Start in the control room, because in this sector the argument is physical, and physicality is exactly what the usual framing of AI governance leaves out.

A July heat event, a transmission control centre. The state estimator solves; a contingency screen flags a post-contingency thermal overload on a 230 kV corridor; an advisory agent — fed the state estimate, the outage schedule, and the library of pre-studied reconfigurations — drafts a switching sequence to relieve the constraint. An operator reads it, checks it against the one-line, and accepts. The order goes to the EMS supervisory-control gateway, out to the substation RTU, and a breaker opens. This is a good afternoon. The recommendation was correct, the operator was engaged, and the constraint cleared.

Now run the tape forward eight months. The agent's acceptance rate has been effectively total since spring. An efficiency change goes through change management: recommendations in a routine class — matching a pre-studied pattern, with the system N-1 secure — now execute without waiting for the click. The ticket is properly approved. The access is properly provisioned. Nothing about the change was hidden, rushed, or non-compliant with the utility's own procedures.

The telemetry, throughout, is good. Every solution, every recommendation, every command to the RTU is logged with timestamps a post-event analyst would envy in most industries.

Then something operates in a condition the underlying study never covered — no lights out, but a sequence the planning engineers cannot reconcile with the study it supposedly matched — and a post-event review asks a question that sounds administrative and is not:

Which certified operator authorised the switching action that opened that breaker?

The record answers a neighbouring question with total confidence. The command was issued by a service account — call it svc-ems-advisory-prod. That account holds supervisory-control access on the gateway. The access was provisioned through the utility's access-management process, has an owner of record in operations technology, and sits inside a security perimeter maintained under the CIP family of reliability standards. The auto-execute behaviour traces to a change ticket with named approvers. Every link in that sentence is real, evidenced, and testable.

None of it is an answer to the question that was asked. It establishes that a system was permitted, on a standing basis, to issue a class of commands. It does not establish that any certified person authorised this operation, on this apparatus, under these system conditions. And in this sector the second half of that sentence is not decoration: switching authority has always been conditional — an instruction to operate is issued against a system state, and the state is part of the authorisation. The record holds neither the person nor the conditions.

FIGURE 1 · THE BRIDGING TICKET The record ends at a service account. The review expects a certified operator. THE OPERATIONAL RECORD what the trace supports state estimator solution heat event · 14:31:07Z contingency screen post-contingency thermal overload flagged advisory agent drafts switching sequence principal: svc-ems-advisory-prod auto-execute rule class-2 match · no operator action pre-studied pattern · conditions unrecorded supervisory control OPEN CB-5232 → substation RTU actor recorded: svc-ems-advisory-prod one principal · no operator identifier · no record of the autonomy window CHANGE TICKET CHG-41772 operator remains in the loop for all switching operations ASSERTION, NOT EVIDENCE THE RELIABILITY REVIEW what it expects A certified operator per action authority to direct switching on the bulk electric system sits with certified system operators, on shift, by name Conditions attached to the authority switching is authorised under stated system conditions — the conditions are part of the authorisation, not context A record that supports both an entitlement held by a service account establishes neither the person nor the conditions The record terminates at a service account. The review expects a certified operator under stated conditions. A ticket closes the gap.

The control-centre chain above, the service account name, the change ticket and the auto-execute rule are a constructed illustration, assembled from patterns documented in public specifications, published reliability guidance and vendor documentation for energy management systems. It is not a report of any real event, utility, operator or deployment, and no part of this piece describes client work.

The objections, stated properly

Two strong responses exist, and both come from people who know this sector better than any generalist writing about AI does. They deserve full strength before either is answered.

The first is the control-environment response. Utilities operating bulk electric system assets run one of the most heavily proceduralised change and access regimes in industry, and they run it under mandatory, enforceable standards with per-violation penalties — a distinction most sectors' AI commentary would kill for. The CIP family requires electronic and physical access to critical cyber assets to be controlled, monitored, and revoked on defined clocks; change management on those systems is a compliance obligation, not a habit; and the EMS sits behind an electronic security perimeter that is itself an audited artefact. Switching, meanwhile, has its own discipline that predates all of this: switching orders are written, reviewed, and executed step-by-step with verification, because the industry learned in hardware what happens otherwise. Nobody in a control centre forgot that actions need authorisation. The claim that an agent slipped into this environment unauthorised sounds, to a utility reader, like a description of a utility that does not exist.

