← Industries/Energy & Utilities

Promethean for Energy & Utilities

NIS2 Annex I makes energy a critical sector — operators are essential entities directly liable for risk-management evidence. AI Act Annex III §2 designates critical-infrastructure AI as high-risk. REMIT requires market-manipulation transparency in trading. Promethean is the per-decision evidence layer that turns regulatory exposure into procurement advantage when selling into TSOs, DSOs, and utility customers.

Updated ·Sector page · Energy & Utilities·Reading time ~ 6 min

Who this is for

Compliance + product teams in energy-tech SMBs (grid optimisation · demand-response · smart-metering analytics · EV-charging platforms · trading + forecasting AI). Typically:

  • Seed–Series C energy-tech SMBs with 10–80 engineers; 1–4 AI features in production.
  • Customer base: TSOs, DSOs, utilities, retailers, aggregators, charge-point operators — all under NIS2 or sector regulation.
  • Decision volume: 10k–10M AI-driven forecasting / dispatch / trading decisions per month.
  • Multi-tenant by customer utility or by jurisdictional regulator; per-customer audit bundles in procurement.
  • Long sales cycles + technical-evaluation phases where evidence-readiness materially shortens time-to-contract.

The regulatory pressure

NIS2 Directive Annex I — energy sector as essential

Electricity, district heating + cooling, oil, gas, hydrogen are designated essential sectors. Operators and key vendors face Art. 21 risk-management + Art. 23 incident-reporting obligations.

EU AI Act Annex III §2 — critical infrastructure

AI systems intended as safety components in management + operation of critical digital infrastructure, road traffic, water, gas, heating, electricity are high-risk. Full Chapter II obligations apply.

Deep-dive →

REMIT (EU) 1227/2011 — wholesale energy market integrity

Market manipulation + insider trading in wholesale energy markets is prohibited. Automated trading + bidding AI requires per-decision evidence to demonstrate market-conduct compliance during ACER + national-regulator inquiries.

Network codes (EU) 2017/2196, 2017/1485 — system operation + emergency

Grid operators must demonstrate emergency-response protocols + balancing decisions. AI-driven dispatch + balancing requires per-decision traceability under network-code audit.

Where LLMs typically run in Energy & Utilities

Demand + load forecasting

Classifier producing forecast bands per zone + interval. Schema-bound output; specHash binds model version per forecast; chain shows forecast accuracy + drift over time.

Automated trading + bidding

Closed-enum verdict (buy / sell / hold) per market window. specHash + modelIdentity per decision; REMIT-relevant evidence layer; always-human reviewer gate on threshold breaches.

Grid-dispatch + balancing recommendation

Drafter producing dispatch + balancing actions for operator approval. Always-human reviewer gate (control-room operator signs each action); reviewer-verdict captured.

EV-charging session optimisation

Classifier assigning charging schedules per session. Closed-enum output; tenant-scoped per charge-point operator; chain provides evidence for grid-impact + tariff fairness.

How the substrate maps to your audit

Your LLM featureWhat the regulator asksPromethean evidence
Forecast accuracyAI Act §2 + network codes: does the forecasting AI perform as documented?L12 chain provides per-forecast specHash + modelIdentity; accuracy computable against chain.
Trading-decision provenanceREMIT: prove decisions weren't market-manipulating.inputHash + specHash + verdict per L12 entry; tamper-evident timeline for ACER inquiries.
Control-room oversightAI Act Art. 14: human oversight on consequential actions.Always-human reviewer gate + operator identifier per L12 entry; override-rate computable.
Incident-timeline (NIS2 Art. 23)Significant incident: reconstruct the AI's role.recordedAtIso + tamper-evident chain; OpenTimestamps anchor for independent timeline verification.
Utility customer procurementTSO/DSO procurement: provide per-decision evidence for their NIS2 supply-chain assessment.Per-customer audit bundle (tenantId-filtered); verifier validates with verify.mjs.

Which Promethean tier fits

Recommended for typical SMBs in Energy & Utilities

Production€499 / month flat

Up to 25 specs · 1M entries / month · hourly OTS anchoring · multi-tenant · federation read-only.

