Utility AI Weekly — October 2, 2026

Third issue. Window: Monday September 28 through Friday October 2, 2026. Seven in-window items, and the Mon–Fri discipline cost more this week than in either prior issue — thirteen of the twenty items the daily log carried across five entries publish before Monday and are held for context rather than re-reported. The largest casualties are the two artifacts that most directly answer this log’s standing question: EPRI’s SAFERai.power autonomy ladder (August 6) and the nine-nation NSA/CISA/FBI “Principles for the Secure Integration of AI in Operational Technology” (December 3, 2025). Both were surfaced for the first time this week and both are out-of-window; they are named here and will be cited as context, not counted. Also held: AAIGF-E (September 24), Cloud Range’s AI Validation Range (September 24), the AI Energy Management Alliance (September 16), Itron IEE Cloud AI (September 16), TransGrid’s EnergyFluo (September 15), Bidgely Agentic CX (September 22), SAP Industry AI (August 17), ScottMadden’s AIMS (August 24), the SAP Architecture Center reference architecture (August 27), and Mariano Nunez’s April 15 Onapsis post. No duplicates from last week’s Sources. The 📜 Regulatory, Standards & Policy section is omitted: nothing published in-window. Supplementary searches for OATI/MCG movement, an in-window regulatory action, and ISO/RTO control-room deployments returned nothing inside the window — MISO’s “slowing use of AI agents” piece is September 16 and ControlRooms’ agentic troubleshooting launch is September 2.

This was the week the containment layer shipped — and the week it became clear that almost none of it is pointed at a utility.

Monday, September 28 produced three things at once, and they are the same argument told from three places in the stack. NVIDIA launched the Open Agent Safety Platform with 100-plus partners, on a diagnosis worth quoting because it is correct: across the recent incident record, “the agent circumvented security controls at the application layer,” therefore the boundary has to sit outside the model and outside the agent harness. Anthropic’s Claude Managed Agents supplied the model-provider half — agent loop on a separate server from the execution sandbox, credentials in a vault outside the agent’s view, per-agent audit trails — now integrated with OpenShell and BlueField so that boundary is enforced in silicon rather than in policy. And SAP announced it is embedding OpenShell into the Joule Studio runtime, contributing code to it directly, and splitting agent authority into two separately enforceable questions: whether an action should execute at all (SAP’s governance layer) and how the agent executes, what it can see, and where inference goes (OpenShell’s runtime). Then on Tuesday, Schneider Electric and SECLAB made the same move one layer further down and actually shipping — a hardware protocol break inline in front of the controller, explicitly motivated by AI-accelerated vulnerability discovery.

The first appearance of grid entities in this story is the finding. NVIDIA’s release names SPP, NextEra Energy, EPRI, Hitachi Energy, Schneider Electric, Siemens Energy, Quanta Services and Worley as critical-infrastructure providers working with the platform’s technologies. That is the first time an agent-containment announcement in this log has named an RTO and an IOU at all. It is also “working with … technologies,” not deployment: no energy participant is quoted, no use case is named, and there is no NERC CIP mapping and nothing on the ADMS/SCADA/OMS boundary anywhere in the platform material.

The counterweight arrived Wednesday from an organization that observes exploitation rather than selling a control. Google Threat Intelligence Group measured the premise every vendor in this log has been asserting: disclosures up 128% to 10,740/month, in-the-wild exploitation from 10.5 to 18 per month, AI-discovered flaws twice as likely to enable remote code execution (50% vs 26%) — and, the finding that should reorganize a utility’s agent policy, 782 CVEs in AI orchestration and agent frameworks in eight months, half of all AI-related flaws, up 347%, with three already exploited in the wild. The agent stack is the most-attacked AI layer. GTIG’s own defender guidance is to sandbox autonomous agentic workloads and segment around AI orchestration middleware — which is the Monday announcements, independently arrived at. GTIG also supplies the discipline: only 0.23% of disclosed vulnerabilities are ever exploited, so the implication is triage and time-to-patch, not universal urgency.

