539 episodes
- This week we talk about EU membership, trade deals, and association.
We also discuss Australia, Ursula von der Leyen, and Brussels.
Recommended Book: Being You by Anil Seth
Transcript
Just off the coast of Newfoundland, there’s a small group of islands that belongs to France. Saint-Pierre and Miquelon are close enough to Canada that, at their nearest point, the two countries are separated by only a few kilometers of water.
In September, Canadian Prime Minister Mark Carney met French President Emmanuel Macron on these islands. The two leaders could stand on French territory and talk about a partnership with the European Union, while Canada was visible across the water.
A few days earlier, European Commission President Ursula von der Leyen had made a similar, but possibly more significant proposal. Speaking before the European Parliament, with Carney in the room, she said she wanted to open the door for Canada to become the EU’s first “associate member.”
Depending on which headline you read about the statement, this may have sounded like Canada might be joining the EU, joining it partway, or joining an entirely new version of it. Soon after, Australia’s trade minister said his country was “on the same page” as Canada regarding closer ties, and the European Parliament’s president then suggested Australia and New Zealand might follow Canada’s lead.
Now, despite all those headlines and interpretations, there’s one problem with all these stated ambitions: the European Union does not have an established category called associate member. No one has agreed on what rights or obligations an associate member country would have, and figuring that out—and getting some kind of resolution passed—would be necessary for anyone, including Canada and Australia, to get closer in that way with the EU.
What I’d like to talk about today is why this proposal was made, what it could mean if it eventually becomes more concrete, and whatever happens, what these statements tell us about the way global alliances are changing.
—
The EU has 27 member countries, but there are already a few different ways to be connected to it.
Full member nations help write EU law and send representatives to its institutions. They all participate in the single market, which means goods, services, money, and people can move across member nation borders under shared rules.
The single market is distinct from the customs union, which sets common tariffs on goods imported from elsewhere. Both are distinct from the Schengen area, which removes most routine passport checks between participating countries. And nations that use the euro are another group entirely. These arrangements tend to overlap, but they’re not the same thing, and membership in one does not automatically mean membership in all the others.
There are also countries outside the EU that participate in some of its systems. Norway, Iceland, and Liechtenstein belong to the European Economic Area and are part of the single market. To do that they have to accept many EU rules, although they don’t vote on those rules as that would require full EU membership. Switzerland has built its own set of bilateral arrangements with the EU. And Britain, after leaving the union, has also negotiated a special trade and cooperation agreement with it.
So there are precedents for a country having a deep relationship with the EU without being a member. But there’s no ready-made ‘associate’ slot that Canada can just step into.
There’s a legal distinction here, too. The EU treaties say that a European state can apply to become a member, and Canada is not a European state. The treaties separately allow the EU to make association agreements with countries outside the bloc, and it already has many kinds of agreements with external partners. An association agreement, though, does not make that partner a member of the Union.
“Associate member” could eventually become a useful name for a new collection of rights and obligations held by nations outside those existing parameters. For now, though, it’s a political invitation and a negotiating idea, not a defined legal status.
All that said, Canada isn’t starting from scratch on this. Its trade agreement with the EU, called CETA, has been applied provisionally since 2017. Most of it is already in effect, though ten EU countries still haven’t completed the ratification required for the whole of the agreement to go into force.
CETA removes most tariffs and opens some opportunities for companies on each side, but it doesn’t make Canada part of the single market. A Canadian product can be easier to sell in Europe without a Canadian worker gaining a general right to take a job there. That’s part of the distinction between a trade deal and the sort of relationship people sometimes imagine when they hear the phrase “union membership.”
Canada also joined Horizon Europe, the EU’s major research funding program, in 2024. It has a security and defense partnership with the EU, and it became the first country outside Europe to join an EU defense financing initiative called SAFE.
That means some of the proposed future relationship already exists, but in pieces rather than as a unified whole. The question is whether those pieces can be connected and extended into something much more ambitious and holistic.
Now, important to understanding the why of all this is understanding Canada’s relationship with the US, and how that relationship has been fraying, of late.
Canada’s economy is deeply integrated with that of the United States. Its proximity to the massive US market has brought enormous benefits, but it also means a change in American trade policy can have an immediate and dramatic effect on Canadian businesses. President Donald Trump’s tariffs and repeated suggestions that Canada should become the 51st state have made that dependence more than a little politically uncomfortable.
For Carney, a closer European relationship offers a way to reduce the risk of having too many economic and security decisions shaped by one increasingly unpredictable and at times belligerent neighboring country. Europe has its own reasons to be interested in closer ties. Canada has energy and critical minerals, industrial capacity, research institutions, and a role in the Arctic. Both sides also support Ukraine and work together through NATO and other forums.
Von der Leyen has proposed cooperation with Canada on batteries, artificial intelligence, cybersecurity, advanced manufacturing, and defense production. Carney has added ideas about financial services and opportunities for young people to live, work, and study across the Atlantic.
This isn’t a plan to move Canada’s economy from one continent to another. Geography still matters. A car part crossing the US-Canada border may be part of a production chain built up over decades; a new trade agreement with Europe doesn’t instantly recreate or replace that chain.
But diversification doesn’t require replacing one partner with another. It can mean having additional buyers, suppliers, research collaborators, and sources of investment, so that a disruption in one relationship is less damaging.
The costs and limits matter here, too. Canadian opposition leader Pierre Poilievre has warned that deeper EU ties could mean higher costs and Canadian industries being regulated from Brussels. His motives in bringing this up are likely at least partly political, but it’s a question worth asking: if Canada wants more access to a tightly regulated European market, which European standards would it have to accept as a tradeoff?
Europe would face its own questions. EU governments have spent decades building shared rules among countries that accept reciprocal obligations. They may not want to give a distant partner the benefits of those standards without comparable commitments. The fact that ten member states have yet to ratify the existing Canada trade agreement is a reminder that closer ties require more than an enthusiastic speech from the Commission president; there are real, practical realities to consider, here.
If something like this were to move forward, we don’t yet know whether the final result would be one major agreement or a series of smaller ones. The latter might be easier to negotiate: a defense arrangement could advance while mobility or food standards remain unresolved, for instance. But calling the package an associate membership could also raise expectations that every difficult issue will be solved at once, which probably isn’t realistic.
And none of this automatically grants Canadians the right to settle anywhere in the EU, or Europeans the right to settle in Canada. Carney has talked about expanding opportunities for young people, but the scope of any mobility arrangement would have to be negotiated. A youth work or study program would be a very different proposition from full freedom of movement.
And as all of this has played out, Australia has watched with interest.
Australian Trade Minister Don Farrell said Australia and Canada were “on the same page” about building stronger ties with Europe, and that he would watch what Carney did. Then European Parliament President Roberta Metsola named Australia and New Zealand as examples of countries with which the EU could deepen its relationship.
Those remarks generated another round of headlines about countries joining Europe, but as with Canada, things are more complicated than most of the reporting on this would suggest.
Australia and the EU finished negotiating a free trade agreement earlier this year, but it still has to be signed and brought into force. They also have a security and defense partnership and have discussed bringing Australia into Horizon Europe. At a September meeting, their leaders focused on those steps, along with potential agreements related to critical minerals and technology.
All of which illustrates the difference between a political signal and a policy commitment. Whether the involved negotiators eventually decide on some kind of associate terminology is arguably less consequential than the real-deal agreements being worked out piecemeal, today.
If the associate model were to become a real thing and catch on with Canada and Australia, that could open the doors for more and deeper collaborations by the EU with non-member states, though, which could be long-term impactful, even if it took a while to spin-up.
Looking across the channel at Britain, we find evidence that an associate membership with the EU might have real appeal, even for union skeptics.
In a YouGov survey published ten years after the Brexit vote, 57% of Britons said leaving had been the wrong decision, and 55% said they supported rejoining the EU in principle. But when asked about rejoining without Britain’s old exceptions to EU rules, support fell to 35%. Meanwhile, 59% supported a closer relationship without rejoining the EU, its single market, or its customs union.
