The mechanism, not the headline
Pennsylvania Governor Josh Shapiro signed Executive Order 2026-05 on August 18, and the substance is more interesting than the topline description of another state adding data center rules. The order applies to any data center project with peak electricity demand of 25 megawatts or more, and it splits the permitting process into two distinct tracks. Track one requires a developer to sign a Consent Order and Agreement, a legally binding commitment covering community benefits and power generation obligations, in exchange for the state's Department of Environmental Protection reviewing the application on a rolling basis. Track two, for developers who decline that agreement, requires them to secure every local approval and environmental authorization on their own before DEP will even begin reviewing the permit.
The order also pulled data centers out of Pennsylvania's fast-track permitting programs entirely, meaning even the cooperative track one path no longer gets the expedited handling that other industrial development can access. Governor Shapiro was direct about the intent behind forcing that choice: 'If you can't agree to our strict requirements and get the community where you want to build to say yes, you're not going to have the Commonwealth's support either.' That is a governor explicitly using state permitting authority as leverage to force developers into local negotiations the state itself is not going to referee.
The local approval requirement is the real teeth
The detail that separates this order from disclosure-focused rules elsewhere is that neither track lets a developer get a state permit without local buy-in. On track one, DEP will not issue the permit until local approvals are demonstrated, even after a developer has signed the binding agreement and gone through rolling state review. On track two, local approval and environmental authorization have to be secured entirely before DEP review even starts. In practice, Pennsylvania has made a municipality's willingness to approve a project a prerequisite for state permitting either way, which functions close to a local veto without the state formally calling it one.
The order also bans nondisclosure agreements between developers and communities, a provision aimed directly at a common industry practice of negotiating land and utility deals under confidentiality terms that keep residents from knowing a hyperscale project is coming until construction begins. Alongside that, the state is standing up a public tracking map covering every proposed project, converting what has historically been fragmented, hard-to-find local zoning board information into a single statewide resource that community groups, competing developers, and enterprise site-selection teams can all use.
Ratepayers get explicit, not implicit, protection
Beyond permitting, the order creates a Special Counsel for Energy Affordability inside the Public Utility Commission structure, tasked specifically with ensuring data center demand does not push up household electricity costs. Two mechanical protections back that up. First, data centers must lose power before residential and other customers during grid stress events, formalizing a curtailment order of operations that has been ambiguous in most states' large-load rules. Second, the cost of participating in reliability backstop auctions, the mechanism grid operators use to secure emergency capacity, falls on data centers rather than getting spread across the general ratepayer base.
The order additionally requires transparent energy demand forecasting from developers, closing a gap that has frustrated utilities and regulators across multiple states this year, where projected data center load has repeatedly come in far higher or far more front-loaded than developers initially disclosed during interconnection queue applications. Requiring accurate forecasting up front, tied to a binding agreement on track one, gives Pennsylvania's grid planners a more reliable basis for capacity planning than the industry-wide pattern of speculative interconnection requests that inflate queues without reflecting real committed demand.
Why Pennsylvania, why now
The order's own numbers explain the urgency. More than 100 data center projects are already proposed across the Commonwealth, with 58 having engaged with DEP at some level of formality, 15 having applied for at least one permit, and only 5 having secured every permit needed for a first construction phase. That gap between proposed and permitted is the story: Pennsylvania is sitting on a pipeline of speculative and early-stage projects large enough to strain grid planning and local land use decisions, and the state moved to impose structure before that pipeline converts into simultaneous construction across dozens of municipalities with no coordinated framework governing any of it.
Pennsylvania's grid position adds urgency beyond its own borders. As a major PJM Interconnection state with substantial existing generation capacity, Pennsylvania has positioned itself as an attractive data center location precisely because power availability looks better there than in tighter grid regions. That attractiveness is exactly what produced the 100-plus project pipeline, and the executive order is the state trying to capture the economic upside of that demand while avoiding the ratepayer backlash and grid strain that unstructured growth has produced elsewhere.
How this differs from the disclosure-only model
Several states have moved this year toward requiring data centers to report energy and water use publicly, a meaningful transparency step but one that leaves permitting timelines and local approval requirements largely untouched. Pennsylvania's order goes further by tying the state's own permitting speed directly to a developer's willingness to sign binding commitments and secure local approval, converting disclosure into leverage rather than treating it as an end in itself. That distinction matters operationally: a reporting requirement changes what the public knows about a project, while a permitting gate changes whether and when the project can actually get built.
For developers and the enterprises that lease from them, this raises the practical cost of entering Pennsylvania's market regardless of which track gets chosen. Track one means negotiating a binding community benefits agreement before construction can begin at any real speed. Track two means a slower, sequential approval process with no state review running in parallel. Neither path is fast, and both are more expensive in legal and community relations spend than the streamlined, disclosure-only frameworks some other states have adopted. Other states weighing their own data center rules now have a live example of the stricter end of the regulatory spectrum to reference.
The roadmap implication for site selection
If Pennsylvania is on your site selection shortlist for any workload requiring new data center capacity, budget for the community benefits agreement negotiation as a real line item, not a formality, and start that conversation with local officials well before you need permits in hand. The 5 out of 100-plus projects with full permits as of this order's signing is the clearest evidence available that the old assumption, that Pennsylvania's power availability translates into fast approvals, no longer holds.
More broadly, this order is worth reading even if Pennsylvania is not on your list, because it is a template other states are likely to study. A state that ties its own permitting speed to binding developer commitments and local sign-off, while explicitly shielding ratepayers through curtailment order and cost allocation rules, gives other governors a more sophisticated model than blanket moratoriums or pure disclosure mandates. Expect variations of this dual-track structure to show up in other states' data center legislation over the next two to three legislative sessions, which means your site selection playbook should start accounting for community agreement negotiations as a standard cost of doing business, not a Pennsylvania-specific exception.

