Ampyx Cyber Blog
The Intersection of Regulation & Resilience
When AI Changes Without a Change Request
On September 28 and 29 I will be at The Utility Change Conference West 2026 in Phoenix to talk about the artificial intelligence (AI) changes that never enter a utility's change process. A vendor feature toggle or a model update can alter what a tool reaches and how it behaves while the configuration baseline shows nothing. This preview walks through the questions those changes raise under the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) standards, using three recent incidents outside the utility sector as context.
Who Owns the Risk? The AI Reliability Boundary Assessment Questions
An AI decision-support platform fails at 2:07 on a weekday afternoon. At 2:22 the fifteen-minute reliability window closes and the vendor is still investigating. This is the full question set from the CYBR.SEC.CON talk, forty questions across four NERC CIP standards plus the ownership map behind them. You score your own answers, and nothing on this page collects anything.
Top 10 Computational Load Accountability Mapping Questions for Leaders
NERC's August 19, 2026 posting split the single Computational Load Entity concept into two registrations, Computational Load Owner and Computational Load Operator, and raised the thresholds to 50 MW and 100 kV. Ten questions that help leaders map who is responsible for the work and who is accountable for the outcome, before registration positions harden.
The Computational Load Entity Just Became Two
NERC's August 19 posting replaced the Computational Load Entity with two separate registrations, Computational Load Owner and Computational Load Operator, raised the thresholds to 50 MW and 100 kV, and moved the test for who is in scope into a new Site definition. What changed between April and August, who should be running the applicability test, and the eight questions to answer before the window closes.
The AI Reliability Boundary: A Black Hat Debrief for the Grid
Almost every conversation at Black Hat came back to AI, and almost every pitch assumed the answer to an AI problem is another product. In the grid, that assumption does not hold. Keirsten Brager's debrief on what the show floor missed, why governance is not a document, and why AI is not automatically out of scope for NERC's Critical Infrastructure Protection standards. It closes with the questions to answer before your next vendor demo.
NERC Computational Load Standards: FERC Sets December 2026 Deadlines
FERC did not accelerate NERC's timeline, it made the calendar a directive and moved registration onto the critical path. The order creates the computational load entity, sets the December 31 and March 1 deadlines, and leaves the AI Reliability Boundary, the line between what the grid must command and what it leaves to private contract, for Phase II to draw. What is settled, what is not, and what to do in the next ninety days.
Computational Load and the Convergence Problem: What NERC's May 2026 Actions Mean for Critical Infrastructure
Documented load losses approaching one thousand megawatts in seconds. A Level 3 Essential Action Alert. A final Reliability Guideline. Proposed registration of a new Computational Load Entity. NERC's May 2026 actions mark a structural shift in how data centers, hyperscale AI training, and cryptocurrency mining are treated under the North American grid reliability framework.