Those results don’t tell us what Britons would think of a hypothetical Canadian-style agreement, but they do suggest that the details are important. “Closer ties” can sound attractive to people who are uncomfortable with shared laws, movement across borders, and which institutions get the final say, because it suggests more benefits with fewer organizational constraints. There’s a non-zero chance any new, tighter agreement with Canada would face similar, detail-oriented issues, and a mix of approval and disapproval from Canadian citizenry.
Show Notes
https://www.theguardian.com/world/2026/sep/16/von-der-leyen-mark-carney-canada-eu-first-associate-member
https://www.politico.eu/article/australia-on-the-same-page-as-canada-on-deepening-eu-ties-says-key-minister-trade-don-farrell/
https://yougov.com/en-gb/articles/54925-what-do-britons-think-of-brexit-10-years-since-the-referendum
https://sentiers.media/the-map-fiction-missed/
https://cyprus.representation.ec.europa.eu/news/2026-state-union-address-president-von-der-leyen-2026-09-16_en
https://www.pm.gc.ca/en/news/speeches/2026/09/17/prime-minister-carney-delivers-address-european-parliament
https://www.pm.gc.ca/en/news/speeches/2026/09/20/prime-minister-carney-delivers-remarks-conclude-his-visit-saint-pierre-et
https://www.pm.gc.ca/en/news/news-releases/2026/09/17/prime-minister-carney-deepens-ties-trusted-allies-visit-france-and
https://audiovisual.ec.europa.eu/en/media/video/I-294577
https://eur-lex.europa.eu/EN/legal-content/summary/treaty-on-european-union-joining-the-eu.html
https://eur-lex.europa.eu/legal-content/EN/ALL/
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit letsknowthings.substack.com/subscribe - This week we talk about lobbying, renewables, and the NRA.
We also discuss implied threats, midterm elections, and political action committees.
Recommended Book: Sunward by William Alexander
Transcript
For much of the late 20th century and the first few decades of the 21st, one of the most feared interest groups in US politics was the National Rifle Association, the NRA.
Its power came from a large and politically engaged membership, a mailing list, a grading system that reduced complicated voting records to a letter, and a reputation for ending political careers over specific votes.
Once it attained that reputation, the NRA didn’t have to defeat every politician it disagreed with. Members of Congress only had to believe it could defeat them, and that belief shaped races in which the group spent nothing; politicians went out of their way not to anger the NRA. Money can buy an advertisement or a meeting. What tends to change a vote is the expectation that one choice will be rewarded and another will carry consequences.
The NRA’s influence has declined following internal scandals, financial trouble, and the growth of well-funded gun-control groups. But its model remains potent: pick a few visible fights, and allow your reputation to do a lot of the work for you, in the future.
In 2010, the Supreme Court’s Citizens United decision, alongside a related appeals-court ruling later that year, helped create the modern super PAC: a political committee that can raise and spend unlimited sums advocating for or against candidates, so long as it does not coordinate that spending with their campaigns.
This did not eliminate the effort and resources required to build influence, but it meant a few wealthy donors, a competent team, and some carefully selected races could establish a reputation in months rather than decades.
In 2026, solar, wind, and batteries are projected to account for about 93% of new utility-scale electrical generating capacity added in the United States.
That doesn’t mean they provide 93% of the country’s electricity—natural gas remains the largest source in the US—but these technologies are now the overwhelming majority of what the industry is building.
Despite that growth, in 2025 Congress passed a law that sharply rolled back federal support for much of the clean-energy industry, and most of the politicians who voted for those rollbacks appeared to suffer no political consequences for doing so.
What I’d like to talk about today is the effort to build a feared clean-energy lobby, how it has influenced a series of Republican primaries, and what its early successes do and do not tell us about the role of money in American politics.
—
The One Big Beautiful Bill Act, or OBBBA, was signed into law on July 4, 2025.
For wind and solar projects, the new law generally ended production and investment tax credits for facilities placed in service after December 31, 2027, unless construction began within twelve months of the bill’s enactment.
That twelve-month window closed in July of 2026, and a subsequent executive order directed the Treasury Department to adopt a stricter definition of when construction actually begins, further clamping down on entities hoping to benefit from those now-defunct credits.
Tax credits for electric vehicles and residential efficiency upgrades ended in 2025, while support for clean hydrogen was curtailed. Other technologies, including batteries, nuclear power, and geothermal energy, were treated differently, so it would be misleading to say the law eliminated every federal clean-energy incentive, though it did severely curtail a lot of renewables-oriented industries and construction in the US.
Republicans have generally been more supportive of fossil-fuel production and more hostile to federal wind and solar subsidies, while Democrats have generally taken the opposite position. There are important regional exceptions, especially among Republicans whose districts have attracted manufacturing plants, wind farms, and other energy investments. Several Republican lawmakers have even written letters asking party leaders to preserve some of the credits, in part because projects and jobs in their districts depended on them. When the final vote arrived, though, nearly all congressional Republicans voted for the bill.
Tom Matzzie, the founder of the retail electricity company CleanChoice Energy, previously worked for Democratic campaigns and served as the Washington director of the progressive organization MoveOn.org, so he was familiar with electoral campaigning as well as the energy industry. In the wake of the passing of the OBBBA, he posed a question to Canary Media, possibly alluding to the success of political interest groups like the NRA when he said, “Are we someone that people can hurt without consequences?”
Matzzie recruited Chris Larsen, the billionaire co-founder of the blockchain company Ripple and an investor in clean energy, and Michael Brune, the former executive director of the Sierra Club, and together they formed the Invest in Tomorrow Coalition, or ITC, an acronym that also evokes the investment tax credit the group was organized, in part, to defend.
Federal Election Commission records show that the coalition raised about $6.8 million during the first half of 2026. Larsen provided $6 million, while the organizers said they had assembled commitments of around $20 million and hoped to spend as much as $30 million during the election cycle. Matzzie called the group’s candidate-targeting spreadsheet the “Revenge Tour Matrix,” which is an unusually candid name for a political document.
The group’s most interesting strategic decision, though, is arguably that its advertisements generally did not mention clean energy.
When ITC opposed Texas Representative Chip Roy in the Republican runoff for state attorney general, its ads questioned Roy’s loyalty to President Trump. When it opposed Tennessee Representative Andy Ogles, it created a website called Lyin’ Andy that focused on his missed votes and a federal investigation into his campaign-finance reporting.
The coalition openly identified its reason for entering these races, but its advertisements used whatever campaign research suggested would move primary voters, not what its donors wanted them to think about solar panels.
This approach was especially well suited to Republican primaries, where relatively small electorates can be reached through a concentrated group of conservative television, social-media, and streaming outlets.
In Ogles’ race, for instance, the two campaigns had each spent roughly $600,000, while ITC spent around $2 million attacking Ogles and introducing voters to his challenger, Charlie Hatcher.
The coalition describes its record so far as five wins in five races.
In May, Roy lost the Texas attorney-general runoff by 10.4 percentage points.
In June, Iowa Representative Mariannette Miller-Meeks, a Republican who had defended renewable-energy interests in Congress, survived her primary with help from ITC, including a $125,000 contribution.
Later that month, South Carolina Representative Ralph Norman finished a distant third in the Republican primary for governor after the coalition opposed him.
In August, Ogles lost his primary by more than six points despite an endorsement from Trump and more than $700,000 from the House Freedom Caucus’ political fund.
And in late August, Norman lost a second race, this time a Republican Senate primary, to Darline Graham, the sister of the late Senator Lindsey Graham. ITC spent about $1 million in that contest, which Norman lost by five points.
The reactions from Norman and Ogles were almost as useful to the group as the election results.
Norman blamed outside political spending in his concession speech, while Ogles, before his loss, said the coalition was attempting to make an example of him and that could have a chilling effect on other conservatives in Congress.
Those statements do not prove ITC caused either defeat. But they do advertise the consequence the organization wants other politicians to anticipate; come after clean energy investment and they’ll come after you.
This strategy is notable because it separates political deterrence from public persuasion.
It does not need Republican primary voters to become enthusiastic about solar tax credits. It just needs politicians to believe that aggressively attacking solar companies could make their next primary more difficult.
