Second issue. Window: Monday September 21 through Friday September 25, 2026. Ten in-window items. The daily log has now run a full weekday cycle, so this is the first digest assembled without reach-back padding — and the discipline cost something, because three of the log’s strongest artifacts this week (the New York PSC inventory order, September 17; Stanford Bits & Watts’ transatlantic roundtable, June 16; Onapsis’s SAPMAP advisory, September 18) publish before Monday and are held for context rather than re-reported. National Grid Partners’ Utility Innovation Survey is dropped on both tests at once: September 18, and already in last week’s Sources.
This was the week the numbers arrived.
For two months the running question in this log has been how much authority utilities and their OT organizations have actually handed to software, and every answer has been an anecdote or a vendor claim. This week three independent survey instruments put figures on it, and they agree on an uncomfortable shape. Takepoint Research (n=302): 87.7% using or planning AI in OT cybersecurity, 7.9% deployed across multiple functions. Honeywell’s inaugural OT Security Benchmark (n=600+): 23% already report autonomous or agentic operation for threat detection and for continuous monitoring — while only 21% hold a complete OT asset inventory. Broad engagement, thin production, and a slice that has already crossed into autonomy standing on a foundation four organizations in five concede is incomplete.
The second thread is a caution against reading AI into every grid headline. The largest action of the week — DOE’s $5.25 billion SPARK selections — never says “AI” in the Department’s own release. The wire coverage supplied that framing. What is actually being bought is conductor and Grid-Enhancing Technologies across nearly 21,000 miles: the real-time sensing layer that every operational-AI claim in this log silently depends on. That is the more useful reading, and it points the same direction as Takepoint’s finding that the binding constraints are data quality (45.4%) and legacy integration (42.4%), not models.
And the third: federal guidance got sharper without ever naming the problem. CISA and the FBI published a joint fact sheet on third-party ICS integrators that says nothing about AI and functions as the cleanest agent-authority checklist a utility can cite in a contract this week — least privilege, on-demand rather than standing access, and the ability to run the process manually if the third party is compromised. Read “integrator” as “agent” and it is the containment answer no AI vendor in this log has yet supplied.
🤖 Control-Room & Operational AI
DOE’s Office of Electricity selected 31 SPARK projects across 26 states — and the most useful fact about the announcement is what it does not say. The selections under the Grid Resilience and Innovation Partnerships (GRIP) program total $5.25 billion: $1.9 billion federal against $3.35 billion in recipient cost-share. Recipients are expected to reconductor or rebuild more than 1,500 miles of transmission and deploy Grid-Enhancing Technologies across nearly 21,000 miles, freeing over 23 GW of additional capacity affecting roughly 100 million Americans. The press coverage frames all of it as a response to AI data-center demand; the DOE release itself never uses the word, quoting Secretary Chris Wright on “commonsense energy addition policies” and OE Assistant Secretary Catherine Jereza on advanced transmission technologies.
That gap cuts both ways. It is a caution against reading AI into every grid announcement — SPARK is a conductor-and-hardware program riding existing rights-of-way to avoid multi-decade greenfield timelines, not an AI procurement. But GETs are precisely the instrumentation layer operational AI has no substitute for: dynamic line ratings, power-flow control and topology optimization exist to produce trustworthy real-time thermal and flow data. A utility that wins a SPARK award is, without calling it that, buying the observability an agentic control-room tool would later have to reason over.
Limits worth stating: these are selections and an intention to fund, not executed awards. No AI capability is named, scoped or required anywhere. Nothing touches agent authority, NERC CIP scope or the OT boundary.
Neither tracked incumbent moved. OATI and MCG Energy Solutions produced nothing new in-window. The strongest operational-thread material available — OATI’s own IEEE PES General Meeting account of the CAISO AI Genie deployment, and GE Vernova’s GridOS for Transmission — both publish before the window and are held for context. The standing anchor is unchanged: AI Genie at CAISO remains the only confirmed production agentic deployment in grid operations this log tracks, with operators retaining final authority and report-building that consumed dozens of analyst hours now running in roughly eight minutes.
