Skip to content

DCS

Technical Community Global

Responses

In your opinion, what outcomes would make the first Global Dialogue on AI Governance a success?

I have spent years designing AI systems that sit inside power grids — systems that feed recommendations into SCADA platforms, outage management tools, and distribution control rooms serving millions of people. When I follow the AI governance conversation at the international level, I rarely recognise the technology being discussed. The dialogue is almost entirely about large language models, social media algorithms, and hiring tools. That is a real problem, but it is not the whole problem. Success for the first Dialogue would mean it produces outputs that are actually useful to the people building and operating AI in critical infrastructure — not just to the people writing about it. Concretely, that means three things. First, a working definition of trustworthy AI that is specific enough to apply to operational technology environments. What does trustworthiness mean when the AI is recommending a switching sequence on a live distribution network? That question has a different answer than what it means for a chatbot. Second, a concrete mechanism for getting the Scientific Panel's findings into the hands of national regulators and utility operators — not just UN member state delegations. The people making AI deployment decisions at utilities are engineers, operations, and managers. They need guidance they can act on, not diplomatic language they have to decode. Third, an honest commitment to capacity-building that is funded and time-bound. Developing nations are deploying AI in power grids and water systems right now, without the institutional capacity to govern it safely. The Dialogue should name that specifically and do something about it, not just acknowledge the gap and move on. If the first Dialogue produces a communiqué that could have been written before it happened, it will have failed.

From your perspective, which of the following thematic areas identified by the General Assembly Resolution 79/325 for the AI Dialogue reflect your priorities for urgent action and active engagement?

  • Safe, secure and trustworthy AI
  • Transparency, accountability, and human oversight
  • Social, economic, ethical, cultural, linguistic and technical implications of AI
  • AI capacity-building

Please briefly explain your selection.

6

I selected these four because they reflect what I actually encounter in my work, not what sounds important from a distance. Safe, secure, and trustworthy AI - I have designed AI inference architectures for utility environments across air-gapped DEV, QA, and production environments serving substations across the U.S. The security threat surface for AI in these environments is fundamentally different from enterprise AI. Data poisoning, model inversion, adversarial inputs to anomaly detection systems - these are real attack vectors that the governance conversation has barely touched. A framework that doesn't distinguish AI running inside an Electronic Security Perimeter from AI running on a consumer device is not a framework I can use. Social, economic, ethical, and technical implications - I have been researching how AI-driven outage restoration systems inherit bias from historical data. The peer-reviewed literature already shows that lower-income communities wait significantly longer for power after storms. When utilities train crew dispatch models on that history without equity constraints, the model learns the disparity and automates it. This is happening now, at the architecture level, before anyone in the governance space is paying attention to it. Transparency, accountability, and human oversight - In every AI system I have built for utility environments, the non-negotiable principle is that a human operator retains final authority over any action affecting grid state. The governance conversation often treats human oversight as a temporary safeguard until AI gets good enough. In critical infrastructure, it is permanent and structural. That distinction matters and the Dialogue should make it explicit. AI capacity-building - Most of the 3,000+ U.S. utilities and their counterparts globally are small cooperatives and municipal operators. They are adopting AI without security architecture expertise. Governance frameworks written for hyperscalers do not reach them.

In your opinion, are there any cross-cutting or emerging issues not captured by the listed themes above? If so, please explain.

1

Two things are missing, and both matter to me directly. The first is critical infrastructure AI as its own governance category. Every theme in the Resolution applies differently when the AI is running inside a power grid, a water treatment system, or a pipeline control room. The governance conversation keeps treating AI as a single technology with a single set of risks. It is not. An AI system making a hiring recommendation and an AI system recommending a feeder switching sequence during a storm restoration event are operating in completely different risk environments. One bad output in the first case means someone doesn't get a job offer. One bad output in the second case can cascade into a multi-hour outage affecting hundreds of thousands of people. The Dialogue needs a dedicated workstream for critical infrastructure AI that involves actual infrastructure operators and sector regulators, not just technology companies and academic researchers. The second is AI and energy equity - and I mean this in a very specific, technical sense, not as a general aspiration. When utilities deploy AI in outage management systems trained on historical restoration data, those models learn the patterns in that data. The patterns include the fact that lower-income and rural communities have historically received slower restoration service. The model doesn't know that's unjust. It learns it as a feature of the optimization landscape. Without equity constraints built deliberately into the objective function and the validation pipeline, AI-driven dispatch systems will automate that disparity at a scale and consistency that human dispatchers never achieved. This is not a future risk. It is a present deployment challenge that no one in the governance space is currently addressing. The Dialogue should name it, because the window to design equity in before patterns entrench is closing.

