Large-Load Grid Integrationv1.31
/
Download PDF DOI

Section 4 of 8

4. Large-Load Ride-Through and Dynamic Performance#

The issue. Most of the public debate misses this reliability issue; NERC treats it as among the most urgent. Power electronics drive large computational loads, and their protection schemes guard servers rather than the grid. Faced with a voltage sag — even a normally cleared fault hundreds of miles away that never threatened their service — they transfer to UPS and drop hundreds of megawatts off the system in under a cycle, uncommanded and unannounced. NERC's January 2025 incident review documented the archetype: on July 10, 2024, a shunted surge arrester on a 230 kV line triggered multi-shot autoreclosing, producing six recordable voltage depressions. About 1,500 MW of voltage-sensitive demand disconnected. With load gone and generation still spinning, frequency and voltage rose — frequency peaked near 60.047 Hz and took about four minutes to settle. NERC documented a comparable cryptocurrency-load event in January 2026, and has traced sub-synchronous oscillations to computational facilities in both the ERCOT and Dominion footprints.

Figure 4 — The failure mode. A voltage disturbance that the load is physically capable of riding through instead produces a large, instantaneous, uncommanded loss of demand. This matters because the resulting contingency

Figure 4 — The failure mode. A voltage disturbance that the load is physically capable of riding through instead produces a large, instantaneous, uncommanded loss of demand. This matters because the resulting contingency approaches the loss of a large generating unit, but arrives without notice and without any obligation attaching to the load. The asymmetry is the point: generators have been required to ride through such events since 2008, and loads have not (Section 4).

Why voltage, and why milliseconds#

The sensitivity follows from what sits between the utility feed and the processor. Servers are powered by switched-mode supplies whose front end is a bridge rectifier converting incoming alternating current to a direct-current bus. That bus holds very little stored energy — milliseconds, not seconds — and the equipment downstream of it behaves as a constant-power load: as input voltage falls, current rises to hold output power steady. A motor slows and draws less when voltage sags, riding the disturbance out on its own inertia. A rack does the opposite, drawing harder into a weakening supply, which is why the protective response has to be fast and why it is set to trigger early.

The governing document is not a grid standard at all. Information-technology equipment is designed to the ITIC (Information Technology Industry Council) curve, published originally by the Computer and Business Equipment Manufacturers Association, which defines the voltage excursions such equipment should tolerate. At 0.7 per unit the curve permits equipment to disconnect within 20 milliseconds, and uninterruptible supplies built to IEC 62040-3 transfer to battery when voltage falls below roughly 0.7 to 0.8 per unit, within one to three cycles — 17 to 50 milliseconds. Now set that against the grid side: a transmission fault depresses voltage to 0.25–0.40 per unit for 42 to 66 milliseconds while protection clears it correctly. The two thresholds were engineered independently, decades apart, by different industries for different purposes. They coincide almost exactly. A fault cleared to specification lands squarely inside the window in which the facility is designed to remove itself.

What the grid actually sees then depends on the uninterruptible supply’s topology, which is why identical-looking facilities behave differently in the same event. A unit operating in bypass or economy mode, with the load fed from the line for efficiency, reaches its threshold in about 20 milliseconds and transfers the entire site to battery in one step — a cliff edge, and the worst case for the system. A double-conversion unit, where the load always runs off the inverter, supplements from its own battery and the grid sees a reduced rather than eliminated draw, tripping only if the dip persists beyond roughly 150 milliseconds. A rotary or diesel-rotary system transfers to a flywheel and starts its engine — and does not hand the load back quickly once voltage recovers, which is why roughly 1,260 MW of the July 2024 event stayed off the grid for several hours after a disturbance lasting 82 seconds. Cooling plant is voltage-sensitive on its own account and can trip independently of the IT load, so a facility may shed in stages rather than at once.

Two consequences follow, and they frame the rest of this section. The first is that nothing malfunctioned. The facility performed exactly as designed, and its design objective — uninterrupted service to the computing load — was achieved by the very act that harmed the system. This is a collision between two correct engineering specifications, not a defect, which is why it cannot be fixed by enforcement of existing rules and requires a new obligation. The second is that the triggering disturbance can be small. A single-phase fault producing 0.7 per unit on the faulted phase is sufficient, and NERC’s January 2026 reviews found facilities where neutral overcurrent protection tripped the whole site on exactly such an unbalanced sag, and others where transformer winding configuration passed the depression straight through to the equipment rather than tempering it. The remedies at that level are unglamorous — ground rather than neutral overcurrent protection, delta-wye staging, wider transfer thresholds — and considerably cheaper than the alternatives discussed below.