And the week’s quietest item names the distribution problem all of this creates. Cyware and WaterISAC are putting agentic threat intelligence into the water sector through an ISAC rather than a procurement, reaching 20,000-plus of the sector’s smallest operators. There is no named product and no timeline, so it is carried for its structure. The structure is the point: if high-risk flaws are weaponized within days, the binding constraint is reaching operators who cannot buy detection — and no E-ISAC equivalent for agentic threat intelligence has appeared in this log.


🤖 Control-Room & Operational AI

The only in-window claim of an agent running in production in grid operations comes from a state-owned Chinese utility, at a promotional venue, and it clears the threshold this log cares about. State Grid Zhejiang Electric Power showcased “Guangqing,” an AI super-agent for the power grid, at the UN Global Compact Leaders Summit on September 28. Its Powertrace service is stated to cover 9,517 transmission and distribution lines and 503 substations in Hangzhou, detect risks within seconds, and generate dispatch strategies within one minute. A second service, Carbonseek, does hourly location-specific emissions accounting for commercial customers.

The threshold: the output is a dispatch strategy, not an advisory summary. That is recommendation-to-action in a live distribution system, at a scope no US deployment in this log approaches.

The silence is louder. Nothing in the release states who approves the strategy, whether an operator may decline it, how the agent’s actions are logged, or how it is stopped. Required discounts: a UN showcase press release, a state-owned utility in a non-NERC jurisdiction, no independent audit of any figure, and latency claims unqualified as to coverage. Carry it as a benchmark US utilities will be asked to compare against — because they will be — not as evidence.

Neither tracked incumbent moved, for a fifth consecutive week. OATI’s newsroom is unchanged since September 17; MCG Energy Solutions remains silent on AI. The standing anchor is therefore unchanged: OATI’s AI Genie at CAISO remains the only confirmed production agentic deployment in US grid operations this log tracks — 500-plus next-day outage requests triaged in under eight minutes, operators retaining final authority. Supplementary search found no in-window ISO/RTO deployment announcement.


🏭 In Production vs. 🔮 Forecast / Marketing

The separation matters unusually much this week, because three of the four Monday announcements are architecture rather than product, and the press framing does not distinguish them.

🏭 In production, available now, or shipping

  • NVIDIA OpenShell — the open-source secure runtime boundary that traces all agent actions and enforces policy is broadly available now, via NVIDIA developer resources and GitHub, and extensible beyond NVIDIA’s Vera platform to Arm and Intel. This is the one piece of Monday’s stack a utility could obtain today.
  • Schneider Electric × SECLAB dedicated OT-protocol configuration — shipping. A SECLAB appliance sits inline on critical communications, enforcing a hardware-based protocol break plus application-level filtering, passing only what the process strictly requires. Enforcement below the software layer, from a control vendor rather than a chip vendor.
  • Anthropic Claude Managed Agents — public beta (since April 8, 2026; GA not stated in any source consulted). The in-window event is the September 28 pairing with OpenShell and BlueField, not the product. Named adopters are Notion, Rakuten and Sentry: no utility, no ISO/RTO, nothing in CIP scope.
  • State Grid Zhejiang’s Guangqing — claimed in production, at the scope and latency above, with the verification caveats above.

🔮 Forecast, roadmap, and marketing

  • NVIDIA Sentry — not a product. It is a reference system design on BlueField-4 DPUs: out-of-band watchdog, agent-identity verification, attested telemetry, quarantine of a boundary-crossing agent in milliseconds from a trust domain “invisible to agents and attackers.” The millisecond kill-switch is the figure that will be quoted at you; it describes a design, not a shipping capability.
  • SAP × NVIDIA OpenShell — the title reads “Working Toward” and should be quoted that way. Real content: SAP is contributing engineering to the OpenShell codebase across four named areas, and the division of authority is stated cleanly (Joule Studio runtime decides whether an action executes; OpenShell governs how the agent executes, what it sees, where inference goes). But FedRAMP and FIPS enablement are roadmap, and the Joule Studio runtime is free only through October 2026 — an adoption window, not a product commitment.
  • SAP AI Agent Hub — the quarter closed without the capabilities that matter. Q3 2026 ended September 30 with no dated release note for agent identity via SAP Cloud Identity Services or AI observability, the two capabilities separating an agent inventory from an agent control plane. One thing did move, and it is worth watching: the product and community material now states that “only verified MCP servers can be called in production workflows” — the Verification Seal described as a runtime gate rather than a label, and the first thread-(c) capability that would actually stop something. It appears on product and community topic pages, not in a release artifact; GA, pricing and customers remain unstated, and revocation propagation is still undescribed.
  • Cyware × WaterISAC — announced partnership, not shipping capability: no named product, no shipping-versus-planned distinction, no timeline, no participating utilities, no metrics.

