01
What is changing or failing?
Oil is among the high-criticality energy sectors covered by NIS2. At the same time, the EU AI framework is in staged application. The Commission’s current FAQ states that the AI Act generally applies from 2 August 2026 and describes later or proposed adjusted timelines for certain high-risk and product-embedded systems. Exact applicability and the legal status of timetable changes must be checked for the use case at the decision date.
NIST’s OT security guidance stresses that cybersecurity controls must respect operational performance, reliability and safety. CISA and international partners frame OT cybersecurity as a business-decision issue, not only a technical configuration issue. That makes “how close should this AI get to OT?” an executive risk-and-value decision before it is an architecture choice.
A refinery pilot can fail before either framework is fully analysed: the business sponsor asks for broad data access, security cannot see the operating value and the team treats governance as paperwork after the model proves itself.
02
Why does it matter commercially?
A read-only, source-traceable starting point often tests most of the value hypothesis at lower integration and cyber cost. It also produces evidence management can use to decide whether greater proximity is justified.
The WIIFM is faster qualified innovation: stop weak ideas earlier and reserve security, integration and operating attention for use cases with a credible value owner.
03
What must management decide?
Management must decide the minimum access and authority required for the next evidence gate—not the maximum architecture a future solution might use.
The decision should name the business owner, data boundary, human approval, failure response and conditions for any move toward operational integration.
Use an access-and-authority ladder
- Offline evidence: curated historical records with no live connection
- Read-only business information: approved reports and document repositories
- Read-only operational data: controlled extraction from an OT-adjacent boundary
- Recommendation: outputs may influence an operating decision but require explicit human approval
- Action: a system can initiate or change an operational state
Each step needs a new value case, threat assessment, failure test and authorised decision. Success at one level is not approval for the next.
04
What evidence is required?
- Named operating problem, baseline and benefit owner
- Data classification and minimum access required
- Source traceability, human review and override design
- NIS2, AI Act, safety and sector-specific applicability assessment
- Stage gate before integration, autonomy or wider deployment
- Network path, identity, logging, isolation and recovery design for every new access level
- Safe degraded mode when the model, data feed or supporting service is unavailable
05
What should happen next?
- Start with a bounded read-only workflow wherever possible.
- Complete the legal, cyber and operating-authority classification before access expands.
- Test value and failure modes on representative cases.
- Require a new management decision at every increase in access, authority or scale.
