Planning and forecasting
Models influence capacity, demand, maintenance, weather, investment, and contingency assumptions.
AI is entering the systems that plan, operate, monitor, and defend essential infrastructure. In operational technology, the relevant standard is not whether a model usually performs well. It is whether the system remains safe under abnormal conditions, attack, degraded communications, and incomplete information.
DOE identifies unintentional failure, adversarial attack, hostile AI use, and compromise of the AI software supply chain as critical energy risks. Its current AI-FORTS program separates securing infrastructure from AI, securing it with AI, and securing the AI used in operations.
AI can improve forecasting, anomaly detection, inspection, maintenance, cyber defense, load management, restoration planning, and operator awareness across complex systems.
A model can fail outside its training distribution, be manipulated through data or interfaces, automate a bad response faster, or remove the operator’s ability to understand and intervene. Essential service magnifies small control failures.
The relevant question is not whether AI appears in the workflow. It is whether its output changes attention, access, price, timing, treatment, judgment, or a person’s practical ability to obtain review.
Models influence capacity, demand, maintenance, weather, investment, and contingency assumptions.
AI can recommend or execute changes in grids, transport, water, communications, and industrial systems.
Detection and response systems prioritize alerts, isolate assets, and recommend action under uncertainty.
Prediction determines which assets receive attention before failure.
Decision support shapes restoration, resource allocation, public warnings, and interdependency management.
Critical-infrastructure governance combines sector regulation, reliability standards, safety engineering, cybersecurity, emergency authority, procurement, and voluntary AI risk frameworks. The control environment must be specific to the physical process.
DOE’s AI-FORTS program addresses AI-enabled attacks, AI for defensive capability, and hardening AI used to operate, control, or defend energy systems. Primary source →
NIST is developing lifecycle practices for trustworthy AI across IT, operational technology, industrial control, and supply chains. Primary source →
DOE’s assessment identifies four broad categories and calls for regularly updated, risk-aware deployment guidance. Primary source →
DOE and LLNL’s Stormbreaker testbed evaluates LLM and agentic AI behavior in power and operational-technology environments. Primary source →
Critical-infrastructure verification must be scenario-based, adversarial, and tied to physical consequence.
| VERIFICATION LAYER | THE QUESTION | REQUIRED EVIDENCE | FAILURE IF OMITTED |
|---|---|---|---|
| Operational envelope | Under what loads, environments, states, and dependencies is behavior validated? | Scenario set, limits, uncertainty, out-of-distribution detection, and safe-state rules. | A system extrapolates beyond evidence inside a live physical process. |
| Security and supply chain | Can inputs, models, tools, updates, or dependencies be compromised? | Threat model, provenance, access control, red-team results, signing, and component inventory. | The control system trusts manipulated data or a compromised AI component. |
| Human and independent protection | Can operators understand, reject, isolate, and recover without the AI? | Alarm design, training, authority, manual mode, independent interlocks, and drills. | The nominal human fallback depends on the same failed system or arrives too late. |
| Incident and recovery | Can the operator reconstruct action and restore essential service safely? | Immutable logs, clock synchronization, decision trace, rollback, continuity plan, and exercises. | The organization cannot distinguish model failure, cyberattack, operator action, or cascading dependency. |
Operational rule: No AI should receive operational authority that exceeds the tested envelope, independent protection, and recovery capability of the system around it.
A concrete pathway reveals where a nominally advisory system becomes practically decisive.
A load-management agent recommends automated demand response during extreme heat. Sensor degradation causes the model to underestimate demand in one region.
The model receives incomplete telemetry but does not cross its confidence threshold.
Automated controls reduce reserve in the wrong area.
Operators receive multiple downstream alarms without a clear originating explanation.
Manual intervention depends on interfaces optimized around the agent’s recommendations.
The Observatory tracks documented events involving energy, water, transport, communications, industrial control, autonomous systems, cyber defense, and infrastructure accountability.
Infrastructure leaders need an authority map that joins AI governance to system safety and operational resilience.
Include recommendations that operators routinely accept.
List conditions, dependencies, data quality, and states outside evidence.
Fallback cannot share the same failure mode.
Define permissions, command limits, rate limits, approval, and isolation.
Exercise ambiguous, cascading, and communications-degraded scenarios.
Controls must reflect the actor, authority, system, population, data, consequence, and environment of failure.
Use least privilege, command allowlists, rate limits, approvals, and hard interlocks.
Document hazards, envelope, scenarios, assumptions, margins, and residual risk.
Use separate sensors, deterministic limits, manual modes, and fail-safe states.
Exercise poisoned data, prompt attacks, compromised tools, outages, latency, and ambiguity.
Sign, stage, validate, monitor, approve, and roll back versions and components.
Maintain logs, drills, offline procedures, restoration priorities, and cross-sector coordination.
A focused review follows one deployed or proposed AI system from signal to physical consequence. It tests authority, safety evidence, cyber exposure, independent protection, human control, recovery, and incident accountability.
This brief relies on selected U.S. energy and AI risk-management authorities. It is not engineering, cybersecurity, regulatory, or legal advice and does not state the requirements governing every infrastructure sector, operator, system, or jurisdiction.
Synthetic Outlaw Research. “AI in critical infrastructure: automation, resilience, and human control” Institutional Risk Brief 09, version 1.0. July 21, 2026. https://www.syntheticoutlaw.com/industries/critical-infrastructure.html.