🛡️ AI & Grid Cybersecurity

The vendor claim is now measured, by an observer rather than a seller. Google Threat Intelligence Group’s Vulnerability Discovery and Exploitation Trends in the AI Era (September 30) is the item the last two weeks of this log implicitly depended on.

  • Pace: disclosures 5,045/month (January 2026) → 10,740 (August), +128% indexed from January 2025; High-Risk 131 → 350, +167%; in-the-wild exploitation 10.5/month (2025 average) → 18/month; 141 exploited year-to-date 2026 against 127 for all of 2025; zero-days 8 → 11 per month with a 22 spike in August, still 62% of observed exploited vulnerabilities.
  • The discipline in the same numbers: only 0.23% — 1 in 431 — of disclosed vulnerabilities are exploited, and roughly 5,000 Linux kernel CVEs were disclosed with zero observed exploitation. The growth is in rapid weaponization of high-risk n-days, not in zero-day volume. The operational implication is threat-intelligence-driven triage, and GTIG says so explicitly — replace mass-patching with it.
  • AI changes the profile, not only the count: AI-discovered flaws enable RCE in 50% of cases against 26%, skew Medium severity (58% vs 28%), and concentrate in memory corruption and logic bypass in core C/C++ libraries.
  • The worked example a utility should read twice: CVE-2026-1731, unauthenticated OS command injection in BeyondTrust Privileged Remote Access — a remote-access product, found by the autonomous agent Hacktron AI, and weaponized by six threat clusters within seven days.
  • The finding for agent policy: 782 CVEs in AI orchestration and agent frameworks in eight months — 50% of all AI-related flaws, +347% — against 2,076 AI-related CVEs cumulative. Three already exploited in the wild, including command injection in a LiteLLM MCP server (CVE-2026-42271). If you are standing up an agent platform, the platform is the attack surface.
  • GTIG’s defender guidance: sandbox autonomous agentic workloads; restrict unauthenticated inference APIs; segment around AI orchestration middleware; monitor for prompt injection in workflow builders; least privilege on model checkpoints.
  • What is absent: no ICS/OT breakdown, no electric-sector data, no NERC CIP mapping. The nearest perimeter signal is edge and security appliances at 14% of exploited vulnerabilities, with 65% of edge flaws High or Critical — which, for a utility, is the remote-access and firewall layer.

The boundary moves in front of the PLC, and this one is shipping. Schneider Electric and SECLAB expanded their OT cybersecurity collaboration (September 29) with a dedicated configuration for Schneider OT protocols: appliance inline on critical communications, hardware-based protocol break, application-level filtering. The stated premise is a timing argument that should be familiar by now — vulnerabilities are exploitable within days, while patching a PLC waits on a maintenance window plus testing and requalification, leaving exposure for months, and that gap widens as AI accelerates discovery. Threat data cited: IBM X-Force, manufacturing at 27.7% of observed 2025 incidents, most-targeted sector for a fifth year, with attackers increasingly targeting PLCs and processes directly.

What it is not: no agent identity verification, no agent-versus-human distinction, no agent-specific policy. It is a process-boundary control that would block an over-privileged agent incidentally rather than by design. No NERC CIP mapping, no named utility, framing industrial rather than electric-sector. Note also that Schneider appears on both halves of the containment question this week — on the NVIDIA energy roster and as the OT-security vendor.

The distribution answer arrives in water first. Cyware and WaterISAC (September 30) will deliver agentic AI operational threat intelligence to US water and wastewater utilities through the ISAC, reaching 20,000-plus of the sector’s smallest operators via the National Rural Water Association, inside a sector of 50,000-plus utilities. Thin as an announcement — no product, no timeline, no metrics, OT “at machine speed” invoked with no SCADA or ICS specificity and no regulatory driver named. Carried for the structure, and the electric read-across is direct: the same gap exists between staffed IOU security operations and municipal and cooperative distribution utilities.


