Regulation explainerElectric Power & Natural Gas

NERC CIP and AI: what applies when models sit near BES Cyber Systems

NERC CIP never mentions artificial intelligence, yet it decides where an AI system can run, who can reach it and how it may change. Obligations follow the system's placement relative to the Electronic Security Perimeter and the information it holds. This explainer covers categorization, placement patterns, BCSI in the cloud, remote access, change management, supply chain and European counterparts.

Reviewed 8 min read

On this page
  1. Why AI projects trigger CIP questions
  2. CIP vocabulary an AI architect needs
  3. Categorizing an AI component under CIP-002
  4. Three placement patterns for AI near the grid
  5. CIP requirements an AI deployment most often touches
  6. Cloud-hosted grid functions remain unsettled
  7. Treating model updates as configuration changes
  8. European counterparts for utilities outside North America
  9. A hypothetical transmission operator classifies substation event records
  10. Questions and answers
  11. Sources

Why AI projects trigger CIP questions

The NERC Critical Infrastructure Protection standards are technology-neutral: a forecasting model or language model is judged like any software, by where it runs, what it connects to and what information it holds.

AI raises CIP questions in three ways: data leaving the perimeter to feed a model hosted elsewhere; new software inside it, when inference runs on a substation or control center server; and new access paths, when a vendor tunes the model. So the first design question is placement, not algorithm.

That is why ColdAI's energy delivery process puts OT/IT integration design ahead of staged deployment1. Compliance determinations belong to the registered entity and its Regional Entity; treat this page as a frame for architecture discussions, not a compliance opinion.

CIP vocabulary an AI architect needs

BES Cyber Asset
A cyber asset that, if unavailable, degraded or misused, would adversely affect reliable operation of the bulk electric system within 15 minutes of its required operation, misoperation or non-operation2.
BES Cyber System and impact rating
BES Cyber Assets grouped to perform reliability tasks. CIP-002 rates each system high, medium or low impact, and most requirements scale with that rating3.
Electronic Security Perimeter (ESP)
The logical border around a routable network connecting BES Cyber Systems, crossed only through Electronic Access Points.
EACMS and PCA
Electronic Access Control or Monitoring Systems guard access to the ESP, such as firewalls and jump hosts. Protected Cyber Assets share the ESP network without a reliability task.
BES Cyber System Information (BCSI)
Information that could be used to gain unauthorized access to a BES Cyber System, such as network address collections, topology and security procedures2.

Categorizing an AI component under CIP-002

Categorization drives everything else. Common outcomes for a model's host, to confirm through your own CIP-002 process:

  • If

    The model's host is inside an ESP, and its failure or misuse could affect grid operation within the BES Cyber Asset window.

    Then

    Treat it as a BES Cyber Asset and apply every requirement of its system's impact rating.

    The test is the effect of failure or misuse, not the software's label.

  • If

    The host sits inside the ESP but performs no reliability task.

    Then

    Classify it as a Protected Cyber Asset, carrying most of the associated system's controls.

  • If

    The model controls or monitors electronic access, such as detection that can block traffic.

    Then

    Treat it as an EACMS, with its own access, logging and supply chain duties.

  • If

    The model runs outside every ESP and only receives copies of data.

    Then

    The host generally falls outside categorization; check whether the data is BCSI and that nothing flows back in.

    One-way designs remove host duties, not information protection.

Three placement patterns for AI near the grid

QuestionOutside the ESP, one-way feedInside the ESPVendor-hosted cloud
Typical usesForecasting and asset health on replicated historian dataLow-latency detection that must survive a network outageManaged ML platforms and large training runs
Status of the AI hostUsually uncategorized, if no path leads back into the ESPBES Cyber Asset, PCA or EACMSOutside what current categorization was designed for
Information dutiesCIP-011 and CIP-004 if the feed contains BCSIFull host controls, plus CIP-011 for stored BCSICIP-004 and CIP-011 for BCSI the provider holds
Access and remote supportCorporate controls; no Interactive Remote Access into the ESPIntermediate System, encryption and multi-factor authentication under CIP-005Provider access governed by contract and the CIP-013 plan
Main residual riskA gateway misconfigured to allow return trafficCompliance overhead slows updates and tempts shortcutsBCSI and privileged access concentrated at one external party

A starting point for discussion, not a compliance determination. Many utilities begin with the first column and move specific functions inward only when latency or resilience requires it.