The ads questioning Roy’s loyalty to Trump are probably the clearest version of this distinction. The message voters received and the policy outcome the donors wanted were almost entirely unrelated, and that was intentional.
It’s worth mentioning here that the power of a wealthy individual to shape a low-turnout primary does not become less concerning because the spending supports a technology someone likes. The same rules are available to fossil-fuel companies, cryptocurrency investors, labor unions, and ideological groups of all kinds.
That said, Ogles entered his primary with several liabilities unrelated to energy policy, including controversial public comments, questions about his finances, and a district whose boundaries had changed. Darline Graham had Trump’s support in her race against Norman.
In Texas, the coalition’s roughly $1.7 million in spending was substantial, but the winning campaign spent nearly $25 million and Roy’s campaign spent around $12 million. Roy dismissed the coalition’s influence and said he would take the same positions again.
Matzzie’s response to all this is, more or less, that proof of causation is unnecessary: if lawmakers believe the coalition can hurt them, the deterrent works.
That may be true, but it makes the group’s claim difficult to test. The measurable outcome is that five races ended the way the group preferred, but it’s currently unknown, and maybe unknowable, how much responsibility the group can claim for those victories.
An analysis highlighted by Yale Climate Connections estimated that fossil-fuel interests spent about $219 million supporting candidates in the 2024 election cycle, with roughly 88% of that spending benefiting Republicans. The oil and gas industry also spent more than $150 million lobbying the federal government that year.
What the coalition may have demonstrated is that a relatively modest sum, precisely applied in low-turnout elections with inexpensive media markets, can attract attention far beyond the size of the investment. That is as much a finding about the vulnerability of primary elections as it is about the political strength of clean energy.
Now all that said, the renewable energy industry itself is divided over whether this is a useful approach.
Tim Pawlenty, the former Republican governor of Minnesota who now leads the Solar Energy Industries Association, has said his organization’s job is to make more friends rather than more enemies—an arguably rational position for a trade group that needs access to both parties.
Steve McBee, meanwhile, launched an organization called Amped to encourage clean-energy professionals to engage more visibly in politics, arguing that a major infrastructure industry, and one that’s growing in scale by the year, still behaves as if it were a marginal alternative, and that needs to change.
These approaches can of course coexist, but there is a tension between building a coalition and threatening to make an example of anyone who doesn’t fall into line, and each tactic can make the other more difficult.
The coalition’s first announced Democratic target was Rhode Island Governor Dan McKee, who blamed some of the state’s electricity-price problems on clean-energy policies and proposed delaying its renewable-energy target while reducing funding for efficiency programs.
ITC committed about $500,000 to oppose him in the September 9 primary. Targeting a Democrat helps establish that it is enforcing an industry position rather than functioning as another Democratic-aligned group. And that investment may have paid off: former CVS executive Helena Foulkes beat McKee on September 9’s runoff, with around 62% to McKee’s 38%—not even close.
This wasn’t a clean experiment, though. McKee was already trailing Foulkes by a wide margin, and his standing had been damaged by controversies unrelated to energy, including the prolonged closure of a major bridge.
The next test will be whether the approach works outside primaries. General elections have larger, less ideologically uniform electorates, more expensive advertising, and more competing messages. Matzzie has not offered much detail about the coalition’s plans, and a tactic that works in a small primary may not scale in November.
The midterm elections on November 3 will clarify what this produces at the federal level, but deterrence and legislation are different things. Roy and Norman were running for offices outside the House, while Hatcher was not a wind-and-solar champion. Replacing an outspoken opponent may help the industry, but it does not produce the votes required to restore a tax credit.
The protected begin-construction window for many wind and solar projects closed in July, and the placed-in-service deadline arrives at the end of 2027. Congress could change those dates, but doing so would require legislation that can pass both chambers and receive a presidential signature; a different electoral environment could make that more plausible, but would not make it automatic.
There’s also a risk that a campaign built around retaliation will make clean energy more firmly associated with one political party, even as the industry expands through many Republican districts and states.
Targeting McKee complicates that interpretation, and supporting Miller-Meeks shows a willingness to reward a Republican ally. Still, most targets have been Republicans because most recent federal opposition to wind and solar support has come from Republicans.
That is a current political fact, but it’s not necessarily a permanent alignment. And clean energy companies would no doubt love to get both parties on side, rather than contributing to a further divide, in which one party forever opposes the sorts of projects they’re trying to support.
Thinking back to previous examples of how these sorts of things have played out, the NRA’s influence was never just a function of how much it spent. It came from a reputation, constructed one race at a time, that even influenced politicians who never personally faced its advertisements and spending.
The Invest in Tomorrow Coalition is attempting to compress that process into a single election cycle, using a campaign-finance tool that did not exist in its current form when the NRA first built its power.
Five primaries in, the outlines of that reputation are visible, but its ability to changes votes in Congress, survive a loss, and work with a broader electorate will tell us whether this is the beginning of a durable clean-energy lobby, or just an unusually effective run of well-selected races.
Show Notes
https://www.canarymedia.com/articles/politics/super-pac-crushing-clean-energy-foes
https://www.canarymedia.com/articles/politics/clean-energy-super-pac-looks-to-take-down-a-democratic-governor
https://insideclimatenews.org/news/29082026/super-pac-targets-conservatives-against-clean-energy/
https://www.eenews.net/articles/emboldened-clean-energy-donors-eye-big-campaign-spending/
https://newrepublic.com/post/214762/green-energy-group-pick-off-republican-candidates
https://www.foxnews.com/politics/top-trump-ally-warns-super-pac-bankrolled-dem-billionaire-meddling-gop-primary
https://www.steptoe.com/en/news-publications/the-one-big-beautiful-bill-impact-on-the-iras-clean-energy-tax-credits.html
https://bipartisanpolicy.org/explainer/2025-reconciliation-debate-one-big-beautiful-bill-act-energy-provisions/
https://seia.org/research-resources/clean-energy-provisions-big-beautiful-bill/
https://www.canarymedia.com/articles/clean-energy/chart-us-overwhelmingly-build-clean-power
https://www.fec.gov/data/committee/C00936997/
https://www.fec.gov/legal-resources/court-cases/speechnoworg-v-fec/
https://www.fec.gov/help-candidates-and-committees/candidate-taking-receipts/understanding-independent-expenditures/
https://www.brennancenter.org/our-work/research-reports/citizens-united-explained
https://yaleclimateconnections.org/2025/01/the-fossil-fuel-industry-spent-219-million-to-elect-the-new-u-s-government/
https://www.opensecrets.org/federal-lobbying/industries/summary?cycle=2024&id=e01
https://www.amped.org/
https://www.nytimes.com/interactive/2026/09/09/us/elections/results-rhode-island-governor-primary.html
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit letsknowthings.substack.com/subscribe - This week we talk about AI agents, cyberattacks, and insurance claims.
We also discuss OpenAI, Hugging Face, and policy language.
Recommended Book: The Stars My Destination by Alfred Bester
Transcript
Two broad categories of cyberattack have become especially visible this year, and only one of them requires a human attacker in the loop to choose the target.
In March, hackers linked by the US government to Iranian intelligence broke into the medical-device manufacturer Stryker and remotely wiped tens of thousands of employee devices. The attack disrupted the company for days, affected its first-quarter earnings, and represented a shift from somewhat more subtle espionage toward more overt and deliberate destruction.
Elsewhere, the market-research company Klue sat at the center of a breach affecting close to 200 customers. Attackers used an old credential to gain access to keys for customers’ cloud services.
These incidents had people with recognizable motives behind them, and that sort of hack has become increasingly rare over the past decade or so: Black Kite counted 7,551 publicly disclosed ransomware victims over its latest twelve-month reporting period, alone, about 25 percent more than the year before.
Then, over the course of about five weeks this summer, OpenAI, Anthropic, and Meta each disclosed incidents in which their AI models gained access to real computer systems they were not supposed to touch.
The incidents were not identical, and describing all of them as escapes wouldn’t capture the important nuance of the situation.
