The Best Sports Data Is Coming From Hospitals, Regulators and a 16-Year-Old
The dossier's newest sports-technology item is a 30 September summary of a panel at LEAP 2026 in which a Pure Sports executive is described as exploring data-native sporting ecosystems, and it arrives the same day that researchers accused the EU of hiding data centre energy use and a 16-year-old was paid $5,000 for an authentication bug in Microsoft's internal analytics platform.

On 30 September, consultancy-me.com published a summary of a LEAP 2026 session featuring a Pure Sports leader, framed around what the outlet calls data-native sporting ecosystems. That is the newest sports-technology item in the dossier. It is also the thinnest. The panel summary contains no capacity figure, no contract value, no named dataset and no measurement of anything.
If you want to know where sports analytics is actually heading, the more useful material this week sits further down the stack: in the hospitals, the regulators and the security advisories that feed it. Start with the data itself. On Monday, the US health secretary, Robert F Kennedy Jr, told a Maha Institute event that medical and lifestyle data should be connected and shared with the government and independent researchers, where AI could search it. According to the Guardian's account, he pointed to Medicaid as a vehicle because it holds hundreds of millions of lives, including tens of millions of children enrolled for 10 or 20 years, and said Medicare gives "enormous amounts of information on older Americans and people with disabilities." Sports organisations will read that paragraph twice. Wearable vendors, club medical departments and national federations have been arguing for a decade that longitudinal athlete health records are the missing layer in performance analytics.
Kennedy's list of what should be linked, immunisation records, clinical data, laboratory results, pharmacy information and insurance claims, is close to a description of the record a professional athlete accumulates from academy to retirement. He also described the current system as fragmented. State-level datasets reported to the CDC were "unusable" because they often collect different data points: "Too many of those systems remain siloed and cannot give us the real-time information we need to understand health at scale."
The infrastructure bill behind the highlight reel
None of this runs without power, water and land, and that is where the numbers get concrete. Europe's data centres used 20.7 terawatt-hours of electricity in 2025, roughly as much as the whole of Croatia, and more than 8 million cubic metres of water, according to European Commission figures cited by POLITICO. That is a 26% rise in electricity use and 52% in water use from 2024. The same figures are incomplete: they are published only in aggregate, after a 2024 law barred Brussels and EU capitals from disclosing information about individual data centres.
On Monday, the Netherlands-based non-profit Lighthouse Reports filed a formal complaint against the Commission under the Aarhus Convention, which the Commission did not comment on to POLITICO. NL Times, working with Lighthouse and Trouw, reported that the Dutch Enterprise Agency has data on only 104 of the 186 commercial data centres in the Netherlands with at least 500 kilowatts of installed capacity, and public figures for electricity use at 44 and water use at 47. Statistics Netherlands puts Dutch data centre consumption at 5.1 billion kilowatt-hours in 2024, 4.6% of national electricity use, nearly double the level five years earlier. Grid operator TenneT projects 10% to 15% by 2030.
For sports, the connection is not metaphorical. Broadcast graphics, live betting feeds, tracking systems and video review all sit on the same racks as everything else, and the domestic game is the buyer of last resort when capacity is rationed.
In the United States, Texas officials have paused data centre permitting, but Meta's $10 billion, 1-gigawatt facility in northeast El Paso is still moving. On Wednesday, administrative law judges at the Public Utilities Commission of Texas released a proposed decision finding that El Paso Electric failed to adequately consider alternatives to a 366-megawatt natural gas plant, called McCloud, and never issued a request for proposals, according to Inside Climate News. The judges recommended approving it only on condition that shareholders, not ratepayers, absorb the capital and operating costs. The five commissioners have not scheduled a vote. The McCloud facility is priced at $499 million and would use 813 modular generators supplied by Enchanted Rock, each rated at 450 kilowatts.
Similar disputes are spreading. On 22 September, New Jersey's Department of Environmental Protection announced a $1.07 million penalty against a Vineland AI data centre operator, identified as DataOne, for installing and operating 62 natural gas generators without permits, Data Center Knowledge reported. The operator disputed the finding and said it would apply for air permits. Abhijit Sunil, a senior analyst at Forrester, told the publication that on-site generation "doesn't eliminate an environmental cost."
Nuclear is the other bet. NPR reported exclusively that Valar Atomics wants to place 456 small reactors on more than 9,000 acres of Bureau of Land Management land near Price, Utah, under the name Project Beehive, producing around 9.6 gigawatts for data centres. Utah currently produces about 4 gigawatts on average. Non-nuclear construction could start by the end of this year, with first reactors in 2028.
Who is actually measuring the athletes
The analytical layer for sport is being assembled by companies whose primary market is not sport at all. On Wednesday, Amazon Web Services announced that Aurora PostgreSQL can now query Apache Iceberg and Parquet data in a data lake directly, using DuckDB's engine embedded in PostgreSQL, with no extract, transform and load pipeline, in versions 17.11 and 18.6 and higher. The AWS News Blog frames it as a way to combine live transactional data with archived records for real-time dashboards and AI agents, and notes that DuckLabs, the team behind DuckDB, recently joined Amazon. A shorter what's-new notice confirms general availability at no extra charge. For a club sitting on years of tracking files in object storage, that is a cheaper query path than a warehouse migration.