🏛️ AI-Provider Posture Toward Critical Infrastructure

September 28 is the most consequential date for utility agent-autonomy policy since the New York PSC ordered an AI inventory, and the reason is structural rather than promotional: the containment argument was made simultaneously by a chip vendor, a frontier lab, and an ERP vendor, and the three versions compose.

NVIDIA — Open Agent Safety Platform. OpenShell broadly available now (above); Sentry a reference design (above). The diagnosis: across recent incidents “the pattern is the same — the agent circumvented security controls at the application layer,” so the boundary must sit outside the model and the agent harness. The energy names — SPP, NextEra Energy, EPRI, Hitachi Energy, Schneider Electric, Siemens Energy, Quanta Services, Worley — are the first of their kind in this log. Scope reaches beyond IT: robotics participants (Figure, Gecko Robotics, Skild AI) are embedding OpenShell into systems that act in the physical world, which is the nearest thing yet to an OT-adjacent containment story. Governance runs through the Open Secure AI Alliance — initiated by NVIDIA, 120-plus organizations, governed by the Linux Foundation, with a Shared AI Findings Exchange. Jensen Huang on the record: “we must accelerate discovery at the frontier of AI safety … safety and security require full-stack engineering.” Limits: “working with … technologies” is not deployment; no energy participant quoted; no named use case; no CIP mapping; and commercial interest in Vera and BlueField-4 is the substrate.

Anthropic — Claude Managed Agents. The model-provider answer to who authorized this and who watches it, and architecturally more specific than anything a frontier lab has previously offered this log: agent loop on a separate server from the execution sandbox; credentials in a vault outside the agent’s view with scoped permissions; end-to-end tracing and per-agent audit trails integrating with existing access controls. Against the standing ASUG frame that answers three of five questions — what rules govern the agent (scoped permissions), who watches it (per-agent audit trail), how it is shut down (credential revocation plus sandbox termination). The September 28 pairing lets those sandboxes be enforced in silicon through OpenShell and BlueField, and Anthropic’s stated principle is that in-model safeguards are complemented by limits outside the model that the agent cannot get past. Status: public beta. No utility, no ISO/RTO, no OT, ADMS, SCADA or OMS story, no CIP reference. The tension worth naming for a procurement file: the containment architecture and the rogue-agent warnings come from the same company — motivation or conflict depending on the lens.

SAP — OpenShell in the Joule Studio runtime. The division of authority, in SAP’s words: the Joule Studio runtime decides whether an action should execute at all (business authorization, role-based policy, process context) before the request reaches the runtime; OpenShell governs how the agent executes, what it can see and do, and where inference goes. That is stronger than the Agent Gateway story because the execution boundary is now an open-source runtime SAP does not own, sitting beneath SAP’s governance layer. Named code contributions: runtime decomposition separating supervisor and agent execution layers, Kubernetes operator support, image-pull-secret management, custom volume claim templates, foreground sandbox deletion, minimized gateway image, heterogeneous compute drivers, supervisor health monitoring. FedRAMP and FIPS are the first compliance regimes named by an SAP primary source in this thread — and they are roadmap. SAP and NVIDIA are both founding members of the Open Secure AI Alliance. Unchanged for a CIP-scoped utility: no NERC CIP mapping, nothing on where agent authority stops at the ADMS/SCADA/OMS boundary, no utility named.

Google — posture by measurement rather than by offer. GTIG’s report (above) is the week’s only AI-provider artifact that sells nothing. For a utility assembling an agent-platform risk case, it is also the most citable, precisely because the publisher has no control to recommend.

The out-of-window context this section needs, named but not counted. Two artifacts surfaced in the daily log this week answer the question all of the above still dodges, and both publish outside the window: EPRI’s SAFERai.power (August 6) supplies an industry-governed autonomy ladder — advisory systems → supervised action → guarded autonomy → exceptional autonomous use — mapped to NERC CIP and IEC 62443, with NERC, PJM and MISO among 28-plus founding members; and the nine-nation NSA/CISA/FBI “Principles for the Secure Integration of AI in Operational Technology” (December 3, 2025) gives the blunt architectural answer: keep AI off the plant floor, push sanitized OT data outbound to separate secured AI systems, “AI should augment, not autonomously control, safety-critical actions,” and demand the contractual ability to disable AI features. Neither is in-window. Both belong in the procurement file this week’s announcements will land in.


