MICKAI®ArticlesCan energy operators run AI on gr…
Article · 18 August 2026

Can energy operators run AI on grid and OT data on-premise to satisfy the Cyber Assessment Framework?

Yes: forecasting and anomaly detection that run entirely on operator-owned hardware keep grid and OT data inside the Cyber Assessment Framework boundary.

Author
Micky Irons
Published
18 August 2026
Follow Micky Irons
LinkedInX
cyber assessment frameworkon-premise aiot securityenergy sectorsovereign ai
Can energy operators run AI on grid and OT data on-premise to satisfy the Cyber Assessment Framework?

Yes. Energy operators can run forecasting and anomaly detection on grid and operational technology data entirely on their own hardware, and doing so is the cleaner path to satisfying the Cyber Assessment Framework, not a workaround. The CAF assesses the security of the boundary around essential-function data, and analytics that never leave operator-owned infrastructure keep that boundary intact. When the AI layer runs on-premise with no outbound connection, SCADA telemetry stays inside the audited perimeter and there is no third-party processor to assess.

Most current guidance stops at "segment your OT network", yet the analytics layer routinely undoes that segmentation by shipping SCADA telemetry to a vendor cloud for modelling. The Cyber Security and Resilience Bill puts the CAF on a firmer statutory footing, and regulators are asking harder questions about where essential-function data is actually processed. An anomaly detector that phones home is now a finding, not a feature.

Why does cloud AI break the CAF boundary?

The Cyber Assessment Framework, published by the NCSC, assesses four objectives: managing security risk, protecting against cyber attack, detecting cyber security events, and minimising the impact of incidents. Several principles turn on data location: Principle B3 covers data security and Principle C1 covers security monitoring. When grid and OT telemetry is streamed to a public cloud AI service for forecasting or anomaly detection, the operator has extended its trust boundary to a party it does not control.

That creates problems an assessor will note. The data sits under a foreign legal regime, which for US-operated clouds means exposure to the CLOUD Act. The processing happens where the operator cannot inspect it, and the model provider becomes a supply-chain dependency. General-purpose public cloud AI services are cloud services by design, and streaming live SCADA data to one pushes an operator's most sensitive telemetry past the boundary the CAF is built to protect.

If the analytics that model your grid cannot run without sending your grid data to someone else, you have not segmented your operational network, you have merely relocated its most sensitive telemetry.

How does on-premise AI keep grid and OT data inside the trust boundary?

On-premise AI inverts the flow. The models run on operator-owned hardware, inside the same perimeter as the historian and the SCADA network. Telemetry is read and scored locally, the result stays local, and nothing is posted outbound.

Mickai is a Sovereign Intelligence Operating System, a SIOS, built for exactly this constraint. It runs offline on operator hardware behind a zero-egress inbound perimeter, so data can enter for processing but no connection is opened to send it back out. Identity is hardware-attested and bound to the audit chain, so every action is tied to an attested device and operator.

What can an auditor actually check?

An assessor wants evidence, not promises. On-premise AI produces the kind an auditor can test directly.

  • Network egress: capture traffic at the perimeter and confirm the analytics layer opens no outbound connection during scoring.
  • Data residency: show that the historian, the models and the inference all run on named, operator-owned hardware.
  • Tamper-evidence: every action is written to a post-quantum signed audit ledger, sealed with FIPS 204 (ML-DSA) as the primary signature standard and FIPS 205 (SLH-DSA) alongside it, so the record verifies offline and cannot be rewritten after the fact.
  • Identity: hardware-attested identity ties each entry to an attested device, supporting the access-control expectations under Principle B2.

The named test is blunt: pull the perimeter capture, run the anomaly detector against live telemetry, and confirm zero outbound packets from the analytics host. If the detector still works and nothing left the building, the CAF boundary held.

Which rule makes this necessary?

The CAF is the assessment method, but a stack of regulation now points the same way. The Cyber Security and Resilience Bill broadens the UK's cyber duties for operators of essential services. NIS2 across the EU covers essential and important entities with tighter incident and supply-chain obligations. DORA, in force since 17 January 2025, holds financial entities to strict controls on where their data is processed, the same location-of-processing scrutiny now surfacing across regulated sectors.