Performance claims still need testing. A paper submitted to arXiv on 29 September by Osayamen Jonathan Aimuyo, Swapnil Gandhi and Christos Kozyrakis describes Purlin, a scale-up communication framework that separates orchestration from the datapath for GPU collectives. Evaluated on A100, H200 and B200 GPUs across seven collectives, the authors report latency speedups of up to 5.14x and bandwidth improvements of up to 4.50x over baselines, and 1.26x average interactivity gains for online LLM inference, with the largest gain under overload. Those are the kinds of numbers that decide whether a live, in-venue model is feasible.
Some of this week's most relevant reading is older and more cautionary. A VLDB CIDR paper by Andrew Crotty, Viktor Leis and Andrew Pavlo, resurfaced on 30 September, argues that memory-mapped file I/O is not a suitable replacement for a buffer pool in a modern database management system, and that several popular systems adopted mmap for larger-than-memory workloads before switching back at significant engineering cost. The specifics are unglamorous. The lesson is not: benchmarks that look fine on a laptop can fail on a matchday.
Security is now part of the box score
Then there is the part nobody puts in a sponsorship deck. The Register reported on 30 September that a 16-year-old researcher named Faav found an authentication flaw in Microsoft's internal Titan analytics service, gained administrator access and ran SQL without valid credentials. He built an AI helper called Antares, found Titan's public API on 25 August and spent 10 days on JSON Web Token checks before an unsigned token with the user principal name "admin" resolved to local user ID 1 and an admin role early on 5 September. Microsoft has since locked the API down and paid a $5,000 bug bounty. The company told Faav, in a statement carried in his blog, that the disclosure "helped us to better protect our customers by hardening our services." Faav wrote that he rewrote the post at Microsoft's request and cut sections and numbers.
Separately, The Register reported on 29 September that researchers affiliated with Glow Security found more than 13,000 sensitive screenshots of corporate software projects from 343 companies posted to public GitHub repositories by AI models, a phenomenon they call PixelLeak. Omer Singer, co-founder and CTO, said agents put images in public repos to work around GitHub's lack of an API for uploading images to pull requests. Glow's examples include a manufacturer with more than 100,000 employees whose security team did not know about the posts until told.
Two breaches show what a sports organisation would be defending. On 30 September, TechCrunch reported that the Defense Manpower Data Center is notifying millions of current and former military personnel that Social Security numbers, names, dates of birth and service details were taken from an unencrypted file-sharing system between October 2025 and mid-July 2026. A Pentagon official put the figure at about 2.8 million living people and close to 300,000 deceased, according to CNN and Federal News Network, and Department of Defense spokesperson Susan Gough confirmed the number in an emailed statement. CNN's earlier piece added that the DMDC held at least 60 million records as of fiscal 2024, and that occupational specialty data was taken in some cases.
Governments are also aggregating plate reads. 404 Media reported on 30 September, based on public records and court documents, that the federal High Intensity Drug Trafficking Area program is being used to funnel local Flock and Axon camera data into federal servers, with some flowing to the DEA's National License Plate Reader Program. Cris van Pelt, who runs HaveIBeenFlocked.com, told the outlet the arrangement "bypasses democratic processes entirely."
In the UK, the Guardian reported exclusively that more than 44,000 people have filed legal objections under article 21 of the UK GDPR to NHS England's Palantir-powered Federated Data Platform handling their data. Palantir says trusts using it recorded 117,000 additional operations, a 14.3% reduction in discharge delays for long-stay patients and a 5.6% improvement in cancer diagnosis within 28 days. A £330m deal runs seven years, with a break clause in force in February 2027.
For sport, the through-line is not ethical discomfort. It is procurement risk. The systems that will hold athlete health records, tracking data and biometric baselines are the same class of systems being tested in public this week, by regulators, by attackers and by teenagers with a laptop and a home-built bot.
Sources
16- 01RFK Jr outlines expansive vision for collecting US health data at Maha eventEN
- 02EU accused of hiding environmental impact of data centersEN
- 03Most data centers refusing to say how much water, electricity they useEN
- 04Texas Electric Utility Only Considered Gas to Power $10 Billion Meta Data CenterEN
- 05Data Center On-Site Power Brings Pollution Risks Closer to HomeEN
- 06Startup Wants to Build Nuclear-Powered Data Center on Public Land in UtahEN
- 07Amazon Aurora PostgreSQL now supports direct querying of Apache Iceberg and Parquet data in your data lakeEN
- 08Aurora PostgreSQL now supports querying of Apache Iceberg and Parquet dataEN
- 09Purlin: Separating Orchestration from the Datapath of CollectivesEN
- 10Are You Sure You Want to Use MMAP in Your Database Management System? (2022)EN
- 1116-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rowsEN
- 12AI models keep posting screenshots showing sensitive data from inside tech companiesEN
- 13Hackers stole millions of US military personnel records during months-long data breachEN
- 14Pentagon data breach of military personnel raises national security concernsEN
- 15How Cities Are Forced to Funnel License Plate Data to a Massive Federal Surveillance ProgramEN
- 16More than 44,000 file legal objections to Palantir NHS platform handling their dataEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.