American Bar Association guidelines now caution legal professionals that the use of generative AI tools is only permissible when absolute security for client information can be guaranteed. This standard is currently driving a massive overhaul in how the energy sector manages its digital infrastructure and sensitive regulatory data. As organizations like Evergy integrate large language models into their operational workflows, the risks associated with proprietary information leaks have become a primary concern for state regulators. A recent petition filed with the Kansas Corporation Commission emphasizes the critical need for a new framework to govern how AI systems interact with confidential files. The challenge is not merely technical but existential, as the very tools designed to increase productivity could inadvertently expose vulnerabilities in the power grid. Balancing the immense potential of machine learning with the requirements for data integrity is the defining struggle of modern utility management.
Distinguishing Between Open and Controlled Environments
The Mechanics of Data Leakage: Inherent Model Risks
Open-source and public-facing AI platforms operate on a fundamental principle of data ingestion, where every piece of information provided by a user is potentially utilized to train future iterations of the algorithm. For a utility company, this means that uploading a sensitive document regarding grid architecture or consumer demand patterns could result in that information being permanently encoded into a third-party model. Evergy’s recent advocacy highlights that once data is ingested by these large language models, there is no reliable way to “delete” or retract that specific knowledge from the system’s weight distribution.
This creates a permanent record of sensitive data that exists outside the utility company’s firewall and regulatory control. The Kansas Corporation Commission is closely examining these risks, as the public nature of many AI development cycles means that proprietary intelligence could eventually be synthesized and presented to unauthorized users. While sharing data is a necessary component of regulatory transparency, utilizing public AI tools to process this information creates an unacceptable vulnerability. Third-party developers often maintain vague terms of service that allow them to analyze and reuse incoming data.
Operational Utility: Enhancing Professional Output
Despite these security risks, the functional benefits of artificial intelligence are becoming difficult for professional teams to ignore in an increasingly complex regulatory environment. Technical experts have observed that AI is already being utilized to transcribe long stakeholder meetings, draft complex legal documents, and summarize massive regulatory filings that often span thousands of pages. These efficiency gains allow utility companies to respond to regulatory requests with greater speed and precision, theoretically lowering the administrative costs that are eventually passed down to the consumer base.
The real challenge lies in capturing these massive efficiency gains without exposing the core intellectual property and consumer privacy data that keeps the electrical grid secure. Utility providers must find a way to utilize the drafting and analytical capabilities of generative models while ensuring that no sensitive data ever leaves their controlled environment. This necessitates a move away from general-use chatbots toward more specialized, enterprise-grade tools that offer strict non-ingestion guarantees. Maintaining this digital perimeter is essential for the industry to evolve responsibly.
Evaluating Competitive and Technical Threats
Tactical Vulnerabilities: AI in Regulatory Proceedings
Beyond the accidental exposure of data, there is a growing threat from the adversarial use of AI by competitors or opposing parties during complex regulatory cases. If sensitive financial records or internal legal strategies are fed into a large language model by one party, an opponent could theoretically use the AI to quickly identify specific weaknesses or deficiencies in that company’s legal position. This turns confidential data into a strategic weapon, allowing outside groups to exploit gaps in a utility provider’s filings with unprecedented speed and data-driven precision.
The speed at which these models can analyze thousands of pages of text means that an adversarial party can find a needle in a haystack within seconds, identifying minor inconsistencies that would have taken human legal teams weeks to uncover. This creates an uneven playing field where the party with the most advanced AI tools can deconstruct an opponent’s filings. Consequently, the protection of data is no longer just about privacy; it is about maintaining a fair and balanced regulatory process where strategic intelligence cannot be harvested by automated scripts through public-facing interfaces.
Industrial Rivalry: The Risk of Tech Sector Competition
Technical experts also warn that the developers of these AI tools could eventually become direct industry competitors themselves, creating a conflict of interest in data handling. By processing vast amounts of data from various infrastructure sectors, tech firms gain a unique inside look at the inner workings of the power grid and other critical systems. This information could be leveraged to create competing services or to influence market dynamics in ways that disadvantage traditional utility providers. The sheer scale of data collection by Silicon Valley firms represents a massive centralizing of industrial intelligence.
Common user errors also continue to plague the digital perimeter of major utilities, such as the accidental creation of public chat links that are quickly indexed by search engines. When an employee uses a public AI tool to analyze a work document, they often create a shareable URL that effectively puts that document on the open internet. This oversight bypasses traditional cybersecurity measures and exposes internal communications to any party capable of performing a targeted search. Securing the perimeter now requires both advanced technical blocks and comprehensive employee training.
Implementing New Standards for Data Sovereignty
Modern Guardrails: The Path to Responsible Development
As the gap between AI capabilities and existing safety standards continues to widen, regulatory bodies are beginning to implement strict guardrails to protect public interests. Organizations like the American Bar Association have established a precedent that is now being adopted across the energy sector, pushing for a nationwide standard of “responsible AI” development. This movement focuses on maintaining the absolute confidentiality of infrastructure information and ensuring that no automated tool can compromise the security of the electrical grid. Regulators are now demanding proof of data sovereignty before AI can be used.
The shift toward these new standards is not just a reaction to fear but a proactive move to define the future of corporate responsibility in a digital age. By requiring that AI tools undergo rigorous security audits and meet specific encryption standards, the industry is creating a safer environment for innovation. This regulatory pressure ensures that the drive for efficiency does not override the fundamental obligation to protect sensitive information. As these rules become more standardized, utility companies will have a clearer roadmap for integrating machine learning safely.
Future Protocols: Adopting Private Intelligence Systems
The most effective path forward involved the widespread adoption of “closed” or in-house AI systems that operated entirely within a utility’s own secure network. By running open-source models locally on their own dedicated hardware, organizations successfully automated repetitive tasks while keeping their data strictly isolated from the public internet. This move toward digital sovereignty ensured that the industry moved toward a high-tech future without sacrificing the control of sensitive intelligence. Utility companies also utilized specialized enterprise tiers of AI services that provided legally binding non-training agreements.
Security teams prioritized the implementation of localized processing units, which eliminated the need for data to travel to external servers for inference. This structural change effectively mitigated the risk of third-party leakage and provided a robust defense against adversarial data harvesting. Regulators eventually standardized these private deployments, requiring all major utility providers to prove that their AI workflows remained air-gapped from public training sets. These actions solidified the security of the national grid while allowing the sector to harness the full power of artificial intelligence.


