Utility AI Weekly — September 18, 2026

Inaugural issue. The research log behind this digest started on Tuesday September 16, so this week’s window — Monday September 14 through Friday September 18 — is thinner than it will be once the daily log has run a full cycle. Seven in-window items made the cut. Everything the log currently holds from before Monday — OATI’s September 9 Utility Dive webinar with CAISO, the August 19 five-agency CISA advisory on AI-generated PLC exploitation scripts, OpenAI’s August 27 “collective cyber defense” open letter, Axios’s September 3 report on OpenAI’s Daybreak pitch at EEI, and the September 12 Amodei essay — predates the window and is held for context only, not re-reported. The standing anchor facts (OATI AI Genie in daily production at CAISO; Daybreak; the Amodei/Huang split) are referenced below only where they change the reading of an in-window item.

Two threads run through the week, and they pull in opposite directions.

The first is that the institutions that govern the North American grid spent this week talking about AI as a load problem, not a control-room problem. NERC’s CEO published an op-ed on Tuesday whose entire AI content is about data centers straining the system — not a word about AI inside operations. Meanwhile PJM is one month out from an executive summit whose premise is the exact opposite: that AI belongs in the RTO. Both framings are live at the same institution-adjacent level, and a utility writing a 2027 AI roadmap has to decide which conversation it is actually in.

The second is that this was a good week for autonomy that inspects and a quiet week for autonomy that decides. A Scottish transmission owner moved a robot fleet from trial into routine service; a Houston utility filed an 8-K over an external API that apparently handed out millions of customer records. Neither involves an agent touching control logic. That gap — between AI that looks and AI that acts — is the one this digest exists to track, and this week it did not close.


🤖 Control-Room & Operational AI

PJM’s inaugural GridAdvance Summit (October 15) is the first executive-level, on-the-record forum in which a U.S. RTO frames AI as a control-room question rather than a planning or back-office one. PJM’s September 15 Inside Lines reminder confirms the program: a keynote from PJM board member Le Xie (co-founder of Harvard’s Power and AI Initiative), a COO fireside chat pairing PJM’s Stu Bresler with NYISO’s Emilie Nelson, and three panels — “From Queue to Connection: Rethinking Planning With AI,” “Innovation vs. Risk: Deploying AI in a Reliability-First Environment,” and “Control Room 2030: Moving From Situational Awareness to Situational Intelligence.”

The participant list is the substantive part: SPP, MISO, ERCOT, CAISO, NERC, EPRI, Dominion, Constellation, Tapestry, GE Vernova and Siemens. CAISO is the one ISO with a documented production agentic deployment (OATI AI Genie triaging 500+ next-day outage requests nightly, operators retaining final authority). NERC is the entity whose view of AI inside CIP-scoped environments has not yet been stated publicly. GE Vernova and Siemens are the two EMS/ADMS incumbents whose roadmaps determine whether control-room AI arrives as a bolt-on or as a native platform feature.

For a utility building an internal AI roadmap, the summit’s three-panel structure — planning, reliability-risk, control room — is a usable template, and “Innovation vs. Risk” is the panel to watch for the first public articulation of RTO agent-autonomy guardrails. Registration closes October 1; in-person at PJM’s Conference & Training Center, and virtual. (Source: PJM Inside Lines, September 15)

The counter-signal came the same week from NERC’s own CEO, and it is worth reading the two side by side. Jim Robb’s September 15 Utility Dive op-ed, “Change 4 mindsets to build a more resilient US grid,” is the reliability organization’s chief executive writing at length about AI — and treating it exclusively as a demand-side phenomenon. His four mindset shifts are siting and permitting, load as an active system participant, technology-mix diversity, and weighing societal benefit against cost. The AI content is entirely about data-center load: NERC is “working at breakneck pace” on criteria for identifying the most consequential large computational loads and the performance requirements that go with them, and EPRI is developing a standardized load-flexibility framework called Flex MOSAIC to bring consistency to curtailing large loads when reliability requires it.