How are the governance gaps and related developments/advances in the thematic areas you selected above affecting your country, region, or sector? Please highlight the most significant challenges.

I work in the U.S. electric utility sector, specifically on AI deployments in operational technology environments — the systems that control power grids. The governance gaps I encounter are not theoretical. They show up in architectural decisions being made right now, on real deployments, with no adequate framework to guide them. The most significant gap is that no existing governance framework — domestic or international — defines what it means for operational technology to be safe and trustworthy. NERC CIP, the primary cybersecurity regulatory framework for U.S. bulk electric system assets, was designed for deterministic control systems. It does not address AI-specific threats: data poisoning of training pipelines, model inversion attacks that reconstruct sensitive grid topology, adversarial inputs that fool anomaly detection systems into reporting all-clear during an active intrusion. FERC's approval of CIP-015-1 for Internal Network Security Monitoring in 2025 is a meaningful step, but it does not reach the AI inference layer specifically. The gap between where regulation is and where AI deployment is moving is widening faster than the regulatory process can close it. The second gap is equity. Research already shows that lower-income communities in the U.S. wait significantly longer for power restoration after major storms. Utilities are now deploying AI-driven crew dispatch and outage management systems trained on historical restoration data that encodes those disparities. There is no regulatory requirement to audit training data for equity before deployment, no mandate to track ETR accuracy by service-territory segment, and no equity-validation gate in any AI governance framework applicable to utilities. The harm is not hypothetical — it is being baked into production systems today. The opportunity is timing. Most U.S. utilities are still in the early stages of AI adoption. The architectural decisions have not yet been entrenched. International governance guidance that reaches infrastructure operators — not just technology companies — could still shape those decisions. That window is narrow and closing.

What role can the AI Dialogue play in advancing international cooperation on AI governance?

The Dialogue's most valuable role is one that no existing forum currently fills: connecting the international policy conversation to the people actually deploying AI in critical systems. Right now, the governance conversation and the deployment conversation are happening in completely separate rooms. International bodies produce frameworks. Engineers and operators build systems. The frameworks rarely reach the engineers in a form they can use, and the engineers rarely have a seat at the table where the frameworks are written. The result is governance that is technically sophisticated about the wrong things and silent about the right ones. The Dialogue can change that if it is designed to. Specifically, it can play three roles that no existing mechanism does well. First, it can create a translation layer between scientific assessment and operational guidance. The Independent Scientific Panel will produce evidence-based reports. Those reports need to reach utility regulators, infrastructure operators, and system integrators in sector-specific form — not as general AI risk assessments but as actionable guidance for the people making deployment decisions in power grids, water systems, and transportation networks. The Dialogue should mandate that translation work explicitly, not leave it to chance. Second, it can function as an early warning system for governance gaps that are sector-specific and moving faster than national regulators can track. AI deployment in critical infrastructure is outpacing regulatory capacity in every country I am aware of. A Dialogue that convenes annually and includes practitioners alongside policymakers could surface those gaps before they become incidents. Third, it can give developing nations genuine standing in shaping the frameworks that will govern AI systems being sold into their infrastructure. The countries most vulnerable to poorly governed AI in critical systems are the ones with the least representation in the rooms where governance standards are set. The Dialogue was designed to fix that. It should.

What are some of the existing initiatives, partnerships, or mechanisms that the AI Dialogue should build upon or connect with, and what added value could the AI Dialogue bring?

