water pressure, cooling temperatures, electrical switching and emergency shutdown functions. EPA states that cyberattacks against public water systems are increasing and identifies cyberattack as a leading malevolent threat to water infrastructure. (US EPA)
The solution must therefore protect both physical resources and digital authority.
Cities should divide water infrastructure into protected service classes rather than placing every customer on the same treated-water network.
Tier One: Protected potable water
This system would serve:
Residential drinking and sanitation
Hospitals and healthcare facilities
Schools
Emergency shelters
Fire protection
Essential food and public-health operations
The city would establish a minimum strategic reserve based on population, drought conditions, wildfire exposure, hospital needs and emergency-response requirements. Industrial withdrawals would be curtailed before this reserve could be breached.
Tier Two: Municipal reclaimed-water network
Treated wastewater, captured stormwater and other approved non-potable sources would be delivered through a separate industrial distribution system. Large data centers, power facilities, industrial campuses and irrigation customers would connect to this network.
Public-health protection requires unmistakable physical separation. EPA reuse guidance calls for prevention of cross-connections, routine monitoring, construction standards, clear identification of non-potable infrastructure and physical separation between potable, reclaimed-water and sewer lines. Purple piping, warning labels, noninterchangeable valves, air gaps and approved backflow prevention should be mandatory. (EPA NEEPS)
Tier Three: Data-center closed process loop
Inside the data-center campus, cooling fluid would circulate through a sealed loop:
Servers → liquid cooling system → heat exchanger → heat-rejection or reuse system → servers
The internal loop should be isolated from municipal water. Leak detection, pressure monitoring, automatic isolation valves and secondary containment would protect the facility and surrounding environment.
A critical distinction is necessary: closed-loop liquid cooling does not automatically mean zero water consumption. If the closed internal loop transfers its heat to an open cooling tower, water will still evaporate at the final heat-rejection stage. To eliminate routine evaporative consumption, the facility must use dry heat rejection, useful heat recovery or another non-evaporative final system.
Tier Four: Separate industrial wastewater treatment
Cooling-water blowdown, reverse-osmosis concentrate and other high-mineral streams should be collected separately from ordinary sewage. Treatment may include softening, filtration, reverse osmosis, crystallization, brine concentration and recovery of reusable water.
The Quincy Water Reuse Utility demonstrates this approach. The city and Microsoft constructed an industrial treatment and recirculation system that reduces reliance on potable groundwater by an estimated 138 million gallons per year. Microsoft financed the capital and operating costs, while the city owns and operates the infrastructure. (US EPA)
Tier Five: Emergency interconnection
A controlled potable-water connection may be retained for life-safety emergencies, commissioning or failure of the reclaimed-water network. It should employ a physical air gap, separate meter, automatic expiration and municipal authorization.
Emergency access must never become a permanent workaround for routine industrial operations.
The best solution is to avoid creating an evaporative requirement rather than attempting to recover vapor after it leaves a cooling tower.
Berkeley Lab’s modeling confirms that there is no single optimum system for every location. Dry cooling reduces onsite water consumption but can increase electricity use; evaporative cooling saves energy but consumes local water. The correct decision depends on climate, grid characteristics, water stress, workload efficiency and the source of electricity. (Energy Technologies Area)
3.1 Direct-to-chip liquid cooling
Cold plates placed directly on processors can capture heat much more efficiently than cooling an entire server room with air. Higher coolant temperatures can permit more hours of compressor-free operation and make dry cooling more practical.
3.2 Immersion cooling
Servers or components are placed in electrically nonconductive fluid. Heat is transferred to a secondary loop and then rejected through dry coolers or a heat-reuse system. Immersion can reduce fan energy and accommodate high-density computing, but maintenance procedures, material compatibility, fluid selection and end-of-life management require careful engineering.
3.3 Dry cooling
Dry coolers transfer heat to outside air without routine water evaporation. Their disadvantage is declining performance when ambient temperature rises. For this reason, cities should not require dry cooling without also examining peak electrical demand and grid capacity.
3.4 Hybrid cooling
A hybrid system operates in dry mode during most of the year and uses limited reclaimed-water cooling during extreme heat. This can substantially lower annual water consumption while avoiding excessive peak electrical demand.