🏭 In Production vs. 🔮 Forecast / Marketing
The separation is unusually clean this week because three instruments measured it directly.
🏭 In production, measured
- Takepoint Research, State of AI in OT Cybersecurity 2026 (n=302): 87.7% using or planning AI for OT cybersecurity; only 7.9% deployed across multiple functions. The report’s own framing of the cause deserves to be quoted in a procurement memo: the gap “isn’t reluctance — it’s architectural.” Top obstacles are data quality (45.4%) and legacy system integration (42.4%), because no industrial plant was designed with AI computing in mind and the control systems underneath produce scattered, inconsistent telemetry.
- Honeywell 2026 OT Security Benchmark (n=600+): AI-assisted use is already broad — threat detection 72%, continuous monitoring 68%, asset inventory 59% — and the benchmark then separates assistance from authority. 23% report autonomous or agentic operation for threat detection, 23% for continuous monitoring, 19% for asset inventory. Roughly one organization in four has crossed from human-in-the-loop to something acting on its own inside an OT security workflow.
- SAP MCP Gateway is generally available in SAP Integration Suite (Premium and Enhanced editions), having shipped in Q2 2026 — a customer-managed governed control plane exposing SAP and non-SAP APIs, integration flows and external MCP servers as tools an agent can discover and call, handling authentication, authorization, rate limiting, payload protection, monitoring and tool lifecycle from one entry point. No Edge Integration Cell or private Kubernetes required. (GA date precedes the window; the confirmation and the naming correction below landed in-window.)
🔮 Forecast, roadmap and marketing
- SAP Agent Gateway — the Joule-side component, frequently conflated with the above — remains not generally available and outbound-only. Three similarly named things now need separate tracking: SAP MCP Gateway (GA, Integration Suite), SAP Agent Gateway (not GA, outbound-only), and Onapsis’s Agentic Gateway / MCP Gateway for SAP Security (previewed since March 17, no GA confirmation, no named customer, inbound/outbound scope unstated).
- SAP AI Agent Hub reached its deadline rather than its target. GA was set for Q3 2026; as of Friday, two of six capabilities are GA — principally the AI registry that auto-discovers agents, LLMs and MCP servers across SAP, Microsoft, Google, AWS and ServiceNow. The four unshipped include exactly the two that matter to an agent-authority policy: agent identity via SAP Cloud Identity Services, and AI observability with session-level monitoring. A registry answers “who authorized this agent to exist” at discovery; it does not answer who watches what it does or how it is stopped. (Sourcing note: the LeanIX roadmap page is a JavaScript application returning no text on fetch; the GA split rests on SAPinsider’s Sapphire reporting and secondary ecosystem coverage.)
- GE Vernova’s Autonomous Distribution — fault detection, isolation and restoration “in seconds rather than minutes” integrated with existing EMS/ADMS — remains whitepaper material, not product. The question no release has answered: what exactly is the model permitted to actuate without a human, and what is the fallback when it is wrong?
The pattern across both columns is the same one this log recorded in the incumbents’ shipping products. What is generally available and spreading is the validated operational data layer — webLineR’s facility ratings, GridOS’s unified control-room environment, MCP Gateway’s governed tool plane. The AI sits one layer above it and is not yet the thing being sold.
🛡️ AI & Grid Cybersecurity
CISA and the FBI issued a joint fact sheet on third-party ICS integrators that never says “AI” and is nonetheless the cleanest federal statement of the agent problem yet written. The agencies describe precisely the risk profile an autonomous system presents: an external party granted control-system design, installation, operational data analysis, device support and daily operational control, holding persistent privileged access into an environment the operator does not fully observe.
The anchoring incident is not hypothetical. Between March and April 2025, foreign actors inside a US industrial automation firm providing SCADA programming to power utilities and transportation entities searched the network for “customers” and “SCADA” and assembled nine .zip files containing roughly 800 files — customer SCADA information, ICS device details and schematics — staged for exfiltration.
Four recommendations transfer to agent authority without modification:
- Least privilege, stated for OT: an external process receives only the minimum access its assigned task requires “and no more.”