The second is the human-gate response. The recommendation architecture was designed around a person: the agent proposes, the certified operator disposes. Every recommendation crossed a human. Even after the automation change, a person approved the rule that allowed the automation, and operators retain a supervisory override at all times. If human-in-the-loop means anything, this is it — and the sector's operating philosophy has said for decades that the operator is in command of the system.

Both of these are right about something, and what they are right about is not the thing at issue.

The CIP family governs the security of the system, not the authority of the action. Access control answers who could touch the system. It is a standing capability — an entitlement, in the vocabulary of the banking piece in this series — and it says nothing about whether any particular command was decided by anyone. The CIP family was written to keep unauthorised parties out of BES cyber systems, and it does that job. It was never written to evidence that each supervisory command issued by an authorised system traces to a qualified person's decision under stated conditions, because when the standards were drafted, the thing issuing commands at machine rate on its own initiative did not exist. Compliance with every access and change requirement in the family is entirely consistent with the authority question having no answer. That is not a criticism of the standards. It is a statement of their scope.

A gate that has said yes four thousand consecutive times is a latency stage, and the sector's own reliability body said so first. NERC's November 2024 white paper on AI and machine learning in real-time system operations makes precisely this point: human-in-the-loop operation requires explicit design decisions to ensure it is not human-in-the-loop in name only, and advanced technologies have historically failed not on the technology but on insufficient attention to the interaction between humans and the system. An operator who has accepted every recommendation since spring is not exercising judgement per action; the judgement moved upstream months ago, to wherever trust in the agent was actually formed, and the click that remains is a formality whose removal — as the constructed illustration shows — changes nothing observable except the latency. The white paper is guidance, not a standard, and I will come back to what that means. But the failure mode is named, in the sector's own literature, by the sector's own reliability organisation.

Which compresses to this: the sector's controls establish that the system was secured and that the humans were present. Neither establishes that the action was authorised, because authorisation — a qualified person deciding this action under these conditions — was never instantiated as a record anywhere in the chain. The environment is compliant. The question is unanswerable. Both are true at once, and no amount of maturity in the first fact produces the second.

What the 2026 instruments actually govern

It is worth being precise about the regulatory position, because energy in mid-2026 is routinely described as a sector where AI regulation is arriving — and the description is true in a way that makes the gap worse, not better. The freshest instruments in the sector are about AI. They are just not about this.

On 18 June 2026, FERC issued show-cause orders to all six FERC-jurisdictional RTOs and ISOs, directing each to justify within sixty days why its tariff remains just and reasonable without provisions tailored to large loads, or to file the tariff changes that address the issues the Commission identified — with a thirty-day informational report on how the operator intends to ensure adequate generation for existing and new large loads. The driver, named throughout the proceeding and its coverage, is the data-centre interconnection queue: gigawatt-scale computational facilities, most of them built to train and serve AI, arriving faster than the interconnection frameworks were designed to absorb.

On 16 July 2026, FERC went further and directed NERC to file new or modified mandatory reliability standards governing the integration of computational loads by 31 December 2026 — and, alongside the standards, changes to NERC's Rules of Procedure including registry criteria that would bring computational-load entities directly under the mandatory reliability framework as a registered class, with a Phase II work plan for additional standards due by 1 March 2027. That is a genuinely significant structural move: a new class of registered entity, defined by what the facility computes rather than what it generates or transmits, inside the compliance registry for the first time.

Read both actions for what they govern. The June orders govern how an AI facility connects to the grid. The July direction governs how an AI facility behaves as demand — its ride-through characteristics, its co-location arrangements, its effect on the interconnected system when a million GPUs shed load simultaneously. In both, the machine appears in exactly one role: a consumer of electricity. The question this piece opened with — the authority under which an AI system acts on the grid — appears in neither, is not the subject of any pending NERC standards project I could verify, and is not promised by the Phase II work plan, whose announced scope is additional computational-load standards.

