Introduction
This client alert is part of our series on the legal and business risks associated with data center development. Our September 8, 2026, alert discussed how the global expansion of data centers may lead to more contract and investment treaty claims. This alert turns to a related practical question: How can customers and providers draft outsourcing and related contracts to address the distinctive risks of data center projects?
Data center outsourcing involves engaging a provider to supply and operate some or all of the facilities, servers, storage, and related services needed to host and support a customer’s computing environment and needs. As illustrated in our prior client alerts, providers and customers alike face an evolving legal and regulatory landscape while confronting intense commercial pressure to accelerate development and operational timelines. Those pressures are compounded by dependencies on power availability, permitting, construction, and equipment supply chains, among other things, creating risks that extend beyond the parties’ immediate control. Outsourcing agreements for other types of services (which we will refer to as “conventional outsourcing” or “conventional arrangement” in this alert, for simplicity) may provide a useful starting point, but they should be adapted and expanded to address the unique risks associated with data center outsourcing, given the variance in the set of dependencies associated with such an undertaking.
Perhaps the biggest difference between a data center outsourcing arrangement and a conventional arrangement is that, in a data center outsourcing, the customer is often not purchasing an existing service. Instead, the customer typically purchases a future service that will only be available based on a chain of events that culminate in the data center being available to the customer.
Diligence Readiness, Identify Uncertainties, and Allocate Risk
Reviewing (or “diligencing”) the service provider is a standard first step in a conventional outsourcing transaction. In a conventional arrangement, the customer can often evaluate an outsourcing provider during the due diligence process by examining its performance history, financial condition, support processes, technology solutions, client references, backup capabilities, and other available information.
Where the data center service depends on a facility that is still under construction or for which power has not been secured, permits remain pending, equipment has long delivery times, or the infrastructure is supplied by third parties, diligence that is performed as part of a conventional outsourcing arrangement may not be sufficient. In those circumstances, diligence should focus not only on past performance but also on whether the provider is prepared to, and has the capabilities to, deliver the promised service. The parties should also consider existing or threatened litigation, citizen suits, community opposition, and regulatory developments that could delay construction, restrict expansion, or interrupt operations.
Following diligencing, the data center outsourcing contract should address the identified risks. The contract should state what each party is expected to do, who bears each risk, and what remedies apply if a key assumption proves incorrect. Given the high costs associated with delays, the parties should clearly define dependencies and consequences as well as the financial responsibility associated with delays.
Define the Services and Responsibilities Clearly
An outsourcing agreement generally places the responsibility for delivering an overall service on the provider through detailed provisions that address the services, the promised outcome, and the dependencies. Such specificity is especially important for data center services, where performance relies on a particularly complex and interconnected set of physical, technological, and regulatory dependencies. Identifying these dependencies should clarify, rather than dilute, the provider’s responsibility for the overall service. These dependencies often are based on actions of third parties, such as utilities, OEMs, permits, or construction delays. In some cases, a force majeure clause would excuse performance based on these third-party actions. As a result, clear drafting, and allocation of these risks, gives the customer an enforceable commitment, enables the provider to manage and price the risks it assumes, and reduces disputes when a critical dependency fails.
For example, if the customer is purchasing capacity at a particular facility, the agreement may identify the location and amount of reserved capacity, the power and cooling needed to support that capacity, and the connectivity and support included in the service. The parties may also decide to address whether these commitments depend on future utility service, the completion of construction, specified equipment, or outstanding approvals. In this example, the customer may also be responsible for providing forecasts, technical specifications, equipment, or other necessary cooperation.
Having identified the service and its key dependencies, the agreement can then clarify the allocation of responsibilities. A schedule or responsibility matrix can identify what the provider, customer, and relevant third parties must do and which party is responsible for managing the risks of delays by third parties. But dividing responsibilities should not make accountability unclear. The agreement should identify who remains responsible to the customer for delivering the promised service when a utility, contractor, equipment supplier, or other third party fails to perform.
Build a Governance Framework That Can Adapt
Conventional outsourcing contracts often establish procedures for monitoring performance, flagging problems, and changing the services after signing as conditions evolve. These procedures are especially important in an as-yet-undefined environment such as that of data center outsourcing, when construction, power, permits, technology, or legal requirements may change, as we have discussed in previous client alerts (e.g., if there are changes to water use or energy use). Governance and change control provisions should provide a clear and timely process for responding to new developments without prescribing every possible outcome in advance.