- On-demand beats standing access: route remote access through operator-observable, monitored and logged paths, and prefer connections the operator must proactively authorize — the procedural equivalent of human-in-the-loop for a non-human actor.
- Inventory all hardware and software the third party supplied, with documentation of how each component connects.
- Manual fallback: confirm the organization can operate critical processes independently if the third party is compromised, with offline backups of all software required to run equipment and practised manual procedures. This is the containment answer the standing frame keeps asking for — not “how is the agent shut down” in the abstract, but whether the utility has rehearsed running without it.
The fact sheet is explicit that cybersecurity and supply-chain requirements belong in the service agreement: data storage location, protection of ICS design documentation, remote-access capabilities, patch and change management, named authorized personnel — and assess whose law governs the data when the provider is foreign-owned. Limits: a fact sheet, not a standard; written about integrator firms rather than software agents; no NERC CIP mapping — that translation remains the entity’s work.
Honeywell’s sector cut is the number for a utility board. 91% of energy and utilities respondents reported a significant OT cybersecurity incident in the past twelve months — the highest exposure of any sector surveyed — alongside average downtime of 16.2 hours, 21% estimating downtime costs above $100,000 per hour and 4% above $500,000 per hour; 40% of incidents affected multiple sites in a region, 16% across regions.
Two findings from the same benchmark deserve to survive the summary. Compliance did not separate outcomes: respondents passing all audits reported significant incidents at 74% versus 73% for those with audit findings — though it did separate recovery readiness (44% versus 26% fully recovery-ready). A NERC CIP pass is a recovery argument, not an AI-safety argument. And legacy systems rank first across three separate risk measures (48% top barrier, 47% leading source of exposure, 45% among top-three downtime contributors), matching Takepoint’s 42.4%.
Honeywell’s own closing framing is the one to quote, because it is the vendor asking the standing frame’s questions back at its own customers: as AI autonomy expands, what is needed is clear decision rights, human oversight and operational testing. Caveats: vendor-published, self-reported throughout, and “autonomous or agentic” is left undefined in the reporting.
Takepoint’s governance number is where this stops being a maturity story and becomes a liability story. Nearly two-thirds of respondents acknowledge that a corrupted or erroneous AI decision could damage equipment, cause an unintended shutdown or produce a safety incident — and only 15.6% have adopted OT-specific AI governance policies. That is a roughly 50-point gap between recognised physical-consequence risk and written policy to govern it.
Idaho National Laboratory’s TOPGEAR attacks a risk class the other federal tools do not: not the intrusion, but the ownership. TOPGEAR (Technology, Organization and Person of Interest Graph Extraction, Analysis and Reporting), led by INL distinguished researcher Gabriel Weaver, continuously ingests SEC filings and EIA data into social, infrastructure and cross-layer influence networks, letting an analyst trace an influence path from a named human actor to a physical asset — a substation or a data center. INL’s own framing is the sharpest statement of the problem this log has seen: the next major threat “could arrive with a handshake and a signed contract” — foreign land purchases near substations, a board seat at an aggregator, no malware and no breach, each transaction routine alone but cumulatively decisive.
It is already in use at state energy offices, with DOE’s Office of Electricity sponsoring technical-assistance engagements and support from CESER, OE and DHS; it was refined with the Naval Postgraduate School from an explicitly adversarial perspective, and the team completed 76 DOE Energy I-Corps market analyses. This is the third federal-lab grid-security capability this log has recorded in about six weeks, after CESER/Sandia’s C2E2 and Argonne’s GridMind — all non-commercial, all reaching public power through channels no frontier-lab program does. The AI connection is indirect but named by INL: as AI accelerates business decision-making, the volume and speed of the transactions that shift influence rise with it. A utility whose aggregator, DER platform or software vendor changes hands has a CIP-013 supply-chain question and an ownership question at once. TOPGEAR is an analytic aid producing maps for human judgment — an influence path is not an allegation.
🏛️ AI-Provider Posture Toward Critical Infrastructure
Google Cloud’s Office of the CISO published a secure agentic-AI blueprint for industrial operations. The framing is manufacturing; the architecture is the one a utility faces. The sentence that matters is a governance sentence, not a product one: agents “should be treated as first-class non-human identities with role-based access controls, strict API boundaries, monitoring controls and automated fallback triggers for human intervention,” and leaders should explicitly define the governance framework needed to move from human-in-the-loop to human-on-the-loop oversight.
