AI Reliability Boundary Assessment

AI is already inside your operations.
Your org chart has not caught up.

When an AI-enabled workflow fails inside a reliability window, somebody has to answer for it. This assessment establishes who, before the question is asked by someone with enforcement authority.

The Problem

At 2:07 on a weekday afternoon, an AI decision-support platform your operators have leaned on for months stops responding. The vendor opens an incident and says it is investigating. At 2:22 the fifteen-minute reliability window closes. The vendor may restore service that evening. In the meantime, the grid still has to be operated.

Most organizations can answer who owns the platform and who signed the contract. Ownership of the fallback is usually undocumented, and in a lot of cases the people who used to perform it have been reassigned or never backfilled.

This is not a tooling gap. It is an accountability gap, and it sits between three parties who each hold a piece of it. The vendor changes the behavior. You control the access and absorb the operational consequence. Your own staff create paths no policy anticipated. Shared control does not mean shared accountability, and the registered entity is the one holding the reliability obligation when it goes wrong.

Why Ampyx Cyber

We have no AI product to sell.

Consider who else is offering to assess your AI risk. Platform vendors assessing risk in their own platforms. Integrators assessing risk in deployments they built. Managed service providers assessing risk in dependencies they sell you. Every one of them has a commercial interest in the answer being yes.

Ampyx Cyber is services only and technology agnostic. We do not make, sell, or promote any hardware or software, and we hold no partnership that pays us when you adopt a platform. For an assessment whose entire output is a judgment about whether a specific vendor can be trusted inside a reliability window, that independence is the basis of the opinion rather than a footnote to it.

We have audited from the other side of the table.

Ampyx consultants have been Regional CIP auditors with delegated authority, sat on standards and interpretations drafting teams, and participated in FERC technical conferences. When this assessment tells you how a categorization decision is likely to read to an auditor, that is coming from people who have made that call from the auditor's seat.

We hand you a decision, not a maturity score.

Most AI risk services run you against the NIST AI Risk Management Framework or ISO 42001 and return a posture report. Useful, and it does not tell you whether to approve the thing on your desk. This engagement starts from a decision your leadership has to approve, expand, or defend, and ends with a written recommendation to proceed, contain, or reject.

What This Is

A decision-support engagement built around one live decision rather than a maturity survey. The framework was developed inside Ampyx Cyber for regulated operators and presented at CYBR.SEC.CON in Houston in September 2026. It has been tested against real vendor incidents rather than derived from a checklist. Bring one AI-enabled workflow, one vendor dependency, or one computational load investment. The one you cannot afford to guess about.

How It Works

01. Map the obligation, dependency, and recovery path. What reliability or regulatory obligation this workflow touches, what it depends on, and what happens by hand if it stops.

02. Name the owner, authority, evidence, and consequence. Who creates or changes the risk, who can see the change, who has authority to intervene, who must produce the evidence, and who absorbs the operational, regulatory, and financial consequence.

03. Test vendor terms and controls against observed availability. Contract language and control claims measured against what the platform has actually done, using published incident histories rather than marketing commitments.

04. Issue a proceed, contain, or reject decision memo. A written recommendation your leadership can act on and your counsel can stand behind.

05. Deliver a board-ready heat map and a 90-day action plan. Where the gaps are, which ones matter inside your time window, and what to close first.

Three Ways to Engage

Boundary Session. Half a day, remote, one workflow. We score the twenty questions live with the people who would actually execute the fallback, and you leave with the heat map and a short findings note. Small enough to approve without a procurement cycle. Most of the value is in the room, because the questions where two of your own people give different scores are the ones worth your attention.

Boundary Assessment. The full five-step engagement on one live decision, with every deliverable below. Fixed scope, fixed fee.

Boundary Watch. Vendor behavior changes without a version string, which is the reason the assessment exists in the first place. A scoring is accurate on the day it is done and decays from there. We re-run the assessment against current platform behavior on an agreed cadence, refresh the heat map, and tell you what moved.

What You Receive

Scored assessment. Twenty questions across CIP-002, CIP-004, CIP-007, and CIP-010, each scored zero to four against evidence you can actually produce today, with the spread inside each section called out alongside the average.

Ownership map. Your specific event types mapped to who creates the risk, who can see it, who can intervene, and who carries the consequence.

Vendor terms findings. Where contract language, notification obligations, log production, and exit terms fall short of what the dependency requires.

Decision memo. Proceed, contain, or reject, with the reasoning written down.

Board-ready heat map. One page, defensible, for the conversation upward.

90-day action plan. Sequenced, with owners.

When to Run It

  • Before approving an AI-enabled platform into an operational workflow

  • Before expanding a pilot that has quietly become load-bearing

  • Before a staffing decision that assumes AI has replaced recovery capacity

  • Before signing or renewing an AI vendor contract

  • After a vendor changes model behavior, permissions, or terms

  • Before a board, a regulator, or an insurer asks who owned the risk

Coverage Range

Scored, five questions each:

  • CIP-002, asset categorization. Whether AI-enabled platforms touching operations have been categorized against current behavior, what re-triggers categorization when a vendor changes behavior without changing a version string, and whether your inventory includes agents and employee-built tools.

  • CIP-004, personnel and access. Whether training covers AI behavior change and degraded output, whether any agent holds standing access and under whose identity, what happens to prompts and agents when a person leaves, and whether access reviews include non-human identities.

  • CIP-007, monitoring and authentication. Whether prompt and tool-use history is a declared log source, whether alert determinations have been reviewed against current platform behavior, whether retention outlasts the reconnaissance window, and what detects a silent model or permission change.

  • CIP-010, baseline and change control. Whether the baseline records origin and provenance rather than only version, what triggers authorization when the vendor files no change, and whether the contract preserves methodology and evidence if the platform changes or exits.

Pressure-tested, not scored:

  • CIP-003. Whether a policy owner has been named for the asset class.

  • CIP-005. How the agentic interface changes the access path.

  • CIP-008. Whether silent drift ever trips your incident criteria.

  • CIP-009. Whether the recovery objective depends on vendor availability.

  • CIP-011. Where regulated data persists in prompts and model history.

  • CIP-013. Whether the contract predates agentic behavior.

  • CIP-015. Whether internal network security monitoring sees both the traffic and the behavior.

It Ports Beyond Electric

The five ownership questions underneath the CIP scoring do not depend on CIP. Who creates or changes the risk, who can see the change, who has authority to intervene, who must produce the evidence, and who absorbs the consequence. Water, pipeline, rail, and healthcare operators can substitute their own obligation and run the same assessment against any AI dependency.

On Audits and Evidence

This is not an audit, and it does not produce compliance evidence. Nobody should represent the output as a control artifact, and we will not describe it that way.

What it does produce is a record of your reasoning. Entities are increasingly expected to show that they have thought about AI inside their reliability obligations at all, and that an AI-enabled workflow reaching operations was categorized and authorized by someone with the standing to do it. A scored assessment and a written decision memo document exactly that thinking, with dates and names attached.

We will also tell you where we think an auditor would land on a given categorization. That is an informed opinion from people who have made those determinations, and it is not a substitute for one.

The scoring rubric is a maturity scale for your own use. A four means you can evidence and measure that control area against current AI behavior. It does not mean any Regional entity has agreed.