The governance framework should cover both ongoing service performance and material developments affecting the underlying infrastructure. The provider may be required to report regularly on permits and approvals, power availability, construction progress, capacity, and critical supplier issues. From the customer perspective, this reporting should be used to understand any dependencies that are becoming critical and to develop plans to address these dependencies; the governance framework should allow for adjustments to address these critical dependencies. Further, the agreement may also require prompt notice of developments that could materially affect the price, timing, or continued service, including enforcement actions, third-party claims, new sourcing restrictions, or other governmental actions.
The agreement should set out the process for either party to propose a change to the contractual commitments, who must approve it, and how the parties will address resulting changes to performance standards, schedules, or prices. A separate process may be appropriate if a change in law makes any part of the service unlawful or requires the service to be modified. The parties may also provide for periodic comparisons with market pricing and performance (or “benchmarking”) and require the provider to identify reasonable improvements over time to address benchmarking results.
The goal is a practical decision-making process that allows the parties to respond to new circumstances without reopening the entire agreement.
Measure the Service That Matters
Conventional outsourcing agreements measure availability, response times, resolution times, and recurring failures, among other metrics. Service levels, performance reporting, service credits, root-cause analysis, and chronic-failure remedies are established outsourcing tools. In the data center outsourcing context, a data center may be 100% available and still fail to deliver the capacity that the customer purchased. Delayed energization, government- or utility-ordered limits on power use (or “curtailment”), or failures in the supporting infrastructure may impair or reduce service without qualifying as a traditional outage that would affect availability metrics.
A data center outsourcing agreement should therefore measure the service that the customer actually needs and receives. Perhaps the most important metric is usable compute. Other important metrics may include the availability of committed power, cooling, network access, rack availability, or expansion capacity. The agreement should also specify the consequences if the provider repeatedly fails to meet its commitments.
Because so many data centers are being created to satisfy the demand for AI, it is particularly important to consider factors that may be disruptive to an AI data center. For example, changes in power and cooling are especially important, as are establishing alternative or backup means to provide power and cooling for data centers. Delays in procuring specialized hardware, such as appropriate chips, may result in delays in receiving the highest level of service. And because these agreements are often long term, an upgrade schedule that contemplates unknown future hardware is critical.
Prepare for Outages and Other Disruptions
Business continuity and disaster recovery provisions are intended to allocate disruption risk by establishing how the parties will prepare for and respond to interruptions. Data center services add infrastructure-specific risks (such as power and cooling failures, utility interruptions, equipment shortages, and supplier failures) to the familiar list of potential disruptions.
Depending on the service, the provider’s commitments may cover backup systems, failover procedures, testing, restoration times, acceptable data loss, redundant power and cooling, and fuel supplies, and, as mentioned above, these are particularly important in the context of data centers for AI. The parties may also consider alternate sites, substitute capacity, or alternative/temporary service arrangements.
A force majeure clause generally excuses a party’s performance when an event outside the party’s control prevents or delays performance. The agreement should specify both the circumstances that qualify as force majeure events and the obligations that remain in effect. Above, we discussed how a force majeure clause can affect the dependencies in the construction phase of a data center. A force majeure clause may also be relevant in the context of the ongoing operation of a data center. For example, an external power outage may be an event that is captured by a force majeure clause but should not automatically excuse performance if the provider had expressly agreed to maintain backup power and implement related business continuity and disaster recovery measures. The agreement should therefore distinguish a truly unavoidable event from a risk the provider had agreed to address.
Make Sure Liability Terms Match the Risk
Warranties, indemnities, service levels and credits, damage exclusions, liability caps, and exclusive remedy provisions determine which party bears a loss when the service falls short. Because infrastructure, equipment, and supplier failures can cause substantial losses, these provisions should be reviewed together and in light of operational and commercial risks, rather than in isolation.
In this context, service credits may not adequately compensate for infrastructure failures but may be appropriate for other kinds of failures to perform. A broad warranty disclaimer should not undermine an express service commitment or continuity obligation. Similarly, exclusions of consequential damages and overall liability caps should be evaluated against the losses that could result from a major outage, delayed opening, or prolonged capacity shortfall, while recognizing the business reality that providers are typically extremely reluctant to assume responsibility for consequential damages. The appropriate terms will depend on the transaction and the parties’ bargaining positions, and the agreement should make the interaction among the various provisions clear.
