AI Data Centre IPOs Stall as Valuation Fears Grow

AI data centre companies are struggling to go public: a Nvidia-backed data centre firm has scrapped its IPO as valuation concerns deepen, the BBC reported on 9 October, following a run of delays that Bisnow detailed in September. We could not access the full BBC article, so the specifics below come from Bisnow’s earlier reporting.

In this report

The September delays

Bisnow reported on 22 September that SoftBank-backed SB Energy delayed an offering after investors reportedly balked at a valuation above $50 billion. The company says it has 8.8 GW contracted or under construction, nearly all tied to an OpenAI-leased campus on federal land, and has not yet brought a data centre online. Nuclear and power firm Holtec postponed a Nasdaq IPO expected at up to $10 billion, citing “uncertainty of data center development”. Aggreko was reported to be slowing its process.

Why investors are cautious

Bisnow lists investor scepticism over valuations, local and state opposition to data centres, scarce large power supplies and labour shortages, and a sell-off in AI stocks over fears of slowing demand. The same pressure shows in Finland’s decision to halt Google data-centre construction.

Who is still lining up

Close to a dozen other firms reportedly still aim to list in the coming months, and Anthropic is reportedly on course for a late-2026 listing, per Bisnow. CyrusOne, Vantage, Switch and Nscale are reportedly exploring IPOs. Many in the industry say they are not worried about a demand slowdown. Note that these are industry-sourced claims from parties with an interest in the sector.

What happens next

Watch OpenAI’s own numbers, which are now in question after a reported revenue revision, and rate expectations given the three-year-high mortgage rates. If you run a business and are weighing where to base it, see our company formation guide.

Data centre IPOs: questions answered

Which data centre IPOs have been delayed?

Per Bisnow, SB Energy, Holtec and reportedly Aggreko, with the BBC reporting a Nvidia-backed firm scrapped its IPO on 9 October.

Why are investors hesitant?

Valuation scepticism, local opposition, power and labour constraints and an AI stock sell-off, according to Bisnow.

Is Anthropic still planning to list?

Bisnow reports it is still on target for late 2026.

Does this mean AI demand is falling?

Not necessarily; many industry figures say they see no demand slowdown, though that is a view from interested parties.

Related reading: US stocks slide as yields climb.

OpenAI Revenue Reportedly $20 Billion Below Projection

OpenAI’s annualised revenue is reportedly “approaching $50 billion”, about $20 billion below the roughly $70 billion figure reported two weeks earlier, according to TechCrunch, which cites the Financial Times. OpenAI had not confirmed the lower number on the record, TechCrunch said.

Inside this story

Where the two numbers came from

Axios reported on 29 September 2026 that OpenAI’s annualised revenue was approaching $70 billion. Per the Financial Times, as relayed by TechCrunch, that figure came from information shared with OpenAI investors and was an attempt to compare OpenAI directly with Anthropic. The Financial Times now reports OpenAI has told investors the figure is closer to $50 billion.

The Anthropic comparison

CNBC reported on 17 August 2026 that Anthropic’s annualised revenue reached $65 billion in July. TechCrunch notes the two companies calculate the metric differently: Anthropic counts sales made through its cloud partners, while OpenAI does not. That accounting difference means the headline numbers are not like-for-like. Anthropic is a competitor of OpenAI, so each side’s figures should be read with that interest in mind.

Funding and IPO backdrop

TechCrunch lists OpenAI’s $122 billion funding round in March 2026, and notes CNBC reported on 19 August that the company’s IPO has been pushed to early 2027. Leaked 2025 financials reported by Inc. showed about $13 billion in revenue, with spending significantly higher. Investor appetite for AI-linked listings is a live question, as our coverage of the data-centre backlash and the stalled listings in our data-centre IPO report shows.

What to watch

The key tests are whether OpenAI confirms its figure, whether investors accept a like-for-like methodology across AI labs, and how the revision affects the IPO timetable. For more on the company’s recent turmoil see our report on the safety researcher resignation.

OpenAI revenue: questions answered

What is OpenAI’s reported annualised revenue now?

Approaching $50 billion, according to the Financial Times as relayed by TechCrunch.

What was the earlier figure?

Axios reported on 29 September that it was approaching $70 billion.

Has OpenAI confirmed the new number?

TechCrunch’s article carries no on-the-record confirmation.

Why are OpenAI and Anthropic hard to compare?

Anthropic counts sales through its cloud partners; OpenAI does not, per TechCrunch.

Related reading: Google bug bounty AI freeze and OpenAI rogue agents alerts.

Google’s $15 Billion AI Push Just Hit a Wall in Finland

Finland has stopped work at two of Google’s data center sites. The order affects a 13 billion euro ($15 billion) AI infrastructure push, Google’s largest single investment in Europe. This Google data center halt came from Finland’s Permit and Supervision Agency, known as the LVV, on Tuesday, October 6, 2026.