Several initiatives are doing serious work that the Dialogue should connect with rather than duplicate. NERC CIP is the most mature sector-specific AI-adjacent governance framework in existence for critical infrastructure. It governs cybersecurity for the U.S. bulk electric system and its 2025 updates — CIP-015-1 for Internal Network Security Monitoring, CIP-013-2 for supply chain risk — are beginning to reach AI infrastructure in operational technology environments. The Dialogue should study this model. A sector-specific, enforceable, regularly updated standard with clear audit requirements is what AI governance in critical infrastructure actually needs to look like. The problem is it only covers the U.S. bulk electric system. The Dialogue could add value by working with NERC, FERC, and equivalent bodies in other jurisdictions to identify what a NERC CIP equivalent for AI in critical infrastructure would require internationally. The NIST AI Risk Management Framework provides a structured approach to AI governance that is sector-agnostic and has been widely adopted. It is a good foundation. Its limitation is that it is voluntary and does not reach the operational level with enough specificity to guide deployment decisions in safety-critical environments. The Dialogue should connect with NIST and push for sector-specific annexes that translate the RMF into actionable requirements for infrastructure operators. CIGRE, the international body for large electric system expertise, has active working groups on AI and cybersecurity in power systems — including Working Group D2.64 on AI in cybersecurity defense of power systems. This is exactly the kind of technical practitioner community the Dialogue needs in the room. These are the engineers who understand both the systems and the risks. The added value the Dialogue brings is a convening authority. NERC reaches U.S. utilities. NIST reaches U.S. agencies. CIGRE reaches power system engineers. None of them reaches all three simultaneously and connects them to the broader international governance conversation. The Dialogue can.

How can different stakeholders contribute to the AI Dialogue? Please share recommendations for the format and structure of the AI Dialogue.

The Dialogue's format will determine whether it produces anything useful. Most international AI governance forums share the same structural problem: governments present positions, civil society observes, industry attends side events, and practitioners who actually build the systems are not in the room at all. The result is governance written by people who have read about AI for people who will read about governance. The Dialogue should be structured in three tracks that run in parallel rather than sequentially. A policy track for governments and regulatory bodies to exchange frameworks, identify gaps, and negotiate commitments. This is the track most forums already do reasonably well. A practitioner track that brings in infrastructure operators, utility engineers, OT security architects, and system integrators — the people who are making AI deployment decisions right now in real systems. Their contribution is not position papers. It is the ground truth about what governance frameworks are actually reaching operational environments and what is falling through the gaps. This track should feed directly into the policy track, not run alongside it without connection. A capacity track specifically for developing nations and smaller operators — cooperatives, municipal utilities, regional grid operators — who are deploying AI without adequate governance frameworks or technical expertise. This track should be structured as peer learning, not a lecture. Countries and operators that have navigated specific deployment challenges should share with those facing them for the first time. The Scientific Panel's annual report should be presented at the opening of each Dialogue session, and its findings should structure the agenda — not serve as a background document that participants reference selectively to support positions they already hold. One structural requirement: each session should produce a short, specific list of commitments with named responsible parties and a timeline. Communiqués without accountability mechanisms are not governance.

Which voices, communities, or perspectives are currently underrepresented in global discussions on AI governance? How could they be included?

Three communities are almost absent from the global AI governance conversation, and their absence is making the frameworks weaker. Infrastructure operators. The engineers and operations managers who run power grids, water systems, and transportation networks are deploying AI right now under governance frameworks that were not written with their systems in mind. They are not at international governance forums because those forums do not speak their language, do not address their regulatory context, and do not produce outputs they can use. Including them requires more than inviting a utility association to send a representative. It requires structured sessions where operational practitioners present specific deployment challenges and governance gaps to policymakers who have the authority to address them. Smaller and rural utilities, cooperatives, and municipal operators. AI governance discussions are dominated by large investor-owned utilities, hyperscale technology companies, and national governments with sophisticated AI programs. The 900-plus rural electric cooperatives in the United States alone serve 42 million customers and are at early stages of AI adoption with minimal governance support. Their counterparts in developing nations are in a similar position. These operators face the same AI risks as large utilities with a fraction of the technical and regulatory capacity to manage them. They need representation that reflects their specific constraints, not frameworks scaled down from hyperscaler guidance. Communities bearing the consequences. Lower-income and rural communities that experience the longest power outages, the least reliable service, and the greatest vulnerability to AI-driven inequities in restoration and resource allocation have no meaningful voice in the governance processes shaping the systems that affect them. Including them requires deliberate outreach through energy justice organizations, community advocacy groups, and public utility commission proceedings — not just open comment processes that assume technical literacy and institutional access. All three of these communities exist at the operational end of AI governance. The Dialogue will not represent that end adequately without deliberate structural design to include them.