That answers two of the standing frame’s five questions — who watches it, how it is shut down — in writing from a frontier provider, and it is notably more concrete than the Daybreak and Fairwind announcements this log recorded earlier in the month, which were programs rather than design rules.
Specifics that transfer directly:
- Gemma 4 runs agentic workflows fully on-premises, which the authors call essential for OT operators that cannot connect to cloud.
- Integration agents manage encrypted unidirectional pipelines from plant-floor controllers to cloud platforms, so telemetry leaves without inbound exposure.
- Adversarial-simulation agents stress-test against high-fidelity digital twins, explicitly including validation of emergency kill switches, rather than against live equipment.
- The recommended sequence is a usable procurement checklist: pick one bottleneck, verify the data is clean and structured enough to support autonomous reasoning, define governance, pilot inside an isolated enclave or digital twin, then require unified IT/OT visibility.
Read that last item against Honeywell’s finding that 23% already run autonomous or agentic OT security functions, and the ordering problem is plain: the blueprint says pilot in an enclave before granting autonomy, and roughly a quarter of respondents are already past that gate.
Two caveats keep this in the positioning column. No industrial customer is named and no deployment is claimed, and the piece is authored by the vendor’s own CISO office. And the blueprint stops at the plant floor — silent on where agent authority ends at a protection-relay or SCADA boundary, which is the unanswered question for a BES operator.
Adjacent, from the SAP stack: Anthropic’s Claude is embedded in Joule, and NVIDIA contributed an open-shell framework for agent safety and operational boundaries; SAP’s Autonomous Suite (224 agents, 51 assistants) is built under an ISO-certified, SOX-audit-compatible process with GA also targeting Q3 2026 or later.
📜 Regulatory, Standards & Policy
NIST published the initial public draft of SP 800-82r4, Guide to Operational Technology Security — 321 pages, comments open through November 30, 2026. SP 800-82 is the document every OT security program in the United States is either built on or measured against, and r4 is the first revision to arrive after agentic AI became a procurement question rather than a research one.
The revision restructures the guide around CSF 2.0, adds the GOVERN function explicitly, aligns OT risk management to enterprise risk via NIST IR 8286r1 and the RMF, expands scope to building automation, water and wastewater, food and agriculture, freight rail, maritime and IIoT/cloud convergence, and adds a full treatment of zero trust architecture in OT. Two passages do real work for anyone writing an agent-autonomy policy:
- Consequence-driven is now the stated mindset. Cyber controls must be evaluated alongside engineering countermeasures — NIST names Cyber-Informed Engineering — so risk reduction covers physical process resilience, not only cyber resilience, and “no single failure should cause unacceptable consequences.” That is the design test for any agent permitted to act.
- Segmentation must extend within OT, separating the operational network carrying process-control traffic from the management network handling configuration, patching and access control. Combining them injects management activity into operational traffic, prevents independent security policy, and lets security events propagate between network types. NIST further requires that external vendor access run over architecturally separate paths with independent credential stores and enforcement boundaries — a rule that reads directly onto a cloud-hosted AI agent calling into an OT landscape.
NIST’s list of OT functions that already embody core zero-trust principles — privileged access management with individually authorized, time-bounded sessions; credential separation so compromised enterprise credentials cannot satisfy OT authorization; content-level validation of file transfers and removable media; continuous monitoring to revoke trust in near real-time — is the most practical starting point a utility will get for extending least privilege to non-human identities without a greenfield program.
Limits: initial public draft, not final, and written for OT broadly rather than the BES, so the NERC CIP mapping is the reader’s work — the same gap this log has flagged repeatedly on the SAP side, and the same gap in the CISA/FBI fact sheet above. Three separate federal documents in one week name the OT boundary and leave the CIP translation to the registered entity.
Funding mechanism, for the record: SPARK — Speed to Power through Accelerated Reconductoring and other Key Advanced Transmission Technology Upgrades — is funded through GRIP, and DOE simultaneously released the Speed to Power RFI analysis that informed the funding design.