The record settles a question that decides how proportionate these rules are. If large loads disconnected only during extraordinary events — a cascading failure, a protection scheme that misoperated, a fault the system was never designed to survive — then requiring them to ride through would be asking for tolerance the grid itself does not offer. The documented record largely does not support that reading. In the great majority of the documented record the protection system worked correctly: in the July 2024 event protection detected and cleared the six faults in 42 to 66 milliseconds, well within design expectations, and the initiating failure of a lightning arrestor counts as ordinary equipment failure, which transmission systems experience continually. Two qualifications apply. The first event in ERCOT’s tabulated record, on October 12, 2022, involved a breaker misoperation that delayed clearing to roughly ten cycles — abnormal, and a more severe disturbance than the system requires equipment to withstand. And ERCOT’s largest large-load event, in west Texas on December 7, 2022, escalated: it began with a single-line-to-ground fault cleared normally in three cycles, then developed related faults including a three-phase fault caused by a breaker failure. The record therefore lacks uniformity, though those two events sit among dozens and the pattern holds in the rest, including the January 2023 west Texas event cleared normally in four cycles and the largest event outside Texas. ERCOT frames its own record the same way: these are reductions during normally cleared faults, with protection operating as designed. The system performed as designed, and about 1,500 MW of load disconnected regardless.

DateSystem / locationLoad lostTrigger and clearingSystem effect and recovery
Oct 12, 2022, 05:56 CTERCOT — west Texas, 138 kV415 MW (about 100 loads in the area briefly cut ~500 MW)Three-phase fault. Clearing delayed to about 10 cycles by a breaker misoperation — abnormal.First event in ERCOT’s tabulated record.
Oct 31, 2022, 23:12 CTERCOT — Dallas–Fort Worth500 MWTransmission fault.Multiple large loads affected.
Dec 7, 2022, 03:50 CTERCOT — 138 kV, west Texas (Odessa area)1,560–1,600 MW: data centers, oil and gas, other industrialSingle-line-to-ground fault cleared normally in 3 cycles, then escalated: related faults including a three-phase fault caused by a breaker failure — delayed clearing, not a normal disturbance.Frequency spiked to 60.235 Hz, returning to 60 Hz in 12 min 30 sec. Two thermal generators tripped (112 MW). Solar unaffected — night. Only five loads were in ERCOT’s interconnection process, contributing 212 MW of the total.
Jan 23, 2023, 12:19 CTERCOT — west Texas, 138 kV177 MW across six tracked loadsSingle-line-to-ground fault, normal 4-cycle clearing.Typical of the recurring pattern.
Jan 2023 – Sep 2025ERCOT — Central and far west Texas, Panhandle, North zone26 events above 100 MW; typically 100–400 MW eachNormally cleared faults. Protection operated as designed; the loads, mostly cryptocurrency facilities, dropped anyway.No customer outage. ERCOT reduced System Operating Limits on affected interfaces because the possible load loss had itself become a contingency.
Jul 10, 2024, 19:00 ETEastern Interconnection — northern Virginia (Dominion / PJM)~1,500 MW across 60 delivery points and 25 substationsLightning arrestor failure on a 230 kV line. Auto-reclosing, set for three attempts at each end, produced six successive faults in 82 seconds. Each cleared properly, in 42–66 ms. Voltage fell to 0.25–0.40 per unit.Frequency rose to 60.047 Hz, back to 60.0 Hz in about four minutes. Voltage reached 1.07 per unit; operators removed shunt capacitor banks. About 1,260 MW stayed off for several hours. No customer lost service.
2024–2025 (multiple)Eastern and ERCOT InterconnectionsSeveral events at or above 1,000 MWVoltage dips caused by ordinary grid faults.The evidentiary basis for NERC’s Level 3 alert.
Jan 2026ERCOT — two NERC incident reviewsCrypto facilities; magnitudes not publishedTemporary voltage dips from faults. Root causes: neutral overcurrent protection tripping whole sites on single-phase depressions, and transformer winding configuration passing sags through to the load.No system consequence; produced design recommendations (ground rather than neutral overcurrent protection, delta-wye staging).
May 4, 2026North AmericaNERC issues a Level 3 Essential Action Alert citing the record since 2022.Responses due August 3, 2026 (Watchlist).

Table 4A — Documented large-load disconnection events. Two columns run thinner than they should: no one publishes facility-level identities, and recovery durations survive only where an operator reconstructed them afterwards. Both gaps trace to the same cause — large loads are not registered entities, so no one can compel the data.

Sources: ERCOT, Large Load Loss/Reduction Events 2020–2024 (PDCWG, Nov 19, 2024); ERCOT Large Load Working Group, Sept 19, 2025; NERC incident reviews (Jan 2025; Jan 2026); NERC Level 3 Essential Action Alert, May 4, 2026.

