Operational notes Observatory

Two data centres declared "of national strategic interest" worth €6.8 billion: who controls them, and under which jurisdiction

7 min read

Corridor of a data centre with rows of closed server cabinets, cables suspended from the ceiling, and a mobile workstation with a blank monitor, in black and white
Every cabinet has a different door and a different key: the question that matters is not whose corridor it is, but who holds each key.

On 4 August 2026 Italy’s Council of Ministers declared two new data centre investment programmes of pre-eminent national strategic interest, one in Lombardy and one in Sardinia: together they mobilise “roughly €6.8 billion in direct investment”, MIMIT writes, taking to seven — worth “over €25 billion” — the programmes approved under the same instrument. The release states the objective without reticence: the two interventions “strengthen the Government’s strategy to consolidate the country’s digital sovereignty” and serve to “attract high-technology-content investment”. Read side by side, these are the reason for this piece: the larger of the two programmes is led by a company with a Singapore corporate form; the other is controlled indirectly by a company listed in New York. This is not a hidden contradiction — the release spells it out in full — but it is the point where the word “sovereignty” deserves to be taken seriously rather than repeated.

Two programmes, two profiles

The first, the larger one, belongs to K2 Strategic Infrastructure Italy S.r.l., “held by K2 Strategic Pte. Ltd. (‘K2’)”: a hyperscale campus “with total capacity of up to roughly 400 MW” at Zibido San Giacomo and Lacchiarella, in the Milan metropolitan area, an investment estimated at “roughly €5.3 billion”. Construction takes four years and requires “around 2,000 work-years annually”; at full operation, “around 200 highly specialised direct jobs” plus “around 1,300 posts in permanent indirect employment”. Minister Urso spoke by phone with Lombardy’s regional president Fontana to check the project’s compliance with the regional data-centre law: state-level acceleration did not bypass the regional level.

The second, “Digital Vault Sulcis”, belongs to Energy Vault Sulcis S.r.l., “indirectly controlled by Energy Vault Holdings Inc.”, at the former Monte Sinni coal mine in Nuraxi Figus, in the Sulcis Iglesiente area: an “Edge AI Data Centre integrated with infrastructure for renewable energy generation and storage”, up to 30 MW, roughly €1.49 billion, around 400 jobs a year between direct and indirect employment. The release links it to the redevelopment of a disused industrial site — a positive fact, and it should be said as such.

Who is behind the two companies

The release states the chain, it does not hide it. K2 Strategic Pte. Ltd. has the legal form of Singapore’s private limited companies — “Pte. Ltd.” — and it is not only the form: on its own website the company states it is incorporated in Singapore, with its registered office in the city, as the digital infrastructure arm of the Kuok Group. Energy Vault Holdings, Inc. is American and listed: CIK 1828536, ticker NRGV, NYSE. Neither chain is opaque — one is checkable on the company’s own website, the other on a federal register — but neither leads to an Italian majority shareholder: in the larger of the two campuses, on the outskirts of Milan, group control runs through a Singapore vehicle.

The instrument: what article 13 does, and what it leaves untouched

The instrument is article 13 of decree-law 104/2023 (the “Decreto Asset”), converted into law 136/2023. Paragraph 1 reserves the declaration for “large foreign investment programmes”; paragraph 2 sets the threshold at one billion euros — both of today’s programmes clear it comfortably. Paragraph 3 provides for an extraordinary government commissioner, agreed with the Region, unpaid. Paragraph 4 gives the commissioner ordinance powers derogating from “any legal provision other than criminal law”, with two firm limits — the anti-mafia code and EU constraints — and fifteen days for the administrations concerned to respond, after which the process continues without their opinion. Paragraphs 5 and 6 concentrate every authorising instrument into a single authorisation, with the effect of a zoning variance and of a declaration of public utility.

Paragraph 7 matters most here: application “remains unaffected in any case” by Regulation (EU) 2019/452 on screening foreign direct investment, and by decree-law 21/2012, Italy’s “golden power”. The instrument that speeds up permits is not the one that screens whether a foreign investor may control a critical asset: two separate tracks, and the 4 August release addresses only the first. On the same instrument, applied to the first batch — Equinix and TechBau’s Trino campus — we already wrote in late July: the legal substance does not change from one round to the next, and we will not repeat it here.

Sovereignty is jurisdiction, not an address

Foreign direct investment in infrastructure is an explicit industrial-policy choice, declared as such — not an omission to be uncovered. And the declaration of strategic interest is administrative acceleration, not a title of public ownership: it does not change who controls the company running the site. The point, for whoever will one day put their own workloads in those halls, is different: the sovereignty of an infrastructure is not a property of its geography, but of the legal regime it is subject to — the two do not automatically coincide. The questions that reduce sovereignty to checkable facts, not a slogan, we already set out. This is the distinction the Data Act puts in writing: article 28 of Regulation (EU) 2023/2854 requires providers to publish “the jurisdiction to which the ICT infrastructure used for the processing of data under each of their individual services is subject” — not the building’s address. We wrote about it yesterday: a duty already in force, which almost no provider has yet checked.

Three consequences for buyers

  1. “Data centre in Italy” does not answer the jurisdiction question. It answers the question of latency and data residency — a real requirement, but a different one. Both must be written separately into the tender: where the data physically sits, and under which legal order whoever runs it answers.
  2. The control chain must be traced, and written into the contract. An Italian S.r.l. held by a foreign vehicle is lawful — both of today’s are. But it is the chain that determines which country’s judicial or administrative orders the supplier may be subject to. MIMIT states it line by line; supply contracts almost never do.
  3. An extraordinary commissioner speeds up authorisation, not compliance. Paragraph 4 itself says so: the derogation does not touch criminal law or the anti-mafia code, nor — under paragraph 7 — golden power. The operator’s ordinary obligations remain once the site is switched on: security, continuity, notification to the CVCN for anyone within the cyber security perimeter, NIS2 where applicable. The faster procedure concentrates these obligations, it does not reduce them.

The other side of it, and it should be said

Italy needs computing capacity and does not have enough of it: these investments bring it, declare real jobs — two thousand work-years on the Milan campus alone, four hundred posts at full operation in Sulcis — and, in Sardinia’s case, redevelop a disused mining site: a positive fact, to be recognised as such. Nothing in the public record indicates anything improper by K2 Strategic or Energy Vault: neither has done anything that Italian law, or the law of their own countries, does not allow, and this article does not suggest otherwise. The open question is not whether these investments should go ahead — that is a declared industrial-policy choice. It is whether the word “sovereignty”, used to describe them, measures what actually happens under the roof of those buildings, or only where they stand.

The control your existing contracts need

Tracing the control chain of a critical supplier — who owns it, who governs it, under which legal order each link answers — is not an exercise you do once, at signature, and file away: it is a control that runs on the buyer’s own contracts and systems, with a register updated at every change of ownership and the trail ready for an inspection. The same system brings together, in a single operating model, an organisation’s scattered data — contracts, suppliers, archives, management systems, system inventories — so AI agents can act on that model and execute decisions with a human operator in command: for large enterprises, defence, public administration and healthcare. Always in two modes — on-premise on autonomous machines with no deep integration into the customer’s network, or a dedicated cloud with its own VPN and the data centre in Italy, premises staffed by us — always under shared management and multi-model: systems already running across several enterprise settings, not a press-release promise.

Want to know who really controls — and under which law — the supplier that will host your data? Thirty minutes to trace the three names that matter, together.

Sources