re-ai-gov Join the waiting list

Kennisbank

AI governance for energy companies: getting a grip on what's really running

What makes the energy sector different

An energy company combines two worlds that rarely have the same owner. On one side is the operational technology: measurement and control systems, grid management, maintenance of critical infrastructure. On the other side is the office: customer contact, billing, planning, legal and compliance departments. AI shows up in both, but with a different balance between risk and convenience. In the operational layer, an AI application quickly touches systems where downtime or a wrong decision has direct consequences outside the organization. In the office layer, it is more often about text, data and decision support, with a risk that resembles other sectors more closely. Governance that treats these two layers as one misses the point: what is an efficiency gain in one layer is a matter of safety and oversight in the other.

On top of that, energy companies often operate under heightened supervision, are bound by sector-specific reporting obligations, and work with data that touches on national infrastructure. That makes the question "who has deployed AI here, and on what" weigh heavier than in an average office environment. The regulatory content behind that — which obligations exactly apply and when — is covered elsewhere; here the focus is on the mechanism by which an organization gains and keeps sight of what is going on.

The IT list is not the full picture

Anyone who asks which AI systems are in use will get a list of approved tools from the IT department. That list is a starting point, not reality. A planner who uses a language model to summarize maintenance reports, an analyst who feeds an external model with measurement data to recognize patterns, a contract employee who consults a chatbot during an incident protocol: this often happens without a request having been submitted or approval having been sought. Not out of ill will, but because it works and nobody has asked about it.

The core of an inventory is therefore not ticking off the known systems, but mapping out what is actually happening. That requires a different tone than an audit. Anyone who wants to know what an employee uses must ask without attaching a penalty to it — otherwise the answer disappears just as quickly as the usage itself. What that conversation looks like and why a sanction backfires is described in how you prevent employees from using a tool nobody knows about. A specific risk within that broader picture is entering company data — measurement data, contract terms, network data — into a free chat window outside the organization; what is at stake there and how to recognize it is covered in how you prevent company data from disappearing into a free chat window.

Classifying by role and risk, not by department

After the inventory comes the question of what a system actually does. An AI application that rewrites text for a customer letter has a different role than a model that helps decide on maintenance planning based on sensor data. The classification must record that role, and the risk level that goes with it, regardless of which department happens to use the tool. This is where the energy sector calls for its own interpretation: a tool that is harmless in a marketing team can carry a different weight in a grid management team because the outcome feeds into a physical system.

This approach — taking inventory, classifying, incorporating into existing governance — is not unique to energy. Similar issues arise in organizations that work with physical installations and safety risks, as described regarding AI governance at installation companies with a technical and operational practice and regarding AI governance in construction where planning and execution come together. Sectors with strict supervisory requirements, too, as seen in AI governance in healthcare where patient safety and oversight come together, show that the shape of governance shifts as the consequences of an error grow larger. Anyone who makes that comparison sees that energy is not unique in the question, but rather in the weight of the answer.

Connecting to what already exists

A governance set that is laid alongside the existing risk structure works better than a new framework next to it. Energy companies generally already have a risk management structure for operational safety and compliance. AI governance should be an extension of that, with the same reporting lines to the board and regulator, not a separate process that has to be maintained apart and that one day sits next to the other risk reports without ever coming together.

From overview to insight into the work itself

Once it is clear which AI applications exist and what risk they represent, another question follows: what does that mean for the work people are doing now. An inventory shows what is running; a work scan shows what that running means for tasks, roles and capacity. The FTE TO AI work scan calculates, per task, what portion of the work can be taken over by AI, placing a capacity picture alongside the risk picture. That is the logical next step after an inventory: not just knowing what is happening, but also what that means for the organization that has to work with it.

Andrewde assistent van de Responsible AI Scan

Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.