NERC CIP-003-9, CIP-012-2, and AI in the OT Environment
On April 1, 2026, NERC CIP-003-9 became enforceable. On that same morning, AI tools were being piloted in control rooms, on SCADA workstations, and in the operational technology environments those standards protect. The collision between the fastest-moving technology adoption cycle in utility history and the strictest cybersecurity framework ever applied to the grid is not hypothetical. It is your compliance problem right now.
The OT Boundary: What CIP Actually Protects
Before you can understand what CIP-003-9 and CIP-012-2 require, you need a clear mental model of what CIP protects and why. Without that model, the requirements look like a bureaucratic checklist. With it, they look like a sensible engineering response to a genuine safety problem.
OT stands for operational technology: the systems and networks that directly monitor and control physical grid equipment. This is distinct from IT (information technology), which covers the business systems, enterprise networks, and administrative infrastructure of the utility. Your energy management system (EMS), SCADA (Supervisory Control and Data Acquisition) platform, advanced distribution management system (ADMS), and the electronic access points to protective relay systems are OT. Your billing system, your human resources platform, and your email servers are IT.
Picture the difference this way. If an attacker compromises your billing system, they might access customer payment data or manipulate invoices. Both are serious, and both are IT security failures. If the same attacker compromises your SCADA system, the consequences are in a different category entirely. SCADA does not store data; it issues commands. A SCADA session with improper access can open a 230 kV breaker at a substation serving 300,000 customers. It can disable a protection relay that is supposed to isolate a fault before it cascades. It can simultaneously trip multiple generating units in a balancing area, causing a frequency excursion that triggers further automatic trips before a human operator can respond. The 2003 Northeast blackout, which left 55 million people without power, was not a cyberattack, but it illustrates the scale of consequence that control system failures can produce. The CIP standards exist precisely to prevent a deliberate version of that scenario.
The NERC CIP family of standards (Critical Infrastructure Protection) creates a tiered framework for managing these risks. Assets are classified as high-impact, medium-impact, or low-impact based on their criticality to bulk power system reliability. High-impact assets, such as major control centers and large generating facilities above defined capacity thresholds, face the most stringent requirements. Medium-impact assets face an intermediate set. Low-impact assets, which include a large number of smaller substations and distribution control systems, face the requirements of CIP-003.
CIP-003 is specifically the standard that covers low-impact BES (Bulk Electric System) cyber systems and transient cyber assets: laptops, USB drives, maintenance devices, and similar equipment that connect temporarily to OT environments. CIP-003-9, which became enforceable on April 1, 2026, addresses vendor electronic remote access and supply-chain security for low-impact BES Cyber Systems, including requirements for transient cyber assets. The version of the standard written before tablets ran AI-assisted diagnostic apps and before portable sensors could stream data to cloud-based AI platforms was silent on those device categories. CIP-003-9 closes that silence.
CIP-003-9: What Changed on April 1, 2026
CIP-003-9 builds on earlier versions of the standard but adds and refines requirements specifically relevant to the 2026 technology environment. The core focus is on two areas: security management controls for low-impact assets, and the treatment of transient cyber assets in those environments.
Transient Cyber Assets and AI-Enabled Devices
A transient cyber asset is any device that connects temporarily to a low-impact BES cyber system environment. Before CIP-003-9, the primary examples were maintenance laptops, USB drives, and diagnostic tools brought by field crews to service protection relays or check RTU (Remote Terminal Unit) configurations at distribution substations. The utility's procedure was simple: wipe the device before it enters the substation, log the connection, confirm no external communications while connected.
In 2026, the transient device population has expanded in ways that earlier procedure writers could not have anticipated. A relay technician arrives at a substation with a tablet running an AI-assisted diagnostic app that communicates with a vendor's cloud platform to interpret protection event logs. A field engineer uses a portable thermal imaging camera that uploads images to an AI analysis service in real time. A vendor installs an AI-inference box in the substation control room that connects to industrial Ethernet and processes SCADA data locally. Each of these devices creates a communication channel that did not exist in the pre-AI maintenance toolkit, and each of those channels is a potential path from an outside network into the BES cyber system boundary.
CIP-003-9 requires that utilities have documented policies and procedures for managing transient cyber assets in low-impact BES environments. The requirements include: authorizing which devices are permitted to connect; maintaining records of connections; protecting against malware introduction through transient devices; and managing communications between transient devices and networks outside the BES cyber system boundary.
The AI-specific challenge is in that last requirement: managing communications with external networks. An AI-inference device or an AI-assisted maintenance app may need to communicate with a cloud platform, a vendor's update server, or an enterprise AI system to function. Each of those communications is a potential path from outside the BES cyber system boundary into the OT environment. Under CIP-003-9, each such communication path must be evaluated, documented, and managed. You cannot plug an AI device into your SCADA network and assume the cloud communication is an IT problem. It is a CIP problem, and the Responsible Entity that owns the BES cyber system is accountable for it.