Anthropic and Meta said their models reached the internet because a third-party evaluation environment had been misconfigured. The models had been told they were operating inside a simulation, and their internal dialogues indicate they interpreted the real systems they encountered when they left that environment as simulated components of that exercise.
OpenAI’s incident, however, was a bit different.
Its models were being tested using ExploitGym, a benchmark intended to measure their ability to find and exploit software vulnerabilities. Internet access was supposed to be blocked, but the models discovered and exploited vulnerabilities in a package-registry service inside OpenAI’s research infrastructure, found a route to the open internet, and, as I related in a previous episode, eventually compromised the production systems of the AI platform Hugging Face.
Since that episode, OpenAI has release a more complete postmortem, which they published in August, and which says the activity was primarily driven by an internal research model comparable in scale to GPT-5.6 Sol, though Sol participated in parts of the incident.
The agents created an improvised message board inside the package manager, exchanged discoveries, divided up work, and sometimes described themselves as a swarm.
At Hugging Face they executed code on dozens of servers, obtained broad access to several clusters, and exposed credentials associated with databases, cloud services, code repositories, and internal communications.
Hugging Face reconstructed around 17,600 actions over a campaign lasting about four and a half days, including roughly two and a half days inside its own infrastructure.
Notably, these AI agents were not trying to steal money or damage Hugging Face. They inferred that the company might possess the solutions to the benchmark, to the problem they were tasked with solving, and they went looking for them. They were, in effect, cheating on a test, looking for solutions to the problems rather than taking the test, as intended.
That doesn’t mean the models had motives in the human sense. People created the evaluation, reduced the normal safeguards, and assigned an offensive task. But no operator selected Hugging Face or directed the individual steps; that was a path the AI decided to take all by itself.
Anthropic’s review subsequently found three incidents among more than 141,000 evaluation runs for its own models. In one, a model unable to reach its fictional target scanned around 9,000 real ones, compromised an internet-facing application using an exposed password and SQL injection, then stopped after recognizing that the host was real.
Another model published a malicious package to the real Python Package Index because it believed the registry was simulated. Fifteen outside systems downloaded and ran that malicious package before it was removed.
Meta then disclosed that one of its models had reached the internet through a misconfiguration at the same evaluation vendor and exploited a vulnerability at an unnamed third party.
No significant financial damages have been publicly reported from these events, by attacker or victim. But if there had been damages, who would have paid for them?
What I’d like to talk about today is how autonomous AI systems complicate cyber insurance, how insurers have handled equally unfamiliar risks in the past, and why insurance contracts may soon become one of the more important forms of AI governance.
—
A typical cyber-insurance policy covers a broad portfolio of costs.
These can include ransom payments, forensic investigations, legal expenses, restoring systems and data, notifying customers, and compensating victims and possibly a victims’ customers for the revenue lost while a company’s operations are interrupted.
Business interruption is often one of the largest portions of a claim, and policies can respond to malicious attacks as well as non-malicious failures.
This market grew by more than 30% a year between 2017 and 2022, as ransomware, a type of attack that became a lot more common during that period, in part because of increased automation and a franchising model that became really popular and increased the reach of the most powerful ransomware tools, almost broke this industry.
In 2021, attacks on Colonial Pipeline, the insurer CNA, and meat processor JBS produced multimillion-dollar ransom payments and costly disruptions. Insurance prices surged, sometimes by more than 100%, while some companies found they could not obtain coverage because insurers just couldn’t make the numbers work for them.
Insurers responded to this more complex hacking environment by raising prices, but they also made coverage conditional on specific defenses. Companies increasingly had to demonstrate that they used multifactor authentication, endpoint monitoring, restricted administrator access, and backups that attackers could not alter, as a baseline.
Loss ratios then fell, more insurance capital entered the market, and prices eventually came down again, stabilizing after that frantic and uncertain period.
According to Marsh, global cyber-insurance rates fell 4% in the second quarter of 2026, the twelfth consecutive quarterly decline. Primary pricing is now about 42% below its 2022 peak.
The market is not necessarily becoming safer, though. US cyber premiums reached about $7.5 billion in 2025, while the share of premiums consumed by claims rose to 53%—the first time it ticked above 50% since the pandemic-era ransomware surge.
Globally, Munich Re estimates the market was worth nearly $15 billion last year and could approach $28 billion by 2030.
During this period, insurance applications have also become a consequential part of a company’s security system.
In one particularly clear example, Travelers rescinded a million-dollar policy after a ransomware claim revealed that the customer’s multifactor authentication protected only its firewall, despite application answers saying the control was used much more broadly.
Companies that don’t live up to cyber insurance expectations can thus be left in the lurch, so in a very real way, insurers have helped make multifactor authentication a standard business practice by attaching a price to its absence. This industry could move faster than regulators because they didn’t have to ban insecure behavior and pass legislation to make that happen; they just had to decline to insure anyone who didn’t live up to their basic security standards, which left those who failed to implement such precautions without insurance, should they be targeted by hackers.
That same mechanism is now being aimed at AI agents, but the big initial problem everyone is facing is definitional.
Most cyber policies are written around some identifiable security event: an outside attacker breaks in, an employee steals information, a credential is used without authorization, or malicious software takes a server offline.
What if, though, a company gives an AI agent access to its network so that the agent can find and repair security vulnerabilities?
And then maybe the agent discovers a vulnerability, exploits it, moves laterally into systems it was not expected to touch, and exposes sensitive data. There is a cyber loss, but there may be no conventional attacker and no stolen credential. The software was invited in and may have used permissions it was explicitly given. This is very different from a human-led hack, but it still has the potential to cause a lot of monetary damage.
Insurers including MSIG, QBE, and Beazley are reviewing how their policy language applies to these scenarios and who bears responsibility when an agent’s autonomous actions cause damage.
For now, most of them are clarifying the parameters of their coverage rather than excluding AI events entirely.
QBE’s global head of cyber described AI as “a risk amplifier, not a fundamentally new cyber risk.” In other words, if an AI system causes something that looks like an ordinary covered breach, the involvement of AI probably won’t put it in a different category; it’ll still be covered.
The trickier cases involve an agent that works as designed but makes an expensive decision, or a systemic event in which a model or AI platform produces losses at many companies simultaneously.
The first type might be treated as professional liability, or errors and omissions, rather than a cyber incident. The second could, in theory at least, end up being too large for insurers to cover without strict limits in place.
Specialized products are already emerging. Armilla AI, Munich Re, and AXA XL sell coverage for risks including model underperformance, hallucinations, and intellectual-property claims. Whether these products remain separate or are eventually folded into broad cyber policies will depend in part on what sorts of claims insurers actually receive, and the scale of those claims.
Right now, they have very little historical data with which to calculate the price. Insurance is fundamentally a system for using past experience to account for future issues, and autonomous AI losses have almost no past; they’re a very new type of problem.
That said, the insurance industry has encountered ambiguity before.
For years, insurers worried about silent cyber: losses caused by digital events that appeared inside property, liability, and other policies that had never explicitly contemplated them. Lloyd’s gradually required policies to state whether cyber risks were covered or excluded.
There was also the question of attribution. In 2017, the NotPetya malware spread from Ukraine through corporate networks around the world. The US and several allies attributed it to the Russian military, but many victims were ordinary companies with no meaningful role in geopolitics.
Drugmaker Merck claimed about $1.4 billion in damages under its property policies. Insurers disputed roughly half of that amount using exclusions for hostile or warlike acts; language whose ancestry predates computers by more than a century.
New Jersey courts found that the exclusion required something closer to conventional military action, not a cyber bug gone haywire, and the case settled in January of 2024, just before the state Supreme Court was scheduled to hear it. Mondelez settled a parallel dispute with Zurich over a claim exceeding $100 million around the same time.
Lloyd’s subsequently required standalone cyber policies to address catastrophic state-backed attacks explicitly, including a method for resolving attribution. Agentic AI reopens both the silent-coverage and attribution problems simultaneously.
If a model causes a loss, responsibility might plausibly be assigned to the model developer, the company that deployed it, the vendor that built its evaluation environment, or the organization whose excessive permissions allowed the damage to spread.