3.5 Waste-heat recovery
Warm-water liquid cooling can produce a more useful heat stream than conventional air cooling. That heat can support:
District heating
Hospital hot-water systems
Wastewater treatment
Industrial processes
Greenhouses
Desalination or water-treatment processes
Absorption cooling
DOE guidance notes that heat reuse can reduce or eliminate reliance on chillers and, in appropriate designs, cooling towers. (The Department of Energy’s Energy.gov)
3.6 Cooling optimization
Existing facilities should raise temperature setpoints within equipment specifications, improve airflow containment, eliminate inactive servers, increase server utilization, use predictive controls, optimize water chemistry and improve cycles of concentration. DOE estimates that increasing cooling-tower concentration cycles from three to six can reduce make-up requirements by approximately 20% and blowdown by approximately 50%. (The Department of Energy’s Energy.gov)
The framework should accommodate differences between wealthy cities, drought-prone regions and developing countries.
Singapore demonstrates how a national water agency can turn treated wastewater into a dependable high-grade resource. Its NEWater program uses advanced treatment to produce reclaimed water and reduce vulnerability to dry conditions. Singapore currently operates four NEWater plants. (Publications Singapore)
Cities do not have to purify all industrial cooling water to drinking-water quality. Treatment should be matched to the application. Data-center cooling commonly requires control of minerals, conductivity, biological growth and corrosion, but not necessarily the full treatment train required for direct human consumption.
A city considering an AI campus should prepare a water-resource balance covering:
Current residential and public-service demand
Population growth
Drought and climate projections
Agricultural and ecosystem requirements
Peak industrial demand
Available wastewater and stormwater
Treatment and pipeline capacity
Electrical-generation water intensity
Emergency storage
Cyber and operational resilience
Water-stressed locations identified through tools such as the World Resources Institute’s Aqueduct platform should face stronger permitting thresholds, lower maximum WUE limits and a presumption against potable-water cooling. (World Resources Institute)
5.1 Potable Water Protection Rule
New AI data centers above a locally determined capacity threshold should not receive routine potable water for cooling when a feasible alternative exists.
Exceptions should be limited to:
Short commissioning periods
Fire protection
Health and life safety
Verified emergency failure
A time-limited waiver supported by an independent engineering report
5.2 Water-Capacity Neutrality
The developer should finance enough conservation, reuse, storage or new non-potable capacity to offset its peak demand—not merely its annual average demand.
This may include:
Reclaimed-water treatment plants
Stormwater capture
Wastewater recycling
Leak-reduction programs
Aquifer recharge
Industrial pipelines
Residential efficiency improvements
Alternative emergency supplies
5.3 Operator-financed infrastructure
Residents should not subsidize the pipelines, treatment systems, power substations or cybersecurity required primarily for a private data-center campus. The Quincy financing model—private capital funding infrastructure that remains municipally controlled—offers a useful precedent. (US EPA)
5.4 Mandatory reporting
Facilities should publicly report, at least monthly:
Potable water withdrawal
Reclaimed-water withdrawal
Stormwater use
Direct evaporative consumption
Blowdown volume and quality
Site and source WUE
Peak-hour water demand
Electricity consumption
Source of electricity
Backup-generation operation
Heat recovered and reused
Material water-supply interruptions
Metrics should be independently audited and reported by season, because annual averages can conceal summer emergencies.
5.5 Citizen priority during emergencies
During drought, wildfire, grid emergency or infrastructure failure, the municipality should possess contractual and technical authority to reduce industrial withdrawals while maintaining safe cooling and shutdown procedures.
This requires collaboration before construction. A city should never discover during an emergency that it lacks the contractual authority, valves, controls or verified operators necessary to curtail a major facility.
The water-energy-data-center relationship creates a combined cyber-physical risk.
