Chapter 6.9
In this chapter · 7 sections
Environment, Health & Safety (EHS) Across Build & Operate
The decisions that raise density and goodput — 800 VDC, liquid loops, on-site gas, maintenance beside live equipment — each put a worker one mistake from a fatality that a continuously-run EHS program must prevent.
What you'll decide here
- Whether arc-flash and DC-shock are run as a one-time engineering study or as a governed, re-validated EHS program with a labeled equipment register, an energized-work permit, and a periodic review and change trigger tied to every power-chain change.
- How the LOTO program is written for a concurrently-maintainable operating facility in which planned isolation remains the normal work basis and energized work is an engineered exception — group vs individual locks, the back-feed and stored-energy boundaries, and who owns the permit when the IT load cannot drop.
- Your coolant chemistry's full EHS envelope before you commit a cooling modality — PG25/glycol vs single-phase dielectric vs named two-phase fluorinated fluids with supplier-specific qualification and PFAS exposure — because the spill-response, exposure-control, and disposal program is a consequence of that choice, not an afterthought.
- Whether high-voltage work at the customer-owned substation and HV yard is performed by an in-house qualified-worker program or contracted to the utility/an HV specialist, and where the qualified-worker boundary sits relative to the 4.3 interface.
- For sites with on-site gas generation or fuel storage, whether a documented covered-process, chemical/flammable threshold, connectivity and exemption analysis establishes OSHA Process Safety Management applicability — and if so, that the 14 PSM elements are stood up before first fuel, not after first incident.
Every preceding chapter in Part 6 designed a hazard into the building. Chapter 6.2 screened an assumed 3,000–3,300 lb wet-rack range on the slab; Chapter 6.5 put lithium BESS in rooms with their own detection, cooling, and deflagration venting; Chapter 6.7 set the rigging paths those racks travel; Chapter 6.8 wrapped acoustic enclosures around gensets running on stored fuel. This is where those hazards stop being lines on a drawing and become things that can kill or maim a human being — and where the discipline shifts from engineering a margin to operating a program. An arc-flash study is a deliverable; an arc-flash program is a labeled equipment register, an energized-work permit system, a PPE-to-incident-energy mapping, and a re-study trigger that fires every time someone changes a breaker setting. The first protects you on the day it is signed. Only the second protects the worker who opens a switchgear door three years later.
The reason EHS earns a full chapter in 2026 — rather than a paragraph in a code-compliance appendix — is that the AI build changed the hazard profile faster than the safety programs around it adapted. The move to 800 VDC distribution (Chapter 4.7) adds lethal contact-voltage shock to a DC-bus hazard that already demanded tool control and arc protection at 48 V. The move to direct-to-chip liquid (Chapter 5.4) puts pressurized glycol and dielectric fluids inside the same enclosure as energized electronics. The move to on-site gas generation (Chapter 4.8/4.9) drops a small power plant — with its own combustible-gas and process-safety regime — onto a data-center campus whose EHS staff were trained for IT, not for turbines. And the move to concurrently maintainable facilities, with the maintained equipment de-energized (Chapter 12.1) means the workforce now maintains an operating building under planned isolation and controlled work conditions; energized work remains an engineered exception under the applicable electrical-safety program. Each of those is a goodput or density decision elsewhere in this guide; each lands here as a named, managed hazard.
Arc-flash and DC-shock as a managed program, not a design margin
The most common and most dangerous EHS failure in a data center is treating the arc-flash study as a one-and-done engineering artifact. The study computes, at every piece of equipment, the incident energy (in cal/cm²) a worker would absorb in an arcing fault, the resulting arc-flash boundary (the distance at which incident energy falls to 1.2 cal/cm² — the onset of a second-degree burn), and the arc-rated PPE required inside it. That study is valid only for the protective-device settings, fault currents, and one-line topology that existed the day it was run. The instant someone re-coordinates a relay, swaps a transformer, adds a UPS module, or energizes a new feeder, the incident energy at downstream gear can move — and the label on the door, the PPE in the cabinet, and the worker's mental model are now wrong. NFPA 70E (2024), 130.5(G), requires accuracy review within five years and an update for system changes that can affect the analysis; the program turns that requirement into a trigger wired to your management-of-change process, so no power-chain modification closes out until the arc-flash impact is re-evaluated. The current edition is 70E-2027 (issued 2026-04-16, effective 2026-05-06), and its most operationally consequential change is new 130.2(A)(2): when an Energized Electrical Work Permit is required and the task uses shock or arc-flash PPE, at least one additional emergency-response-trained person must be present, stationed outside the greater of the limited-approach or arc-flash boundary — a staffing line-item for every live-adjacent fit-out and IST task, and a staffing gap at that boundary is a stop-work condition. The edition the employer’s electrical-safety program adopts is the operative one. The 2027 edition also adds dedicated DC-hazard coverage (new Article 310), though it is still not an 800 VDC design standard.