The parties should also consider who bears the risk of claims that the data center’s technology infringes on another party’s intellectual property rights. The provider may agree to obtain a license, modify or replace the affected technology, or terminate the affected service if the problem cannot otherwise be resolved. A right to terminate the affected service may result in a substantial supply disruption, so customers should consider carefully whether that is acceptable.
Plan for Transition and Exit
Termination rights, exit assistance, and orderly transition are familiar protections against outsourcing lock-in.
In a conventional outsourcing arrangement, the parties negotiate a transition period that gives the customer time to identify a replacement provider, migrate data and services, and complete an orderly transition, while giving the provider a defined time frame in which to wind down operations and reallocate resources. In a data center outsourcing arrangement, however, replacement capacity may not be readily available. For example, securing new space and power, relocating specialized equipment, and migrating workloads may require substantial time and coordination across numerous dependencies. As a result, the customer may need more time than the provider is willing or able to commit to, making the negotiation of the duration of the transition period particularly complex. The parties should therefore consider the exit scenarios in light of these limitations, including the potential that the customer may not be able to procure replacement capacity and that the provider will not have available spare capacity.
The required transition will depend on the data center service model. A colocation customer may need continued site access, time to remove equipment, and time to secure replacement space and power. A managed hosting or infrastructure customer may also need to migrate workloads and recover or delete its data. These transitions can be difficult because facilities, power commitments, site-specific infrastructure, and specialized equipment may not be readily replaceable, and, in addition, the provider may have commitments to its suppliers that require a smooth transition and the replacement of the customer with an alternative customer. The parties should therefore plan for a transition before the customer becomes operationally dependent on the service.
The agreement should provide enough time for an orderly transition period (if possible), identify the assistance the provider must supply, and address whether service will continue during migration. Depending on the arrangement, the agreement may also cover equipment removal, transfer of assets or licenses, workload migration, and the return or deletion of customer data.
Practical Takeaways:
- Diligence readiness, not just past performance. If the facility is not yet operating, assess the provider’s and its suppliers’ ability to deliver—including the status of construction, power, permits, equipment, suppliers, and regulatory or litigation risks—and address remaining uncertainties in the agreement.
- Identify dependencies without weakening accountability. Draft the agreement to define the services and committed capacity, identify customer and third-party dependencies, and allocate responsibility clearly across the parties. Clarify who is responsible for delivering the promised service, but do not obscure who remains accountable.
- Measure usable service, not just technical uptime. Focus service levels and remedies on the performance that matters to the specific arrangement. Performance standards may need to be based on usable compute, power, cooling, and network capacity, as well as the overall “availability” of a data center. Consider specifics relating to AI data centers, such as updates or upgrades to hardware.
- Make the contract’s provisions work together, in alignment with risk. Draft the agreement so that mechanisms for addressing change, continuity obligations, force majeure provisions, liability caps, and remedies are consistent with the risks each party agrees to bear.
- Plan for transition before the arrangement becomes difficult to unwind. Because physical capacity, site-specific infrastructure, scarce equipment, and power commitments may be difficult to move or replace, establish realistic transition periods, continued-service obligations, exit assistance, and procedures for equipment, workloads, assets, licenses, and customer data.
Final Thoughts
Data center outsourcing is no longer simply a technology procurement exercise. Increasingly, it is the amalgamation of infrastructure, energy, construction, regulatory, and technology risks all in a single agreement. Contracts that merely replicate conventional outsourcing agreements may fail to address the issues that matter most in these deals.
Of course, no agreement can eliminate every operational, regulatory, or infrastructure risk associated with outsourced data center services. But a well-structured agreement can identify those risks, assign responsibility before problems arise, and give the parties practical options if the service is delayed or disrupted. Customers and providers should adapt familiar outsourcing tools to the physical and regulatory realities of data centers. That means assessing readiness, identifying critical dependencies, measuring usable service, planning for disruption, aligning liability terms with operational risk, and preparing for transition.
WilmerHale’s lawyers regularly counsel clients (including both customers and providers) on complex outsourcing, technology, AI, and infrastructure matters. We help clients structure data center arrangements that address evolving operational, regulatory, and infrastructure risks; assign responsibility for critical dependencies; and provide practical protections against delay, disruption, and other performance failures.