All briefs
Brief 04/05 Critical Infrastructure & Energy Updated July 2026 8 min read

EXECUTIVE BRIEF · CRITICAL INFRASTRUCTURE & ENERGY

AI for operations that can't depend on the public cloud

Energy and critical-infrastructure operators run essential services under NIS2 and strict OT security constraints. On-premises and network-isolated AI agents bring modern assistance to engineering and operations without introducing external dependencies.

For operators' CIOs, CISOs, OT security leaders, and heads of engineering and operations.

The critical-infrastructure edition as a print-ready PDF — OT segmentation, NIS2 evidence, and knowledge-capture workflows for your security and operations leads.

Mapped to NIS2Data sovereigntyEU AI Act OT-segmented & air-gapped

The pressure

What is forcing the decision

Essential-service resilience

NIS2 raises the bar for security and resilience of essential and important entities, including any AI they introduce.

OT/IT segmentation

Operational technology environments are segmented and often offline; hosted AI cannot cross that boundary safely.

Aging workforce and knowledge

Deep operational knowledge is retiring; capturing it in accessible, governed AI is increasingly urgent.

Knowledge loss as experts retire

Decades of tacit operational know-how leave with retiring engineers. Private retrieval over manuals, maintenance logs, and incident history preserves that expertise in a governed, searchable form inside the OT boundary.

Why on-premises

The case for private deployment

On-Prem Private AI for Energy & Critical Infrastructure

A network-isolated, optionally air-gapped platform brings AI to engineering and operations without adding external dependencies that expand the attack surface or violate OT segmentation. Logging and access controls map cleanly to NIS2 obligations for essential entities.

Compliance mapping

Mapped to your obligations

NIS2

Network isolation, access control, and logging support resilience and incident-handling obligations.

Data sovereignty

Operational and grid data stays inside the operator's perimeter and control.

EU AI Act

Human-oversight and documentation controls for operational high-risk use.

Systems & data

Where the agents actually work

Procedures, SOPs & manuals
Equipment manuals, switching procedures, and safety documentation made answerable in the field instead of searched page by page.
Maintenance history & work orders
Decades of asset history becomes queryable context: what failed, what was tried, and what actually fixed it.
Incident & outage records
Post-incident reports and operator logs surface precedent during response, when nobody has time to read an archive.
Historian and asset data (read-only)
Contextual reads from the process historian for advisory answers, inside the segmentation model your OT security team already enforces.

First workflows

Where to start for fast payback

First workflows for deploying NIS2-aligned private AI in energy and critical infrastructure.

  1. Engineering knowledge assistant

    Private retrieval over manuals, procedures, and maintenance history gives engineers grounded, cited answers — capturing retiring expertise.

  2. Maintenance and work-order support

    Agents draft work orders and summarize asset history from internal systems, speeding planning under audit.

  3. Incident and procedure guidance

    Agents surface the right procedures and prior incidents from internal sources during response, inside the perimeter.

  4. Regulatory and safety reporting

    Agents assemble internal data into first-draft compliance and safety reports for expert review.

The first 90 days

A phased path to production

  1. Days 0–30

    Deploy in the IT zone, prove the segmentation story

    Begin outside the OT boundary with corporate engineering documentation. This gets the platform, logging, and access model reviewed by OT security without touching the process network.

    Exit criteriaOT security approval of the deployment pattern and data-flow direction.

  2. Days 31–60

    Index the knowledge that is walking out the door

    Ingest manuals, SOPs, and maintenance history for one asset class or site. Engineers ask real questions; the answers cite the procedure and revision, which is what makes the output usable in a safety context.

    Exit criteriaA knowledge assistant in daily use by one engineering or maintenance team.

  3. Days 61–90

    Move inside the segmented zone

    Deploy an isolated instance in the OT or plant zone for incident and procedure guidance, running with no egress. Log every retrieval so the deployment produces NIS2 resilience evidence rather than consuming it.

    Exit criteriaAn air-gapped instance serving operations, with logging mapped to your NIS2 reporting.

The cost model

Why the economics work differently

Operators do not measure AI in tokens; they measure it in avoided truck rolls, shorter outages, and procedures found in seconds rather than hours. The economic case rests on availability — a system that only works when the corporate network reaches the internet cannot be relied on during exactly the events where it would pay for itself.

