By Sagar Shankaran, Founder of CallSphere
NERC CIP does not ban the cloud, it puts the burden on you. Why on-site AI now fits utility drawings, relay settings and storm damage assessment work.
Key takeaways
You asked about this in 2024. You took it to the CIP compliance manager, she asked one question — "where does the document go when someone types the question?" — and the project stopped there. She was right to stop it. What has changed is not the rule. It is that the answer to her question can now be "nowhere; it stays in this building."
That is worth an hour of your time, because the documents a utility most wants a search assistant for are precisely the documents it is least allowed to be casual with.
Every utility has them, and they are not the same pile with four labels.
First, information about the cyber systems that run the grid: control centre network drawings, energy management system configuration, remote access designs, relay and protection settings tied to those systems. Under CIP-011 this is information whose exposure would help someone compromise the bulk electric system, and you carry a documented programme for protecting it.
Second, critical energy infrastructure information as FERC defines it: substation one-line diagrams, transmission maps, physical security plans, vulnerability assessments. It has its own handling rules and its own non-disclosure paperwork, and your regulatory team already redacts it out of rate case responses.
Third, large customer data under contract. Fifteen-minute interval demand for a semiconductor fab or a cold storage warehouse is a picture of that customer's production schedule. Your service agreement very likely says what you may do with it, and "put it in a third party's system so an assistant can search it" is not obviously inside that.
Fourth, the medical certificate and life-support customer list, which drives who gets called first before a planned outage and who cannot be disconnected in July. That is health information about your customers in everything but name, and state commission rules treat it accordingly.
Hear it before you finish reading
Talk to a live CallSphere AI voice agent in your browser — 60 seconds, no signup.
Running AI on your own machines means the model files sit on hardware you own inside your own building, so the question and the document never leave the property — nothing goes out and nothing has to be trusted to come back.
Get this right, because the folklore is wrong in both directions.
CIP does not ban the cloud. Since the start of 2024, the standards governing access management and information protection have explicitly contemplated storing information about bulk electric system cyber systems with a third party, provided you can demonstrate the protections and control who can actually read it. Plenty of utilities do exactly that, with documented encryption and key control.
What CIP does is put the burden squarely on you, and keep it there. Every place that information lands is a place you must describe to a regional entity auditor, with evidence, for every year since the last audit. Add a vendor and you have added supply chain risk obligations, change management questions and a new set of access reviews. None of that is impossible. It is just expensive in the currency your compliance team is shortest on, which is hours and defensibility.
And there is one place where it genuinely is a hard line: inside the electronic security perimeter. The systems in your control centre and your medium and high impact substations do not reach the internet. Remote access to them goes through an intermediate system by design. An assistant that has to call out to somebody else's service to answer a question is not going in there, this year or any year. If you want an assistant that operators can use at the console, it runs locally or it does not run.
Two things changed. Processors built for local work — the Qualcomm Dragonwing class and its peers — got good enough that a tablet or a small on-site server runs a capable model without calling anywhere, and for high-volume repetitive work running locally comes in around ninety per cent cheaper than sending it to a cloud service. And large organisations stopped treating on-premises as the compromise: Cisco is rolling a personal AI agent out to roughly 90,000 employees with a deliberate on-premises emphasis for control and data protection, routing different jobs to different models rather than sending everything outside.
For a utility that reads as permission. The pattern you would have had to invent and defend on your own two years ago is now the pattern serious enterprises are choosing on purpose.
flowchart TD
A["Relay and protection setting sheets"] --> D["On-site assistant inside the control centre"]
B["Substation one-line drawings, CEII"] --> D
C["Switching orders and clearance logs"] --> D
D --> E["Protection engineer asks a question at 2:14am"]
E --> F["Answer returned with the drawing sheet it came from"]
F --> G["Question and answer logged on site for the CIP evidence file"]
A ground fault trips a 69 kV line and the reclose does not hold. The system operator has a one-line on the wall and a protection engineer on the phone who was asleep four minutes ago. The question is ordinary and the answer is buried: what are the current settings on that relay, when were they last changed, what did the last setting change memo say about coordination with the downstream recloser, and has this line done this before.
Today that is three phone calls and someone driving in to open a drawing cabinet, or twenty minutes searching a document system indexed by whoever scanned the drawings in 2011. With an assistant sitting on hardware in that building, it is one question and an answer carrying the setting sheet revision it was read from and the date on it. Nothing left the room. Nothing needs a vendor risk assessment. The question and answer get logged on the same site, which is one more line of evidence rather than one more thing to explain.
Still reading? Stop comparing — try CallSphere live.
CallSphere ships complete AI voice agents per industry — 14 tools for healthcare, 10 agents for real estate, 4 specialists for salons. See how it actually handles a call before you book a demo.