Energy SMBs commonly run 5–15 specs (forecasting per region, trading per market, dispatch per customer) — Production tier (€499/mo) covers this with 1M entries/month allowance + multi-tenant primitives. Enterprise (€2,499/mo) matters once selling into TSO / DSO / government-owned utilities that need the framework-handoff templates (NIS2, AI Act Annex IV); on-prem deployment is on the roadmap. 15-min Bitcoin-anchored OTS shortens incident-evidence latency — material for NIS2 Art. 23 24-hour reporting.

Larger Energy & Utilities operators with multi-tenant or framework-template needs upgrade to Enterprise (€2,499 / month flat).

What this looks like in practice

Hypothetical: a forecasting-AI SMB during a TSO procurement evaluation

A demand-forecasting SMB competes for a multi-year contract with a national TSO. The technical-evaluation phase asks: 'Demonstrate forecast accuracy with audit evidence; demonstrate how operators retain meaningful oversight; demonstrate that under failure modes the system falls back safely; produce evidence in a form your TSO customer can independently verify.' Without Promethean: PDFs + spreadsheets + verbal assurances. With Promethean: a Production-tier deployment, an audit bundle for the previous 90 days, the TSO's evaluation engineer runs verify.mjs against the bundle and reads chain-derived statistics (forecast accuracy, reviewer override rate, fallback-trigger count). The procurement moves from 'tell us about your AI' to 'verify what your AI did' — and the SMB wins on evidence-readiness against larger incumbents.

Frequently asked

We're a small AI vendor selling into utilities — not a utility ourselves. Why does NIS2 apply?

It doesn't apply to you directly unless you're scoped as a managed-service provider under NIS2's digital-infrastructure section. But your utility customers are essential entities under NIS2 Annex I; their Art. 21(2)(d) supply-chain risk obligations mean they will ask you for evidence about the AI you deliver. Promethean is the layer that lets you answer those requests positively without becoming an essential entity yourself. You compete on evidence-readiness in procurement.

Automated energy trading: how does REMIT affect our exposure?

REMIT prohibits market manipulation + insider trading; ACER + national regulators investigate suspected manipulation across wholesale energy markets. If your AI is producing trading recommendations (or executing trades), per-decision evidence is the difference between 'we cooperate with the inquiry' and 'we cannot reconstruct what happened'. The L12 chain captures the spec + inputs + verdict per decision; modelIdentity + specHash bind the configuration. ACER asking 'why did your system bid X at hour Y' gets a verifiable answer, not a regression run.

Grid-dispatch AI: do we need always-human review on every action?

AI Act Art. 14 + network codes both expect meaningful human oversight on consequential operational actions. In practice this typically means the control-room operator approves any AI-recommended dispatch action; the reviewer-gate primitive captures that approval in the L12 entry. Routine forecasts (read-only outputs) typically don't need always-human review; they need the audit trail + drift-detection that the chain provides naturally.

We use AI to optimise EV-charging tariffs. Is that high-risk under AI Act?

Probably not high-risk under Annex III (charging is a service, not 'safety component of critical infrastructure'), but pricing decisions can trigger GDPR Art. 22 if they materially affect access to services — and the AI Act's general transparency obligations still apply. The L12 chain provides the per-session decision evidence + per-customer tenant scoping that lets you answer regulatory and customer-fairness questions cleanly. ACER + national-regulator scrutiny of EV-charging tariff fairness is increasing; evidence-readiness is a procurement advantage.

What about NIS2 24-hour incident-reporting timelines?

The 24-hour early-warning + 72-hour notification under Art. 23 demand fast timeline reconstruction. Promethean's L12 chain is already tamper-evident + ordered; the OpenTimestamps anchor (15-min Bitcoin-anchored on Enterprise tier) gives independently-verifiable timing. When a significant incident hits and your customer needs to reconstruct the AI's role within hours, you (or your customer) export the relevant chain slice + run verify.mjs — the evidence is ready, not built on demand under pressure.

Definitions used on this page

The substrate primitives referenced above (L12 receipt chain, spec hash, reviewer gate, fallback behaviour, OpenTimestamps anchor, tenant ID) all have canonical definitions in the glossary:

See full glossary →·See citations index →