Financing the compute build-out – Taking Swedish-law security over GPU hardware in data centres
The AI infrastructure boom has turned high-value GPU servers into a financeable asset class of their own. Financings secured on this hardware are becoming steadily more common, and the sums involved are large – often tens or hundreds of millions. For lenders financing that hardware into Swedish data centres — frequently for foreign borrowers and foreign lenders – the question that decides bankability is whether Swedish law lets them take security that is both valid and, crucially, enforceable. It does. But the value of that security turns on a handful of structuring points that are easy to miss.
Why this has become a financing question
The economics of training and serving large AI models have made compute capacity a scarce and capital-intensive commodity. Operators and investors are racing to stand up GPU clusters, and the Nordics — with abundant low-carbon power, a cool climate and stable grids — have become a natural home for them. As that build-out accelerates, debt-financing the hardware itself has moved from a niche arrangement to an increasingly common one, and the tickets are substantial: a single build can involve tens or hundreds of millions of dollars of servers — not real estate, not intellectual property, but rows of movable hardware running inside someone else’s building. As more of this capital is deployed, more of it is lent against the kit, and the security question moves to centre stage.
That profile is unusual for a lender. In most asset-backed financings the collateral is real property, shares or receivables. Here, almost the entire value of the security sits in movable units — GPU servers and related networking — that the borrower does not itself house. They sit in a third-party data centre under a colocation or hosting agreement, and the borrower and its financiers are frequently outside Sweden, sometimes outside the EEA altogether. The threshold question is therefore a Swedish-law one: can a lender take, perfect and enforce security over movable hardware that is physically held by a third-party operator on Swedish soil? The short answer is yes — but only if the transaction is built the right way. This article sets out how, and where the pitfalls lie. It does not address the tax treatment of these structures, which is a separate question for tax counsel.
First, keep the hardware movable
The analysis begins with a characterisation question that is easy to overlook. Under Chapter 2 of the Swedish Land Code (Sw. jordabalken), equipment installed in a building or on an industrial property can become a fixture (Sw. fastighetstillbehör) and thus an integral part of the real property. If that happens, the hardware can no longer be pledged separately by the borrower as tangible movable property; it forms part of the real property owned by the property owner and is therefore unavailable as separate security for the lender’s loan. For a financing whose entire value sits in the kit, that would be fatal.
The decisive protection is the ownership-identity rule in Chapter 2, Section 4 of the Land Code: property brought onto the land by someone other than the property owner does not become a fixture. The key point is therefore not who ultimately owns the equipment within the borrower group, but that it is brought onto the site by an owner other than the owner of the real property. As long as the borrower (or its special-purpose vehicle) acquires the hardware and brings it in — rather than buying it in place from the property owner or operator — it remains tangible movable property that can be pledged separately. Two practical points follow: ownership should be documented (supply contract, invoice, title), and the sequencing should ensure the equipment is genuinely acquired and installed by the borrower. Anything that is already an installed fixture owned by the property owner does not become the borrower’s separately pledgeable tangible movable property, as against third parties, until it is physically separated from the property (Chapter 2, Section 7) — so newly acquired, not-yet-installed hardware is the cleaner starting point.
The security itself: a possessory pledge, perfected by notice
The natural security over the hardware is a possessory pledge (Sw. handpant) over tangible movable property (Sw. lös sak). Swedish law does not perfect a pledge by registration or by the mere signing of a security agreement; it requires that the pledgor be deprived of control over the asset (Sw. rådighetsavskärande). Where the pledgor holds the asset itself, that means handing it over. But GPU hardware is not held by the borrower — it is physically held by the data-centre operator as a third party. Swedish law solves this through perfection by notice (Sw. denuntiation) under the Act on the pledging of movable property held by a third party (Sw. lag (1936:88) om pantsättning av lös egendom som innehaves av tredje man). Once the operator holding the equipment is notified of the pledge, it holds the equipment for the secured party’s account, and the pledge is perfected.
This is a genuine advantage of the third-party-holding structure: the borrower never had possession to give up, and the operator’s acknowledgment does the work that physical delivery would otherwise do. It also means the operator is not a bystander to the security — it is the very mechanism through which perfection is achieved.
The line that matters: operational access versus control
Notice is only effective if it reflects a genuine loss of control. This is the point most often misunderstood by non-Swedish parties. The borrower can, and will, retain operational access to run the GPUs — typically remote or software operation — so that the compute business keeps functioning day to day. What the borrower must not retain is the ability to remove or dispose of the hardware without the lender’s involvement. If the borrower has unrestricted physical access allowing it to take the equipment at will, perfection is at risk and the pledge would be vulnerable in the borrower’s insolvency.