FIGURE 2 · TWO QUESTIONS, ONE INSTRUMENT SET Governed as load. Inherited as operator. THE 2026 INSTRUMENTS · WHAT THEY GOVERN: THE DEMAND THE MACHINE PLACES ON THE GRID FERC show-cause orders · 18 June 2026 six orders to the RTOs/ISOs on large-load integration — 60 days to justify or reform tariffs for data-centre-scale connection FERC order · 16 July 2026 NERC directed: computational-load reliability standards filed by 31 Dec 2026 · registry criteria for a computational-load entity class · Phase II plan 1 Mar 2027 THE GAP the authority of the action — which certified person authorised this switching operation, under which conditions — has no sector instrument written for it THE OPERATING QUESTION · COVERED ONLY BY INHERITANCE the CIP family the cyber security of the systems — not the authority of actions operator certification the humans in the seats — a class the agent does not belong to the Nov 2024 white paper AI/ML in real-time operations — a posture, not a standard The instruments face the machine as a consumer of electricity. Nothing yet faces it as a participant in operating the system.

What the operational side has instead is a posture. The November 2024 NERC white paper on AI and machine learning in real-time system operations is a serious document: it surveys the roles AI can play in the control room, gives sustained attention to human factors, and treats the cyber risk of AI components in real-time operations as a first-order topic. Its expectations are the right ones — human-in-the-loop as a designed property, scoped deployment, monitoring, explainability. But a white paper attaches no compliance obligation to anyone. No utility can be found in violation of it, no auditor samples against it, and its expectations become enforceable only if and when they are translated into a standard through the NERC standards process — a translation which, as of the date on this piece, has not been initiated for this subject.

If that structure sounds familiar, it should. It is the same shape as banking's April 2026 position, examined at length elsewhere in this series: the agencies there revised the interagency model risk guidance, expressly placed generative and agentic AI outside its scope, and left each institution responsible for determining appropriate governance in the interval. Energy has arrived at the same posture by a different route — not by carving agents out of an existing framework, but by pointing its newest framework at a different question entirely. In both sectors the practical consequence is identical: the institution deploying the agent is, for now, the author of its own control specification, and whatever standard eventually arrives will be written against what the field has already built.

The physical fact: rollback that respects physics

Everything above is regulatory context. This section is why energy cannot simply import the answer from sectors that got there first — and why the usual framing of the agent-authority problem, built on financial-sector examples, understates what this sector needs.

In a servicing chain at a bank, the worst case is remediable: money moved wrongly can be moved back, a letter sent wrongly can be corrected, and the harm window is measured in days. The grid does not offer that deal. A breaker that opened can be re-closed in seconds — the topology is almost perfectly reversible — but re-closing restores the state, not the history. The protection operations the transient triggered have operated. The industrial customer whose process tripped on the voltage dip has lost the batch. The interval the system spent outside its studied operating envelope has been spent, and if a second contingency had arrived during it, the consequence would have compounded at electrical speed. Rollback, in the sense the software industry uses the word, restores topology and not consequence, and the gap between those two is exactly the set of things that make grid operations a licensed, certified, procedure-bound discipline.

  1. The consequence is irreversible even when the action is not. Most grid actions have a clean inverse — open has close, raise has lower. None of their effects do. This is the opposite of the software case, where the action is often hard to invert but the effects usually are.
  2. The timescale of harm is seconds. Electrical transients propagate in cycles; thermal and stability limits bind in seconds to minutes. Any control that requires a synchronous human decision inside that window is either bypassed in practice or fictional on paper. This single property drives the entire architecture of the companion piece: the human decision cannot live in the action path, so it must live somewhere else — and where it lives must be recorded.
  3. The system is coupled. A local action is never local. The interconnection is one synchronous machine, and the blast radius of a wrong operation is bounded by electrical distance and protection coordination, not by the org chart of the entity that made it. This is why the sector's accountability regime attaches to certified individuals and not only to firms: the person in the seat can affect assets their employer does not own.

This inverts the usual argument, and the inversion is the point. In the financial-sector version of this argument, the authority record is evidence — the thing that lets an institution demonstrate, after the fact, that a decision had an owner. Build it late and the cost is an ugly retrofit. On the grid, the authority record and the safety mechanism are the same object, because the only place a human decision can survive contact with a seconds-scale action path is in advance: a bounded grant, issued by a qualified person, scoped to operating conditions, checked at execution time. If that object exists, the evidence exists as a by-product. If it does not exist, then not only can nobody answer the review question afterwards — nothing was actually constraining the agent to the conditions the study assumed, at the moment it mattered. In this sector, the audit artefact and the control are the same artefact, and its absence is not a documentation gap. It is an unenforced envelope.

