Companion page to the Utility Voice article The Questions We Need Answered, September 2026. Every question the Autonomous Enterprise series has put to the community, harvested from the ten articles. Article numbers in parentheses refer to the series index on the home page.
Roughly fifty questions appear across the series. They are not interchangeable — they sort by who has to answer them, and that sort is the most useful thing in this document. A question you put to your own team is a readiness exercise. A question you put to SAP is a procurement position. A question you put to a peer is a request for evidence. Mixing them is how a good question gets asked of the wrong room.
A. The Regulator Test — the spine of the whole series
This one question, in slightly different clothes, appears in three separate articles (2, 7, and by reference in 5). It is the series’ load-bearing question.
If your utility deployed an AI agent into production tomorrow, could you tell your regulator:
- Who authorized it to exist?
- What rules govern what it should be doing?
- Who is watching what it actually does?
- Where does it sit in your organization?
- How would you shut it down?
“If more than one of those gets a shrug instead of a name, the technology is ready well before the organization is. That is not a reason to avoid the autonomous enterprise. It is the project plan.” — Article 7
B. Questions to ask inside your own utility
The self-assessment set. These are the ones a reader should be able to take into their own Monday morning meeting.
On governance and accountability
- If not SAP’s governance framework, then what? (1)
- How are you planning to operationalize agentic AI, with true write access to production, in a way that satisfies your security team, your compliance function, your internal audit, and your regulator? (1)
- When an agent acts on production data — closes a work order, adjusts a rate schedule, dispatches a field crew — who is accountable? (1, 7)
- Would we have let a new employee do this on day one, unsupervised? (7 — the test for the “act” tier)
- Who approved capability thirty-one? (7 — the capability-creep question)
- Who is accountable for the integrity of AI-generated code accumulating in our internal tooling right now — code no single developer wrote or reviewed line by line? (7, 8)
On data
- When an agent closes a work order, recommends a switching plan, or proposes a rate adjustment, what exactly is it reading — and can we vouch for it? (3)
- Can you tell your regulator, and your own operators, that the data your agents read is governed, current, and traceable to a source you trust? (3)
- Does this data mean what the AI thinks it means? (7 — the question a technical review never asks)
- Not “how do we migrate our data lake into BDC?” — article 3 names that as the wrong first question. The right one is what to federate in place, what to replicate, and what to leave alone.
On the customer
- When a customer-facing agent answers a ratepayer next year, what customer does it actually see — and is that customer real, current, and consented? (4)
- If a customer-facing agent went live tomorrow, could you guarantee it saw one accurate, consented, current view of each ratepayer — and knew exactly where its authority stopped? (4)
- Which product owns which job — and which one owns the truth? (4 — for the CX lead and the data governance lead, in the same meeting)
On integrations and the API policy
- Which of our integrations sit on the wrong side of the published-API line? (6)
- Which of our AI experiments are driving in an endorsed lane? (6)
- What happens to our limits when agents multiply the traffic? (6)
- Have you run the three-pile sort on your integration landscape? What fraction landed in pile two — and did any mission-critical flow turn out to be standing on ODP-RFC? (6)
- Have we modeled 2027 API consumption against the documented limits — calls per prompt, prompts per user, users per process? (6)
On cost
- Can a utility predict and control what an autonomous SAP process will cost? (9 — the article’s central question)
- How are we planning to treat metered AI consumption in our rate case? (9)
- Have we drawn the line between the read tier and the act tier in writing, before an incident forced it? (7)
On the security surface
- Has anyone put Joule Work Desktop through a security architecture review? (9)
- Have we classified any of our BTP AI pilots against Annex III? (8)
C. Questions to put to SAP and your account team
The procurement set. These are negotiating positions, not curiosities — several are explicitly framed in the series as things to get into the agreement rather than bookmark.
The six cost questions — article 9 calls these “the most reusable thing in this article”
- How many actions will a given business process generate, in our configuration?
- What precisely constitutes one action in each agent implementation we are licensing?
- How do retries, branches and tool invocations map onto actions?
- Can consumption be attributed to a named business process or cost centre?
- Can we impose a hard ceiling, and what happens at it?
- Can SAP return a pre-execution estimate, or a bound, before an intent is dispatched?
Questions one through three are the ones with no published answer today. That is the gap, stated as narrowly as the series states it.
On the API policy
- Is the architecture we intend to run on the validated endorsed list — and what does it take to get it there? (6. Note: do NOT ask about “substitutability rights”; article 6 establishes that language exists nowhere in the policy or FAQ.)
