01The state of AI in energy and utilities
Energy and utilities should be a natural home for enterprise AI. The sector already instruments almost everything it owns, from generation plant and substations to the meter on the side of a house, and its operating model is the continuous conversion of sensor readings, market signals and asset condition into decisions about supply, price and safety.
That is not what has happened. Most generators, network operators and retailers now run promising pilots: an outage-prediction model here, a predictive-maintenance trial there, a demand-forecasting notebook in a data-science team. Far fewer have those systems in production, informing real operational and commercial decisions across the business. That gap between demonstration and deployment is where most utility AI initiatives live, and where many quietly end.
The pressure to close that gap is not abstract. The energy transition is loading networks with distributed generation, storage and electrified demand that the original grid was never planned for, ageing assets are being asked to run harder for longer, and extreme weather is turning reliability and resilience into board-level and public issues. Each of those pressures is an argument for AI, and each is being made in utility strategy papers right now.
If you run operations, asset management, markets or data for an energy business, you do not need convincing on the opportunity. The harder questions are why AI stalls in this sector specifically, and what the organisations reaching production do differently.
02The energy and utilities data problem
A typical integrated utility runs a different data estate in every part of the value chain. Generation lives in plant historians and control systems. Networks live in SCADA, distribution management and outage systems. Retail lives in billing, CRM and meter data management. Each was bought or built separately, in a different era, often through a different acquisition, and the promised consolidation programmes rarely finished the job.
Assets are described in more than one place at once. The asset register says one thing, the maintenance system says another, and the geographic information system (GIS) that holds the network model says a third, each with its own identifiers, hierarchies and conventions. The same transformer can appear under three references, and reconciling them is somebody’s spreadsheet, updated when there is time.
Operational technology and information technology sit on opposite sides of a deliberate divide. SCADA and telemetry stream from the field in real time on tightly controlled networks, while asset, work-management and market data live in enterprise systems, and the two rarely share a common model of the same physical thing. A reading from a sensor and the record of the asset it sits on are, structurally, strangers.
Then there is metering. Smart meters generate interval data at enormous volume, distinct again from the market and settlement systems that price it and the customer systems that bill it. The same connection point is described differently by the meter, the market and the retail record.
The consequence: the same asset, the same feeder and the same customer are described differently in every system that touches them. Point an AI system at that estate directly and it will answer instantly and confidently, and it will be inconsistently wrong in ways nobody can trace, which in a safety-critical, always-on sector is not a tolerable failure mode.
03What governed AI could deliver
Set the data problem aside for a moment and the potential is easy to state; the same use cases appear in every utility’s strategy paper:
- Outage and fault prediction. Telemetry, weather, asset condition and network topology read together to anticipate faults and outages, so crews are positioned before customers are affected rather than after.
- Asset management and predictive maintenance. Condition data across the fleet used to prioritise inspection and intervention on the assets that actually need it, extending life and deferring capital where it is safe to do so.
- Load and demand forecasting. Consumption, generation, weather and market signals combined into forecasts that hold up as distributed energy and electrified demand make the old patterns unreliable.
- Compliance and ESG reporting. Emissions, reliability and sustainability disclosures assembled from consistent, traceable data instead of hand-stitched spreadsheets under deadline.
- Network planning and connections. Hosting-capacity, connection and augmentation questions answered from a governed view of the network rather than from stale extracts.
- Field and customer operations. Field crews and contact-centre teams supported with grounded answers drawn from the whole record instead of one system’s fragment of it.
Nothing on that list is speculative; every capability has been demonstrated inside utilities. The interesting question is why so little of it is in production, and the answer is rarely the models.
04Why initiatives stall
Four forces hold energy and utilities AI between pilot and production, and they compound.
Safety and reliability obligations. Utilities keep essential services running, so the bar for any system touching operational decisions is set by safety and reliability regulation, not enthusiasm. A pilot that cannot demonstrate that it is safe, resilient and controllable does not get promoted anywhere near the network.
The operational-technology boundary. The separation between operational technology and enterprise IT exists for good security reasons, and it will not be dissolved for a data-science project. Any AI initiative that needs both field telemetry and enterprise asset data has to bridge that boundary without weakening it, which most pilots are not built to do.
Explainability and accountability. When an AI-informed decision contributes to an outage, a safety event or a disputed bill, regulators, ombudsman schemes and boards can ask why. “The model said so” is not an answer any operator will defend. Every AI-assisted operational or commercial decision needs a traceable line from source data to output.
Legacy integration cost. Each initiative that connects directly to historians, GIS, asset and meter systems pays the full integration tax alone: bespoke connections, bespoke mappings, bespoke security review across the OT boundary. The second project pays it all again. Integration spend crowds out the value the project was meant to deliver.
Underneath all four sits the data problem. Models acting on inconsistent data produce inconsistent decisions, and at utility scale that means thousands of dispatch, maintenance and service decisions drifting apart until a regulator, an auditor or a public inquiry asks the question.
05The regulatory landscape
None of that caution is optional; the regulatory perimeter is already in place. Five kinds of obligation matter most for energy and utilities, and while the named regulators differ by market, every developed jurisdiction enforces an equivalent of each.
