AI tools are rapidly becoming part of day-to-day workflows across the electric power industry. Engineers are using them to summarize standards, review documentation, analyze datasets, and even assist with compliance checks (the final three of these activities introduces real risk that we'll discuss in this article.)

These tools can provide real productivity gains. But as adoption increases, compliance leaders are beginning to ask an important question:

What happens when sensitive grid and protection system data is entered into general-purpose AI tools?

For organizations subject to NERC requirements — particularly CIP — this is not just a technology decision. It can become a compliance risk.

What Counts as Sensitive Compliance Data?

Many NERC compliance workflows involve information such as:

Even when this information is not explicitly classified as BES Cyber System Information (BCSI), it may still fall under operationally sensitive information that organizations carefully control.

Uploading this data into public AI tools can create uncertainty around:

These questions matter — especially when viewed through the lens of CIP requirements.

CIP Considerations When Using Public AI Tools

While applicability depends on each organization's architecture and policies, several CIP areas may come into play when operational data is shared outside controlled environments.

CIP-002 — BES Cyber System Categorization & Identification

Organizations must identify and classify BES Cyber Systems and associated information. If sensitive operational data tied to BES Cyber Systems is uploaded to external AI services, organizations must consider whether that data is being handled consistently with their categorization and protection requirements.

CIP-003 — Security Management Controls

CIP-003 requires documented security policies governing how BES Cyber System information is handled. Use of external AI tools may introduce:

If personnel begin using AI tools informally, it can create shadow workflows outside defined security controls.

CIP-004 — Personnel & Training

CIP-004 requires personnel with access to BES Cyber Systems or information to follow defined security practices. As AI tools become more common, organizations may need to clarify:

Without guidance, well-intentioned employees may unknowingly introduce risk.

CIP-011 — Information Protection

CIP-011 focuses specifically on protecting BES Cyber System Information (BCSI). Depending on the nature of the data, uploading protection settings, topology, or system configuration data into external AI platforms could raise questions around:

Even when tools claim strong protections, utilities still need to ensure alignment with internal controls.

CIP-013 — Supply Chain Risk Management

CIP-013 requires organizations to evaluate risks associated with vendor products and services. Use of AI platforms introduces:

This doesn't mean AI cannot be used — but it does mean organizations should evaluate it intentionally.

The Emerging Pattern

We're seeing many utilities take a cautious approach:

The goal isn't to slow AI adoption — it's to adopt AI responsibly.

Where Purpose-Built Systems Help

When compliance workflows run inside purpose-built, closed-loop systems:

This allows organizations to benefit from automation without introducing uncertainty around data handling.

As utilities continue exploring AI, the most effective approach is emerging: Use AI to assist knowledge work. data phleet's controlled systems execute compliance validation.

That balance helps reduce risk — while still moving forward.