The 2026 wrinkle is that AC arc-flash intuition does not transfer to the 800 VDC world the dense racks are driving toward. A DC arc has no current zero-crossing — in a 60 Hz AC system the current passes through zero 120 times a second, which helps a breaker extinguish the arc; a DC arc can persist while its source and gap sustain it; rated protective interruption must clear the fault. That makes DC arcs harder to clear and DC arc-flash energies harder to bound with the AC-derived IEEE 1584 model that most studies still lean on. The shock side is starker still, but it runs opposite the arc/thermal side at 48 V. Under US 29 CFR 1910.333(a)(1), the below-50-V-to-ground de-energization exception also requires no increased electrical-burn or arc-explosion exposure. Use the selected rack’s actual voltage; NVIDIA’s cited DGX GB power shelves are nominally 50–51 VDC. Either way a conductive dropped tool across the NVL72's paired busbars meets a stiff parallel supply: the bars feed roughly 2,800 A of aggregate load, while the bolted-fault current is far higher (Chapter 7.13). Arc exposure is quantified from available fault current, clearing time, working distance, and task; PPE follows the study. At 800 VDC, Ohm's-law screening at an illustrative 1,000 Ω body resistance gives about 800 mA; actual current and injury depend on contact impedance, path and duration, while the absence of a current zero-crossing makes the DC arc harder to clear. The voltage step that Chapter 4.7 justified on efficiency grounds therefore adds a lethal shock regime; it does not create the need for arc discipline, because the 48 V bus already had it.
| System / class | Dominant hazard | Shock threshold posture | Incident-energy-analysis method | PPE-category method | Program control that matters most |
|---|---|---|---|---|---|
| 48 VDC legacy IT bus | Low contact-voltage shock risk; severe arc/thermal-burn exposure at high current | Below the 50 V threshold only if the selected rack's nominal output is — NVIDIA's GB power shelves are 50–51 VDC; low shock risk does not cap arc energy | Calculate from DC fault current and clearing time; select arc-rated PPE from the result | Outside the 2024 DC category table’s >150–600 V range; select PPE through analysis | Guard or cover busbars, control conductive tools, and wear study-selected arc-rated PPE |
| 415/480 VAC distribution | Arc-flash burns; shock | Approach boundaries from the 70E AC table — which starts at 50 V, not 100 V; insulated tools/gloves | Use calculated incident energy and working distance; label equipment and select an arc rating above the result | Use the applicable AC task/equipment row and every stated condition | 2024 basis: review within 5 years; update for result-affecting changes |
| 800 VDC rack/row distribution | Electrocution + sustained DC arc | Illustrative I=V/R: about 800 mA at 1,000 Ω; actual current and injury depend on impedance, path and duration; DC-specific approach boundaries | Use DC-specific engineering analysis; select DC-rated PPE from the result | Outside the 2024 DC category table’s voltage range; use incident-energy analysis | Re-baselined DC electrical-safety program before first energization |
| Medium-voltage feeders (15–35 kV) | High incident energy; reach-in arc-flash | MV-qualified approach; barriers and remote racking | Calculate at the working distance; prefer remote operation where exposure outruns the PPE strategy | Use only within the table's voltage and equipment scope; otherwise use analysis | Remote racking and switching to keep workers outside the boundary |
| HV yard / substation (≥69 kV) | Flashover, induced voltage, step-and-touch potential | Utility-grade clearances; ground-grid step/touch limits | Use task-specific engineering analysis and live-line rules; de-energized or remote work preferred | Outside the category-table method at this voltage class | Qualified HV-worker program + the 4.3 ownership boundary |
At every voltage class the thing that protects the worker is not the PPE in the cabinet but the program control that keeps the study, the labels, and the human's training synchronized with the as-built power chain. Workers can mistake a nominal 48 V bus for low total risk even though conductive tools can bridge its high-current conductors. Keep tool control and study-selected arc-rated PPE in the task plan; carry the low-risk habit to 800 V and the error also includes electrocution. → the voltage architecture itself is set in Chapter 4.7; the resilience model that requires isolating the maintained component while the other paths keep carrying load is Chapter 12.1.