FIGURE 3 · ROLLBACK THAT RESPECTS PHYSICS Software rollback restores the state. Re-closing the breaker does not restore the afternoon. A SOFTWARE DEPLOYMENT A SWITCHING OPERATION Reversing the action redeploy the previous build; prior behaviour returns re-closing restores topology, not consequence: protection operations, process trips and the unstudied interval have already happened Timescale of harm minutes to hours, usually with an alerting window transients in cycles; thermal and stability limits bind in seconds to minutes — harm can complete before a human reads the alarm Propagation along mappable service dependencies; fire-breaks exist one synchronous machine; a local action propagates at electrical speed through a coupled AC system The accountable party a product or service owner, identified after the fact a certified system operator, on shift — the accountability unit is the certified seat, not the firm What the evidence must show who approved the release, and when who authorised this operation, under which system conditions, within which studied bounds — the conditions are part of the authorisation Where the action touches physics, the authorisation and its conditions must exist before the action, because nothing after the action can un-happen it.

And the deployment pattern that makes this urgent is not hypothetical. The most instructive production signal in energy this quarter is ADNOC and SLB's AI real-time operations centre — announced by the companies as live across ADNOC's full onshore and offshore drilling fleet, more than 120 rigs, developed and hosted inside ADNOC's UAE sovereign cloud, with company-published figures on engineering effort, incident response times and avoided downtime. The claims are the vendors' and the operator's own, and I am citing them as such rather than as audited fact. But the shape is what matters: fleet-scale, centralised, AI-driven operations across physical assets is not a pilot pattern in this sector. It is the reference architecture that national champions are shipping, with sovereignty and governance marketed as part of the release.

So the honest reading of the field is not "energy is cautious and the question is premature." It is: the operational deployment is proceeding at fleet scale, the demand side of AI has seized the entire attention of the sector's regulators, and the authority of AI action on physical systems is being governed, by default, by each operator's own change-management culture. That is the same deferral structure as banking's — with seconds where banking has days, and physics where banking has ledgers.

What fails, at mechanism level

Generic AI-risk arguments are cheap in every sector. Here is what specifically breaks, in this sector's own terms.

The certified-seat mapping collapses. The reliability regime's distinctive feature is that authority to direct operations of the bulk electric system attaches to certified individuals — NERC's System Operator Certification program exists precisely so that the person directing switching holds a live credential for that class of decision. The mapping the regime assumes is: action, to seat, to certificate. A chain in which recommendations execute under a service account maps every action to the same principal, which holds no certificate and occupies no seat. It is not that the wrong person is recorded. It is that the record's answer to "which certified seat does this action belong to" is a type error — the sector's equivalent of the bank's many-to-one entitlement collapse, but harder, because the expected terminal object is not just a named person but a credentialed one.

The autonomy window is configuration, not grant. The auto-execute rule — class-2 recommendations, N-1 secure, pre-studied pattern — looks like a bounded delegation, and defenders of the deployment will present it as one. Look at what it is made of. It is configuration: a standing predicate, evaluated by the same stack that generates the recommendations, changed through tickets, owned by nobody on shift. No record is produced when a window opens, closes, or changes; no operator's identity is bound to any particular period of autonomy; and when the review asks "was the system inside the approved envelope at 14:31:07, and who approved that envelope for that afternoon" the answer must be reconstructed from configuration history and telemetry — which is exactly the reconstruction-from-logs approach this series has argued, in sector after sector, does not survive contact with an examiner. A window that leaves no record of being open is not a grant. It is an entitlement with a filter on it.

Two operational consequences follow, and they are the ones that hurt during an event rather than after one. The first is revocation. When the agent's recommendations come under suspicion — a bad pattern in one study class, say — the utility's options are to revoke the service account's supervisory-control access, which severs every automated pathway including the ones behaving correctly, or to leave it, accepting unbounded exposure while the investigation runs. There is no object with the granularity of "this class of autonomy, granted for these conditions," so there is nothing between the blunt outage and doing nothing. In a sector where the automated pathway may itself be load-bearing for reliability, the blunt outage is not obviously the safe choice — which is a sentence nobody should be comfortable writing.

The second is population scoping. After a defect is found — the study that under-modelled a condition, the recommendation class that was wrong in a corner — the first question is which operations were taken under the defective authority. If authority is ambient, the population is every command the service account issued in the window, across every study class and every substation, and the review must over-scope at enormous analytical cost or under-scope on judgement it cannot evidence. The banking version of this problem costs remediation budget. The grid version costs the credibility of the post-event analysis itself, in a sector whose entire safety culture rests on the belief that events are reconstructed exactly.