Two patterns in that record deserve emphasis. The first is that severity is not driven by the size of the disturbance but by the concentration of load behind it: a 42-millisecond fault removed about 1,500 MW because 60 delivery points across 25 substations all saw the same sag and all responded identically. Load diversity, which has historically kept aggregate demand smooth and predictable, does not exist among facilities built to the same reference design with the same protection settings. The second is the asymmetry in recovery. Frequency recovered in about four minutes, but roughly 1,260 MW of the lost load did not return for several hours — so the system had to hold four minutes of surplus and then absorb a multi-hour reconnection ramp of a size no generator would be permitted to impose without scheduling it.

One distinction governs how the table should be read, because the figures invite a comparison that does not hold. Everything above records uncommanded load loss: facilities disconnecting themselves, on their own protection logic, without instruction. Uncommanded loss differs from involuntary load shedding, where an operator deliberately interrupts firm customers to save the system: the Southwest blackout of September 2011 at about 2,700 MW, the Northeast blackout of August 2003 at more than 61,000 MW, Winter Storm Uri in February 2021 at up to roughly 20,000 MW. In those events customers lost power. In the events in Table 4A, no customer did. The two categories are not additive.

They are, however, the right yardstick for scale. The uncommanded loss of about 1,600 MW in west Texas in December 2022 — the event isolated below, and the only one in the table large enough to make this comparison — is more than half the firm load interrupted in the 2011 Southwest blackout, and it arrived with no operator decision, no warning and no scheduling. ERCOT’s modelled threshold of about 2,600 MW sits between the two. A disturbance class that has so far produced no customer outage is therefore operating within the same order of magnitude as the events that did.

One number in the December 2022 row deserves separate attention. Of about 1,600 MW that disconnected, only 212 MW came from the five facilities then inside ERCOT’s large-load interconnection process. The remaining seven-eighths sat outside it — unstudied, unmodelled, and invisible to the planning cases that were supposed to anticipate exactly this. A ride-through standard binds the facilities an operator can identify, which is why registration (Section 4, and the December 31, 2026 filing) is not a separate reform from ride-through but a precondition for it.

A precedent for imposing such obligations exists, because the generation side of the grid addressed the same question first. ERCOT introduced ride-through requirements for new generators in 2008, grandfathering some existing wind farms — the same structure, and the same grandfathering compromise, that NOGRR282 and NPRR1308 applied to load seventeen years later. Those generator requirements were tightened after the Odessa event of June 4, 2022, in which a single 345 kV single-line-to-ground fault caused 2,555 MW of generation to drop off — 1,711 MW of it solar — taking frequency down to 59.7 Hz and consuming 2,343 MW of the 2,442 MW of responsive reserve available at that moment. That left roughly 100 MW of unused responsive reserve, and the cause was equipment that did not ride through a fault of a type the system is designed to clear.

Load reached comparable magnitude within six months. The December 7, 2022 west Texas event removed about 1,600 MW of mixed load and pushed frequency to 60.235 Hz — an excursion five times larger than the July 2024 Virginia event, taking twelve and a half minutes to recover rather than four. ERCOT drew the conclusion at the time, telling its board in June 2023 that the event showed the need for an improved interconnection process for large loads and better simulation models of new load types. The generators’ obligation dates from 2008 and the loads’ from 2025 — a seventeen-year interval across which the underlying physics did not change.

A substantial regulatory gap remains. Generators must ride through voltage and frequency excursions under the NERC protection and control standards PRC-024-4 and, for inverter-based resources, PRC-029-1. No mandatory NERC Reliability Standard presently applies to large loads at all. ERCOT has closed that gap inside its own footprint. NOGRR282 and NPRR1308 impose frequency and voltage ride-through obligations on Large Electronic Loads, approved through the stakeholder process, and grandfather facilities that had cleared energization approval or completed their interconnection study by November 14, 2025. Those obligations bind by ERCOT protocol rather than by continent-wide standard, and ERCOT itself flags the exempt population as a residual risk. From the system's perspective a 1 GW load trip equals a 1 GW generator trip with the sign reversed — yet only one carries regulation as such across the interconnections.

ERCOT has put a number on the exposure. In a September 2025 study built on a 2030/31 case containing roughly 15.2 GW of modelled large electronic load, ERCOT screened three-phase faults and identified about 2,600 MW as the threshold of instantaneous load loss beyond which frequency excursions become significant — losses above that level could carry system frequency past 60.4 Hz. Measured against that threshold, the fleet is already large: by the April 2026 Large Load Working Group about 9 GW of large load had been approved to energize, against an observed simultaneous peak near 3.7 GW in March 2026. The gap between approved and observed is diversity in operating patterns, not head-room, and it narrows as facilities ramp toward their contracted demand.