The line, in other words, is drawn at control over removal and disposal, not at physical proximity or day-to-day use. A well-structured deal lets the borrower keep running its compute business while ensuring that the hardware cannot leave the facility, or change hands, other than through the lender. Delivering that distinction is largely a matter of the arrangements with the operator.
Why the data-centre operator is the key counterparty
Because perfection runs through the operator, and because the operator physically controls access to the hardware, the operator is the single most important counterparty in the security package. A lender should insist on a tripartite direct agreement (an operator acknowledgment and waiver) — and that document needs to do considerably more than merely record notice of the pledge.
There are two reasons. First, the direct agreement is how perfection and control are delivered in practice: the operator acknowledges the pledge, confirms that it holds the equipment for the lender’s account, undertakes not to release or permit removal of the equipment without the lender’s consent, and gives the lender a direct contractual right to obtain access to, and require release or removal of, the equipment on enforcement. Second — and this is the point that catches lenders out — standard colocation and hosting terms frequently give the operator its own rights over customer equipment. It is common for such terms to allow the operator, on a customer payment default, to refuse the customer access to its equipment and to hold that equipment as security for the operator’s unpaid fees, alongside acceleration of the remaining fees and a right to remove the equipment on termination. That is a competing claim over the very asset the lender is taking as security, and if left unaddressed it means the operator may hold the hardware for its own account rather than the lender’s — undermining both perfection and priority.
The direct agreement must therefore make the operator’s holding of the equipment expressly subject to the lender’s security and subordinate or waive the operator’s contractual retention and removal rights in the lender’s favour. Reviewing the colocation agreement specifically for these rights, and neutralising them in the direct agreement, is one of the highest-value pieces of diligence in the whole exercise. The security is only as good as the operator arrangement that sits behind it.
A complement, not a substitute: the business mortgage
Swedish law also offers a floating charge — the business mortgage (Sw. företagshypotek) — over the movable assets of a business carried on in Sweden. It has attractions as a complement: it does not require any control cut-off, and it needs neither a Swedish company nor a Swedish branch, only that business is carried on in Sweden. It is registered with the Swedish Companies Registration Office (Sw. Bolagsverket) and captures movable business assets generally — including the hardware, and typically inventory and receivables — though not cash and bank balances, financial instruments intended for general circulation, or property that can itself be mortgaged.
There are two things to keep in mind. First, priority: a business mortgage is a general, floating charge, and a specific possessory pledge over particular equipment ranks ahead of it in that asset. Where nearly all the value sits in identifiable hardware, the perfected possessory pledge should be the primary security, with any business mortgage as a backstop over the wider asset pool. Second, cost: granting a new business mortgage registration attracts Swedish stamp duty of 1% of the mortgaged amount, so a large facility implies a material duty cost. A possessory pledge, by contrast, carries no stamp duty. One point often missed is that a business mortgage registration is not consumed by the first debt it secures — once released it can be re-pledged for future debt without new duty — so the cost is most acute when fresh registrations have to be taken out.
Following the value: security over insurance
Hardware of this value will be insured against damage and theft, and a lender should make sure its security follows the value if the asset is damaged, lost or stolen rather than stopping at the physical kit. That means taking security over the relevant insurance claims and proceeds and having the lender named as loss payee. It is a small addition to the package, but it closes an obvious gap: without it, a total loss of the hardware could leave the lender with a pledge over nothing and the insurance money flowing to the borrower.
Enforcement: can a foreign lender really take the kit?
The question that ultimately matters to a lender is whether, on a default, it can actually realise its security — and, if it is a foreign lender, whether that changes anything. It does not. Security over assets situated in Sweden is governed by Swedish law (lex rei sitae), and a validly created and perfected Swedish pledge is respected irrespective of the nationality or domicile of the lender or the borrower.
Realisation of the possessory pledge (Sw. pantrealisation) is, once the secured debt is due and payable, effected by private sale or public auction, in such manner and on such terms as the secured party deems fit under the security documents. Two main limits apply. Swedish law does not permit foreclosure: the secured party may not simply keep the asset without accounting for its value, and forfeiture clauses (lex commissoria) are void under Section 37 of the Contracts Act. And the secured party owes a fiduciary duty (Sw. vårdplikt): to notify the borrower, allow a reasonable period to redeem (case law and doctrine indicate not less than around 30 days), take reasonable steps to obtain the best possible price given the circumstances, and account for any surplus.