This is the argument that lands with operations people faster than any compliance argument. On day two after a hurricane, a large share of your territory has no cellular service, because the towers are on your poles and running on batteries that died overnight. Your damage assessors are in exactly those places, because that is where the damage is.
An assistant that needs a connection is dead at the moment of maximum value. One running on the assessor's tablet is not. It reads the pole tag and the crossarm equipment from a photograph, fills the damage assessment form, drafts the material list — two crossarms, a 25 kVA transformer, 300 feet of triplex — and holds it until the tablet finds a signal or the assessor reaches the staging site. He keeps walking the circuit instead of standing on a hill hunting for a bar of service.
| Assumption (illustrative) | Value |
| Customers served | 910,000 |
| Customers out at peak | 62,000 |
| Damage assessors in the field | 180 |
| Assessment period | 6 days |
| Minutes lost per assessor per day to no signal | 40 |
| Assessor hours recovered | 720 |
| Restoration pulled forward for the last 18,000 | 25 minutes |
| Customer-minutes of interruption avoided | 450,000 |
| Equivalent average interruption duration | 0.49 minutes |
| 180 tablets at $1,300, over 3 years | $78,000 per year |
Now the honest footnote, because a reliability engineer will raise it immediately: if that storm clears the major event day threshold under IEEE 1366, those customer-minutes come out of your reported figures anyway and the 0.49 never appears in what you file. The gain is real but it shows up elsewhere — in 720 assessor-hours, in crews idle for less time waiting on assessment, and in the 6 a.m. call with the county emergency manager where you can say which circuits are patrolled.
Do not run everything locally out of principle. Ordinary corporate work — drafting a memo, cleaning up a board deck, summarising a vendor proposal — has none of these constraints, and standing up on-site hardware for it buys cost and staffing you did not need. Match the location to the sensitivity of the document.
Do not put the assistant inside the electronic security perimeter first. Start outside it, on the corporate side, with CEII drawings and setting sheets, where the compliance argument is manageable. Anything that touches the perimeter is a project with change management, access reviews and evidence attached, and it should follow a win rather than be one.
And keep the human where the consequence is. An assistant reading a setting sheet is a faster filing cabinet, not a protection engineer. It does not approve a setting change, it does not authorise a switching order, and it does not decide whether a line is safe to pick up. In damage assessment it drafts the form; the assessor signs it, because that form drives crew dispatch and material ordering and someone has to own it.
Auditors do not accept or reject tools; they test whether your documented programme matches what you actually do. Keeping the information on premises makes that conversation shorter, not longer, because there is no third party to describe. Write the assistant into your information protection programme, log what it reads, and review the access list on the same cycle you review everything else.
Less than most people assume. A small server pair in a room you already have will carry document search for a control centre and an engineering group. The bigger cost is not the machines; it is a named owner for them and a records person who keeps the drawing library current, because an assistant pointed at a stale drawing cabinet gives you confident answers from a 2011 revision.
It depends entirely on what your protection programme and your customer contracts actually say, and that is a question for your compliance manager and counsel, not a general rule. The useful test is the one she asked in 2024: name every physical location the document and the question travel to, and be ready to evidence the controls at each one. If that list has one entry and it is your own building, everything downstream gets easier.
One last thought about the phones. The same storm that knocks out your damage assessors' signal fills the public line with outage reports, wire-down calls and people asking when the lights come back. CallSphere builds AI voice and chat agents that answer business phone lines and web chat, capture details and book appointments around the clock — a sensible place to take pressure off the front line while your protected engineering data stays exactly where the compliance manager wants it.

Written by
Sagar Shankaran· Founder, CallSphere
LinkedInSagar Shankaran is the founder of CallSphere, where he builds production AI voice and chat agents deployed across healthcare, hospitality, real estate, and home services. He writes about agentic AI, LLM engineering, and shipping voice agents that handle real calls in production.
See how AI voice agents work for your industry. Live demo available -- no signup required.
Supplement brands get adverse events reported by ticket, not by form. On-premises AI reads all 3,400 a month without that text ever leaving the building.
The monthly IEEE 1366 reliability close takes 64 hours across three people. What goal-driven agents change, the arithmetic, and what stays with the engineer.
Concealed-damage claims cost a warehouse manager half a Friday. On-site AI searches your own footage and scan trail without any data leaving the property.
Casino surveillance footage cannot leave the property. On-premises AI in 2026 cuts a 90-minute disputed handpay review to nine, with no video sent to a vendor.
Custody orders, health plans, subsidy files and classroom video can stay in the building. What on-premises AI unlocks for a child care center in 2026.
How commercial GCs search restricted SSI and CUI drawing sets using AI that runs on hardware in their own server room, with a worked cost example for one job.
© 2026 CallSphere Inc. All rights reserved.
Made within San Francisco
Watch how CallSphere handles real customer calls, schedules appointments, and processes payments — live.
Try Live DemoBook a DemoCalculate Your ROI