The change we follow here: how long a major US Internet outage lasts is now set mostly outside the network. Transformer lead times, diesel logistics, patch backlogs and a provider's standing with Washington will likely matter more than how fast engineers can repair routers or DNS.
Key points
- For any grid outage longer than about three days, Internet recovery in the affected region depends on grid restoration and fuel delivery, not network repair.
- AI-driven vulnerability discovery is finding flaws faster than operators can patch them, so edge routers and admin panels stay exposed for longer.
- Adversary access already sits inside US carrier routers, so a disruptive attack would take days to weeks of carrier-by-carrier reimaging to undo.
- Government leverage over core providers, through designations, the .com agreement and Section 706, is now a plausible cause of outages in its own right.
- The likely winners are operators with on-site power, spare hardware and diverse vendors. Concentrated hubs like Northern Virginia and smaller network facilities lose most.
The change
For years, operators treated a long outage as a network incident: find the fault, fix it, restore service. The evidence now points elsewhere. Large transformers take 2.5 to 5 years to replace, against a supply deficit of about 30%1. Most data centers hold 48 to 72 hours of fuel2. Mythos-class models have surfaced more than 10,000 high- or critical-severity flaws3. State actors already sit in provider-edge routers at major carriers4. Data center loads can also destabilize the grid that powers them5. We judge it likely (about 70%) that the next US outage lasting more than a week will be bounded by power, hardware or politics rather than by a software fix. Our convergences piece traces how these pressures reinforce each other.
What follows
First-order
- Continuity plans move from hours to weeks. Operators will need fuel contracts, spare transformers and hardware inventories, not just failover scripts.
- Patching turns into triage. Operators have to choose which zero-days to fix first, and router firmware and OT keep falling behind3. AI-written exploits against web admin tools are already appearing in the wild6.
- Insurers put a price on concentration. The 15-hour us-east-1 DNS failure cost up to $581M in insured losses7, and premiums will likely follow control-plane location.
Second-order
- Power and cloud become one failure domain. FERC's standards for computational loads, due by December 31, 20265, matter as much to the Internet as any network rule. Rising baseline blackout risk leaves less margin when an attack lands8.
- The network layer can fail before the cloud does. IXPs, carrier hotels and cable landing stations usually have thinner backup than hyperscale sites2, so connectivity can go down while servers are still running.
- The defensive response slows. Threat-sharing protections now survive on short extensions while CISA loses staff9. A lapse during a mass-exploitation event would likely delay coordination across ISPs, cloud providers and utilities.
Third-order
- Standing with the government becomes an operational risk. The Pentagon's designation of Anthropic, later ruled unlawful retaliation10, shows how a policy dispute can force contractors to migrate off a vendor. Applied to a DNS provider or CDN, the same tool would reroute critical traffic overnight.
- DNS concentration becomes a geopolitical argument. With root zone publication, root servers and .com all at Verisign under US oversight11, other states have a ready case for alternative roots and a more fragmented Internet.
- Shutdown authority stops being purely theoretical. Section 706 still allows executive shutdown orders without congressional approval12. Combined with coercive designations, a politically driven outage is plausible, though we rate it unlikely (about 10% this decade).
- Regulation shifts toward safety obligations on frontier models13. Visibility into misuse still lags capability14, so defenders will depend on a few model vendors whose own standing is contested.
Who gains, who loses
- Gain: operators with on-site generation, stored fuel and spare transformers, which recover on their own schedule.
- Gain: firms with access to frontier defensive models. The shadow side is that this access is concentrated in a few partners and tied to one vendor's standing with the government310.
- Lose: Northern Virginia and Texas cloud hubs, where one utility footprint concentrates national control planes75.
- Lose: regional ISPs and smaller exchange points with thin backup and slow patch cycles.
- Lose: users in outage zones, who lose connectivity along with power, payments and emergency information, since recovery tracks the grid.
A glimpse ahead
March 2029, a status page: "Service in the Mid-Atlantic region remains degraded. Our facilities are on generator power, day six. Fuel deliveries depend on regional road access. Restoration depends on replacement of two substation transformers. The utility estimates partial service in 14 weeks. Customers should migrate workloads to other regions, subject to current federal vendor certification rules."
Sources
- Large power transformer lead times reach 2.5 to 5 years amid a roughly 30% supply deficit, while substations remain soft targets · journalism · also powermag.com, cisa.gov ↩
- Data center backup power is sized for 48, 72 hours and depends on diesel logistics that fail in regional disasters · journalism · also mansfield.energy ↩
- Mythos-class AI finds more than 10,000 high/critical vulnerabilities across every major OS and browser · disclosure · also helpnetsecurity.com ↩
- Chinese state actors hold persistent access inside US ISP backbone and provider-edge routers · institutional ↩
- NERC issues a rare Level 3 alert after 1,000+ MW data center loads drop off the grid in seconds · journalism · also powermag.com ↩
- Google confirms the first AI-generated zero-day used in a planned mass-exploitation campaign · disclosure · also cnbc.com ↩
- One DNS race condition in AWS us-east-1 cascades into a 15-hour outage of global control-plane services · expert · also gremlin.com ↩
- DOE models a 100x rise in US blackout risk by 2030 as load outruns firm capacity · institutional ↩
- The legal basis for US cyber threat-sharing survives on short-term extensions while CISA loses staff · journalism · also congress.gov ↩
- The Pentagon labels a leading US AI company a 'supply chain risk'; a court rules the label unlawful retaliation · journalism · also cnbc.com ↩
- Verisign stays the single root zone maintainer through the early 2030s while also running the .com registry and two root servers · disclosure · also icann.org, ntia.gov ↩
- The President's Section 706 authority to seize or shut down US communications remains unreformed · expert · also uscode.house.gov ↩
- EU AI Office gains enforcement powers over systemic-risk general-purpose models · institutional · also artificialintelligenceact.eu ↩
- International AI Safety Report 2026: capability gains widen harm pathways faster than visibility into misuse · institutional ↩