The agency told Tuike Finland, the local company representing Google, to immediately suspend preparatory work at its Muhos and Kajaani sites. It set a deadline of October 23, 2026. The reason is simple: regulators say large areas of forest came down before anyone ran the environmental review the law requires.

Why Finland Ordered a Google Data Center Halt

Google data center halt

Google announced the 13 billion euro investment in September 2026. The plan covers four sites: Muhos, Vaala, Kajaani, and Hamina. Google called the package its biggest single European commitment to date.

Work moved fast. Crews cleared trees, stripped topsoil, built access roads and storage areas, and altered drainage ditches at Muhos and Kajaani. Hanna Halmeenpää, who chairs the Finnish Association for Nature Conservation, says more than 300 hectares came down at Muhos alone. That is roughly 420 football fields. Some of the cleared land held sites worth protecting under Finnish conservation rules, she says.

Tommi Muilu of the LVV confirmed the physical changes on the ground: trees removed, soil stripped, roads built, drainage altered. His agency’s position is clear. None of this should have happened before a formal environmental impact assessment. Finnish law requires that review first for large projects that could significantly change the local environment, not after construction starts.

What Investigators Found at the Google Data Center Site

The LVV’s inquiry began after reports surfaced in September 2026. Investigators compared satellite imagery against the company’s own survey claims. Halmeenpää says the images show protected-worthy areas already leveled by the time anyone raised a formal objection.

Finland’s Environment and Climate Minister, Sari Multala, called the situation “a serious matter.” She said the projects will likely face delays if the claims against the company and its subcontractors hold up. The LVV has given Tuike Finland until October 14, 2026, to explain its plans. Formal enforcement proceedings could follow if the company does not satisfy the agency.

Google’s Response to the Data Center Dispute

Google spokesman Sondre Rönander acknowledged the company fell short of its own standards. He said Google had acted in good faith and would study the LVV’s findings. Google also separately maintains that the clearing complied with Finnish law. The company says it surveyed the site in advance to avoid damaging high-value environmental areas.

That claim sits directly against Halmeenpää’s account. She disputes the idea that the survey caught everything, pointing again to the satellite record. Google has offered to plant trees across 130 hectares at Muhos as a partial remedy. That pledge does not resolve the core question: did construction start before approval?

The dispute lands at an awkward moment for the AI industry’s buildout. Demand for AI compute has pushed Google, Amazon, Microsoft, and others to race through site selection and construction. Many of these sites sit in regions with limited spare power and water capacity. Finland offered Google cool air, cheap renewable power, and political goodwill. A regulatory halt tied to environmental law now complicates that pitch for every company chasing similar deals elsewhere in Europe.

No Confirmed Date for Google’s Finnish AI Buildout to Resume

Nothing about this dispute is settled yet. Tuike Finland has to respond by October 14. The LVV’s own deadline for ending the suspended work runs to October 23. Either date could slip if negotiations drag on, and enforcement proceedings would add months, not weeks, to any resolution.

Other large tech buildouts have run into similar friction this year. Amazon faced its own backlash over secrecy around data center permitting in the US. Chip demand tied to AI has also kept pressure on supply chains worldwide, as seen in South Korea’s record AI chip exports. Financing for AI infrastructure keeps climbing too. Nvidia’s market value keeps rising on chip demand, and that demand fuels exactly the kind of expansion regulators in Finland now want to slow down.

For now, the practical effect is narrow: two sites, paused, pending explanations. The broader effect may be wider. Regulators elsewhere are watching how Finland handles a company with Google’s resources and leverage. If the LVV holds firm, it sets a precedent. Environmental review comes before the bulldozers, not after.

Questions About the Finland Data Center Halt

  • Why did Finland halt Google’s data center construction? The Finnish Permit and Supervision Agency (LVV) says Tuike Finland, Google’s local company, cleared forest and altered land at two sites before completing the environmental impact assessment the projects required.
  • Which sites are affected? The suspension applies to the Muhos and Kajaani sites. Google’s wider Finnish investment also covers Vaala and Hamina, which are not named in the halt order.
  • How much forest was cleared? Campaigners cite roughly 300 hectares cleared at Muhos, about 420 football fields, based on satellite imagery and public reporting cited by the LVV.
  • What does Google say happened? Google says it surveyed the land beforehand to avoid high-value environmental areas and that the work complied with Finnish law, while also acknowledging it fell short of its own standards.
  • What happens if Tuike Finland doesn’t comply? The LVV can open formal enforcement proceedings, which would extend the delay well beyond the current October 23 suspension deadline.
  • Does this affect Google’s other European data centers? Not directly yet. The order names only Muhos and Kajaani, but it raises scrutiny questions for Vaala, Hamina, and similar AI infrastructure projects elsewhere in the EU.