Scope & caveats
Specific DGX GB200 configuration. Nominal output is not the task voltage-to-ground measurement and does not establish a general low-voltage exception.
LOTO in a facility that is never fully off
Lockout/tagout is the bedrock control for working on equipment that could energize or move unexpectedly: isolate the energy source, lock it in the safe state, tag it, and verify zero-energy before a hand goes near it. In a conventional plant you can often de-energize a whole system to work on it. In a concurrently-maintainable AI data center you normally isolate the maintained equipment while another path serves IT — the Tier III/IV site-infrastructure premise is that required capacity components and distribution paths can be removed for planned maintenance while the IT load keeps running (Chapter 12.1). That is a feature for uptime and a trap for LOTO, because the worker is now isolating one leg of a system whose other legs are deliberately, continuously live. The boundaries that LOTO must draw — back-feed from a parallel UPS or genset, stored energy in capacitor banks and DC buses, the closed-transition path that could re-energize an 'isolated' bus during an automatic transfer — are exactly the boundaries that concurrent maintainability is engineered to keep hot.
The program consequence is that generic LOTO procedures are not safe here; the facility needs equipment-specific energy-control procedures for every maintainable boundary, written against the actual one-line and the actual transfer logic, naming every isolation point and every stored-energy source. The split is organizational: individual LOTO (each worker applies their own lock) is unambiguous but does not scale to multi-trade work on a large lineup; group LOTO (a lockbox holds the isolation, each worker adds a personal lock to the box) scales but introduces a single authorized-person accountability that, done loosely, becomes the failure mode in the incident report. And because the IT load cannot drop, the highest-consequence question — who owns the permit, and who has the authority to refuse the work when isolating a component would violate concurrent maintainability — has to be answered in writing before the first live job, not negotiated on the floor at 2 a.m.
The pump disconnect misses a separately fed control circuit
Trace every way the task can acquire energy. The motor’s main feed reaches the drive; the DC link can remain charged after that feed opens; the separate control supply reaches the terminal enclosure; and the water branch can retain pressure or drain under gravity after its valves close. The listed drive disconnect interrupts only one of those paths. Reject the task boundary and keep pump removal on HOLD, even if the BMS says “off” and the IT load is running normally.
The electrical qualified person and mechanical authorized person revise one coordinated isolation: identify and control both electrical supplies, follow the drive’s discharge procedure, verify absence of hazardous voltage at the work boundary with suitable test equipment, and prove the tester by the applicable procedure. Isolate, depressurize and drain the water branch, prevent reaccumulation, secure moving parts, and apply the personal/group-lock arrangement to every exposed worker. Only then can the accountable work controller release the removal. Operations accepts the temporary loss of redundancy; it cannot trade that risk for an unverified energy state.
Flip case: the work becomes eligible when every source reaching the task is identified, controlled and verified; discovery of even one omitted source reverses release. A 24 V control supply can initiate motion or bridge a hazardous boundary, so its label does not settle the task. OSHA 1910.333(b)(2)(ii)–(iv) supplies the electrical de-energization and verification basis; the mechanical energy-control program follows 1910.147(d)(5)–(6) and (f)(3) where applicable. This chapter owns work authorization; Chapter 5.13 defines the hydraulic boundary and Chapter 14.12 carries the maintenance/retest handoff.