CIP requirements an AI deployment most often touches

NERC CIP-002: BES Cyber System Categorization

North America (registered entities)

Applies whenA model's host joins networks containing BES Cyber Systems.

  • Rate BES Cyber Systems high, medium or low impact, and revisit the rating when the environment changes3.

NERC CIP-004-7 and CIP-011-3: BCSI access and information protection

North America (registered entities)

Applies whenTraining data, features or model artifacts include BCSI.

  • Authorize, review and revoke provisioned access to BCSI, including key-based access in third-party systems5.
  • Protect BCSI in storage, transit and use, including with vendors; both revisions took effect in January 20246.

NERC CIP-005: Electronic Security Perimeters

North America (registered entities)

Applies whenData or remote sessions cross the ESP, such as inbound model updates or vendor tuning.

  • Allow only necessary access through Electronic Access Points, broker Interactive Remote Access through an Intermediate System, and be able to disable vendor sessions4.

NERC CIP-007 and CIP-010: system security and configuration change

North America (registered entities)

Applies whenInference runs on a BES Cyber Asset, PCA or EACMS.

  • Baseline installed software, authorize deviating changes, limit ports and services, evaluate patches and log security events7.

NERC CIP-013: Supply Chain Risk Management

North America (registered entities)

Applies whenProcuring AI products or services for high or medium impact systems and their EACMS and PACS.

  • A supply chain plan covering vendor incident notice, vulnerability disclosure, software integrity and remote access coordination8.

NERC CIP-015-1: Internal Network Security Monitoring

North America (registered entities)

Applies whenNetworks inside the ESPs of high impact and certain medium impact systems; FERC approved it in Order No. 907 in June 2025, with phased implementation9.

  • Monitor and retain east-west traffic data inside the perimeter; if ML does the detection, scrutinize the tool's own access too.

Cloud-hosted grid functions remain unsettled

Treating model updates as configuration changes

Inside the perimeter, model weights and runtimes change more often than control software. Keep each update visible and authorized:

  1. Put the model in the baseline

    List the runtime, libraries, model version and open ports in the CIP-010 baseline, so retraining is an authorized change, not a silent file swap.

  2. Verify what you received

    Confirm the software source and package integrity before installing, for example with signed artifacts, as CIP-010 expects where possible7.

  3. Test away from production

    Evaluate on held-out data in an environment mirroring the host; high impact systems need changes tested first.

  4. Check ports and patches

    Confirm no new ports open and runtime patches are tracked under CIP-007.

  5. Release with a rollback ready

    Keep the previous model ready, update the baseline and watch output quality after release.

European counterparts for utilities outside North America

Europe has no single CIP equivalent; obligations come from cybersecurity law, an electricity network code and the EU AI Act.

NIS2 Directive (Directive (EU) 2022/2555)

European Union, through national law

Applies whenIn-scope electricity, gas, hydrogen and district heating undertakings, listed among sectors of high criticality12.

  • Cybersecurity risk-management measures, including supply chain security, and staged reporting of significant incidents.

UK Network and Information Systems Regulations (SI 2018/506)

United Kingdom

Applies whenOperators of essential services in electricity, gas and oil above the Regulations' thresholds13.

  • Manage risks to network and information systems and report incidents, commonly assessed against the NCSC Cyber Assessment Framework14.

Network code on cybersecurity (Delegated Regulation (EU) 2024/1366)

European Union

Applies whenEntities affecting cross-border electricity flows and identified as high-impact or critical-impact15.

  • Join the code's risk assessments and apply its minimum and advanced controls.

