For the complete documentation index, see llms.txt. This page is also available as Markdown.

Energy and utilities compliance

Energy and utilities compliance — NERC CIP/OPS, FERC, state PUC/CPUC, PHMSA, OSHA, EPA, ISO/RTO market rules.

Energy compliance combines federal reliability rules (NERC) + federal energy regulator (FERC) + state PUCs + pipeline / OSHA safety + environmental (EPA) + market rules (ISO/RTOs). AI in this sector inherits all layers.

Regulatory frame

Regime
Applies when
Evaluation-evidence shape

NERC CIP

Bulk Electric System cyber assets

Asset classification; access control; incident response

NERC OPS / PRC / TPL / etc.

BES reliability

Procedure compliance; protection coordination

FERC orders

Interstate transmission, wholesale markets

Order-specific requirements (e.g., 880, 881, 2222)

State PUC / CPUC rules

Retail rates, service quality

Tariff filings; rate cases

CPUC wildfire rules (CA)

CA electric utilities

Wildfire mitigation plans; AI risk-modeling oversight

PHMSA (49 CFR 192/195)

Gas / liquids pipelines

Integrity management; record retention

OSHA 1910.269

Electric power generation/T&D

Switching/working-on rules; LOTO; PPE

EPA Clean Air / Water Acts

Power generation; water utilities

Emissions / discharge monitoring

ISO/RTO market rules

Wholesale market participants

Specific market protocols

Privacy laws (CCPA, etc.)

Customer-data scope

DSR; consent; retention

CALEA / state surveillance

Carrier-like services (some utilities)

Lawful intercept

NIST AI RMF

Voluntary; cited in DOE / NREL guidance

GOVERN/MAP/MEASURE/MANAGE evidence

NERC CIP

NERC Critical Infrastructure Protection standards apply to BES Cyber Systems:

  • CIP-002: Cyber asset categorization

  • CIP-003: Security management

  • CIP-004: Personnel and training

  • CIP-005: Electronic security perimeters

  • CIP-007: Systems security management

  • CIP-008: Incident reporting

  • CIP-010: Configuration change management and vulnerability assessments

  • CIP-011: Information protection

  • CIP-013: Supply chain risk management

Penalties up to $1M per day per violation.

Stratix posture:

  • Stratix is not a BES Cyber System; it is a SaaS evaluation platform

  • For utilities using Stratix to evaluate AI that influences BES operations, the AI itself and its operational-deployment footprint may be in CIP scope (depending on impact rating)

  • BYOK custom models recommended for sensitive workloads

  • NERC CIP-013 supply-chain diligence package available — talk to enterprise

FERC orders

Selected high-impact orders:

  • Order 880 — Cybersecurity reporting requirements

  • Order 881 — Ambient-adjusted ratings for transmission

  • Order 2222 — DER aggregation in wholesale markets

  • Order 2023 — Generator interconnection reform

Each carries specific compliance evidence requirements.

State PUC / CPUC

State-by-state regulation of retail service:

  • CPUC AI rules (CA) — Active rule-making; wildfire-mitigation AI is most scrutinized

  • NY PSC / CT PURA / TX PUC / IL ICC / others — Per-state proceedings on AI-influenced decisions

  • Service-quality penalties when AI-driven systems contribute to outages

Stratix evaluation evidence:

  • AI use-case inventory tied to filings

  • Drift dashboards for regulator-pull-on-demand

PHMSA (49 CFR 192/195)

Gas-pipeline (192) and liquids-pipeline (195) safety:

  • Integrity management programs

  • Operator qualification

  • Public awareness

  • Incident reporting

Stratix evaluation evidence:

  • Hard rule on field-safety AI: cite 49 CFR section

  • Audit log of AI guidance vs. recorded incidents

OSHA 1910.269

Electric power generation, transmission, distribution. The dominant federal worker-safety standard for line work.

Stratix evaluation evidence:

  • LOTO + PPE rules on every field-safety AI output

  • Manual-version match rule

EPA

Clean Air Act / Clean Water Act apply to generation and water utilities. AI used in compliance reporting must produce verifiable inputs.

ISO/RTO market rules

Each ISO/RTO has its own protocols:

  • PJM, MISO, ERCOT, CAISO, ISO-NE, NYISO, SPP

  • Settlement disputes are common; AI-augmented bidding must produce auditable trail

  • FERC enforcement on market manipulation extends to algorithmic strategies

Stratix evaluation evidence:

  • ISO-rule compliance rule per market output

  • Settlement-data freshness check

Privacy laws

CCPA / state privacy / GDPR — same framework as retail compliance.

NIST AI RMF

Cited as voluntary best practice in DOE and NREL AI guidance. For DOE-funded R&D, NIST AI RMF mapping is a common deliverable.

  1. Pro tier minimum; Enterprise for utilities and ISO/RTO participants

  2. SSO + RBAC for dispatch / NOC / customer-service / field roles

  3. BYOK custom models for NERC CIP-touching workloads

  4. Hard rules: advisory-only on dispatch, switching-procedure citation, NERC standard compliance, OSHA 1910.269 / PHMSA citation, medical-baseline routing

  5. Group-fairness scorers on customer-affecting AI

  6. Audit retention matching the longest applicable NERC / PHMSA / state requirement (default 7+ years; 6 years for many NERC standards)

  7. AI use-case inventory tied to NERC and state filings

  8. NIST AI RMF mapping retained per use case

  9. DPA executed; tenant data residency where contracted

See also

Last updated

Was this helpful?