Confined space, work at height, and heavy rigging
The mechanical hazards of the build and operate phases are ordinary, which is exactly why they kill people: the program fails through familiarity, not novelty. Falls remain the single leading cause of death in construction: of 1,034 construction fatalities in 2024, 389 were fatal falls, slips, and trips; fall-protection enforcement is another reason to retain the controls under schedule pressure. A data-center build is a fall-rich environment — open structural steel, elevated pipe racks for the facility water loop, rooftop heat-rejection plant, mezzanines for electrical gear — and the controls (guardrails, personal fall-arrest, controlled-access zones, a competent-person inspection regime) are well understood and routinely skipped under schedule pressure. The EHS program's job is not to invent new controls; it is to make the known controls non-negotiable on a critical-path schedule that is screaming for speed-to-power.
Confined spaces proliferate in the AI build in ways the IT-trained operator may not anticipate: large CDU and tank interiors, the inside of thermal-storage and chilled-water reservoirs, deep electrical vaults and cable trenches, and the let-down/scrubbing vessels on a gas-conditioning skid (Chapter 4.9). Each space must be evaluated against the jurisdiction's confined-space definition and hazards; only a space meeting the applicable criteria is permit-required. Where entry is permit-required, controls include atmospheric testing as applicable, an attendant and a site-specific rescue plan. The statistic that should anchor the program: a large share of confined-space deaths are would-be rescuers who entered an untested space to save a downed coworker. The rescue plan is the deliverable that prevents one fatality from becoming two or three. Heavy rigging closes the set — multi-tonne transformers, chillers, prefab power/cooling modules (Chapter 6.4), and the guide-assumed 3,000–3,300 lb wet-rack screening range carried into Chapter 6.7 — where the controls are engineered lift plans, certified rigging gear, exclusion zones under suspended loads, and qualified signal/rigger roles. The rigging path defined for civil reasons in Chapter 6.7 is, on this ledger, a struck-by and crush-hazard corridor that the EHS plan has to own.
| Task | Required control evidence | Hold trigger |
|---|---|---|
| Excavation / trench | Utility locate, protective system, access and competent-person inspection | Unresolved utility, water or protective-system condition |
| Concrete cutting / drilling | Applicable silica control method, exposure assessment and respiratory program where required | Uncontrolled dust or unapproved method |
| Hot work near operating plant | Combustible control, fire permit and impairment coordination | Unprotected combustible path or affected live fire system |
| Roof / lifting work | Weather limit, fall protection, lift plan and rescue arrangement | Condition outside the approved envelope |
| Heat / noise exposure | Task exposure plan, engineering controls and worker monitoring | Symptoms, control failure or exceeded action threshold |
Coolant, glycol, dielectric, PFAS: the chemistry is an EHS decision
Liquid cooling did not just change the thermal design — it introduced a chemical-handling program where air-cooled halls had none. The coolant chemistry you select in Chapter 5.4–5.5 carries its EHS envelope with it, and that envelope — exposure controls, spill response, disposal, and regulatory liability — is a consequence of the cooling fork, not a separable add-on. Three families dominate, and they sit at very different points on the hazard map.
Propylene-glycol/water (PG25 and relatives) is the workhorse single-phase direct-to-chip coolant. Its acute toxicity is low (propylene glycol is far less toxic than ethylene glycol, which is why the industry standardized on it), so the dominant hazards are physical: it is conductive enough that a leak onto energized 800 VDC electronics is a fault and shock risk, it is slip and slick on the floor, and at scale a spill is an environmental-reporting event and a disposal stream. Single-phase dielectric fluids (synthetic or hydrocarbon) trade the conductivity problem away — an uncontaminated fluid’s specified dielectric performance can reduce leakage-current risk, but moisture, particles and hot surfaces must remain inside its qualification envelope — but reintroduce flammability/combustibility classification, vapor and dermal-exposure considerations, and a heavier disposal burden. Two-phase fluorinated fluids (the PFAS family) were, until recently, the high-performance immersion answer — and they are this section's cautionary tale.
Whatever the chemistry, the operate-phase program is the same skeleton: a maintained SDS library and chemical inventory; exposure controls and PPE matched to the fluid; secondary containment and spill kits staged at the loops; a spill-response procedure matched to the adopted NFPA 75 edition and the selected liquid-cooled equipment — including the de-energization sequence for a conductive-coolant leak onto live gear; and a disposal/recycling stream with the manifesting and reporting the local regime demands. You are choosing this program when you choose the coolant — so price the spill, exposure, and end-of-life liability into the cooling fork rather than discovering it on the floor.