What is absent is the tell. The CEO of the ERO wrote a full-length AI piece with no mention of AI in operations, no mention of agent autonomy, and no mention of what AI inside a CIP-scoped environment would require. That is not an oversight so much as an accurate reflection of where NERC’s institutional attention sits: AI is a load to be managed, not a tool to be governed. Utilities should read that as the current regulatory baseline — and read PJM’s “Innovation vs. Risk” panel as the venue where it might first shift. (Source: Utility Dive opinion, September 15)


🏭 In Production vs. 🔮 Forecast / Marketing

In production this week: one, and it is robotics rather than agents. SSEN Transmission has deployed seven new inspection robots across its HVDC estate in northern Scotland — at the Blackhillock, Spittal and Kergord converter stations and the Noss Head DC switching station at Wick — bringing its fleet to eight and explicitly marking, in the company’s own words, “a move from innovation trials towards routine use of robotics across its network.” The machines carry out autonomous inspections and monitor electrical equipment, feeding asset-condition data to operational teams; they are expected to complete more than 5,000 autonomous inspections and travel over 1,700 km in the next year. They have captured thermal and ultraviolet imagery from energised HVDC halls — areas engineers cannot safely enter while assets are in service — helping identify potential faults earlier. The deployment follows three years of work with Ross Robotics.

Label this precisely: this is autonomous inspection and data capture, not an agent making or recommending operational decisions. No control logic is touched, no dispatch or switching recommendation is generated, and the AI content is in the perception and anomaly-detection layer rather than in any reasoning loop. That said, it is the only item this week that crossed the trial-to-routine line with a stated volume commitment attached, and the pattern — autonomy earning its place first in the observation layer, where a wrong answer costs an unnecessary truck roll rather than an outage — is the one most utilities will follow. (Source: Energy Live News, September 16)

Forecast / agenda this week: the PJM GridAdvance Summit (agenda-setting; PJM has announced no production AI of its own) and the UK’s promised “AI in Energy Strategy” (a plan to publish a plan next year). Kilowatt Intelligence Issue #18 (September 15) is an aggregation of prior-week items — Daybreak, the Amodei/Huang split, the OATI/CAISO proof point — rather than a source of new deployment evidence.

Scoreboard for the inaugural week: 1 production (inspection robotics, transmission asset monitoring, SSEN), 0 new production agentic-AI deployments in operations, 2 forecast/agenda. The standing production benchmark for agentic control-room AI remains OATI AI Genie at CAISO, which predates this window. This digest will keep the count explicit each week so the ratio is visible over time.


🛡️ AI & Grid Cybersecurity

CenterPoint Energy filed a Form 8-K on September 14 confirming that an unauthorized third party obtained personal information for “a portion” of its customers through one of the company’s externally accessible systems. The filing followed a forum post by a threat actor claiming roughly 7.49 million customer records pulled from a CenterPoint-controlled API that allegedly lacked adequate authentication and rate limiting; the claimed fields include names, phone numbers, email and service addresses, account and premise identifiers, billing amounts, payment information, autopay status and the last four digits of Social Security numbers. CenterPoint has not confirmed the record count, the API description or the authenticity of the published dataset — those remain the threat actor’s claims. The company activated its incident-response protocols, engaged external cybersecurity specialists, notified law enforcement and certain regulators, and stated that electricity and gas delivery were not affected. It expects incident-response costs, partially offset by cyber insurance, and does not currently expect a material financial impact.

