AI will earn its place in the control room step by step — better information for operators, earlier problem detection, and more automated, more efficient asset operation. As AI unlocks more flexibility from those assets — across forecasting, dispatch, and asset health — less spare capacity is needed, and fewer buffers have to be held in reserve. That leaves operators adopting AI-driven optimization to decide how far to push AI-enabled efficiency against system resilience and safety margins.
Nowhere is this becoming more relevant than in the Middle East. The region is running one of the most aggressive asset and grid buildouts on the planet: GCC interconnection expanding, utilities integrating solar, wind, and storage at a pace few grids have had to absorb, and distributed energy resources, smart meters, and IoT devices onboarded from a growing list of vendors and protocols. AI is the tool being reached for to manage that complexity. Which means the region could adopt AI in the control room faster than most. The downside: it’s accumulating the trust and security problems faster than most.
Because the harder question sits one layer down. As AI takes on planning, operations, dispatch, switching, and balancing decisions — acting faster than a human can check — accountability gets murky fast. When one of those decisions causes an outage, who answers for it? The operator who trusted the system? The vendor who built it? “No one” is not an acceptable answer, and it won’t stay hypothetical much longer.
The starting position: you cannot hold anyone accountable for a decision built on data you can’t verify and trust. Before we argue about whether AI belongs in the control room, we have to answer something more basic — do we actually trust the data and commands flowing through it? Most energy systems today can’t say yes with certainty. A signal from a solar inverter, a command to a relay, a reading from a power analyzer — traditional VPN and TLS protect the pipe, not the contents. They don’t stop a spoofed device, a tampered telemetry stream, or a fake command from looking completely legitimate by the time it reaches an operator’s screen. An AI model making split-second decisions on unverified inputs isn’t intelligent. It’s fast and blind.
Regulators across the GCC are moving to close that gap. Saudi Arabia’s NCA Operational Technology Cybersecurity Controls (OTCC-1:2022) set explicit requirements for OT environments in critical infrastructure, energy included. The UAE’s Information Assurance standards push critical infrastructure operators in the same direction under tightening 2026 compliance cycles. Different regulators, same direction: past “is the network encrypted?” and into “can you prove the device and the data are what they claim to be?”
This is the layer of the problem we spend most of our time on. Rather than ripping out existing OT and cloud infrastructure, energy asset owners and operators are turning to a cryptographic, data-centric trust overlay — what is called Explicit Private Networking (XPN) — that binds verification directly to the data and commands themselves, not just the network path. Every measurement and command is digitally signed. Every device proves its identity before it’s trusted. Tampering, spoofing, and unauthorized injection become visible in the control room in real time, rather than surfacing weeks later in a forensic report. Operators get a live trust and integrity view of the critical infrastructure they manage alongside the operational dashboards they already use — and because it sits on top of a multi-vendor, multi-protocol environment, nothing has to be replaced to get there.
It also changes what compliance costs. Frameworks like OTCC-1:2022 ask operators to demonstrate device authentication, data integrity, and auditability across OT environments — exactly the evidence a cryptographic overlay produces as a byproduct of how it works. Every signed measurement is itself an audit trail. Compliance stops being a periodic scramble and becomes something the system proves continuously.
That is what AI-ready actually means. Not a bigger model. An infrastructure where the data feeding the model is provably authentic, so that when AI makes the call, there’s a real chain of accountability behind it.
The energy industry doesn’t need to choose between transformative power and existential risk. It needs to decide what trust is built on before it decides how much autonomy to grant. Get the data layer right, and AI in the control room is a force multiplier. Skip it, and the efficiency gains come with outages you can’t explain, decisions you can’t audit, and accountability you can’t assign.