Scope & caveats
The boundary criterion is 1.2 cal/cm². It is not a PPE-category assignment; incident-energy and category methods are alternatives for a given item.
Scope & caveats
Illustrative Ohm’s-law arithmetic at an assumed 1,000 Ω; potentially fatal exposure, not a prediction of current through a person, an injury threshold, a DC arc model or permission for exposed work. The source’s protective-grounding context does not become a rack-maintenance procedure.
Scope & caveats
Edition dates from NFPA; the edition the employer’s electrical-safety program adopts, and the AHJ enforces, is the operative one.
Scope & caveats
Historical 2024 edition: review incident-energy analysis for accuracy at intervals not exceeding five years; update it for electrical-distribution changes that can affect its results. Select the employer’s governing edition before adopting the program.
Scope & caveats
Reported forecast estimate, not a measured deployment census or a project cooling-selection rule. The cited PMR cold-plate category is broader than single-phase DTC.
Reported forecast estimate, not measured fleet share; PMR's published cold-plate category is broader than single-phase DTC and is not a project-selection rule.
High-voltage qualified-worker programs and the HV-yard interface
When a campus owns its substation and HV yard (Chapter 4.3), it inherits a hazard class most data-center EHS staff have never managed: medium- and high-voltage work, utility-grade clearances, induced-voltage and step-and-touch-potential risk across the ground grid, and switching operations where a wrong move flashes over at energies no PPE survives. The installation's actual function sets the OSHA scope: work performed as electric-power generation, transmission, or distribution falls under 29 CFR 1910.269; customer premises-wiring work falls under Subpart S. The control here is not better PPE — it is the qualified-worker program: a documented, demonstrated competency for each person allowed inside the HV boundary, refreshed on a cadence, with demonstrated competence in remote racking and switching. Use a written switching order and remote operation where practicable to establish isolation before maintenance, keeping workers outside the assessed arc-flash boundary.
The workforce question is make-vs-buy. In-house HV qualification gives operational control and faster response but demands a sustained training, tooling, and competency-audit program that is hard to keep current at a single site. Contracting the utility or an HV specialist for substation work outsources the competency but introduces interface and response-time risk, and it relocates the question of where the qualified-worker boundary sits — which is the same line as the ownership boundary negotiated in Chapter 4.3. Get that line wrong and you have either workers operating beyond their qualification or a campus that cannot perform routine switching without waiting on a third party. The EHS program and the 4.3 ownership model have to draw the same boundary, or the gap between them becomes the incident. → the substation ownership and NERC-compliance framing is Chapter 4.3.
OSHA and Process Safety Management for on-site gas and fuel
The behind-the-meter generation strategies of Chapter 3.5 and the fuel-supply engineering of Chapter 4.9 drop a process-industry hazard onto the campus: combustible gas, pressurized vessels, fuel storage, and rotating prime movers. OSHA Process Safety Management applicability depends on a covered process, listed-chemical or flammable-material threshold, connected/co-located process scope and any applicable exemptions under 29 CFR 1910.119; inventory alone does not settle it. It is a regime that data-center operators rarely arrive prepared for. PSM is not a checklist; it is process-hazard analyses (HAZOP/LOPA), mechanical-integrity programs, management-of-change discipline, operating procedures, contractor-safety management, pre-startup safety reviews, and incident investigation — the full apparatus of running a small process plant.
The decision is binary and early: determine PSM applicability before first fuel through a documented covered-process, threshold, connectivity and exemption analysis, and if you are in, stand up the program ahead of commissioning rather than discovering the obligation during an inspection or — worse — an incident. Even below the PSM threshold, on-site gas brings combustible-gas detection, relief and venting, hot-work permitting, and the process-safety interlocks of Chapter 4.9 into the EHS program. This is the cleanest example in the chapter of a goodput/availability decision made elsewhere (firming the power with on-site generation) cascading into an EHS obligation that has to be owned here. → the energy-supply strategy is Chapter 3.5; the gas-process and fuel engineering is Chapter 4.9; commissioning the generation and microgrid controls is Chapter 13.4.