This is a customer-data breach on the IT side, not an OT incident, and there is no AI tradecraft reported in it. It belongs in this digest for two reasons. First, the alleged vector — an unauthenticated, unrate-limited external API — is exactly the class of exposure that the August CISA advisory (AA26-231A) and the August 27 frontier-lab open letter describe as newly dangerous, because AI-assisted reconnaissance and code generation shorten the time between asset is reachable and tooling exists to drain it. Second, the two AI-related asks in that open letter that map directly onto this incident — raise the bar for what you deploy “including AI-generated code,” and apply compensating controls where essential systems cannot be patched — are things a utility security team can act on this quarter without waiting for any vendor’s AI product. The unglamorous lesson is the same one AA26-231A drew for PLCs: AI on the attacker side raises the urgency of the basics, not the sophistication of the required defense. (Sources: CenterPoint Energy Form 8-K, September 14; Reuters, September 14; CyberInsider, September 15)

The week’s second security item is a deadline, not an incident. DOE’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER) held its industry-engagement webinar on Wednesday September 16, 3–4 p.m. EDT, walking through the Request for Information it published in the Federal Register on September 9 under Executive Order 14421, “Securing the United States Bulk-Power System” (signed August 26). The RFI seeks input across eight areas — how to define “bulk-power system electric equipment” and which transaction types, equipment classes and risk thresholds to prioritize; how to identify covered foreign entities; supply-chain governance practices; methodologies for evaluating cybersecurity, national-security and supply-chain risk; inventories of existing installed equipment; and candidate mitigation measures. Written responses are due October 9, 2026.

There is no AI language in the EO or the RFI, and that is the point for this digest’s purposes: the definitional work happening now — what counts as covered equipment, what supply-chain governance a utility must be able to evidence — will set the frame that AI-bearing grid equipment and AI-enabled vendor software eventually get judged against. A utility that files comments has a chance to shape whether “software with an embedded model” and “vendor-hosted inference touching operational data” land inside or outside the covered-equipment definition. A utility that does not file inherits whatever definition emerges. Three weeks left. (Sources: Federal Register 91 FR 57322, September 9; DOE CESER webinar, September 16)


🏛️ AI-Provider Posture Toward Critical Infrastructure

No in-window primary source. The frontier-lab thread was loud in the two weeks before this window — the August 27 collective-cyber-defense letter (128 signatories, no dollars or deadlines), the September 3 Axios report on OpenAI’s ~$1B Daybreak pitch to Duke, Exelon, Southern and NextEra at EEI, and the September 12 Amodei essay “We Must Pace the Frontier” with its weekend reaction wave — and none of it produced a new primary document between Monday and Friday. Those items are on file in the research log and will be picked up here when there is an in-window source to attach them to.

Worth noting as the open question this section exists to track: the two AI vendors selling hardest into the utility sector are giving opposite guidance on agent autonomy — Amodei warning about rogue-agent proliferation on a 6–12 month horizon, NVIDIA’s Huang forecasting utilities running hundreds of thousands to millions of continuous agents. A utility drafting agent-autonomy policy is doing so against a forecast its own suppliers cannot agree on.


📜 Regulatory, Standards & Policy

The UK became the first major market this week to commit to a named, standalone AI-in-energy policy instrument. On September 14 the Minister for Local Energy and Jobs, Martin McCluskey, confirmed that an “AI in Energy Strategy” will be published next year. It follows an independent review led by Lucy Yu, the UK Government’s AI Champion for Clean Energy, which recommends moving the grid toward AI-enabled, risk-based operation and planning and — the more operationally interesting half — establishing clear governance for AI systems specifically in order to speed up deployment of AI solutions that have already been proven to work.

That framing is worth lifting regardless of jurisdiction: the review treats governance as an accelerant rather than a brake, on the theory that the absence of an agreed assurance route is what strands proven tools in pilot purgatory. Any utility that has watched a working model sit unblessed for eighteen months will recognize the diagnosis. The review also warns explicitly that greater AI use changes the electricity network’s attack surfaces and the ways threats propagate, and that security has to be designed in at deployment rather than bolted on — which is the same conclusion the U.S. federal advisories reached from the incident side, arrived at from the policy side.