🔍 Vendor Watch

OATI — no new material in-window; newsroom unchanged since September 17, a fifth consecutive week without AI movement. Standing position unchanged: AI Genie in daily production at CAISO, 500-plus next-day outage requests triaged in under eight minutes, operators retaining final authority. The energy-native-versus-general-purpose procurement distinction OATI drew at IEEE PES remains the most useful frame this log has for reading the week’s announcements — none of Monday’s three is energy-native.

MCG Energy Solutions — silent on AI, fifth consecutive week.

Onapsis — did not move for the third, fourth, fifth, sixth and seventh consecutive checks. Blog and press pages were fetched directly on September 28, 29 and 30 and October 1 and 2; newest dated items remain the September 18 SAPMAP advisory and the July 30 State of AI, Security and ERP study. Agentic Gateway / MCP Gateway for SAP Security is still previewed since March 17 — seventh month, no GA, no named customer, inbound/outbound scope unstated; the August 27 CrowdStrike integration remains the only shipping item. ORL SAPMAP: no follow-on. The structural weakness is unchanged: the Agentic Gateway is inbound enrichment for someone else’s agent via MCP, not governance of agents acting on SAP.

SAP — the vendor that moved most, in two directions at once. OpenShell co-development is real engineering with a named compliance roadmap (above). The AI Agent Hub missed its own quarter: Q3 closed September 30 with agent identity and AI observability still lacking a dated release note. The Verification Seal moved from label to stated runtime gate on product and community pages, undocumented in any release artifact. Watch the Joule Studio runtime free-through-October-2026 window.

NVIDIA — from referenced architecture to shipping runtime plus a 120-organization Linux Foundation alliance in one announcement, with the first grid-entity roster in this log. The gap to watch is whether any of SPP, NextEra, EPRI, Hitachi Energy, Siemens Energy or Quanta produces a statement of its own. “Working with technologies” is where this stops until one of them does.

Schneider Electric — on both sides of the ledger this week: the NVIDIA energy roster, and a shipping OT protocol-break configuration with SECLAB.

Google — GTIG’s measurement is the week’s most useful provider artifact and sells nothing.

GE Vernova, Siemens (grid software), Itron, Bidgely — nothing in-window.


⚡ Utility-Sector Relevance Flags

  1. The agent platform is now the attack surface, with a number on it. 782 CVEs in AI orchestration and agent frameworks in eight months — half of all AI-related flaws, up 347% — and three already exploited in the wild, including a LiteLLM MCP server. If your organization is standing up an agent platform, orchestration middleware belongs in the vulnerability-management program now, not after the pilot.

  2. Sandbox and segment, from the source with no product to sell. GTIG’s defender guidance — sandbox autonomous agentic workloads, restrict unauthenticated inference APIs, segment around AI orchestration middleware, monitor workflow builders for prompt injection — is this week’s most citable requirement language precisely because Google publishes it as an observer. Put it in a design review before a vendor puts their version in a proposal.

  3. Read Monday’s three announcements as one requirement, not three products. Boundary outside the model and harness (NVIDIA); credentials outside the agent’s view plus per-agent audit trail (Anthropic); separation of whether an action may execute from how the agent executes (SAP). That composite is a specification you can hand a vendor. Only OpenShell is obtainable today; Sentry is a reference design and SAP’s compliance work is roadmap.

  4. A millisecond kill-switch is a design, not a capability. Sentry will be quoted at you. Ask whether the BlueField-4 hardware, the out-of-band trust domain and the attested telemetry exist in the proposal, or only the architecture diagram.

  5. “Working with our technologies” is not a deployment, and SPP and NextEra have not said anything. The grid-entity roster is genuinely new and genuinely thin. Do not let it function as a reference in a procurement until one of the named entities describes what it is actually doing.

  6. Triage, not mass-patching — and the one to triage first is remote access. 0.23% of disclosures are ever exploited, but CVE-2026-1731 in BeyondTrust Privileged Remote Access went from agent-discovered to six threat clusters in seven days, and edge and security appliances are 14% of exploited vulnerabilities with 65% of edge flaws High or Critical. Remote-access and perimeter appliances are where the compressed timeline actually bites a utility.