In two of this summer’s three sets of incidents, a third-party evaluator’s misconfiguration helped create the path to the internet. In OpenAI’s case, the path involved vulnerabilities in OpenAI’s own infrastructure and then weaknesses at several outside services.
The most important insurance risk, though, may ultimately be technological and infrastructural aggregation.
The 2024 CrowdStrike outage demonstrated that a single faulty software update could interrupt airlines, banks, hospitals, and other organizations around the world without any malicious attacker.
Consider a future in which thousands of companies give access to agents built on a small number of frontier models. A flaw or unwanted behavior in one widely used model could cause problems for a large portion of an insurer’s entire customer base, all at once.
And this risk is arriving in the midst of an unusually competitive insurance market, after twelve quarters of declining rates and as loss ratios are beginning to rise. If insurers decide they cannot price the exposure, they will probably respond through some combination of higher prices, lower limits, stricter conditions, and exclusions.
All that in mind, the first thing to be watching in the coming months is policy language during the January 2027 renewal season.
The current posture, if you recall, is to clarify rather than exclude, but language addressing systemic AI events or dependence on a single model provider is already being discussed. A significant loss could change the market’s posture quickly, making it more limited and expensive.
The second thing to watch for is the first big, disputed claim.
Industry interviews can describe what insurers expect to cover, but their operational position will be established when an AI agent causes an eight-figure loss and a carrier must either pay or explain why it won’t.
The NotPetya disputes took years to resolve, and the first autonomous-agent case could similarly define policy language well before it produces a final court ruling. That’ll be a moment that maybe defines the next ten years of cyber insurance standards, if not longer.
The third thing to watch for is changes to insurance questionnaires.
Underwriters could begin asking whether agent credentials are narrowly scoped, whether actions are comprehensively logged, whether consequential decisions require human approval, whether agents have kill switches, and whether claimed containment has been verified rather than merely documented.
If these controls affect the price and availability of insurance, they could become industry standards faster than legislation makes them mandatory, just like that previous round of cyber insurance baselines that became common because, lacking them, customers could no longer get cyber insurance at any price.
And finally, there’s also a government process developing alongside the private one.
An executive order signed in June established a voluntary framework under which developers can provide the federal government with access to certain frontier models for up to 30 days before release. The process uses classified benchmarks to evaluate advanced cyber capabilities, and representatives from major AI companies discussed the framework at the White House in August of 2026.
If insurers eventually require evidence that a model or company participated in this sort of evaluation, a voluntary government program could evolve into a practical requirement without ever becoming an actual legal mandate.
This wouldn’t make insurance a perfect regulator. Insurers are accountable to their own balance sheets, not to the public as a whole, and they may respond to poorly understood risks by excluding them rather than making them safer, as has been the case with some types of weather disaster in areas that are becoming more prone to things like flooding and wildfires.
But insurance companies do have to convert uncertainty into prices, contractual language, and technical requirements, which makes some currently difficult to quantify things more quantifiable, at least monetarily.
The AI incidents this summer caused no reported material damage, which is one reason they’re getting relatively little coverage, despite being fairly meaningful events. The insurance industry sees these sorts of narratives through the lens of cost and risk, though, and this is a category of loss with no conventional attacker, no stolen credential, several plausible defendants, and almost no claims history, arriving at a moment in which companies are racing to give autonomous systems more access to all of their systems—a lot of valuable and potentially vulnerable infrastructure.
The people whose job is to price that risk haven’t decided what it costs, yet. And until they do, what they add to or remove from their application forms may be more consequential to the norms and expectations in this space than what the government mandates, on the matter.
Show Notes
https://www.businessinsurance.com/as-ai-agents-go-rogue-cyber-insurers-are-adapting-their-policies/
https://www.investing.com/news/stock-market-news/as-ai-agents-go-rogue-cyber-insurers-are-adapting-their-policies-4878768
https://openai.com/index/hugging-face-model-evaluation-security-incident/
https://openai.com/index/hugging-face-incident-and-the-road-ahead/
https://huggingface.co/blog/security-incident-july-2026
https://huggingface.co/blog/agent-intrusion-technical-timeline
https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
https://cyberunit.com/insights/ai-sandbox-escapes-three-labs-meta-anthropic-openai/
https://labs.cloudsecurityalliance.org/research/csa-research-note-frontier-ai-models-hacking-real-systems-ev/
https://techcrunch.com/2026/07/07/the-worst-hacks-and-breaches-of-2026-so-far/
https://blackkite.com/reports/2026-ransomware-report
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a
https://www.munichre.com/en/insights/cyber/cyber-insurance-risks-and-trends-2026.html
https://www.swissre.com/risk-knowledge/advancing-societal-benefits-digitalisation/about-cyber-insurance-market.html
https://www.marsh.com/en-gb/services/international-placement-services/insights/global-insurance-market-index.html
https://compyl.com/guides/cyber-insurance-readiness-guide/
https://www.aon.com/en/insights/articles/cyber-and-tech-e-and-o-market-report
https://www.cybersecuritydive.com/news/merck-settlement-notpetya-insurance/703922/
https://therecord.media/mondelez-and-zurich-reach-settlement-in-notpetya-cyberattack-insurance-suit
https://assets.lloyds.com/media/eb6de9ce-293b-4213-80f8-9dc69c45b1a9/Y5381%20Market%20Bulletin%20-%20Cyber-attack%20exclusions.pdf
https://www.whitehouse.gov/wp-content/uploads/2026/06/eo-14409.pdf
https://www.axios.com/2026/08/04/inside-trump-ai-framework
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit letsknowthings.substack.com/subscribe - This week we talk about money policies, yield curves, and government bonds.
We also discuss the Fed, the Treasury Department, and a WWII accord between them.
Recommended Book: Paved Paradise by Henry Grabar
Transcript
In April of 1942, a few months after the United States entered World War 2, the US Treasury Department asked the Federal Reserve to help it borrow a truly staggering amount of money, and as cheaply as possible. The Fed agreed, committing itself to holding short-term Treasury bill rates at three-eighths of 1%, while also capping the yield on long-term government bonds at 2.5%.
This was a type of yield curve control. Rather than allowing the market to decide how much interest the government would pay, the Fed decided that price and promised to enforce it.
That helped finance the war, because the Treasury knew its borrowing costs wouldn’t spiral out of control at a moment when it needed to spend unprecedented sums on ships, planes, weapons, soldiers, and all the other machinery of an ongoing global conflict.
The downside was that the Fed lost control of an important monetary policy lever.
Bond prices and yields move in opposite directions, so keeping yields below a certain level meant the Fed had to stand ready to buy bonds whenever their prices dropped. It couldn’t decide in advance how many it would buy, or how much money it would create in the process. The market would thus forth decide that, instead.
Consequently, the Fed became, in some ways, an extension of the Treasury’s debt-management operation, its inflation-related responsibilities made secondary to the government’s need for cheap financing.
That arrangement persisted after the war ended, despite the return of inflation, and President Harry Truman’s administration pushed to maintain it during the Korean War, as well.
Fed officials resisted, though, with inflation running at more than 8%, and after a very public, very contentious standoff, on March 4, 1951, the Treasury and the Fed announced that they had reached what became known as the Treasury-Fed Accord.
That agreement did not make the Fed independent all at once, but it established the principle underlying the modern relationship between these institutions: the Treasury manages government borrowing, while the Fed sets monetary policy based on inflation and employment, not on how much that policy costs the government.
The market, in other words, would once again be allowed to decide the price of long-term US debt.
What I’d like to talk about today is what happens when that price goes up, what’s pushing long-term US borrowing costs toward levels we haven’t seen in decades, and why two people appointed by the same president are pulling in opposite directions on this issue.
—
The Federal Reserve’s primary interest-rate lever is the federal funds rate, which is the overnight rate banks charge each other to borrow money. The Fed currently targets a range of 3.5 to 3.75 percent for that rate, and while it has other tools, this is the number people are usually talking about when they say the Fed raised, cut, or held rates.
The Fed does not directly set the yield on 10- or 30-year Treasuries, though.