What innovative engagement formats could most effectively foster meaningful and dynamic engagement during the AI Dialogue?

The formats that would make the Dialogue genuinely useful are not innovative in a theatrical sense. They are just different from what international forums typically do. Pre-session technical briefings. Before each Dialogue session, the Scientific Panel should produce short, sector-specific briefings — not the full annual report, but a two-page summary of findings relevant to critical infrastructure, healthcare AI, or financial systems AI, depending on the session's thematic focus. Practitioners in those sectors should receive these briefings in advance and come prepared to respond to specific findings rather than presenting general positions. Red team exercises. Invite practitioners and security researchers to present concrete failure scenarios — specific ways AI deployments in critical infrastructure have gone wrong or could go wrong — and ask governance experts and policymakers to respond with what existing frameworks would or would not address. This format surfaces governance gaps faster than any document review process and grounds the conversation in operational reality. Structured cross-regional practitioner exchanges. Pair infrastructure operators from developed and developing nations facing similar AI deployment challenges — a U.S. rural electric cooperative and a regional utility in sub-Saharan Africa, both deploying predictive maintenance AI, for example — and give them structured time to compare what governance support they have received, what they have not, and what they actually need. This format produces concrete capacity-building insights that policy discussions alone do not. Commitment tracking sessions. Open each annual Dialogue with a structured review of the specific commitments made at the previous session. Which were implemented? Which were not, and why? This is not innovative — it is basic accountability — but almost no international governance forum does it consistently. Without it, the Dialogue will produce the same gap analysis every year and call it progress.

Please share examples of policies, practices, platforms, or approaches that promote effective AI governance or offer concrete solutions to addressing its challenges.

5

The most effective AI governance I have encountered is not at the international level. It is sector-specific, enforceable, and connected to the operational reality of the systems it governs. NERC CIP is the clearest example. It is not perfect, and it was not designed for AI, but it demonstrates what effective critical infrastructure governance looks like in practice: specific technical requirements, defined audit evidence, mandatory compliance timelines, and real penalties for non-compliance. When FERC approved CIP-015-1 for Internal Network Security Monitoring in June 2025, it extended that framework to address a specific emerging risk - lateral movement through internal network segments - in a way that infrastructure operators could implement and auditors could verify. That is what actionable governance looks like. The AI governance community should study it, not ignore it, because it is sector-specific rather than universal. The air-gapped multi-environment deployment model I have implemented across utility AI projects - separate DEV, QA, and production environments with security gates at each promotion stage, no internet connectivity in production, cryptographically signed model artifacts - represents a governance practice that works at the operational level. It is not a policy framework. It is an architectural pattern that enforces governance requirements through engineering rather than compliance checklists. The Dialogue should be collecting and disseminating these kinds of operational best practices, not only high-level principles. The NIST AI Risk Management Framework's structure - Govern, Map, Measure, Manage - is the right skeleton for AI governance across sectors. Its limitation is voluntary adoption and insufficient sector-specific guidance. The most productive near-term work the Dialogue could support is developing sector-specific annexes to the NIST AI RMF that translate its functions into concrete requirements for critical infrastructure operators, with NERC CIP as the model for what enforceable sector specificity looks like. The pattern across all three examples is the same: governance that works is specific, enforceable, and designed by people who understand the systems it governs.