Ampyx Cyber Blog
The Intersection of Regulation & Resilience
When AI Changes Without a Change Request
On September 28 and 29 I will be at The Utility Change Conference West 2026 in Phoenix to talk about the artificial intelligence (AI) changes that never enter a utility's change process. A vendor feature toggle or a model update can alter what a tool reaches and how it behaves while the configuration baseline shows nothing. This preview walks through the questions those changes raise under the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) standards, using three recent incidents outside the utility sector as context.
Who Owns the Risk? The AI Reliability Boundary Assessment Questions
An AI decision-support platform fails at 2:07 on a weekday afternoon. At 2:22 the fifteen-minute reliability window closes and the vendor is still investigating. This is the full question set from the CYBR.SEC.CON talk, forty questions across four NERC CIP standards plus the ownership map behind them. You score your own answers, and nothing on this page collects anything.
The AI Reliability Boundary: A Black Hat Debrief for the Grid
Almost every conversation at Black Hat came back to AI, and almost every pitch assumed the answer to an AI problem is another product. In the grid, that assumption does not hold. Keirsten Brager's debrief on what the show floor missed, why governance is not a document, and why AI is not automatically out of scope for NERC's Critical Infrastructure Protection standards. It closes with the questions to answer before your next vendor demo.