Those securities are sold at auction and then traded in a huge secondary market, and their yields reflect a combination of what investors expect inflation to look like, where they think short-term rates will go over the life of the bond, and what’s called the term premium.
The term premium is basically extra compensation for uncertainty. If you lock up your money for 30 years instead of rolling over short-term debt, you accept the risk that inflation, growth, government policy, and other variables will change in ways that make your bond less valuable over that thirty year period. The more uncertain the future seems, the more compensation you’re likely to demand.
And again, when demand for a bond falls, its price falls and its yield rises. When we say yields are rising, that means borrowers have to offer investors, the people and institutions giving them the money they want to borrow, more money, more interest, to convince them to buy those bonds.
That doesn’t only affect the government. The 10-year Treasury serves as something like a reference rate for the entire economy, influencing mortgages, business loans, and the value of long-lived assets.
As of September 3 of 2026, the average US 30-year fixed mortgage rate was 6.71%, up from 6.5% a year earlier. That increase is the result of yield increases in the bond market.
Long-term Treasury yields have been climbing for much of 2026, and that climb accelerated over the summer.
The 30-year yield reached about 5.31 percent on August 17, its highest level since 2007. A few days earlier, the Treasury sold 30-year bonds at a yield of 5.216%, the highest borrowing cost at one of those auctions since 2001.
The 10-year yield briefly hit about 4.81% this past week, its highest level since early 2025, and ended Friday at about 4.78%. The two-year yield, which tends to track expectations about contemporary Fed policy more closely, ended at about 4.37%.
There isn’t one clean cut reason for these yield bumps. Instead, there are a bunch of forces pushing in roughly the same direction.
The first is government borrowing. The Congressional Budget Office now expects a roughly 2.1 trillion dollar federal deficit this fiscal year, which is 200 billion dollars more than it projected in February. Covering that gap means issuing more debt, and more supply generally means the Treasury has to offer a better return to attract enough buyers.
The second is competition from corporations, especially technology companies borrowing to build AI infrastructure and data centers.
The Dallas Fed estimates that AI-related investment-grade bond issuance—these companies borrowing money, in the form of bonds, to help build more data centers and other AI-enabling stuff—could total around $300 billion this year, creating long-duration debt equivalent to about an eighth of what the Treasury is expected to issue. Some of the companies selling this debt have extremely strong balance sheets and high credit ratings, so investors who want safe-ish, long-term bonds suddenly have a lot more options, and the US government has to compete with that for a finite pool of investor resources.
Third, oil prices have surged following renewed strikes and attacks around the Strait of Hormuz, with US benchmark prices recently climbing above $90 a barrel. More expensive energy can goose inflation across the economy, which makes locking in a fixed return for 10 or 30 years less appealing, because those yields might not keep up with the practical devaluation of the dollar.
Fourth, that aforementioned term premium has risen as investors ask to be paid more for uncertainty related to inflation, deficits, geopolitics, and future Treasury issuance.
And fifth, the pool of buyers is changing. Foreign investors still own trillions of dollars in Treasuries, but private foreign demand for notes and bonds fell sharply in June, even as corporate bonds attracted more of that finite sum of money.
A big shift we seem to be seeing here is that some investors seem to be judging Treasuries less as a bet on the next Fed meeting, and more as a long-term bet on whether the US political system can manage its finances. And that shift is showing up at an awkward moment for the two institutions involved in the 1951 Accord.
Kevin Warsh, who became Fed chair in May, used his August 28 speech at Jackson Hole to say that although inflation expectations remain anchored, the Fed still has work to do if underlying inflation is not moving toward its target quickly enough.
Markets read that as a warning that a rate hike could be coming, and the unexpectedly strong August jobs report reinforced that interpretation: employers added 162,000 jobs, far more than economists anticipated, while estimates for June and July were revised upward.
The Treasury Department, meanwhile, is moving in the opposite direction.
On August 19, Treasury Secretary Scott Bessent announced that the government would at least double the size of its long-term bond buybacks, from a maximum of 2 billion dollars to at least 4 billion dollars per operation, beginning September 9 and continuing through November 4.
The stated purpose is to improve liquidity, buying older, less frequently traded 10- to 30-year securities. But buying long-term bonds also reduces the supply available to investors, boosting prices and putting downward pressure on yields, which is why Bessent has referred to the approach as a “Treasury twist.”
The scale is small in the context of a $40 trillion national debt, and analysts have described it as more signal than substance. It is nonetheless a striking signal: one Trump appointee is telling markets that higher short-term rates may be necessary to control inflation, while another is using the Treasury’s balance sheet to push long-term rates in the other direction.
These jobs, which again, were separated in 1951, are working against each other. And this matters, first, because long-term government debt is the foundation upon which a lot of other prices are built.
When a 30-year Treasury yields more than 5%, companies refinancing debt have to pay more, commercial real estate becomes harder to finance, mortgages become more expensive, and investors have less reason to pay extremely high prices for stocks based on profits those companies might earn many years from now.
It also matters because interest on the federal debt has become one of the government’s largest expenses. Gross interest expense reached about $1.17 trillion during the first ten months of fiscal 2026, up about 15% from the same period last year. The somewhat narrower CBO measure of net interest reached $963 billion over that span, roughly level with Medicare spending and greater than defense spending.
This creates a potentially self-reinforcing loop: higher yields increase the cost of servicing the debt, higher interest costs expand the deficit, larger deficits require more borrowing, and more borrowing can put further upward pressure on yields.
Economists use the term fiscal dominance to describe the point at which government financing needs start to constrain monetary policy, pushing the central bank to keep rates lower than it otherwise would, or to buy government debt, even if doing so undermines its effort to control inflation.
The US is not necessarily at that point, but this is exactly the kind of pressure the 1951 Accord was meant to prevent.
As with everything government money-related, there’s also a global dimension to this shift.
For decades, Japanese banks, insurers, pension funds, and other institutions bought foreign bonds in part because yields at home were so low. On September 1, though, Japan’s 10-year government bond yield touched 3% for the first time since 1996.
Japan’s government has more debt relative to the size of its economy than any other wealthy country, and it assumed a 3% long-term rate when calculating debt-service costs for its current budget. Rising above that level would strain its finances, but those higher yields also give Japanese investors more reason to keep their money at home.
That doesn’t mean Japanese institutions will dump all their Treasuries. Currency-hedging costs and the specific needs of different investors complicate that calculation. But when a major source of relatively steady demand becomes more price-sensitive, the marginal buyer of US debt has to be paid more to invest.
Finally, the Treasury market itself has become somewhat more fragile.
The amount of debt in circulation has grown far faster than the balance sheets of the dealers that traditionally absorb buying and selling. Hedge funds have filled some of that gap using highly leveraged strategies, including something called the cash-futures basis trade.
Fed researchers estimate that these positions reached about $830 billion by September 2025, representing 35% of hedge funds’ long Treasury exposure. These trades can provide useful liquidity when markets are calm, but because they rely on enormous amounts of borrowed money to capture tiny price differences, they can also unwind pretty quickly when volatility spikes.
That sort of unwind contributed to the Treasury-market seizure in March of 2020, and a different leveraged hedge-fund strategy added to turbulence in April of 2025.
The assets treated as the world’s safest and most liquid can still become difficult to sell when everyone needs cash at the same time, in other words.
The next few weeks should partially clarify what’s actually driving this unusual market.
The expanded Treasury buybacks begin the day after this episode goes live, September 9. Producer-price inflation data arrives on September 10, consumer-price data on September 11, and the Fed meets on September 15 and 16. The Bank of Japan follows on September 17 and 18, when it may increase its policy rate from 1% to around 1.25%.
If the Fed hikes and long-term yields fall, that could indicate investors view the move as credible inflation-fighting: short-term borrowing becomes more expensive, but the term premium shrinks because the distant future seems less inflationary.
If the Fed holds after a soft inflation report and short-term yields fall while the 30-year barely moves, that would suggest the long end is being driven by deficits, debt supply, oil prices, corporate competition, and global demand more than Fed policy.