CISA, EPA and the FBI have issued specific guidance for securing water systems. Recent advisories have documented threat activity directed at water, wastewater and energy operational technology. In December 2025, CISA warned that pro-Russia hacktivists were conducting opportunistic attacks against industrial control systems in the water and energy sectors. CISA also updated an advisory in July 2026 concerning Iranian-affiliated actors exploiting programmable logic controllers. (CISA)
A compromised water or cooling account could potentially be used to:
Alter pump or valve settings
Change cooling temperatures
Disable alarms
Manipulate sensor readings
Interrupt reclaimed-water delivery
Change chemical-treatment parameters
Shut down pumps or chillers
Overload electrical equipment
Conceal abnormal water consumption
Delay emergency response
NIST recommends that remote access to operational technology be justified, restricted to the business need, encrypted, authenticated and capable of being disconnected. It also recommends layered OT architectures and emphasizes logging the identity associated with operational events. (NIST Publications)
Traditional MFA is better than a password alone, but authentication can still fail after the login event.
Attackers may:
Trick a user into approving a push notification
Relay an OTP through a fraudulent login page
Steal browser cookies
Steal OAuth access or refresh tokens
Compromise a help desk
Reuse a valid session from another endpoint
Take control of an already authenticated computer
CISA has documented threat actors stealing web-session cookies and using them to bypass the need to repeat MFA. NIST’s current identity guidance states that manually entered OTP methods are not phishing-resistant because an impostor can relay the code. NIST also warns that the presence of an access token should not, by itself, be interpreted as evidence that the subscriber is still present. (CISA)
OAuth remains an important authorization standard, but reusable bearer tokens create risk when stolen. The OAuth Security Best Current Practice recommends sender-constrained and audience-restricted tokens to reduce replay. It also requires that access tokens be protected as sensitive secrets. (RFC Editor)
For critical water, cooling and grid controls, authentication should answer more than:
“Does this browser possess a valid token?”
It should answer:
“Is this the verified authorized human, using the approved device, acting within assigned authority, during an approved session, to perform this specific infrastructure action?”
Nimbus-Key® ID could be positioned in front of the existing identity provider and operational-access gateway—not as a replacement for SCADA safety controls, network segmentation or engineering interlocks, but as a stronger verified-access and authorization layer.
8.1 True User Verification™
The operator is verified through a combination of identity proofing, AI-assisted image verification, biometric confirmation (KYC / AI / Biometric), registered-device UUID and a user-controlled Master PIN.
This provides stronger assurance that the person accessing the system is the enrolled and authorized operator rather than someone who merely obtained a password, OTP or browser token.
8.2 DE-MFA®
Dynamically Encrypted Multi-Factor Authentication avoids dependence on a permanently reusable login credential. The authentication event should be short-lived, bound to the approved session and renewed according to the sensitivity of the operation.
8.3 Transaction-level verification
High-risk actions should trigger fresh authorization rather than relying entirely on the original login. Examples include:
Changing a chemical-dosing parameter
Opening a cross-system water valve
Switching from reclaimed to potable water
Disabling a cooling alarm
Changing pump pressure
Disconnecting a facility from the electrical grid
Activating emergency generators
Overriding a drought restriction
Authorizing remote vendor access
8.4 Nimbus-Key® TID (Transaction ID) evidence
A Nimbus-Key® TID could provide a cryptographic pointer to an auditable authorization record containing:
Company ID
Utility or division ID
Verified user ID
Approved device
AI-agent ID, when applicable
Requested action
Authorization level
Date and time
System and facility
Approval result
The TID should document who authorized the action without placing sensitive operational information directly into a publicly exposed QR code or URL.
8.5 Short, controlled sessions
Nimbus should work with the downstream identity and control systems to enforce:
Short-lived sessions
Inactivity expiration
Reverification for sensitive actions
Device-bound sessions
Audience-restricted tokens
Rapid revocation
No persistent browser authorization for critical controls
No direct internet connection to PLCs
Just-in-time vendor access
Complete access and action logging
NIST recommends periodic reauthentication and defines shorter session limits for higher assurance. It also requires phishing-resistant cryptographic authentication at its highest assurance level. (NIST Publications)
8.6 Dual control and safety independence
The most consequential actions should require approval by two independently verified operators. Physical safety interlocks and local manual controls must continue to function even if Nimbus-Key, the cloud identity provider or the external network becomes unavailable.
Nimbus-Key should strengthen authority verification; it should never become a single point whose failure prevents a water utility from safely operating during an emergency.
A secure water or cooling-control transaction could operate as follows:
The operator requests access through the utility or data-center portal.