The cost of that exposure is already being paid in operations rather than waiting on a future event. ERCOT has reduced System Operating Limits on some interfaces because a sudden loss of load could by itself cause a violation — which means the possibility that large loads may trip is now constraining how much power can be moved across the network before any fault occurs. Every user of those interfaces bears that constraint, on account of the ride-through behaviour of a subset of loads.

One feature distinguishes this problem from every other in this report: the rules are anticipatory. ERCOT characterises the impacts of the events observed so far as minimal, and it has not identified a case in which a conventional data center reduced consumption in response to a transmission-level voltage disturbance — the documented events involved other classes of large electronic load. No customer is on record as having lost service because a large load disconnected itself. The standards are therefore being written against a modelled threshold rather than an experienced failure. The anticipatory character constitutes both their justification and their principal political vulnerability: they impose cost now to prevent an event that has not yet occurred, and opponents can accurately observe that nothing has gone wrong yet. Every other section of this report describes a problem with a cost already incurred and measurable — auction prices, household bills, stranded assets. This one does not, and it is the one NERC treats as most urgent.

The evidentiary position is limited, for a structural reason. Because large loads are not registered Market Participants, ERCOT has limited means to perform thorough event analysis when these disturbances occur — it can see the aggregate signature on the system but cannot compel the facility-level data that would explain it. The registration work described below is therefore not procedural but a precondition for knowing whether the modelled threshold errs toward caution or optimism, and it explains why the December 31, 2026 filing deadline matters more than its procedural framing suggests.

Proposed solutions#

  • NERC Level 3 Essential Action Alert (May 4, 2026). Seven essential actions spanning modeling, studies, instrumentation, commissioning, operations, protection and control. Listed registered entities owed responses by August 3, 2026. A Level 3 Alert ranks as NERC's most serious non-standard instrument.
  • NERC Reliability Guideline: Risk Mitigation for Emerging Large Loads (May 2026). Voluntary, but it is the template for the mandatory rule: treat clustered voltage-sensitive load loss under a single contingency as a reserve-sizing input comparable to generation MSSC under the NERC resource and demand balancing standard BAL-002; require Interpersonal Communication capability between large loads and their TO/DP; make large loads subject to Operating Instructions (TOP-001/IRO-001) with trained personnel (PER-005).
  • Registration criteria for computational loads. NERC defines physical and electrical thresholds above which large loads become NERC-registered entities with direct compliance obligations. Draft criteria went out for comment through May 15, 2026.
  • Project 2026-02 Reliability Standards. Standard Authorization Request posted April 1, 2026; an initial mandatory large-load Reliability Standard should arrive by the end of 2026.
  • FERC Docket RD26-7-000 (July 16, 2026) — the schedule becomes an order. Acting on its own motion, FERC directed NERC to file one or more new or modified mandatory Reliability Standards addressing bulk-power-system risks from computational-load integration by December 31, 2026; to revise its Rules of Procedure to require registration of computational-load entities by the same date; and to file a Phase II work plan for further standards by March 1, 2027. The order rests on the record NERC assembled in RM26-4 and was framed by the Chairman as removing any doubt that NERC's own accelerated timetable is not optional.
  • ERCOT NOGRR282 / NPRR1308. ERCOT has moved ahead of NERC with mandatory frequency and voltage ride-through obligations for Large Electronic Loads — the first such requirements imposed on demand in North America — plus dynamic modeling requirements and mandatory registration under NPRR1325. The rules grandfather facilities that had cleared energization approval or completed their interconnection study by November 14, 2025, an exempt population ERCOT has itself identified as a continuing reliability exposure.
  • Modeling reform. Replacing static ZIP/constant-power load models with dynamic models that actually reproduce voltage-sensitive trip behavior; EMT-level representation at the point of interconnection (POI). NERC has a dedicated Data Center Load Modeling Workshop scheduled for September 15–16, 2026.
  • Facility-side hardware. Wider UPS ride-through windows, coordinated protection settings between POI and facility switchgear, and POI voltage support (STATCOMs/SVCs). Research work is also examining circuit-breaker-operated braking resistors to absorb the energy imbalance when GW-scale load does drop.

Cite as: Zavadsky, V. (2026). Large-Load Grid Integration: A Primer: The Eight Problems — and the Decade That Frames Them (v1.31). Zenodo. 10.5281/zenodo.21464969
Data current through July 21, 2026. Generated from the same source as the PDF edition.