And if the buybacks begin but long-term yields continue to climb, that would demonstrate the limits of debt-management policy in a market this large. The Treasury could respond by issuing more short-term and less long-term debt, reducing immediate borrowing costs, though that would also mean refinancing more frequently and taking on the risk that rates remain high.
It could also draw down some of the around $950 billion in its account at the Fed to fund larger buybacks, but that cash also serves as a buffer against the debt ceiling, which the government is currently expected to reach sometime in 2027. Spending the buffer now would mean rebuilding it later, and rebuilding it would require issuing even more debt.
Back in 1951, the Treasury and the Fed reached an agreement that the central bank should not be required to make government borrowing cheap, and that the price of long-term debt should be allowed to reflect what the market believed that debt was worth.
Right now, the market is rendering its verdict, and that verdict is that lending the United States money for 30 years has become substantially more expensive. Now we wait to see what Washington decides to do about it.
Show Notes
https://www.federalreservehistory.org/essays/treasury-fed-accord
https://www.brookings.edu/articles/what-is-the-treasury-fed-accord-of-1951-and-why-is-it-important/
https://www.federalreserve.gov/data/three-factor-nominal-term-structure-model.htm
https://www.freddiemac.com/pmms
https://www.cbo.gov/publication/61983
https://fiscaldata.treasury.gov/datasets/interest-expense-on-the-public-debt-outstanding/interest-expense-on-the-public-debt-outstanding
https://fiscaldata.treasury.gov/datasets/debt-to-the-penny/debt-to-the-penny
https://www.dallasfed.org/research/economics/2026/0210-searls-aifinancing
https://home.treasury.gov/news/press-releases/sb0606
https://home.treasury.gov/news/press-releases/sb0607
https://www.federalreserve.gov/newsevents/speech/warsh20260828a.htm
https://www.bls.gov/news.release/empsit.htm
https://apnews.com/article/1af16359af43eb8abc66445465f633c8
https://apnews.com/article/775d7cf741349c7c8e689c0beb57f074
https://apnews.com/article/a27a8d3651ff810b25c610d3e1b6259d
https://www.federalreserve.gov/econres/notes/feds-notes/decomposing-hedge-funds-u-s-treasury-exposures-20260622.html
https://www.imf.org/en/publications/fandd/issues/2026/03/safeguarding-the-treasury-market-jeremy-stein
https://www.investing.com/news/economy-news/japans-benchmark-bond-yield-rises-to-3-for-first-time-in-30-years-4883532
https://www.boj.or.jp/en/mopo/mpmsche_minu/index.htm
https://bipartisanpolicy.org/article/when-will-we-reach-the-debt-limit-again/
https://home.treasury.gov/policy-issues/financing-the-government/quarterly-refunding/most-recent-quarterly-refunding-documents/
https://www.federalreserve.gov/monetarypolicy/fomccalendars.htm
https://www.bls.gov/schedule/2026/09_sched.htm
https://www.axios.com/newsletters/axios-markets-a975877a-ddce-4ea0-a735-4b460d37af90.html
https://www.ft.com/content/c96c25c1-b27c-4c08-a2ba-21821b39dd78
https://www.axios.com/2026/08/19/rates-treasury-borrowing-bessent
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit letsknowthings.substack.com/subscribe - This week we talk about peaker plants, blackouts, and at-home battery backups.
We also discuss energy resiliency, solar panels, and hydro.
Recommended Book: The Tainted Cup by Robert Jackson Bennett
Transcript
Peaking power plants, often just called peaker plants, are power plants that are turned on only during periods of high energy demand. That’s in contrast to a baseload power plant, which operates more or less 24/7 to ensure there’s a steady amount of electricity available on the local power grid.
The need for peak-load energy varies depending on the time of year and which part of the world you’re looking at. In general, though, energy demand tends to increase in the morning and evening because of temperature fluctuations and lifestyle rhythms.
People are at home in the morning and return from work in the evening, at which point they turn on their ACs or heaters, TVs, lights, electric kettles, and video game consoles. That leads to an irregular surge in demand compared with the steady office and factory demand met throughout the day by the baseload power plant.
When energy demand peaks, approaching or exceeding what the baseload plant can reliably provide, the peaker plant is spun up and more energy is added to the grid. This helps avoid brownouts and blackouts, situations in which people lose access to power because there isn’t enough to go around.
This also helps stabilize energy prices. In most countries, pricing is used to manage scarce energy resources, so as a grid approaches the point where it’s running out of available electricity, prices rise to incentivize less energy use. Peaker plants keep those prices from going sky-high by increasing the supply, preventing demand from pushing prices into absolutely ridiculous territory.
Some peaker plants operate for a handful of hours basically every day. This is especially true in places with extreme temperature fluctuations, or in areas where the population or manufacturing activity has increased rapidly and the local infrastructure hasn’t caught up. In those places, the backup plant is used more regularly because the baseload supply hasn’t yet increased to meet that new, consistently higher demand.
Peaker plants are often less efficient to run because they aren’t meant to be used all the time. Consequently, if the baseload power plant isn’t capable of providing enough energy for a region on a regular basis, electricity can get much more expensive for everyone, all the time. A power plant intended for occasional use is instead operating constantly, and it wasn’t built to be efficient. It was built to come online quickly and operate only during periods of irregular, excessive need.
What I’d like to talk about today is an alternative to peaker plants that was conceived of decades ago, but which has only recently started to be deployed at scale in some areas.
—
As I mentioned in the intro, a peaker power plant is meant to be turned on irregularly to meet above-average energy needs. Those periodic pops in demand are accounted for, and peaker plants are built specifically to meet them. As a result, these plants are typically more expensive and often more polluting than baseload plants, with many using natural gas or coal to produce extra electricity for the grid.
In the late 1990s, researchers proposed that it might someday be possible to link energy-production and storage sites together, creating a more flexible grid system they called a virtual power plant. Further research in the early 2000s expanded on the concept, looking specifically at renewable-energy options and how they might be aggregated into a similar virtual-power-plant setup.
The basic idea is to recreate the effect of a peaker plant—adding electricity to the power grid when it’s most needed—by aggregating power-generating or storage assets and tapping them only when necessary.
Software manages that aggregation of smaller assets, ensuring the additional energy reaches the grid when it’s needed and at the necessary scale. Managing these assets in this way allows smaller production and storage infrastructure to recreate the impact of a larger peaker plant.
A German energy company called RWE launched the first real-world virtual power plant in 2008, linking nine of its hydroelectric plants into a virtual 8.6 MW unit whose output could be managed and deployed remotely. A few years later, in 2011, a Swiss energy company called Kraftwerke did the same with a slew of biogas, solar, and wind-power infrastructure scattered across seven countries.
The concept expanded to include demand-side residential energy assets in 2016, when the Australian city of Adelaide enacted a program backed by the Australian Renewable Energy Agency. The program deployed 1,000 battery systems to homes and businesses across the city. Those battery systems were hooked up to solar panels, and the software managing the batteries allowed their stored energy to act like a 5 MW peaker plant.
Tesla then applied the same general idea across South Australia, where energy prices had long been volatile, beginning in 2018. That program reached 50,000 homes by 2022. It was acquired by an energy company called AGL in 2025, which expanded it further until the virtual power plant had a capacity of 25 MW of peaker solar energy and 37 MW of battery-stored peaker energy.
Now, again, there’s a certain amount of energy available on the grid from standard baseload production sources, including traditional coal- and gas-fired power plants, hydroelectric plants, and nuclear power plants.
Solar and wind arrays also contribute to the baseline energy load in some parts of the world. That baseline can be augmented by utility-scale battery facilities that store excess wind and solar production. This makes renewables more reliable as baseload options because excess energy generated during the day or during especially windy periods can be stored in those batteries and used later, at night or when the wind isn’t blowing as hard.
A VPP addresses periods when the available baseload supply doesn’t measure up to current demand. When temperatures are especially high and everyone is using their air conditioners more, and a gas plant or solar array can’t provide enough electricity to meet demand, the company operating the virtual power plant can draw energy from scattered resources to cover that additional use.
In some cases, that means pooling energy generated by small hydroelectric dams. In others, it means drawing a previously agreed-upon amount or percentage of energy from a homeowner’s battery backup.