The existing IdP redirects the privileged login through Nimbus-Key ID®.
Nimbus performs True User Verification™ and registered-device verification.
Nimbus issues a short-lived, purpose-limited authentication result.
The operator enters a segmented operational-access gateway—not the PLC directly.
The system applies role, facility, time, location and risk policies.
A high-impact command triggers a new DE-MFA® authorization event.
A second operator is required when dual control applies.
A Nimbus-Key® TID is generated for the authorization record.
The OT policy engine validates the command against engineering safety limits.
The approved instruction is delivered through the segmented control architecture.
Sensors confirm the physical result, and discrepancies create an immediate alert.
The session expires automatically and all temporary access is removed.
This model separates identity verification, authorization, engineering validation and physical execution. No single credential, administrator or AI agent should possess unilateral authority over all four stages.
First 12 months
Cities should inventory data-center water use, map existing potable and reclaimed infrastructure, identify peak demand, assess water stress and require cyber-risk assessments for connected operational systems.
New permitting applications should include water source, cooling design, source WUE, peak-day use, wastewater characteristics, cyber architecture and emergency operating procedures.
One to three years
Municipalities should create industrial reclaimed-water zones, require separate metering, adopt potable-water restrictions, establish public reporting and implement stronger verified access for water and power control systems.
Existing facilities should be offered a transition schedule with measurable annual water-reduction requirements.
Three to seven years
Cities should expand reclaimed-water pipelines, integrate stormwater capture, develop industrial wastewater treatment, deploy heat-reuse districts and establish regional water-energy-data planning authorities.
Seven to fifteen years
The objective should be a circular municipal model in which potable water is reserved for citizens and essential services; industrial water is recycled; data-center heat becomes an energy resource; and every consequential infrastructure action is verified, authorized and auditable.
AI growth does not have to become a competition between technological development and safe water for citizens. The risk arises when massive computing facilities are approved without integrated water, electricity, wastewater, cybersecurity and emergency planning.
The necessary response is a new infrastructure compact:
· Citizens receive first priority for safe drinking water.
· AI operators finance the infrastructure their facilities require.
· Routine data-center cooling moves away from potable water.
· Cooling systems minimize evaporation through liquid cooling, dry heat rejection, hybrid operation and heat reuse.
· Municipalities measure peak demand and total water footprint.
· Industrial and potable networks remain physically separated.
· Critical digital commands require verified humans, approved devices and transaction-level authorization.
Nimbus-Key® ID can provide an important part of this protection by strengthening True User Verification™, dynamic authentication and auditable authorization at the entrance to water, energy and data-center management systems. However, its greatest value will come from integration with physical safety systems, segmented OT networks, least-privilege access, short-lived sessions and independent engineering controls.
The water infrastructure of the AI era must be designed not only to conserve water—but also to ensure that no stolen password, static token, compromised session or unauthorized AI agent can control the systems upon which entire cities depend.
References
2024 United States Data Center Energy Usage Report — Lawrence Berkeley National Laboratory
https://eta-publications.lbl.gov/publications/2024-lbnl-data-center-energy-usage-report (LBL ETA Publications)The Water Use of Data Center Workloads: A Review and Assessment of Key Determinants — Lawrence Berkeley National Laboratory
https://eta.lbl.gov/publications/water-use-data-center-workloads (Energy Technologies Area)Energy and AI: Energy Demand from Artificial Intelligence — International Energy Agency
https://www.iea.org/reports/energy-and-ai/energy-demand-from-ai (IEA)Water Reuse Case Study: Quincy, Washington — U.S. Environmental Protection Agency
https://www.epa.gov/waterreuse/water-reuse-case-study-quincy-washington (US EPA)CISA, EPA, and FBI Release Top Cyber Actions for Securing Water Systems — Cybersecurity and Infrastructure Security Agency
https://www.cisa.gov/news-events/alerts/2024/02/21/cisa-epa-and-fbi-release-top-cyber-actions-securing-water-systems (cisa.gov)
Blog by: Jose Bolanos MD / Secure Identity & Authentication with Nimbus-Key ID®. Nimbus-T.com / www.josebolanosmd.com

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.