The practical mechanics of taking and removing the hardware are where the operator arrangement earns its keep. Because a third party physically holds the equipment, a secured party cannot help itself against an unwilling holder; repossession from a party that will not release voluntarily must go through the Swedish Enforcement Authority (Sw. Kronofogden). This is exactly what the direct agreement is designed to pre-empt: a well-drafted operator acknowledgment gives the lender a consensual, out-of-court route to take and remove the equipment on enforcement, with the Enforcement Authority available only as a fallback. In the borrower’s Swedish bankruptcy (Sw. konkurs), a possessory pledgee can generally realise the pledged asset without the administrator’s intervention, subject to statutory safeguards — notably that, absent the administrator’s consent, a sale may not take place earlier than four weeks after the oath-taking meeting (Sw. edgångssammanträde), and the administrator must first be given the opportunity to redeem the asset.
The business mortgage is realised differently, and lenders should not assume it behaves like a pledge. It is not a self-help remedy: the holder cannot seize and sell the charged assets itself. Instead it confers a priority right (Sw. särskild förmånsrätt) that is realised through a collective or official process — the borrower’s bankruptcy, or attachment by the Enforcement Authority — in which the holder is paid out of the proceeds ahead of unsecured creditors but behind any specific possessory pledge over the same asset. Finally, where the borrower is a foreign entity, a foreign insolvency does not defeat a validly perfected Swedish pledge: under the situs rule the security should continue to be respected, though enforcement will need to be coordinated with the foreign process, and matters such as stays, moratoria and clawback should be confirmed with local counsel.
The case for a Swedish SPV
None of the above requires the borrower to be a Swedish company. Under the situs rule a foreign owner can grant a Swedish-law pledge over Swedish-situated hardware, perfected by notice to the operator, in exactly the same way as a Swedish entity could. A Swedish special-purpose vehicle is not, therefore, a legal prerequisite for the security. But there is a strong practical case for one.
An SPV that owns the hardware delivers ring-fencing and bankruptcy remoteness: the equipment and the financing are isolated from the operating group’s other liabilities. It also gives the lender a single, predictable insolvency forum — a Swedish bankruptcy, run under Swedish law in a Swedish court — rather than leaving the lender to rely on recognition of its Swedish security within a foreign insolvency and to coordinate between a foreign main proceeding and the Swedish assets. And it opens up a further, powerful piece of security: a share pledge over the SPV, which, combined with customary negative-pledge and ring-fencing undertakings, gives the lender clean structural control over the vehicle that owns the kit. The natural vehicle is a private limited liability company (Sw. privat aktiebolag), which is quick and inexpensive to establish and whose shares can themselves be pledged. The trade-offs are the cost and time of forming and maintaining the entity, and the intra-group step of moving the hardware into it — the tax dimension of which is beyond the scope of this article. On balance, for a financing of any size, the predictability and structural control an SPV brings will usually justify it.
A note on Swedish company-law limits
One point deserves a flag, precisely because it is not the subject of this article. Where the borrower group sits partly or wholly outside the EEA, Swedish company-law rules can shape how the financing is structured — in particular the loan prohibition in Chapter 21 of the Swedish Companies Act (Sw. aktiebolagslagen) and the value-transfer restrictions in Chapter 17. In broad terms, these rules constrain when a Swedish company may lend to, or provide security or guarantees for, its owners and related parties, and they can bear on whether and how a Swedish SPV supports debt incurred elsewhere in the group. They rarely prevent a well-planned structure, but they can dictate its shape, and they should be considered early rather than discovered late. A full treatment belongs in a separate piece.
What a lender should look for
- Confirm the hardware is acquired and brought onto the site by the borrower or its SPV — not by the property owner or operator — so it stays movable and separately pledgeable.
- Take a possessory pledge over the equipment and perfect it by notice (Sw. denuntiation) to the operator.
- Put in place a tripartite operator direct agreement that subordinates or waives the operator’s retention and removal rights, bars release or removal without consent, and gives the lender a direct enforcement access right.
- Restrict the borrower to operational use of the hardware, with no unilateral right of removal or disposal.
- Consider a business mortgage as a backstop over the wider asset pool, weighing the 1% stamp duty against its weaker priority.
- Take security over the insurance claims and proceeds, with the lender named as loss payee.
- Consider a Swedish SPV to own the hardware, with a share pledge and ring-fencing undertakings, for predictability and structural control.
- Check the Swedish company-law limits early where the group extends outside the EEA.
In short
Swedish law lets a lender take robust, enforceable security over GPU hardware sitting in a Swedish data centre, and it does so for foreign lenders and foreign borrowers alike. The security is creatable and the enforcement path is real. What separates a bankable package from a fragile one is a small number of structuring points: keeping the hardware movable rather than a fixture, perfecting the pledge by notice to the operator, and — above all — getting the operator direct agreement right so that the operator holds the kit for the lender and not for itself. A Swedish SPV, while not strictly required, adds the predictability and structural control that make the whole package easier to underwrite. Get those elements right, and movable compute hardware becomes exactly what a lender needs it to be: collateral it can rely on.






