For U.S. readers the contrast with the NERC op-ed above is stark: the UK is writing an operations-AI governance strategy while the U.S. ERO is writing about computational load. Neither is wrong; they are answering different questions. But the UK document, when it lands next year, will be the first published template for how a grid operator proves an AI system is fit for operational use — and that template will get read on this side of the Atlantic. (Source: Energy Live News, September 14)

Also in the policy pipeline (pre-window, tracked for continuity, not re-reported): FERC’s July 16 directive creating the Computational Load Entity as a new registered-entity class, with NERC’s mandatory standards for computational loads due December 31, 2026 and a Phase II work plan due March 1, 2027; and EPRI’s Flex MOSAIC load-flexibility framework, referenced this week in Robb’s op-ed. Both are load-side, both set the vocabulary AI-related grid regulation will inherit.


🔍 Vendor Watch

OATI — no new product or deployment announcement inside the window. The most recent items on OATI’s news page are the September 3 FERC 881 regional-deployment release and the September 9 Utility Dive webinar with CAISO (“How to Move AI from Pilot to the Utility Control Room”), both pre-window and both already in the research log. The webinar’s production-readiness checklist — legacy-system integration, operational-data grounding, constraint awareness, sensitive-data protection, evidence-cited recommendations, retained human authority — remains the most procurement-ready artifact the vendor has published; the companion “AI in the Control Room” whitepaper is the next pull for the vendor file. OATI, Siemens and GE Vernova will share the PJM GridAdvance stage on October 15, which is the next scheduled opportunity for a public statement.

MCG Energy Solutions — no AI announcement inside the window. Versify OMS / IAM / Control Area Scheduling remain the adjacent incumbent watch-item: the structured, document-heavy outage-scheduling and market-submission workflows that OATI is compressing with agents at CAISO are MCG’s core franchise, and whether MCG ships production AI in Versify — and on what human-in-the-loop terms — is the open question. Still not a shipped-AI proof point.

GE Vernova / Siemens — no in-window announcements; both confirmed at PJM GridAdvance.

Ross Robotics — new to the vendor file this week on the strength of the SSEN deployment (see Production). A three-year development partnership that ended in a fleet of eight units in routine service across four HVDC sites is a more credible reference than most AI-in-utilities announcements carry, and the reference is checkable with the asset owner.

Aggregator note: Kilowatt Intelligence Issue #18 (Todd Durocher, September 15) was the in-window vehicle that surfaced the OATI/CAISO, Daybreak and Amodei/Huang items to this log. It is cited as a secondary source; every item it carried was traced to a primary source in the daily log.


⚡ Utility-Sector Relevance Flags

  • The governing institutions are having two different conversations about AI. NERC’s CEO wrote about AI as load; PJM is convening on AI as an operating tool. Both published the same week. Before a utility’s AI roadmap goes to its board, decide which conversation the roadmap is in — because the reliability-compliance questions and the operational-benefit questions have almost no overlap and very different owners.
  • New-production count: one, and it is an inspection robot. No agentic-AI deployment entered operations this week. Keep the vendor-claim discount high: the only production agentic deployment on file remains a single bounded use case at a single ISO. The SSEN pattern — autonomy proving itself in observation before decision — is the realistic sequencing for most utilities, and it is a defensible answer to a board asking why the agent pilot hasn’t shipped.
  • October 9 is a live deadline. DOE’s EO 14421 RFI closes then. The definitions being set — covered equipment, supply-chain governance evidence, risk-evaluation methodology — will frame how AI-bearing equipment and vendor-hosted inference get treated later, even though the RFI says nothing about AI. Filing is cheap; inheriting someone else’s definition is not.
  • External-facing APIs are now a board-level exposure. CenterPoint’s 8-K is a reminder that customer-facing IT surfaces — billing APIs, portals, outage maps — sit outside NERC CIP scope and are exactly where AI-accelerated attackers look first. An inventory of externally reachable APIs, with authentication, rate limiting and data minimization checked per endpoint, is a concrete non-AI action that the AI-threat literature of the past month directly motivates.
  • Governance as accelerant, not brake. The UK review’s core claim — that a clear assurance route makes proven AI deploy faster — is the most useful argument in this week’s material for anyone inside a utility trying to unstick a model that works but has no one empowered to approve it. Worth borrowing the framing ahead of the strategy’s publication next year.
  • Contract language to lift. The frontier labs’ own commitment to “ensure agentic identities are traceable and accountable” (pre-window, now the operative norm) is language a utility can require of any vendor whose agent touches OMS, EMS or market systems. Pair it with the OATI/CAISO checklist as RFP evaluation criteria.