On the EU AI Act, the high-risk Annex III obligations once due on 2 August 2026 were deferred by the Digital Omnibus to 2 December 2027, with embedded Annex I high-risk duties moving to 2 August 2028 and the Article 50 transparency rules largely unchanged. We read that as a build window, not a reprieve. Operators that move analytics on-premise now will arrive at the tighter regime prepared rather than retrofitting under a deadline. ISO/IEC 42001 frames how to govern the AI itself.

How does forecasting and anomaly detection run with zero egress?

Forecasting and anomaly detection do not need the cloud. Load forecasting, demand prediction and OT drift or intrusion detection are pattern problems a well-built model runs locally on operator hardware. Mickai runs sovereign models on-premise and uses cross-model consensus, where more than one model scores the same event and agreement is required before an alert is raised, which reduces false positives on noisy SCADA feeds. Because the whole loop is local, latency drops and detection keeps working through a wide-area network outage, exactly when it matters most. The zero-egress architecture and the sealed audit chain behind it are the subject of 104 filed UK patent applications, approximately 2,340 claims, owned by Mickai LTD, filed and patent pending.

What should an energy operator do first?

Start by mapping where essential-function data actually flows, including every analytics and monitoring integration, not just the SCADA core. Replace the cloud-dependent analytics with on-premise inference behind a zero-egress perimeter, then re-run the CAF self-assessment with the perimeter capture as evidence. The aim is to remove the leak, not to bolt a security layer onto a leaky one.

Frequently asked questions

Does running AI on-premise mean giving up model quality?

No. Load forecasting and OT anomaly detection are narrow, well-defined problems that sovereign models run to high accuracy on operator hardware. Cross-model consensus, where several models must agree before an alert fires, often improves precision on noisy grid data compared with a single cloud model. The trade is not quality for control; you keep both.

Can on-premise AI still satisfy CAF Objective C for security monitoring?

Yes, and it strengthens the case. Objective C is about detecting cyber security events, and a local anomaly detector that reads OT telemetry inside the perimeter provides that detection without exporting the very data you are trying to protect. The monitoring evidence, alerts and their provenance all live in the tamper-evident audit ledger the assessor can inspect offline.

Is a private cloud or sovereign cloud region enough for CAF?

It depends on who holds the keys and where the legal control sits. A hosted region still involves a third-party operator and, for US-owned providers, potential CLOUD Act reach, so the boundary extends beyond the operator. Running the analytics on operator-owned hardware with zero egress removes that dependency entirely, which is the cleanest position to evidence under the CAF.

How does the audit ledger prove nothing was tampered with?

Every action is chained and signed with post-quantum digital signatures, FIPS 204 (ML-DSA) as the primary standard and FIPS 205 (SLH-DSA) alongside it. Any change to a past entry breaks the signature chain, so an auditor can verify the whole record offline and detect tampering without trusting the operator's word. The verification needs no live connection to any vendor.

Does the Cyber Security and Resilience Bill ban cloud AI outright?

No. The Bill strengthens duties and oversight for operators of essential services rather than banning any specific technology. The practical effect is that where you process essential-function data becomes something you must justify to a regulator. On-premise analytics with a demonstrable zero-egress boundary is the position that survives that scrutiny with the least friction.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/energy-caf-ai-on-premise-ot-data. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles
18 Aug 2026
How Telecoms Operators Meet the Telecommunications Security Act With AI That Never Leaves the Network
Telecoms operators meet the Telecommunications Security Act code of practice with AI that runs inside the security-critical boundary on operator-owned hardware. A zero-egress perimeter keeps network configuration and signalling data within operator control, so nothing sensitive crosses out to a public cloud service.
18 Aug 2026
How Airports Meet EASA Part-IS from February 2026 with On-Site AI
Part-IS applies to aerodrome operators from 22 February 2026 and makes the airport, not its vendor, accountable for information-security risk. Running AI on operator-owned hardware behind a zero-egress perimeter keeps passenger and operational data inside that boundary, so a supplier's SOC 2 cannot discharge it.
18 Aug 2026
Can Automotive Suppliers Use AI on OEM Design Data While Keeping TISAX Prototype Protection?
Automotive suppliers can run AI on OEM design and prototype data and keep TISAX prototype protection, but only when the model runs on their own hardware inside the protected zone. Public cloud AI transmits the data outward, which prototype protection forbids.
18 Aug 2026
Can councils run AI on resident and social care records without adding a cloud data processor?
Councils can run AI on resident and social care records without adding a cloud data processor by running it on hardware they own, with no data leaving the building. If no third party ever receives the records, there is no processor to contract or record.