Hackers Accessed More Personal Records Than Denmark Has People

Hackers broke into Denmark’s national population register. They pulled records on about 8.8 million people, Danish authorities said on October 5, 2026. That is more than Denmark’s entire population of roughly 6 million. The Denmark CPR data breach exposed records going back years, including people who have died or moved abroad. Names, home addresses and national ID numbers were all exposed.

What the Denmark CPR Data Breach Exposed

Denmark CPR data breach

The Central Person Register, known as the CPR, is Denmark’s core identity database. It assigns every resident a personal ID number. That number gets used across healthcare, banking, taxes and government services. Cybernews’ reporting on the incident says attackers used access credentials that belonged to a private Danish company to search the register. The register itself holds roughly 11 million records. That explains why a breach of 8.8 million entries can outnumber the country’s living population.

People already enrolled in Denmark’s name and address protection scheme were not affected, officials said. Everyone else had their name, home address and CPR number exposed. Whoever misused that stolen access now holds that information.

Why a National ID Breach Hits Differently Than a Typical Hack

Most consumer data breaches expose usernames, emails or card numbers. Those can usually be changed after a breach. A CPR number cannot be changed. It follows a Danish resident for life. It links medical records, tax filings, pension accounts and government correspondence together. That permanence is exactly why Denmark’s Minister of Research, Education and Digitalization, Christina Egelund, called the incident “a deeply serious incident.” She urged citizens to stay alert “now and in the future,” according to ITPro’s account of the government’s response.

Denmark’s MitID two-factor login system should stop attackers from directly impersonating someone using a CPR number alone. Still, officials warned residents to expect a wave of phishing attempts. Fake texts, calls and emails may come from people posing as banks or government agencies. Those scammers already know their target’s name, address and ID number. That makes the scam far more convincing than an ordinary phishing attempt would be.

What Security Researchers Say Went Wrong at the CPR

The breach traces back to legitimate access, not a software flaw. A private company had standing permission to search the CPR system. Attackers appear to have hijacked that access rather than breaking in directly. Cybersecurity researchers quoted by ITPro flagged two separate problems with that setup. One researcher pointed to the lag between when the intrusion began in September and when staff first noticed irregular activity. That activity surfaced on the night of Friday, October 2. The researcher called that detection gap a common weakness whenever a breach arrives through a third party. Another researcher warned that centralized national databases carry outsized risk whenever outside partners get direct search access. That expert recommended stricter limits on what partners can view, paired with monitoring for unusual search patterns.

Denmark is not the first European country to face a breach of this scale. Government identity systems have become frequent targets. A single successful intrusion can expose data on nearly an entire population at once. European data protection law requires member states to report major breaches quickly. It also requires them to notify affected individuals when the risk is high. Danish officials have not yet said whether every affected resident will get an individual notice, or only a general public warning.

Denmark has reported the incident to its national data protection authority. Police are now investigating alongside other agencies. The government has not named the company whose access was exploited. It has not identified any suspects either.

How Denmark Is Responding to the CPR Data Breach Now

Officials revoked the abused access credentials. They say they have added new protections to the CPR system since. A broader security review is underway across government agencies that rely on the register. Denmark’s response mirrors a pattern now familiar across the tech industry. Companies and governments alike are tightening data access, even as they rethink how they screen for vulnerabilities in increasingly complex systems.

The incident also lands amid wider scrutiny of how technology platforms handle sensitive data and automated systems. That theme surfaced days earlier at a city council hearing on AI governance in New York. It surfaced again in an unrelated trade secrets dispute between Apple and OpenAI set for mid-October. None of those cases involve the Danish breach directly. But they reflect a broader year in which lawmakers and regulators on both sides of the Atlantic have pushed harder on how data gets stored, shared and protected.

For now, Danish residents have been told to avoid sharing passwords or one-time login codes with anyone who contacts them unexpectedly. That holds true even if the caller already knows personal details. Security firms recommend verifying any unexpected request through an official phone number or website, rather than a number the caller provides.

Denmark Data Breach: What People Are Asking

How many people were affected by the Denmark CPR data breach?

About 8.8 million records were accessed, out of roughly 11 million total entries in the register. Those entries include deceased people and former residents.

What information was exposed?

Names, home addresses and CPR numbers, Denmark’s national ID number, were exposed. People enrolled in the country’s address protection program were excluded from the exposure.

How did hackers get into the system?

They used access credentials belonging to a private Danish company. That company had legitimate permission to search the register, so this was not a technical break-in.

When was the breach discovered?

Irregular activity was first spotted on the night of Friday, October 2, 2026. The government confirmed the scope of the breach and went public on October 5.

Can someone use a stolen CPR number to steal my identity?

Denmark’s MitID two-factor system limits that risk. Still, officials warned residents to watch for phishing calls, texts and emails from people who already know their personal details.

Has anyone been identified as responsible for the breach?

No. Officials had not named a suspect as of their statements. They had not confirmed whether the breach originated from a criminal group or another source.