How Grid Operators Decide Who Loses Power in a Rolling Blackout
An explainer on how electrical grid operators use load shedding and rolling blackouts to prevent total grid collapse when demand outpaces supply.

Photo: Lupus in Saxonia · CC BY-SA 4.0 · source
When a heatwave or cold snap pushes electricity demand to the breaking point, utilities sometimes cut power deliberately to some neighborhoods rather than let the whole grid fail. It looks like a random inconvenience from the outside, but it is actually a fast, automated engineering decision governed by strict technical thresholds.
The basic problem: supply and demand must match, instantly
Electrical grids cannot store meaningful amounts of power for later use the way a reservoir stores water. Supply and demand have to balance in real time, every second, and the grid’s alternating-current frequency — 50 or 60 hertz depending on the country — is the signal engineers watch to know whether that balance is holding. When demand outstrips available supply, frequency starts to drop. If it drops too far and stays there, generating equipment across the grid can automatically disconnect to protect itself, which can cascade into a much larger and far more damaging blackout than the one operators are trying to avoid.
Load shedding: the controlled fix
The tool operators use to prevent that cascade is called load shedding — deliberately cutting off predetermined blocks of demand to bring supply and demand back into balance before the whole system fails. According to a technical summary on load shedding, the most common form is under-frequency load shedding, in which automated relays “shed predetermined amounts of load when the system frequency drops below specific thresholds,” acting in as little as roughly 0.2 seconds — far faster than any human operator could react. A related method, under-voltage load shedding, protects against dangerous voltage drops instead of frequency drops, and deliberately uses longer delays — typically above three seconds — specifically to avoid triggering on brief, harmless fluctuations.
How specific areas get chosen
The choice of which circuits go dark is not random, but it is not about fairness either — it is engineering and economics. The same summary notes that operators select which section of the grid to shed based on “the bus distance from the contingency location as well as economic considerations,” meaning the physical layout of the transmission network and the cost of interrupting different types of customers both factor into the automated or pre-programmed shedding scheme. How this works in practice is spelled out by the Texas grid operator. In an ERCOT explainer on load shed, the operator describes rotating outages as a last resort, used only after appeals for conservation and three escalating Energy Emergency Alert levels have failed to close the gap. ERCOT then tells transmission operators how much demand must come off the grid in total, and each operator’s share is set by its percentage of the previous year’s system-wide peak demand, published in summer and winter “Load Shed Tables.” Customers providing critical public services — hospitals, police and fire stations, critical water and wastewater facilities, critical gas facilities and nursing homes — are generally prioritized if they have registered as critical load with their local distribution utility, though ERCOT notes they may still be affected in a deep or long event. The exact protections and procedures vary by grid operator and country.
Why blackouts are “rolled” rather than sustained
Rather than leaving one area without power for an extended period, many grid operators rotate the outage across different sections of their service territory — a rolling blackout. A Wikipedia summary of rolling blackouts describes the practice as “an intentionally engineered electrical power shutdown in which electricity delivery is stopped for non-overlapping periods of time over different parts of the distribution region,” used specifically as a controlled demand-response measure “when demand for electricity exceeds the power supply capability of the network.” The rotation spreads the burden more evenly across customers instead of concentrating it on one neighborhood, and jurisdictions often cap how long any single area can be without power in a cycle — the same summary notes Italy’s emergency plan limits any single controlled outage to 90 minutes, while blackouts in Canada have been rolled so no area went more than an hour without power. In Texas, ERCOT says smaller transmission operators tend to target shorter rotations of roughly 10 to 30 minutes per customer, while larger ones may run 60 minutes or more.
Rolling blackout versus total blackout
The distinction matters because the two events look similar to an affected household but are operationally very different. A rolling blackout is a deliberate, controlled intervention specifically designed to prevent a full collapse — power is cut to some areas so it can be preserved everywhere else, and outages are cycled so the same customers are not left dark indefinitely. A true grid collapse, by contrast, is what happens when this controlled process fails or comes too late: automatic protective disconnections cascade uncontrolled across the network, and restoring power afterward — a process called a “black start” — takes far longer than ending a planned rolling blackout, because generators, transmission lines and local distribution all have to be brought back online in a carefully sequenced order rather than simply switched back on.
The takeaway
A rolling blackout is not a failure of the grid — it is the grid’s built-in circuit breaker working as designed, cutting demand automatically and in stages to keep frequency and voltage within safe limits and prevent a far larger, far slower-to-fix collapse. The areas affected are chosen by pre-set technical and economic criteria tied to the network’s physical layout, not by which neighborhood drew the short straw, and the rotation between areas is a deliberate attempt to spread a temporary hardship rather than concentrate it.
Deliberate, controlled failure is a pattern across infrastructure — see how a food recall gets triggered and traced and what an airspace closure actually means for flights.