Energy and market regulation. Economic regulators and market operators set reliability standards, licence conditions and the rules for participating in wholesale and network markets. An AI system that informs dispatch, trading, connections or network investment operates inside those rules, and its outputs have to be as defensible as any other basis for a regulated decision.
Critical-infrastructure security obligations. Energy is treated as critical infrastructure almost everywhere, with security and resilience duties that extend to the third parties and systems that touch essential services. In the European Union the network and information security regime (NIS2) classifies energy operators as essential entities with the most stringent duties; other markets enforce their own critical-infrastructure equivalents. An AI system that reads operational data and informs how the network is run sits squarely inside them.
Environmental and ESG reporting. Emissions, environmental performance and sustainability disclosure are moving from voluntary narrative to assured reporting, through climate-related disclosure standards such as the ISSB’s and the European Union’s corporate sustainability reporting rules. Figures that once lived in a slide now need lineage to source and will be tested by assurance.
Data-protection law. Privacy regimes such as the European Union’s General Data Protection Regulation and equivalent national laws govern the personal information utilities hold, and smart-meter interval data is personal data: it can reveal when a household is occupied, awake or away. Sending that data to external AI services raises questions many privacy teams cannot answer comfortably.
The direction of travel. The EU AI Act treats AI used as a safety component in the management and operation of critical infrastructure, including the supply of electricity, gas and water, as high-risk, with obligations covering data governance, logging, transparency and human oversight. Wherever your assets sit, that is a preview of where utility AI regulation is heading.
Read together, these frameworks converge on a single requirement: a utility must be able to demonstrate control over what its AI systems saw, did and decided, with evidence. That requirement is architectural, and it is exactly what a control plane exists to satisfy.
06The control plane approach in energy and utilities
An enterprise AI control plane is the infrastructure layer that sits between an organisation’s systems and its AI tools, a governed layer above the data platform you already run, that resolves the estate’s data into one consistent semantic layer and governs every interaction between the two. The full architecture is set out in the reference guide; what follows is how the pattern lands in energy and utilities specifically.
One semantic layer across the estate. The control plane connects to historians, SCADA, GIS, asset registers, meter data management and market systems where they are, resolves the same asset, the same feeder and the same connection point once, and stores the result as one governed, unified semantic layer inside the utility’s own tenancy, continuously hydrated from the sources. The systems of record keep doing their jobs and existing platform investments carry forward: weeks-scale deployment rather than a multi-year consolidation programme as the precondition for AI.
Least-privilege access on every interaction. Access rules are enforced at the moment AI consumes data, as least-privilege controls over the underlying data sets, inherited from the utility’s existing identity and access management. A field-operations copilot sees the assets and areas its user is entitled to. A market-facing assistant cannot reach operational telemetry it has no business touching.
Complete lineage on every assisted decision. Every operational or commercial decision assisted by AI carries a traceable record from source systems through transformation to output: which data, which model, which policy, whose authority. When a regulator, an ombudsman scheme or an inquiry asks why, the evidence already exists.
Deployment inside your own tenancy. The control plane runs inside the utility’s own cloud environment, on the cloud and model providers of your choice. Operational, meter and customer data is not transmitted to or processed on external systems, which keeps critical-infrastructure and personal data under the utility’s own legal and security boundaries and keeps the privacy and security assessment tractable.
- Each pilot integrates directly with historians, GIS and meter systems
- The same asset means different things to different models
- Access rules rebuilt per project, enforced unevenly
- Explaining a decision means forensic reconstruction across OT and IT
- One semantic layer across grid, asset, meter, SCADA and GIS data
- Every AI interaction passes one enforcement point
- Access inherited from existing IAM, applied every time
- Lineage and audit produced automatically for every output
Fig. 1 · Two operating models for utility AI: per-project integration versus shared, enforced infrastructure.
DataReadyAI implements this pattern as three layers: a semantic normalisation engine that resolves grid, asset and meter data into one stored, governed layer, an AI orchestration engine that routes work across clouds and models, and a governance and activation layer that enforces least-privilege access over the underlying data sets and maintains immutable audit trails. The platform deploys inside your own Databricks, Snowflake or BigQuery environment, and we are working with organisations across financial services, insurance and government.
07Use cases in depth
With the control plane in place, that list stops being aspirational. Here is how each use case works, and where the human authority sits.
Outage and fault prediction
Telemetry, weather feeds, asset condition and network topology are read together against one model of the network, so emerging faults and likely outages are flagged with the context an operator needs to act. Crews and switching plans can be positioned ahead of an event rather than dispatched after it. The control-room operator holds the decision, with the model surfacing the signal and its supporting evidence, not issuing the instruction.
Asset management and predictive maintenance
Condition, inspection, work-history and operating data are resolved onto the same asset, so maintenance is prioritised on the units that genuinely need attention rather than on a fixed calendar. Interventions can be deferred where the evidence supports it and brought forward where risk is rising. Asset engineers keep authority over the maintenance plan, working from a complete picture instead of a reconciliation exercise.