  7. The PLC timing gap is the argument, and it is not an AI argument. Days to exploit against months to a maintenance window is why a protocol break in front of the controller beats a faster patch cycle you cannot have. The Schneider/SECLAB case is worth citing in an OT architecture review whether or not AI is in scope.

  8. There is no E-ISAC equivalent for agentic threat intelligence. Water got one this week, through an ISAC, reaching 20,000-plus small operators. The same capability gap sits between staffed IOU security operations and municipal and cooperative distribution utilities, and nothing in this log addresses it. If you sit on an E-ISAC or trade-association committee, this is the ask.

  9. Still nobody maps to NERC CIP. Every in-window artifact this week — NVIDIA, Anthropic, SAP, Schneider, GTIG, Cyware — is silent on NERC CIP and on where agent authority stops at the ADMS/SCADA/OMS boundary. The two documents that do the mapping, EPRI SAFERai.power and the nine-nation OT principles, are out-of-window and were surfaced this week. Pull both into the file. That translation remains the registered entity’s own work.

  10. The New York clock: inventories due November 16. Six weeks. Agents that arrived through a vendor platform upgrade, a bundled copilot or a departmental pilot are exactly what an inventory of this kind surfaces. Utilities outside New York should treat it as a template — and note that the autonomy ladder an inventory needs in order to be meaningful now exists, from EPRI, at $15,000–$40,000/year membership and a toolkit not due until 2028.

  11. Benchmark pressure is coming from outside NERC’s footprint. A state-owned utility claims an agent generating dispatch strategies in under a minute across 9,517 lines and 503 substations. It is a promotional press release with no audit and no stated human-authority model, and it will still be in somebody’s board deck. Have the “what would it take to verify that” answer ready before you are asked to match it.


📚 Sources

Primary (in-window, September 28 – October 2, 2026):

  • NVIDIA — NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment (September 28) · https://nvidianews.nvidia.com/news/open-agent-safety-platform · technical detail · https://developer.nvidia.com/blog/nvidia-open-agent-safety-platform-a-reference-for-continuous-in-silicon-agent-monitoring/
  • SAP News Center — SAP and NVIDIA OpenShell: Working Toward Governance and Security for Auditable AI Agents in Enterprise Systems (Andre Lamego, SVP and Chief Product Officer, SAP Business AI Platform Fabric; September 28) · https://news.sap.com/2026/09/sap-nvidia-openshell-auditable-ai-agents-enterprise-systems/
  • Anthropic — Claude Managed Agents: get to production 10x faster (public beta since April 8, 2026; the September 28 OpenShell/BlueField integration and Paul Smith quote are carried via NVIDIA’s release) · https://claude.com/blog/claude-managed-agents · platform documentation · https://platform.claude.com/docs/en/managed-agents/overview
  • GlobeNewswire / State Grid Zhejiang Electric Power — State Grid Zhejiang Electric Power’s AI-Powered Green and Resilient Energy Solution Showcased at UN Global Compact Leaders Summit (September 28) · https://www.globenewswire.com/news-release/2026/09/28/3369927/0/en/state-grid-zhejiang-electric-power-s-ai-powered-green-and-resilient-energy-solution-showcased-at-un-global-compact-leaders-summit.html
  • Google Cloud / Google Threat Intelligence Group — Vulnerability Discovery and Exploitation Trends in the AI Era (Robin Grunewald, Supriya Mazumdar, Kelli Vanderlee; September 30) · https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era/
  • PR Newswire / Cyware — Cyware and WaterISAC Join Forces to Strengthen Water Sector Cyber Defense (September 30) · https://www.prnewswire.com/news-releases/cyware-and-waterisac-join-forces-to-strengthen-water-sector-cyber-defense-302891576.html
  • SAP — AI Agent Hub product and community topic pages, fetched October 2, now stating runtime MCP verification (“only verified MCP servers can be called in production workflows”) · https://www.sap.com/products/artificial-intelligence/ai-agent-hub.html · https://pages.community.sap.com/topics/ai-agent-hub
  • Onapsis blog and press pages — re-fetched directly September 28, 29 and 30 and October 1 and 2, 2026; unchanged since September 18 · https://onapsis.com/blog/ · https://onapsis.com/company/news-press/press/ · Agentic Gateway baseline, still the March 17 preview · https://onapsis.com/press-releases/onapsis-unveils-capabilities-to-unlock-agentic-ai-sap-cybersecurity-workflows/