The limits of the argument, and what would falsify it

Four things could be wrong here, stated at their strongest.

A counterexample deployment would confine the claim. I am describing the prevailing pattern in the agent frameworks and EMS-adjacent architectures whose documentation is public. A utility whose gateway mints a per-action or per-window execution credential, bound to a certified operator's identity and to stated system conditions, and verified at the point of execution, already has the object — and this piece does not describe them. I have not found such a deployment in any primary source, but the sector publishes less architecture than most, and absence of publication is weak evidence. One public, checkable counterexample would reduce this piece to a description of everyone else.

I cannot quantify the gate's decay, and I will not pretend to. The claim that a routinely-accepted recommendation stream turns the human gate into a latency stage is a mechanism argument, supported by the human-factors literature the NERC white paper draws on — not by a measured acceptance-rate curve from real control rooms. I could not find a published measurement of operator acceptance rates for AI switching recommendations over time, and anyone who quotes one should be asked for the primary source. If field data eventually showed operators sustaining genuine per-action scrutiny at high recommendation volumes indefinitely, the gate-decay half of this argument would weaken, though the record half — the click, however genuine, produces no grant object — would stand.

The regulatory reading could break toward specification. NERC's standards process could take up operational AI directly — a standards authorization request could be initiated next quarter, and the Phase II computational-load work plan due 1 March 2027 could in principle widen. In that world, a utility that built the authority layer early built it early, and absorbed a design constraint while its agent estate was small. The asymmetry is the same as in every sector this series has covered, but sharpened by the compliance model: NERC standards, once effective, are mandatory and enforceable with penalties, and they are written through a process in which the industry's existing practice is the primary input. What the field has built by the time drafting starts is not just the cheapest compliance position. It is the raw material of the standard.

The strongest falsifier is behavioural, and I cannot close it. If post-event reviews and compliance audits in practice accept the change ticket and the access records as sufficient — if "the automation was approved and the account was secured" is treated as answering "who authorised the operation" — then the gap has no institutional consequence and this argument reduces to a preference about evidence. I have no basis for claiming reviewers reject it, and I will not invent one. What I can point at is the sector's own settled practice for humans: nobody accepts "the lineman had a key to the substation" as an answer to "who issued the switching order." The entire discipline of switching orders exists because access and authorisation were understood, in hardware, to be different things. The argument of this piece is that the sector already believes its own doctrine — for people.

One more limit, stated plainly because it cuts against the commercial use of arguments like this one. Nothing above claims that an agent-caused switching event has occurred, that any utility's deployment is unsafe, or that the constructed illustration has a real-world instance. I am not aware of a published incident in this sector turning on this failure, and if I were, it would be cited in the sources rather than implied in a paragraph. The argument concerns what an operator can demonstrate when asked, and what is actually constraining the machine in the interval before anyone asks — a narrower claim than a prediction of harm, and the only kind this series makes.

What an answer would have to be

This is the teardown, so I will name the properties and stop; the construction is the companion piece's job.

  1. The grant is an object created at the recommend–execute boundary. Not an entitlement filtered by configuration, and not a click that leaves no residue. Something is constructed when authority to execute passes, or there is nothing to evidence and nothing enforcing the envelope.
  2. The grant is scoped to operating conditions, and the conditions are checked at execution. A grant that does not carry the system state it was issued against cannot answer this sector's authority question, because here the conditions are part of the authorisation. Checking them at issuance only is reconstruction waiting to happen.
  3. It terminates in a certified operator, and the terminal link carries the credential. The regime's unit of accountability is the certified seat. A chain of service identities, however well-formed, ends in the wrong type. The root grant must bind a person, their live certification, and their shift.
  4. It is pre-positioned, because the action path has no room for a human. The seconds-scale timescale means the operator's decision must be made ahead of need — at shift start, at study approval, at window issuance — and must expire on condition change, not only on the clock. This is the property the other sectors' versions of this argument never needed, and it is the one that makes the energy construction distinctive.

None of this is exotic to the sector. It is a machine-rate version of the switching order: written, bounded, condition-laden authorisation from a qualified person, issued before the action, verified at the point of work. The industry has run on that structure for a century. What has not been done is building it into the layer where agents now operate — and the interval in which to do it on the field's own terms is the interval before the standards process arrives, which, on the evidence of this summer, is currently pointed at the other side of the meter.