📚 Sources

Primary (in-window, September 14–18, 2026):
– PJM Inside Lines — Reminder: PJM GridAdvance Summit One Month Away (September 15) · https://insidelines.pjm.com/reminder-pjm-gridadvance-summit-one-month-away/
– Jim Robb (NERC President & CEO) — Change 4 mindsets to build a more resilient US grid, Utility Dive opinion (September 15) · https://www.utilitydive.com/news/grid-infrastructure-transmission-data-center-ai-nerc-robb/829592/
– Energy Live News — Robots take over Scottish network monitoring (SSEN Transmission / Ross Robotics, September 16) · https://www.energylivenews.com/2026/09/16/robots-take-over-scottish-network-monitoring/
– Energy Live News — ‘AI in energy strategy’ plan released next year (Lucy Yu independent review; Minister McCluskey, September 14) · https://www.energylivenews.com/2026/09/14/ai-in-energy-strategy-plan-released-next-year/
– CenterPoint Energy — Form 8-K, U.S. Securities and Exchange Commission (September 14) · https://www.sec.gov/Archives/edgar/data/1130310/000110465926107560/tm2625326d1_8k.htm
– Reuters — CenterPoint Energy discloses customer data breach in SEC filing (September 14) · https://www.reuters.com/legal/litigation/centerpoint-energy-discloses-customer-data-breach-sec-filing-2026-09-14/
– CyberInsider — CenterPoint Energy confirms data breach after hacker claims 7.49M records (September 15) · https://cyberinsider.com/centerpoint-energy-confirms-data-breach-after-hacker-claims-7-49m-records/
– U.S. DOE / CESER — industry-engagement webinar on Executive Order 14421 and the associated RFI (September 16) · https://www.energy.gov/ceser/articles/ceser-holds-industry-engagement-webinar-covering-recent-bulk-power-system-executive

Supporting primary (published September 9, discussed in-window; comments due October 9):
– Federal Register — Securing the United States Bulk-Power System, 91 FR 57322, DOE Request for Information under EO 14421 (September 9) · https://www.federalregister.gov/documents/2026/09/09/2026-18370/securing-the-united-states-bulk-power-system

Secondary / aggregator (in-window):
Kilowatt Intelligence Issue #18 — Todd Durocher (September 15) · https://www.linkedin.com/pulse/kilowatt-intelligence-issue-18-september-15-2026-todd-durocher-n8djc/

Context only (pre-window; not re-reported):
– OATI — How to Move AI from Pilot to the Utility Control Room (Utility Dive webinar, September 9) · https://www.oati.com/events/ai-pilot-to-utility-control-room/
– OATI — Under the hood of CAISO’s AI outage management pilot · https://www.oati.com/news/under-the-hood-of-caisos-ai-outage-management-pilot/
– CISA — Advisory AA26-231A, Defending Against an Active Threat to Siemens S7 Series PLCs (August 19) · https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a
– OpenAI — A call for collective action on cyber defense (August 27) · https://openai.com/collective-cyberdefense/
– Axios — OpenAI unveils plan to protect critical services from AI cyberattacks (September 3) · https://www.axios.com/2026/09/03/openai-critical-infrastructure-cyber-ai-models
– Dario Amodei — We Must Pace the Frontier (September 12) · https://darioamodei.com/post/we-must-pace-the-frontier