EU AI Act (Regulation (EU) 2024/1689)

European Union

Applies whenAI intended as a safety component in operating electricity or gas supply, listed as high-risk in Annex III16.

  • Risk management, data governance, logging, human oversight and cybersecurity duties.

A hypothetical transmission operator classifies substation event records

Questions and answers

Does NERC CIP prohibit using public cloud AI services?

Not outright. Since the CIP-004 and CIP-011 revisions took effect in January 2024, a cloud provider can hold BCSI if provisioned access and protection are managed5. Hosting BES Cyber Systems, EACMS or PACS in a third-party cloud remains unsettled, so cloud analytics on copied data raise far fewer questions than cloud services that would control or monitor grid assets.

Is a model trained on BES Cyber System Information itself BCSI?

The standards do not say, so record it as a judgment in your information protection program. A model that could reveal addresses, topology or security settings, for instance by reproducing memorized records, is safest handled as BCSI. Models trained only on operational measurements, with sensitive fields removed first, are easier to keep out of scope.

Do low impact BES Cyber Systems matter for AI projects?

Yes, though the duties are lighter. CIP-003 sets controls for assets containing low impact BES Cyber Systems, including electronic access controls, and recent revisions add vendor remote access controls. Review any AI tool that needs connectivity into a low impact substation, or a vendor connection, against it before installation.

Does NERC CIP apply to natural gas utilities?

NERC CIP covers entities registered for bulk electric system functions, so a gas-only distribution company sits outside it. US gas pipelines have their own regimes, including federal pipeline safety rules and, for designated critical pipelines, Transportation Security Administration security directives. Combined utilities often run both programs side by side.

Sources

  1. Electric Power & Natural Gas: energy delivery process — ColdAI
  2. Glossary of Terms Used in NERC Reliability Standards — North American Electric Reliability Corporation · checked 10 October 2026
  3. CIP-002-5.1a: Cyber Security — BES Cyber System Categorization — North American Electric Reliability Corporation · checked 10 October 2026
  4. CIP-005-7: Cyber Security — Electronic Security Perimeter(s) — North American Electric Reliability Corporation · checked 10 October 2026
  5. CIP-004-7 R6 and CIP-011-3 R1: Cloud Solutions for BCSI (ERO-endorsed implementation guidance) — NERC Reliability and Security Technical Committee · checked 10 October 2026
  6. CMEP Monthly Update Letter, January 2024: standards effective January 1, 2024 — ReliabilityFirst · checked 10 October 2026
  7. CIP-010-4: Cyber Security — Configuration Change Management and Vulnerability Assessments — North American Electric Reliability Corporation · checked 10 October 2026
  8. CIP-013-2: Cyber Security — Supply Chain Risk Management — North American Electric Reliability Corporation · checked 10 October 2026
  9. Critical Infrastructure Protection Reliability Standard CIP-015-1 (Internal Network Security Monitoring), Order No. 907 — Federal Register · checked 10 October 2026
  10. Project 2023-09 Risk Management for Third-Party Cloud Services: drafting team meeting agenda — North American Electric Reliability Corporation · checked 10 October 2026
  11. Virtualization Reliability Standards, Order No. 919 (Docket No. RM24-8-000), issued March 19, 2026 — Federal Energy Regulatory Commission · checked 10 October 2026
  12. Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive) — EUR-Lex · checked 10 October 2026
  13. The Network and Information Systems Regulations 2018 (SI 2018/506) — legislation.gov.uk · checked 10 October 2026
  14. Cyber Assessment Framework — National Cyber Security Centre · checked 10 October 2026
  15. Commission Delegated Regulation (EU) 2024/1366: network code on sector-specific rules for cybersecurity aspects of cross-border electricity flows — EUR-Lex · checked 10 October 2026
  16. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026

More in Electric Power & Natural Gas

Back to Electric Power & Natural Gas

Next step

Share the AI design your CIP team is reviewing

Send the architecture sketch and the data each model needs. We will reply with the placement options we see, the CIP questions each one raises and what to settle with your compliance team first.

Discuss a CIP-aware design