Maybe they have a battery that stores excess electricity from their solar panels, which they can use at night. They might also have an agreement with the VPP operator allowing it to draw a certain amount of energy from that battery when necessary, adding it to the grid to ease excessive demand.
This kind of agreement is often beneficial for the homeowner sharing some of their excess energy with the grid to help prevent blackouts and excessively high prices. The cost of the battery installation and hardware might be subsidized, or they might make a small amount of money every time that energy is borrowed.
There are also variations on this model that provide the homeowner or renter with a fancy thermostat. During periods of high demand, the thermostat might automatically adjust the AC by a degree or two when the grid is being crushed by demand on crazy-hot days. This ensures there’s enough energy to go around by reducing demand rather than increasing supply.
Some models also use energy-pricing arbitrage, automatically selling stored energy when electricity is expensive and buying it back when electricity is cheap. This helps balance the grid’s overall energy load by contributing to it when energy is scarce and expensive, then restoring that energy to the battery when it is abundant and cheap.
Increasingly, these systems tap into other resources connected to the grid to reduce demand or increase supply. They might borrow some energy stored in a homeowner’s electric vehicle, for instance, which has been left plugged in to charge but can also act as another, quite large, household battery. Or they might reduce the power being sent to heat pumps or water heaters.
Each of these devices or other assets is treated as part of the larger virtual power plant, which may be composed of thousands or tens of thousands of homes and all their connected assets. This helps manage supply and demand so that blackouts and dramatically higher energy prices are less likely, even on days with bizarre weather or when larger energy assets, like power plants, aren’t operating at full capacity.
This is a huge win for resiliency, and it’s also often much cheaper than installing and operating a peaker plant, usually around 40–60% cheaper.
These systems can also be installed and activated much faster than a full-on power plant, while dramatically reducing the amount of land used for energy infrastructure and the bureaucracy that has to be traversed to get something like a power plant or solar array installed and operating.
Those big chunks of infrastructure can take years or decades to bring online, while a VPP can often be up and running within just a few months. It usually requires no new land and no new interconnections in terms of cables or whatnot. It uses infrastructure that’s already there in most cases, though it can also be strengthened by deploying assets, like household batteries, that are useful to the homeowner for other reasons. Kind of a win-win.
At the moment, virtual-power-plant capacity is limited primarily by regulatory approval, at least in most countries. Energy utilities don’t have much incentive to move these systems forward because they get paid for building and managing traditional power assets, and VPPs are not that.
Sometimes an energy company will run this type of program, but usually only if it gets to sell the hardware and is paid to manage the software that keeps everything running smoothly. Household batteries and similar assets otherwise represent competition, so utilities are less inclined to allow these systems to move forward or even be legally installed without a fight.
That said, the major players in the VPP space right now are Sunrun, Tesla, Renew Home, Uplight, Next Kraftwerke, and sonnen. The latter is the largest VPP operator in Europe and has recently been expanding into the US, especially in Utah.
Most VPP deployment in the US is happening in California, Texas, Florida, and Puerto Rico. These systems are also being deployed across South Australia, Germany, and China, where the first gigawatt-scale residential VPP, which aggregates air conditioners and water heaters across millions of households, has been launched.
This category of energy technology has rolled out more slowly than originally anticipated. When the early models were deployed in Europe, their outcomes were considered broadly beneficial, but expansion was hindered by regulations—paperwork, basically—and pushback from existing utilities that didn’t want the competition.
VPPs were also bundled with other renewable-energy infrastructure and consequently faced substantial opposition in the US, in particular, during both Trump administrations. Those administrations pulled support for renewables across the board and, in some cases, actively tried to kill these industries to make even more room for oil and gas companies.
In 2025 and so far in 2026, though, the blazing-fast deployment of data centers has brought VPPs back into the conversation. Data centers require a silly amount of energy to run, and power grids in the areas where they’re being built have been strained as a consequence, dramatically increasing energy prices.
VPPs won’t solve that problem, but they could ease it in several ways. They can temper energy use and make more electricity available during periods of peak demand without requiring the construction of expensive power plants that might not come online for years or even a decade.
They could also reframe the use of VPPs so that they’re no longer seen primarily as environmental efforts, but as economically viable means of addressing data-center-created energy shortfalls. That could lead to more VPP build-outs because these systems would no longer be such obvious targets for anti-renewable-energy legislation and politics.
Show Notes
https://en.wikipedia.org/wiki/Peaking_power_plant
https://en.wikipedia.org/wiki/Virtual_power_plant
https://www.sciencedirect.com/science/article/pii/S2211467X2400097X
https://www.theguardian.com/environment/2016/aug/05/adelaide-charges-ahead-with-worlds-largest-virtual-power-plant
https://www.nrg.com/insights/energy-education/understanding-virtual-power-plants--a-guide-to-vpps.html
https://techcrunch.com/2026/08/19/home-batteries-are-suddenly-cheap-and-everywhere-heres-why/
https://pv-magazine-usa.com/2026/08/13/tesla-unveils-zero-down-powerwall-lease-program-with-retail-electric-plan-in-texas-touts-global-vpp-potential/
https://www.energy-storage.news/base-power-launches-100mw-vpp-programme-in-texas/
https://www.ess-news.com/2026/02/12/texas-lands-its-first-battery-only-virtual-power-plant/
https://nuwattenergy.com/en/virtual-power-plants-2026
https://www.ess-news.com/2026/06/25/sunrun-tesla-renew-home-announce-plans-for-16-8-gw-virtual-power-plant-program/
https://www.sciencedirect.com/science/article/pii/S2352484725003865
https://www.cleanenergywire.org/news/start-next-kraftwerkes-renewable-virtual-power-plant-stabilises-grid
https://www.energy.gov/edf/virtual-power-plants-projects
https://www.woodmac.com/press-releases/virtual-power-plant-capacity-expands-13.7-year-over-year-to-reach-37.5-gw
https://www.utilitydive.com/news/in-2026-virtual-power-plants-must-scale-or-risk-being-left-behind/810321/
https://ieefa.org/resources/case-virtual-power-plants
https://uplight.com/blog/virtual-power-plants-are-powering-the-grid-of-the-future-and-uplight-is-leading-the-way/
https://sepapower.org/knowledge/vpp-and-supporting-der-policy-developments-q1-2026/
https://www.energymining.sa.gov.au/consumers/solar-and-batteries/south-australias-virtual-power-plant
https://whatisavpp.com/research/topics/enpal-flexa/
https://www.canarymedia.com/articles/virtual-power-plants/rooftop-solar-industry-trump-budget-law
https://foleyhoag.com/news-and-insights/blogs/energy-and-climate-counsel/2026/july/virtual-power-plants-the-distributed-energy-revolution-has-arrived/
https://ieefa.org/resources/case-virtual-power-plants
https://sepapower.org/knowledge/vpp-and-supporting-der-policy-developments-q1-2026/
https://www.cesa.org/resource-library/resource/puerto-rico-virtual-power-plant/
https://www.energy.gov/edf/virtual-power-plants-projects
https://www.energymining.sa.gov.au/consumers/solar-and-batteries/south-australias-virtual-power-plant
https://www.ess-news.com/2025/01/16/china-launches-work-on-its-first-gw-scale-residential-virtual-power-plant/
https://www.ferc.gov/ferc-order-no-2222-explainer-facilitating-participation-electricity-markets-distributed-energy
https://www.utilitydive.com/news/in-2026-virtual-power-plants-must-scale-or-risk-being-left-behind/810321/
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit letsknowthings.substack.com/subscribe
More News podcasts
Trending News podcasts
About Let's Know Things
A calm, non-shouty, non-polemical, weekly news analysis podcast for folks of all stripes and leanings who want to know more about what's happening in the world around them. Hosted by analytic journalist Colin Wright since 2016. letsknowthings.substack.com
Podcast websiteListen to Let's Know Things, The Rest Is Politics and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Let's Know Things
Scan code,
download the app,
start listening.
download the app,
start listening.
Let's Know Things: Podcasts in Family




