Standing clock (context, pre-window): the New York PSC’s September 17 order requires every New York utility to disclose all uses of AI in operations within 60 days, plus the policies, procedures and protocols governing that use. Set against Takepoint’s 15.6% OT-specific-governance figure, the second half of that order will be the harder filing for most respondents. The deadline falls in mid-November.
🔍 Vendor Watch
OATI — no new material in-window. Standing position unchanged: AI Genie in daily production at CAISO triaging next-day outage requests with operators retaining final authority; webLineR at 32 transmission entities, and explicitly not marketed as AI, which remains the useful finding. The procurement distinction OATI drew at IEEE PES — energy-native versus general-purpose, meaning built on operational grid data, aware of physical and market constraints, integrated with systems of record, auditable line by line — is the one three independent parties have now converged on this month.
MCG Energy Solutions — no movement in-window.
Onapsis — thread did not move for the third, fourth and fifth consecutive scans. Blog and press pages were fetched directly on September 22, 24 and 25; newest dated items remain the September 18 SAPMAP advisory and the July 30 State of AI, Security and ERP study. All four watch-items unchanged: Agentic Gateway / MCP Gateway for SAP Security still previewed since March 17 with no GA confirmation, no named customer and inbound/outbound scope unstated; ORL SAPMAP with no follow-on; Verification Seal enforcement still undescribed in any primary source; no NERC CIP mapping on a utilities solution page that names CIP and IT/OT-SCADA convergence.
SAP — the one vendor that moved. MCP Gateway GA confirmed (above); AI Agent Hub at its Q3 deadline with the identity and observability capabilities unshipped. If Q3 closes without them, that absence is itself next quarter’s finding. Worth tracking directly rather than through vendor releases: SAP is a Gold member of the Agentic AI Foundation under the Linux Foundation and co-chairs the Agent Identity and Security workstream, which is where the agent-identity standard all of this depends on is actually being written.
GE Vernova, Siemens, Schneider — nothing in-window.
⚡ Utility-Sector Relevance Flags
-
Read “integrator” as “agent.” The CISA/FBI fact sheet is contract-ready language a utility can cite this week for least privilege, on-demand access, supplied-component inventory and — the one that does the most work — rehearsed manual fallback. It is the only containment requirement from any source this month that is testable rather than aspirational.
-
The autonomy has outrun the inventory. 23% of OT security organizations report autonomous or agentic operation; 21% hold a complete OT asset inventory. If your organization is in the first group, establish which asset picture the agent is reasoning over before the next audit asks.
-
A CIP pass is not an AI-safety argument. Honeywell’s all-audits-passed cohort reported significant incidents at 74% against 73% for those with audit findings. Compliance separated recovery readiness (44% vs. 26%), not incidence.
-
The constraint is instrumentation, not models — now stated four ways in one week: Takepoint’s 45.4% data quality and 42.4% legacy integration; Honeywell’s legacy systems ranking first on three measures; Google Cloud’s “verify the data is clean and structured enough to support autonomous reasoning” as a gate before governance; and DOE putting $5.25B into conductor and sensing while saying nothing about AI at all.
-
Three federal documents, one missing translation. NIST SP 800-82r4, the CISA/FBI fact sheet and DOE’s SPARK release all touch the OT boundary and none maps to NERC CIP. That translation is the registered entity’s work, and nobody is coming to do it.
-
NIST r4 is open for comment through November 30. The zero-trust-in-OT and within-OT segmentation sections are the ones that will govern how a cloud-hosted agent is permitted to reach an OT landscape. A utility with a view should file it.
-
The New York clock runs out in mid-November. Utilities outside New York should treat the inventory requirement as a template to prepare against. AI that entered through a vendor platform upgrade, a bundled copilot or a departmental pilot is exactly what an inventory of this kind surfaces — and exactly what an agent-autonomy policy must enumerate before it can govern.
-
An ownership change at a vendor is a CIP-013 question. TOPGEAR exists because influence shifts through routine transactions rather than intrusions. If your aggregator, DER platform or software vendor changed hands this year, that is a supply-chain review, not a news item.