Policies and Procedures for Low-Impact Assets
CIP-003-9 requires that Responsible Entities have documented, senior-management-approved policies and procedures for the security management of low-impact BES cyber systems. This is not new in concept, but the enforcement-ready version that took effect April 1, 2026 has a higher evidence bar than earlier versions. An auditor reviewing CIP-003-9 compliance will expect to see: a current policy document that reflects the actual technology in use, including AI tools if they are present in OT environments; procedures for physical access, electronic access, and transient device management that are operationally realistic; training records showing staff have been trained on the current policy; and evidence of periodic review and update of the policy as the technology environment changes.
The common failure mode looks like this. A utility's CIP-003 policy was last updated in 2022. At that time, the policy accurately described the transient devices used in low-impact substation work: maintenance laptops with a standard malware-scan procedure, USB drives with an access-controlled checkout process. Since 2022, the utility's field workforce has adopted tablets running an AI-assisted protection relay configuration tool, and the vendor who provides that tool communicates with a cloud-based licensing server every time the tablet is used. The policy does not address the tablet. It does not address the cloud communication. The actual OT environment has changed; the policy has not. In a CIP-003-9 audit, that gap is a finding, not a technicality. The auditor's question is: do your documented procedures match the actual technology in your OT environments? If the answer is no because the policy was not updated when new AI-enabled devices appeared, that is a compliance gap you own.
CIP-012-2: Protecting Real-Time Data Between Control Centers
CIP-012 is a different standard from CIP-003. Where CIP-003 covers low-impact assets and transient devices, CIP-012 covers the communications links between control centers that carry real-time operating data.
Control centers rely on real-time data flows to operate the grid. Your EMS at one control center receives telemetry from substations, generating units, and grid sensors. It may also exchange data with adjacent control centers (neighboring utilities, your ISO/RTO, transmission operations centers). These data flows carry the state-estimation inputs, the real-time load and generation balance data, and the contingency analysis results that operators use to make decisions. CIP-012-1 established the baseline obligation to protect the confidentiality and integrity of these data flows. CIP-012-2, effective July 1, 2026, adds protection of the availability of those communication links as a required attribute, closing a gap that earlier versions left open.
Why CIP-012-2 Matters for AI
The AI question for CIP-012-2 arises whenever an AI system needs to consume real-time operating data from a control center. Consider a topology optimization tool that needs live SCADA data to recommend switching sequences. Or a load forecasting model that ingests real-time load telemetry to produce an updated short-term forecast. Or a grid analytics platform that receives EMS state-estimation output in near-real time to monitor congestion. Each of these use cases involves pulling real-time operating data from the control-center environment.
Under CIP-012-2, the communications link that carries that data is a protected link. The requirements include: identifying the communications links that carry real-time data between control centers; protecting those links against unauthorized access and data manipulation; and monitoring the links for anomalous activity that could indicate an attack or unauthorized access.
If an AI platform is connected to the real-time data feed, the connection itself becomes part of the CIP-012-2 scope. The utility must document the connection, ensure it is protected according to the standard's requirements, and include it in the monitoring program. An AI vendor who tells you that their platform simply "connects to the SCADA API" without addressing CIP-012-2 obligations is describing an arrangement that may not be compliant. The compliance obligation belongs to the utility, not the vendor.
The Vendor Does Not Absorb Your CIP Obligation
This point deserves emphasis because it is the most common misunderstanding in AI procurement for the OT environment. When you purchase an AI tool from a vendor and that tool connects to a CIP-protected system or data feed, the vendor's contractual obligations do not replace your NERC CIP obligations. You remain the Responsible Entity. You are the one NERC audits. You are the one that receives the notice of alleged violation and the associated penalty. The vendor's contract may contain security representations, but those representations are between you and the vendor. NERC's standards apply to you.
This means that before deploying any AI tool in or adjacent to the OT environment, your compliance team must answer: Does this deployment create, modify, or depend on any BES cyber systems or electronic access points covered by CIP? Does it involve transient cyber assets entering the low-impact environment? Does it involve communications links carrying real-time operating data? If the answer to any of these questions is yes, you need a documented CIP analysis and a plan for meeting the applicable requirements before the tool goes live.
Worked Example: The Topology Optimization Deployment
A utility's operations team wants to deploy a topology optimization AI tool that receives real-time SCADA data and recommends switching sequences to reduce congestion. The vendor has delivered a demonstration showing 5 to 15 percent congestion cost reduction. The operations VP is enthusiastic. The compliance lead is being asked to give the green light for production deployment.
Here is how a CIP-informed compliance professional works through the analysis.
First, classify the data connection. The tool receives real-time SCADA data from the EMS. This is a communication link carrying real-time operating data between the EMS (a control center function) and the AI platform (an external system). This connection is within CIP-012-2 scope. The compliance team must document the connection, ensure the link is protected per CIP-012-2 requirements, and include the link in the monitoring program before the tool goes live in production mode.