Deep dive: building the program once — the EHS management system that spans build and operate
The hazards in this chapter arrive in two waves with very different ownership. During build, the general contractor and trades own most of the risk (falls, rigging, trenching, confined-space entry), and the owner's EHS role is to set the safety expectations into the contract (Chapter 2.4), audit them, and manage the interface between construction and any energized/occupied portions of a phased turnover (Chapter 6.6). During operate, the owner's organization owns it directly — electrical-safety, LOTO, coolant-handling, HV, and PSM all become standing programs run by facility EHS staff. The failure mode is treating these as two disconnected regimes with a hard handoff at substantial completion, because the most dangerous moments are exactly the overlap: partial energization during construction, commissioning live systems while trades are still on site, and the first operate-phase maintenance on equipment whose as-built differs from the design the EHS procedures were written against.
The control is a single EHS management system — ISO 45001 is the common backbone — that spans both phases with continuous ownership of the hazard registers, the permit-to-work system (covering hot work, energized electrical work, confined-space entry, and working at height under one governance), incident reporting and investigation with management-of-change feeding back into the arc-flash and PSM programs, and a training/competency matrix that maps every role to the qualifications it requires. The program is real when it produces a permit that a named person signed last week, a re-study that fired because someone changed a relay setting, and a refusal that someone was authorized to make — not a binder on a shelf. → the owner's organization and contracting model that assigns this ownership is Chapter 2.2; the construction-safety interface is Chapter 6.6; operational ownership lives in the run-phase organization of Part 14.
Deep dive: the 48 V → 800 V electrical-safety re-baseline
Of every hazard in this chapter, the DC-voltage step is the one most likely to produce a fatality from a workforce that believes it is safe — because the danger is invisible in the way the work looks. The same physical task (open a bus enclosure, verify de-energization, work on the connections) at 48 VDC and at 800 VDC presents identically to the worker's hands and eyes, but the consequence changes in kind. At 48 V, a below-50-V-to-ground reading alone does not remove electrical-burn or arc-explosion exposure; the paired busbars feed roughly 2,800 A of aggregate load from a stiff parallel supply with far higher bolted-fault current. Available fault current, clearing time, working distance, and task set arc exposure, and the study sets PPE; 800 V adds electrocution and an arc without a natural current zero, requiring a suitable DC interruption strategy. Three program elements have to change in lockstep, or the gap kills someone. Verification method: you cannot assume an 800 VDC bus has bled down — capacitive and source-side stored energy means zero-energy verification must be measured, with a known-good DC-rated tester, every time. PPE and tools: AC-rated gloves, tools, and arc-rated clothing selections do not automatically cover the DC case; the selection has to be re-derived for DC energies that the dominant IEEE 1584 AC model does not natively produce. Training and labeling: the qualified-worker definition, the approach boundaries, and the equipment labels all have to be re-authored for DC and taught before the first lineup goes live.
The trade is blunt: if your density roadmap commits you to 800 VDC (and for Kyber-class racks it does), the cheapest place to absorb that EHS cost is at design and pre-energization, by re-baselining the electrical-safety program as a deliverable of the 800 VDC project itself. The most expensive place to absorb it is after the first DC incident, when the program gets rebuilt under investigation. → the 800 VDC architecture and its efficiency rationale is Chapter 4.7; the density ramp that forces it is set back in Chapter 1.1.
Release work from the verified isolation and the crew’s demonstrated qualifications, with operations owning any loss of redundancy. If either is missing, delay the task; the price of a longer maintenance window is smaller than asking a worker to discover an omitted energy source by contact.
Cite this chapter
Fehn, J. (2026). Environment, Health & Safety (EHS) Across Build & Operate (Chapter 6.9). The Definitive Guide to AI Data Centers. https://aidatacenterguide.com/part-6-the-building-civil-structural-fire-life-safety-and-construction-execution/6-9-environment-health-and-safety-ehs-across-build-and-operate (accessed 2026-09-29).
@misc{aidc-6-9,
author = {Fehn, Jacob},
title = {Environment, Health & Safety (EHS) Across Build & Operate (Chapter 6.9)},
howpublished = {The Definitive Guide to AI Data Centers},
year = {2026},
url = {https://aidatacenterguide.com/part-6-the-building-civil-structural-fire-life-safety-and-construction-execution/6-9-environment-health-and-safety-ehs-across-build-and-operate},
note = {Accessed 2026-09-29}
}