Key points
- In December 2025, ASD’s ACSC, CISA and seven other agencies set four principles for AI in operational technology (OT). They advise limiting AI control of OT without a human in the loop.
- In May 2026, ASD and five partner agencies advised using agentic AI only for low-risk tasks, and never giving it broad access to critical systems.
- AI already adds value. The IEA reports that AI-based fault detection can cut outage durations by 30–50%.
- The uses already in service improve what people know. They do not need the AI to operate plant.
- Advisory AI with human approval keeps accountability clear, gives people the chance to catch errors before they reach plant, and keeps the network able to run without the AI.
AI tools that detect faults, track equipment health and forecast output are already in use on power networks. For a control room, the harder question is not whether AI can help. It is whether AI should be allowed to act on plant.
In December 2025, ASD’s Australian Cyber Security Centre (ACSC), the US Cybersecurity and Infrastructure Security Agency (CISA) and seven other agencies published joint principles for AI in OT. Their message is balanced: use AI where it helps, but keep people in charge of control.
This article explains what the guidance says, where AI already adds value, and why an advisory design, in which AI proposes and a person decides, suits critical infrastructure.
What the December 2025 principles say
The joint guidance covers machine learning, large language models (LLMs) and AI agents. It sets four principles:
- Understand AI.
- Consider AI use in OT.
- Establish governance and assurance.
- Embed oversight and failsafes.
On control, the guidance is direct. It advises operators to limit active AI control of OT without a human in the loop. It also names risks that control rooms will recognise. Model drift means a model becomes less accurate as the network changes around it, for example after new connections or a feeder reconfiguration. A lack of explainability means an operator cannot see why a model gave its answer, and so cannot check it. False alarms waste attention and teach people to ignore the tool.
Ultimately, humans are responsible for functional safety.
Joint guidance by ASD’s ACSC, CISA and partner agencies, December 2025
The guidance does not ban AI in OT. It asks operators to understand each use, govern it, and build in oversight and failsafes.
In Australia, this guidance matters all the more. The National AI Plan, released on 2 December 2025, builds on existing laws rather than adding new mandatory AI guardrails. Existing duties, guidance like this and each operator’s own governance therefore set the practical expectations.
Agentic AI: low-risk tasks only
Agentic AI adds a new kind of risk. An AI agent does not only answer questions. It can plan steps and use tools to take actions.
On 1 May 2026, ASD and five partner agencies advised never giving agentic AI broad or unrestricted access to sensitive data or critical systems, and using it only for low-risk tasks. Switching on a live network is rarely low-risk: a wrong step can interrupt supply or put a field crew in danger.
The business case is also uncertain. Gartner predicts that over 40% of agentic AI projects will be cancelled by the end of 2027, because of cost, unclear value or weak risk controls. The prediction is not specific to energy, but weak risk controls matter most where a mistake can cut supply.
Security is a further reason for care. The IEA reports that cyberattacks on energy utilities tripled in four years and are becoming more sophisticated because of AI. Any AI system that can issue commands is one more path an attacker can try to use.
Where AI already adds value
None of this means AI has little to offer. The IEA reports that AI-based fault detection can cut outage durations by 30–50%, and that AI-based grid tools could free up to 175 GW of transmission capacity without new lines.
Many uses are already in service. In the United States, AI monitors more than 10,000 transformers and 22,000 circuit breakers. In Chile, an AI forecasting model up to 15% more accurate reduced wind curtailment. In India, AI solar forecasting cut penalties for forecast errors. IRENA reports that predictive maintenance, real-time monitoring and AI-enabled asset management are lowering operating and maintenance costs and extending the life of renewable assets.
These uses share a pattern. They find faults sooner, track equipment health and forecast output. Their value comes from better information, and none of them needs the AI to operate plant.
The IEA also points to limits. Fragmented data holds back AI adoption in energy, and an IEA survey of energy companies found that the lack of digital skills is the single largest barrier.
Why advisory design suits critical infrastructure
In an advisory design, the AI proposes and a person decides. For critical infrastructure, that brings practical strengths.
Accountability stays clear. The guidance places responsibility for functional safety with people. When a named person approves each action, it is clear who is responsible for it.
Errors can be caught before they reach plant. Drift, weak explanations and false alarms should be expected. When a person checks each answer first, a wrong one can end as a rejected suggestion rather than a wrong switching action.
There is less to attack. If the AI has no control path, taking over the AI gives an attacker no way to operate plant. A compromised AI could still give misleading advice, which is one more reason each suggestion should show its reasons.
The network can run without the AI. The National AI Centre’s Guidance for AI Adoption sets six essential practices, and the sixth is to maintain human control. It advises keeping other ways to run critical functions if AI fails. When operators still make the decisions, their skills and procedures stay in daily use. Losing the AI becomes an inconvenience, not an outage.
Value can be proved first. An advisory tool can run beside the current system on live data, and its advice can be compared with what operators actually did. That tests value with evidence while the risk stays low.
Advisory design has costs. Human approval adds time, and a person asked to approve many suggestions may start to approve without checking. The answer is advice that is quick to check: a clear recommendation, the reasons, a confidence level and the expected effect. Where fast, repeatable automation is justified, engineers can approve it in advance within tested limits, with interlocks and a way to switch it off.
How we approach this
Ozari is built on the same idea: the AI advises, and people decide.
- ozari+, our AI advisor, has no command field and no control path. It explains and ranks options, with a confidence score and a rationale for each.
- By default it is statistical and rule-based, and it needs no outside connection.
- Operator commands need approval from two different people. Closed-loop automation stays off until an administrator arms it. Once armed, it acts without per-action approval, but never bypasses interlocks or the tamper-evident audit log.
We suggest starting with a read-only shadow pilot, so you can judge the advice on your own data before relying on it.
Sources
- Australian Signals Directorate, Principles for the secure integration of Artificial Intelligence in Operational Technology, 3 December 2025.
- CISA, ASD’s ACSC and partner agencies, Principles for the Secure Integration of Artificial Intelligence in Operational Technology (PDF), 3 December 2025.
- IAPP, Australia unveils AI policy roadmap, 2 December 2025.
- Australian Signals Directorate, Careful adoption of agentic AI services, 1 May 2026.
- Gartner, Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027, 25 June 2025.
- International Energy Agency, Energy and AI: Executive summary, April 2025.
- International Energy Agency, Key Questions on Energy and AI (PDF), 16 April 2026.
- IRENA, Renewable Power Generation Costs in 2024: Executive summary (PDF), July 2025.
- National AI Centre, Guidance for AI adoption: implementation guidance, October 2025, updated May 2026.