Second, classify the tool's deployment environment. Does the AI tool run on a server inside the BES cyber system boundary, or outside it? If inside, it is a BES cyber system (or an associated electronic access point) subject to the applicable CIP requirements for that impact level. If outside, the data connection from inside to outside crosses the boundary, making the boundary crossing itself subject to CIP access management requirements. Most AI analytics platforms are designed to run outside the BES cyber system boundary precisely to avoid the full suite of CIP requirements, with the data flowing out to them rather than the platform reaching in. Verify which architecture your vendor is proposing.
Third, assess the transient asset risk. The vendor's implementation team will likely bring laptops and diagnostic devices on-site for installation and configuration. Those devices are transient cyber assets under CIP-003-9. They must be authorized, have malware prevention applied, and their communications outside the OT environment must be managed before they connect to any network in the BES cyber system boundary. The vendor's statement that their engineers "always use clean laptops" is not a CIP-compliant transient asset management procedure. Your policy and procedures need to cover the vendor's devices explicitly.
Fourth, verify the operator boundary. The topology optimization tool provides recommendations. The operator makes the decision. Under the cardinal rule of reliability, the operator's accountability for the switching decision does not transfer to the AI model because the AI recommended it. Your operating procedures need to document explicitly: what the tool outputs, what format the recommendation appears in, how the operator reviews and validates it, and what the override protocol is. These procedures need to be in the operator training record.
The result of this analysis is not "do not deploy the tool." It is "deploy the tool after you have documented the CIP-012-2 data link, managed the transient cyber assets, and written the operating procedures." The AI tool may deliver real congestion cost savings. The compliance framework tells you how to deploy it safely.
Buying an AI tool and plugging it into your SCADA network is not deployment. Documenting the CIP scope, managing the boundary, and training the operators is deployment. The vendor's enthusiastic sales team will help you with the first step. The compliance work is yours.
Practical Steps for the Compliance Lead
If you are responsible for NERC CIP compliance at a utility that is evaluating or has deployed AI tools in or adjacent to OT environments, here is your starting checklist.
- Inventory AI tools against OT systems: List every AI tool being piloted or deployed. For each, answer: does it connect to, communicate with, or reside within a BES cyber system? Does it receive real-time operating data from a control center? Does it introduce transient devices into the OT environment? Any yes answer begins a CIP analysis.
- Review CIP-003-9 policies against the actual environment: Pull your low-impact BES cyber system policy. Check when it was last updated. List the technology elements it covers. Verify that AI tools, cloud-connected devices, and modern transient assets are addressed. If they are not, the policy needs updating before the next audit cycle.
- Assess data links under CIP-012-2: Identify every communication path that carries real-time operating data from your control center to an external system. Include AI analytics platforms, vendor monitoring services, and ISO/RTO data exchanges. Verify each link is documented and protected as required.
- Engage procurement before deployment: Any AI vendor whose tool will connect to OT systems or real-time data feeds must understand your CIP obligations in the contract. Include security representations, right-to-audit provisions, and incident notification requirements. Do not accept "our platform is secure" as a substitute for specific CIP-relevant contractual provisions.
- Train operators on the human-AI boundary: If an AI tool provides recommendations in the control room or in proximity to control-room decisions, operators must be trained on what the tool outputs, how to evaluate its recommendations, and how to document their decision regardless of whether they followed the AI or overrode it.
Key Takeaways
- NERC CIP-003-9 became enforceable on April 1, 2026 and addresses vendor electronic remote access and supply-chain security for low-impact BES Cyber Systems, including requirements for transient cyber assets that are increasingly AI-enabled maintenance and diagnostic devices.
- CIP-012-2 protects the communications links that carry real-time operating data between control centers; any AI tool that connects to a real-time SCADA or EMS data feed is subject to CIP-012-2 requirements for that connection, regardless of whether the tool resides inside or outside the BES cyber system boundary.
- The vendor does not absorb your CIP compliance obligation. When you deploy an AI tool connected to a CIP-protected system, you are the Responsible Entity, subject to NERC audit and potential penalties.
- The most common CIP-003-9 failure mode for AI deployments is a policy document that describes the 2022 OT environment while the actual 2026 environment includes cloud-connected devices, AI inference tools, and modern transient assets that the policy does not address.
- A topology optimization, forecast, or analytics AI tool can deliver real operational value and comply fully with CIP-003-9 and CIP-012-2 requirements, but only if the CIP analysis, data-link documentation, transient asset management, and operator training are completed before production deployment.
- The operator's reliability accountability does not transfer to an AI tool: the switching decision, the dispatch order, and the contingency response are human decisions, regardless of what the AI recommended.
- Compliance leads should inventory all AI tools against OT systems, review CIP-003-9 policies for currency, assess CIP-012-2 data links, engage vendors on CIP-specific contract provisions, and train operators on the human-AI decision boundary before any OT-adjacent AI goes live.
Skill.re