Downtime dwarfs licence cost

Minutes of restoration time carry costs that make the platform line item close to a rounding error, which is why availability outranks unit price.

Expertise is a wasting asset

Knowledge capture has a deadline set by retirement dates, not budget cycles; deferring it raises the cost of every future incident.

One platform across IT and OT zones

The same deployment pattern serves engineering, maintenance planning, and compliance reporting without a separate tool and assessment for each zone.

Compare the two models in detail: committed flat pricing vs. pay-as-you-go.

Proof points

What similar organizations achieve

−45% procedure lookup time
Zero OT boundary crossings
−35% work-order prep time

Proven in a transmission operator

A grid operator deployed an engineering knowledge assistant inside a segmented OT zone. Engineers accessed cited answers from maintenance history and procedure libraries without any external connectivity — preserving expertise as senior staff retired.

Proven in a utilities company

A water utility used on-prem incident-guidance agents during response drills. Procedure retrieval stayed in-network and every agent action was logged for NIS2 resilience documentation.

Objections

What buying committees push back on

"Nothing new goes inside the OT boundary."

That instinct is correct, and it is why the first phase sits entirely in the IT zone with read-only corporate data. The OT-side instance is introduced only after the segmentation, logging, and access design have been reviewed — and it runs with no outbound path at all.

"Our documentation is a mess — the answers will be wrong."

Retrieval exposes documentation quality rather than hiding it: unanswerable questions and conflicting procedure versions become a visible backlog. Most operators treat the first indexing pass as a documentation audit they had been deferring anyway.

"We are not putting AI anywhere near control actions."

Nor should you yet. These workflows are advisory and read-only by design — surfacing procedures, history, and precedent to a qualified human. Any write path into an operational system requires explicit approval gates and network zoning, deliberately kept out of the first 90 days.

Evaluation checklist

Questions to put to any vendor

  • Can it run fully inside a segmented zone with no outbound connectivity and no cloud dependency?
  • Does every answer cite the procedure, revision, and date, so it can be trusted in a safety-relevant decision?
  • What is the update path for models and software into an isolated zone, and who controls the cadence?
  • Does the logging output map to the incident-handling and reporting evidence NIS2 expects of essential entities?
  • Can the same platform serve corporate engineering and plant operations without a second procurement?

The full procurement version: Enterprise AI Agent RFP Checklist · On-Prem AI Reference Architecture

Questions

What leaders ask first

Can this operate inside a segmented OT network?

Yes. The platform deploys into isolated network zones and can run fully air-gapped, with no dependency on external inference endpoints — so it respects OT/IT segmentation.

How does it help with NIS2?

Network isolation, role-based access control, and complete audit logging map to NIS2 obligations for essential and important entities, and on-prem deployment avoids introducing new third-party risk.

How do you capture retiring workforce knowledge?

Ingest manuals, SOPs, maintenance logs, and incident post-mortems into a private retrieval index. Engineers query in natural language and receive cited answers — institutional knowledge stays accessible after experts leave.

Can AI touch SCADA or live OT systems?

The platform supports read-only retrieval and advisory workflows first. Action integrations into OT systems require explicit approval gates and network zoning — the architecture is designed for segmented deployment, not blanket OT access.

What is the right first workflow for utilities?

Engineering knowledge assistant or incident procedure guidance: immediate operational value, read-only data access, and no new external dependencies in the ICT supply chain.

Does the assistant keep working during an outage or network event?

An instance deployed inside the operational zone continues serving procedure and incident retrieval with no dependency on corporate connectivity or the public internet. Availability under degraded conditions — precisely when the knowledge is most needed — is usually the deciding argument for on-premises deployment in critical infrastructure.

The briefing

Thirty minutes, built around your constraints

For Critical Infrastructure & Energy, we walk your security, risk, and platform leads through the deployment model, the compliance position, and the first workflow worth funding. Three things we cover:

  1. Segmentation-safe deployment

    Where the platform sits relative to your IT/OT boundary, and what crosses it — usually nothing.

  2. Knowledge capture, concretely

    Which document sets to index first for the biggest reduction in lookup time and succession risk.

  3. NIS2 evidence by default

    How access control and retrieval logging feed the resilience and incident-handling documentation you already produce.

Briefs for other regulated industries