Load and demand forecasting
Consumption, embedded generation, storage behaviour, weather and market signals are combined into forecasts that reflect a grid reshaped by the energy transition. Because every input traces to a governed source, forecasts can be explained and challenged rather than trusted blindly. Planners and traders act on the forecast; the control plane makes its basis inspectable.
Compliance and ESG reporting
Emissions, reliability, environmental and sustainability figures are assembled from the same governed semantic layer the rest of the business uses, with every value traceable to source. The disclosure that took weeks of spreadsheet assembly becomes a governed output that finance and sustainability teams can stand behind under assurance, with lineage attached rather than reconstructed afterwards.
Network planning and connections
Hosting-capacity, connection and augmentation questions are answered from a current, governed view of the network model rather than from extracts that were already stale when they were pulled. Planners get consistent answers to the same question, and the assumptions behind each answer are visible and auditable.
Field and customer operations
Field crews and contact-centre teams, and the copilots that support them, see a single governed view of the asset or the customer, filtered by what each role is entitled to see. Fewer transfers, fewer repeated questions, and answers grounded in the whole record rather than one system’s fragment of it.
08Implementation considerations for utilities
Utilities that reach production tend to follow the same sequence, and it is deliberately unheroic.
Start with one domain and one workflow. Predictive maintenance on one asset class, or outage prediction on one part of the network. A bounded scope makes the risk assessment finite, gives the initiative a named owner, and produces a result the rest of the organisation can inspect.
Connect read-only first. The control plane’s first weeks are observation: scanning and mapping the estate, resolving assets and connection points, surfacing the real rather than documented state of the data. Nothing writes back to control systems, which keeps the initial security review, and the crossing of the OT boundary, proportionate and fast.
Bring operations, security and compliance in early. The functions that can veto an initiative at sign-off become its sponsors once they see least-privilege access, lineage and audit output working. Their requirements, including human-in-the-loop checkpoints wherever an output affects safety, supply or a customer, should shape the design rather than review it afterwards.
- One domain, one workflow, one named owner. Expand from evidence, not ambition.
- Read-only connection first. Observe and unify before anything acts, and cross the OT boundary carefully.
- Operations, security and compliance at the table from week one, not at sign-off.
- Human-in-the-loop checkpoints wherever decisions affect safety, supply or customers: switching, dispatch, connections, billing.
- Expand only once the semantic layer exists. The second workflow inherits the first one’s foundations.
The economics follow. The first workflow carries the cost of standing up the semantic layer and governance machinery; every workflow after it inherits them. That is why second and third use cases land in a fraction of the time, and why utilities that reach production tend to accelerate rather than stall again.
DataReadyAI’s deployment pattern for utilities follows this sequence directly: read-only connection and semantic discovery first, with first value typically inside 2 to 3 weeks and production-grade activation of the first governed workflow in 6 to 8 weeks. Access control inherits your existing IAM from day one, the platform is cloud- and model-agnostic across Databricks, Snowflake and BigQuery, and everything runs inside your own environment, so it fits the estate you have.
09Frequently asked questions
Can a utility run AI on SCADA and meter data without it leaving its environment?
Yes, and for most operational-technology and security teams it is the only acceptable pattern. A control plane deploys inside the utility’s own cloud tenancy, so operational, meter and network data is not transmitted to or processed on external systems. AI works against a governed, unified layer of grid, asset and meter data stored inside that tenancy, within the utility’s own legal and security boundaries.
How does a control plane help with critical-infrastructure security obligations?
Critical-infrastructure regimes come down to demonstrable control over the systems and data that keep essential services running, and over the third parties that touch them. A control plane enforces least-privilege access on every AI interaction with the underlying data sets and produces immutable audit trails as a by-product of normal operation, which is the evidence those regimes require. It does not replace your security programme; it gives it infrastructure.
Does this replace our SCADA, GIS or meter data management systems?
No. The control plane connects to SCADA historians, GIS, asset registers, meter data management and market systems as they are and resolves their data once into a governed, unified semantic layer stored inside the utility’s own tenancy, kept continuously current. The systems of record remain the systems of record, and existing operational and market reporting keeps running. That is what makes weeks-scale deployment credible.
How does governed AI support ESG and emissions reporting?
Emissions and sustainability figures are only as defensible as the data lineage behind them. Because the control plane resolves generation, network and meter data into one governed layer and records lineage on every value, ESG and emissions disclosures can be assembled from consistent, traceable data rather than hand-stitched spreadsheets, with the evidence a reasonable-assurance review now expects attached by default.
10Sources and further reading
- European Union, Regulation (EU) 2024/1689 (the EU Artificial Intelligence Act), including its high-risk classification of AI used as a safety component in the management and operation of critical infrastructure such as electricity, gas and water.
- European Union Agency for Cybersecurity (ENISA), Cybersecurity of critical sectors and the NIS2 Directive, under which energy operators are treated as essential entities.
- IFRS Foundation, ISSB Sustainability Disclosure Standards, including IFRS S2 Climate-related Disclosures.
- European Data Protection Board, guidance on the General Data Protection Regulation, including the processing of smart-metering data.
- DataReadyAI, Enterprise AI Control Plane: Definition, Architecture and Buyer’s Guide.