- Where does the overage penalty land in the new Premium AI model, given the deck scopes the 30-point discount reduction to the packages being phased out? (9)
- Is remediation of integrations relying on non-published APIs inside our RISE scope, or ours? Ask before you sign. (6)
On certification and compliance
- Is your standard cited in the Official Journal? (8 — the question that settles a vendor certificate claim)
- EN 18286 has been on the shelf since July. What is your plan for it, and what happens to your position the day it is cited? (8 — the harder follow-up)
- What does Verification Seal verification actually test? Who can grant it, revoke it, and audit it? (2)
- Does agent inventory extend to tool-level dependencies, or only to agents? (7 — determines whether it answers an auditor or gestures at one)
On the 2026 acquisitions — added 2026-09-07 from article 10 (Reltio closed May 7, Dremio July 6, Prior Labs July 17, n8n stake May 12; status as of Sept 7: announced and closed, not delivered)
- Which master data product is an IS-U shop supposed to standardize on, now that Master Data Governance and Reltio both sit inside Business Data Cloud? (10)
- Which agent actions belong on the governed backbone (Integration Suite) and which on the agile layer (n8n in Joule Studio)? A governance decision dressed as a tooling one; runs straight into the OT boundary. (10)
- When does a tabular foundation model (TabPFN / RPT) become a product a regulated utility can license and put in a rate case — rather than a benchmark under an evaluation-only license? (10)
- What is generally available today — not what was announced in May? (10, Honest Caveats — the question to ask the account team in place of the scorecard)
The standing “what we still need to influence” asks (compiled across 1, 2, 3, 4, 5, 7)
- Where does agent authority stop at the OT boundary — SCADA, ADMS, OMS? Asked in six of nine articles and never resolved by any source.
- Published NERC CIP mapping for the agent governance stack — access management, change control, evidence generation.
- Agent identity lifecycle guidance: provisioning, credential rotation, certification, deprovisioning.
- SAP-aware SOAR response actions for agents: suspend an agent, quarantine its outputs, revoke its seal.
- Agent-specific detection content, and the guarantee that agent actions are distinguishable from human actions at every hop.
- A utilities lane in the AI Golden Path — IS-U data products, meter-to-cash agent patterns, the OT boundary.
- Right-sized BDC entry tiers so a co-op or municipal can validate without an enterprise-scale commitment.
- Post-promotion pricing commitments, not promotions.
- Security for the autonomous enterprise cannot become an upsell.
D. Questions to ask each other — the peer-evidence set
Every one of these is a “has anyone actually done this” question. They are the ones that make a working group worth attending.
- Has anyone successfully negotiated a hard cap or an alert threshold on AI consumption — and what did it cost you elsewhere in the agreement? (9. “I would rather hear it from a co-op or a municipal that actually signed one.”)
- Has anyone built the capability registry — a living inventory of every AI tool, its owner, and its risk tier — and did it survive a real integration backlog? (7)
- Has anyone taken the accountability question to an internal auditor and gotten a useful answer back? (7)
- Has anyone asked a vendor whether their standard is cited in the Official Journal, and what came back? (8)
- Is anyone treating a CRA declaration as CIP-013 evidence today, and how did your auditor react? (8)
- Has anyone inventoried the AI experiments touching SAP data, or modeled agent-era API consumption against the published limits? (6)
- Has your account team told you which master data product you are meant to be on now that there are two — and what did they say? (10)
- If you have numbers — even rough ones — bring them. (6. The recurring ask: compare inventories before renewal season and negotiate from evidence rather than anecdote.)
E. The questions nobody has answered
The series is consistent that the gap list matters more than the disagreement list.
- The OT boundary. Neither SAP’s published architecture, nor the AI Golden Path, nor the DSAG survey answers where agent authority stops relative to SCADA, ADMS and OMS. (5: “An agreement list is drawn from what everyone talks about. The gap list is drawn from what no one does, and that silence should worry us more than any disagreement.”)
- How many actions a real business process generates. SAP has defined the unit and published the rate. The mapping from a utility process to a billable action count has no published answer. (9)
- Whether a European conformity artifact survives a CIP-013 audit. Nobody has run it end to end. (8)
- How the agent governance stack maps to NERC CIP. Every utility is currently doing that translation alone. (2, 7)
- Where the n8n/Integration Suite split lands at the OT boundary. SAP has stated the split (deterministic backbone vs. human-in-the-loop layer) but not where either stops relative to a switching order. (10)
- What the affordability question even looks like in a docket. Arizona’s AI docket named affordability as the Commission’s responsibility, then asked seven topics, none of which can produce an answer about cost. (9)
F. The one-question-per-article spine
If you would rather read chronologically than by room, each article closes on a single question:
| # | Article | The question it leaves you with |
|---|---|---|
| 1 | Why It’s the Right Move | If not SAP’s governance framework, then what? |
| 2 | Who Secures It | Could you tell your regulator who authorized your agent, what rules it follows, who watches it, where it sits, and how you’d shut it down? |
| 3 | The Data an Agent Reads | Can you vouch for what your agents are reading? |
| 4 | The Customer an Agent Sees | Is the customer your agent sees real, current, and consented? |
| 5 | The Agreement We Aren’t Noticing | If everyone agrees the foundation comes first — what is your utility waiting for? |
| 6 | The Audit We Already Owe | Where are you in the integration inventory? |
| 7 | The Accountability Gate | Who owns the outcome when an agent acts? |
| 8 | Europe Certifies the Artifact | Is your vendor’s certificate the thing you think it is? |
| 9 | The Meter Is On | Can a utility predict and control what an autonomous SAP process will cost? |
| 10 | The Questions We Need Answered | Can we answer each other? |