-
Watch the SAP Q3 close. Agent identity via Cloud Identity Services and session-level AI observability are the difference between an agent inventory and an agent control plane. Five days remained as of Friday.
📚 Sources
Primary (in-window, September 21–25, 2026):
- U.S. Department of Energy, Office of Electricity — Energy Department Announces Speed to Power Investments Across 26 States to Lower Electricity Costs and Improve Grid Reliability (SPARK selections under GRIP; September 24) · https://www.energy.gov/articles/energy-department-announces-speed-power-investments-across-26-states-lower-electricity
- CISA and FBI — Considerations for Critical Infrastructure Operators Working with Third-Party ICS Integrators (joint fact sheet, September 2026) · https://www.cisa.gov/resources-tools/resources/considerations-critical-infrastructure-operators-working-third-party-ics-integrators
- U.S. National Institute of Standards and Technology — SP 800-82r4 (Initial Public Draft): Guide to Operational Technology (OT) Security (September 21; comments through November 30, 2026) · https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r4.ipd.pdf
- Honeywell Technologies — 2026 OT Security Benchmark Report (inaugural; 600+ global industrial cybersecurity leaders) · https://www.honeywell.com/us/en/insights/research/2026-ot-security-benchmark · press statement · https://www.honeywell.com/us/en/news/press-releases/2026/09/honeywell-technologies-report-reveals-significant-gaps-in-industry-s-ot-cybersecurity-protection
- Takepoint Research — Survey Report: The State of AI in OT Cybersecurity 2026 (n=302) · https://takepoint.co/product/survey-report-the-state-of-ai-in-ot-cybersecurity-2026/
- Google Cloud — A manufacturing blueprint for secure agentic AI (Vinod D’Souza, Office of the CISO; Sri Gourisetti) · https://cloud.google.com/transform/a-manufacturing-blueprint-for-secure-agentic-ai
- Idaho National Laboratory — Mapping hidden organizational influence in US critical infrastructure (TOPGEAR; Lisa Wilmore) · https://inl.gov/feature-story/mapping-hidden-organizational-influence-in-us-critical-infrastructure/
- SAP Community (Technology Blog Posts by SAP) — MCP Gateway in SAP Integration Suite: Your APIs, Ready for the Age of Agents · https://community.sap.com/t5/technology-blog-posts-by-sap/mcp-gateway-in-sap-integration-suite-your-apis-ready-for-the-age-of-agents/ba-p/14438250
- Onapsis blog and press pages — re-fetched directly September 22, 24 and 25, 2026; unchanged since September 18 · https://onapsis.com/blog/
Secondary (in-window reporting used to source the above):
- Industrial Cyber — CISA, FBI warn critical infrastructure operators of third-party ICS risks, urge least privilege and remote access controls (Anna Ribeiro; September 24) · https://industrialcyber.co/industrial-cyber-attacks/cisa-fbi-warn-critical-infrastructure-operators-of-third-party-ics-risks-urge-least-privilege-and-remote-access-controls/
- Industrial Cyber — Honeywell 2026 OT Security Benchmark highlights gaps in OT visibility, incident recovery, cybersecurity readiness (Anna Ribeiro; September 23) · https://industrialcyber.co/reports/honeywell-2026-ot-security-benchmark-highlights-gaps-in-ot-visibility-incident-recovery-cybersecurity-readiness/
- Industrial Cyber — NIST SP 800-82r4 draft expands OT security guidance with zero trust, CSF 2.0, consequence-driven risk management (Anna Ribeiro; September 22) · https://industrialcyber.co/nist/nist-sp-800-82r4-draft-expands-ot-security-guidance-with-zero-trust-csf-2-0-consequence-driven-risk-management/
- Industrial Cyber — AI adoption in OT security accelerates as legacy infrastructure and poor data expose readiness gaps (September 22) · https://industrialcyber.co/features/ai-adoption-in-ot-security-accelerates-as-legacy-infrastructure-and-poor-data-expose-readiness-gaps/