Secondary (in-window reporting used to source the above):

  • Industrial Cyber — Schneider Electric, SECLAB expand OT cybersecurity collaboration for industrial infrastructure (September 29) · https://industrialcyber.co/news/schneider-electric-seclab-expand-ot-cybersecurity-collaboration-for-industrial-infrastructure/ · secondary · https://itnerd.blog/2026/09/29/schneider-electric-seclab-expand-ot-security-partnership/
  • Industrial Cyber — Cyware, WaterISAC partner to deliver AI-powered threat intelligence to U.S. water and wastewater utilities · https://industrialcyber.co/news/cyware-waterisac-partner-to-deliver-ai-powered-threat-intelligence-to-u-s-water-and-wastewater-utilities/
  • CyberScoop — WaterISAC reckons with range of threats after summer of cyberattacks · https://cyberscoop.com/water-utility-cyberattacks-waterisac-cyware-threat-intelligence/
  • SecurityWeek — Google: AI Is Changing the Pace and Profile of Vulnerability Discovery · https://www.securityweek.com/google-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery/
  • Infosecurity Magazine — AI-Found Vulnerabilities More Likely to Enable RCE, Google Says · https://www.infosecurity-magazine.com/news/ai-found-vulnerabilities-rce/
  • CSO Online — Nvidia releases Open Agent Safety Platform to monitor and govern agentic AI · https://www.csoonline.com/article/4227843/nvidia-releases-open-agent-safety-platform-to-monitor-and-govern-agentic-ai.html
  • SAPinsider — NVIDIA Launches New Security Platform for AI Agents as SAP Builds OpenShell Into Joule Studio · https://sapinsider.org/blogs/nvidia-ai-agent-security-openshell-sap-joule-studio
  • Unite.AI — Anthropic Adds NVIDIA OpenShell Controls to Claude Managed Agents · https://www.unite.ai/anthropic-adds-nvidia-openshell-controls-to-claude-managed-agents/

Out-of-window, named for context and not counted in this issue’s seven:

  • EPRI — EPRI Launches Effort to Reduce Risk in AI Power Sector Deployment (SAFERai.power; GlobeNewswire, August 6, 2026) · https://www.globenewswire.com/news-release/2026/08/06/3340219/0/en/EPRI-Launches-Effort-to-Reduce-Risk-in-AI-Power-Sector-Deployment.html · initiative site · https://msites.epri.com/saferai
  • NSA / CISA / FBI with ASD-ACSC, the Canadian Centre for Cyber Security, Germany’s BSI and the NCSCs of the Netherlands, New Zealand and the UK — Principles for the Secure Integration of Artificial Intelligence in Operational Technology (Cybersecurity Information Sheet, December 3, 2025) · https://www.cisa.gov/resources-tools/resources/principles-secure-integration-artificial-intelligence-operational-technology
  • Seunghwan Myeong — AAIGF-E: An AI and Agentic Intelligence Governance Framework for Electric-Sector Smart-City Infrastructure, Smart Cities 2026, 9(10), 161 (September 24, 2026) · https://doi.org/10.3390/smartcities9100161
  • Cloud Range — Cloud Range Launches AI Validation Range and AI Readiness Framework (Business Wire, September 24, 2026) · https://www.businesswire.com/news/home/20260924650460/en
  • ScottMadden — AI-Enabled Outage Management Planning with AIMS (last modified August 24, 2026) · https://www.scottmadden.com/insight/ai-enabled-outage-planning/

Assembled from UtilityAI_Research_Log.md entries for September 28, 29 and 30 and October 1 and 2, 2026, under the strict Monday–Friday window. Supplementary searches for OATI/MCG movement, in-window regulatory action and ISO/RTO control-room deployments returned nothing inside the window. Unattended automated run; the window judgments and the omission of the Regulatory, Standards & Policy section are noted above.