- Industrial Cyber — Google Cloud unveils secure agentic AI blueprint for manufacturing amid push to scale industrial AI (Anna Ribeiro; September 21) · https://industrialcyber.co/manufacturing/google-cloud-unveils-secure-agentic-ai-blueprint-for-manufacturing-amid-push-to-scale-industrial-ai/
- Industrial Cyber — INL develops TOPGEAR to identify organizational influence risks across physical and digital infrastructure (Anna Ribeiro; September 21) · https://industrialcyber.co/cyber-physical/inl-develops-topgear-to-identify-organizational-influence-risks-across-physical-and-digital-infrastructure/
- Associated Press via Spectrum News — Energy Department will spend $2 billion to squeeze more electricity from aging power grid (September 24) · https://spectrumlocalnews.com/us/snplus/environment/2026/09/24/energy-department–2-billion-power-grid
- SAPinsider — SAP Sapphire 2026: The Autonomous Enterprise Arrives—with Guardrails (Radhika Ojha) · https://sapinsider.org/blogs/sap-sapphire-2026-autonomous-enterprise-ai-agents/
- The New Stack — SAP launches AI Agent Hub at Sapphire 2026 to tame vendor agent sprawl · https://thenewstack.io/sap-ai-agent-hub/
- Crave Infotech — MCP Gateway in SAP Integration Suite: A Working Guide for SAP Architects (edition, prerequisite and Agent Gateway status detail) · https://www.craveinfotech.com/blogs/mcp-gateway-in-sap-integration-suite-a-working-guide-for-sap-architects/
Context only (pre-window; referenced above, not re-reported):
- New York State Public Service Commission — inquiry into utility use of artificial intelligence (September 17; 60-day disclosure deadline) · reported by WWNY/Gray Media · https://www.wcax.com/news/2026/09/17/state-orders-national-grid-other-utilities-disclose-all-ai-use/
- Stanford Bits & Watts Initiative, with Eurelectric, EPRI Open Power AI Consortium and Terna — AI x Energy: A Transatlantic Utility Perspective (June 16) · https://bitsandwatts.stanford.edu/news/report-electric-utilities-can-use-ai-improve-service-while-hopefully-meeting-ai-power-demands
- Onapsis Research Labs — Threat Advisory: The New SAP Exploitation Toolkit SAPMAP (JP Perez-Etchegoyen; September 18) · https://onapsis.com/blog/sapmap/
- OATI — IEEE PES GM 2026: AI for energy, the flexible grid, and microgrids (Farrokh Albuyeh; July 31) · https://www.oati.com/insights/ieee-energy-ai-takeaways/
- OATI — OATI delivers FERC 881 compliance and unlocks transmission capacity across three regions (August 28 / September 3) · https://www.oati.com/news/ferc-881-regional-deployments/
- GE Vernova — GE Vernova Introduces GridOS® for Transmission and New AI Whitepapers at Orchestrate 2026 (June 9) · https://www.gevernova.com/news/press-releases/ge-vernova-introduces-gridosr-transmission-new-ai
- SAP Architecture Center — Third-Party MCP Access to SAP Solutions (reference architecture RA0029; updated June 8) · https://architecture.learning.sap.com/docs/ref-arch/137800
- CISA — Using Cyber Decoys to Strengthen Detection and Response (September 2026) · https://www.cisa.gov/resources-tools/resources/using-cyber-decoys-strengthen-detection-and-response
- Argonne National Laboratory — GridMind: Powering the control room of the future with AI agents (March 25, updated April 22) · https://www.anl.gov/article/gridmind-powering-the-control-room-of-the-future-with-ai-agents
Dropped this week:
- National Grid Partners, 2026 Utility Innovation Survey (September 18) — fails both tests: published before Monday, and already carried in the September 18 digest’s Sources. Its headline figures (74% say AI-driven data-center load growth is affecting reliability; 78% deploying or operationalizing at least one AI application for interconnection demand) are referenced nowhere above.
- Onapsis named utility customers (SNOPUD, OG&E) — no publication date in-window; and the names attach to RISE migration security, not to any agentic product. Disclosure retained from the daily log: the companion SNOPUD session features this log’s own framing author, so it is not cited as independent evidence.
