rotascale

Solutions — sector

The agent can open the breaker. Prove it was allowed to.

Every other sector on this list can unwind a bad decision with a credit note. Here the action is physical, it is immediate, and the review afterwards is conducted by people who will ask who authorised it — in writing, under oath, in front of a committee.

EU AI Act Annex III(2) · NIS2 · GDPR National energy regulators and NIS2 competent authorities clause map
Status
High-risk under Annex III where used as a safety component in the supply of electricity, gas, heating or water
Applies to
Grid operations, dispatch, demand response, field service, metering

Blast radius is the whole problem

In most sectors the dangerous agent is the one that does the wrong thing. Here it is the one that does the right thing too many times. A setpoint change is unremarkable; ten thousand of them inside a minute is an event with a name and a public inquiry.

This is why bounds is a gate of its own and sits ahead of policy in the order. Policy asks whether this action is permitted. Bounds asks how much of it there may be — a limit on scale rather than on kind, checked before the action, not reconciled after it.

The limit is on the tree, not the call
Spend and scale debit every ancestor of a delegated grant, so an orchestrator that fans out to fifty workers cannot exceed its own ceiling by dividing the work.
An exhausted bound refuses, it does not warn
The outcome is exhausted, distinct from deny, because "you were not allowed to do that" and "you had run out" are different findings and lead to different remedies.
The refusal costs nothing
The budget is debited last, after every structural check has passed, so an action refused at an earlier gate does not consume the allowance it never used.

NIS2, and what this does not do about it

RotaGrant ships no clause map for NIS2. It is a directive transposed differently in each member state, and a single map would be wrong in twenty-seven ways. What the platform contributes is the evidence an incident report needs — what acted, under whose authority, within what bound, and what was refused — assembled as a query rather than as a fortnight of reconstruction. Whether that satisfies your competent authority is regulatory interpretation, and it rests with you and your counsel.

The agents your teams are about to ship

Utilities have run automation for forty years. What is new is automation that decides on its own initiative, at a speed no control-room operator can review, against consequences that are measured in customers rather than currency.

  1. 1 authority Is there any authority for this?
  2. 2 status Is the grant active?
  3. 3 window Is now inside the grant's window?
  4. 4 scope Does the grant cover this action?
  5. 5 clean_context Was the context clean, where that is required?
  6. 6 bounds Do the per-action limits hold?
  7. 7 policy Does the policy on the grant permit it?
  8. 8 budget Is there room under the ceiling?
  9. 9 review Does this need a person?
Nine gates, evaluated in this order before the action. The lit ones are the gates that hold the four agents below — which is what differs between one industry and the next. The order does not.
Dispatch and balancing agent bounds

Watches frequency and load, and issues setpoint changes to generation and storage to hold the system inside its operating envelope.

Consequential action
Changes the setpoint of a generating asset
What goes wrong
The correct action for one asset, applied to a fleet. Nothing about the individual instruction is wrong; the number of them is.
What is recorded
The bound that was set, the scale the call attempted, and the refusal — which is the artefact an incident review actually wants.
Demand response agent budget

Curtails or shifts load across enrolled industrial and domestic sites to avoid a constraint.

Consequential action
Curtails supply to a customer site
What goes wrong
Curtailment carries contractual penalties and, at some sites, safety consequences. A per-call limit with no aggregate ceiling is not a limit.
What is recorded
Every debit against the mandate, the remaining ceiling at the moment of the call, and the refusal when it ran out.
Outage triage and switching agent authority

Diagnoses faults from telemetry and proposes — or executes — switching to restore supply to the largest number of customers.

Consequential action
Operates a switching device on the distribution network
What goes wrong
Switching is the action that puts field crews at risk. Ambient permission to switch is not a governance gap, it is a safety incident waiting for its date.
What is recorded
The named engineer whose authority the agent acted under, the scope of that authority, and its expiry.
Field service scheduling agent clean_context

Reads work orders, asset histories and contractor notes to plan and dispatch crews.

Consequential action
Dispatches a crew to a live asset
What goes wrong
Free-text notes from a third-party contractor are untrusted content, and an agent that treats them as instructions can be steered by whoever writes them.
What is recorded
Which retrieved content was untrusted, where it entered the trajectory, and whether the dispatch after it was allowed to stand.

Ambition is the point of these: none of them is a chatbot. Each is an agent taking an action with a consequence somebody has to answer for — which is exactly the moment a bounded authority stops being paperwork and starts being the reason the project is allowed to ship.

What an incident review will ask

Not hypothetical questions. These are the ones that arrive in writing, with a deadline, and the honest answer to most of them is a query rather than a project.

Who authorised the action that caused this?
A grant, signed for by a named accountable human, with a scope and an expiry. The decision record cites the grant it acted under — there is no ambient permission to operate anything.
Was the control enforcing at the time, or only watching?
Enforcement is a mode on the grant — observe, shadow, canary, enforce — and it is sealed into the record at the moment of the decision. A pack states the mode that was live then, not the one configured now.
Show us what the system refused.
Refusals are recorded with the same weight as allowances. In this sector that is the more valuable half: an agent stopped at a bound is the evidence the envelope held.
Can this run inside the OT boundary?
Single-tenant in your environment, including airgapped, and the deployment refuses to start if any setting selects a service outside your network. It also names which evidence property you gave up by disconnecting it.

Identifiers this deployment verifies here

Every one of these is a checksum, not a shape. The claim is “this is a valid VAT number and the check digits agree”, not “this looks like one” — which is why the count on a screen can be cited rather than caveated.

FamilyHow it is verified
EU VAT number — per-state check digit where the state publishes one
Bank account (IBAN) — mod-97 over the rearranged string
National identifier (PL, BE, NO) — scheme-specific weighted checksum
Australian Business Number — modulus 89 after the documented subtraction

And what it does not look for. Names, addresses and dates of birth in free text carry no checksum, and finding them needs a model this deployment does not run. Neither are card numbers, medical record numbers, or national schemes beyond the three above. A clean screen means no verified identifier was found — never that the payload holds no personal data.

See it on your own problem

Bring the dispatch or switching agent. We will set the envelope, run it until it hits the bound, and show you the artefact an incident review would actually ask for.

A walkthrough is a working deployment with your control room and OT security leads in the room, not a slide deck — bring the agent you are most nervous about and we will put it behind a grant while you watch. If you would rather look first, the demo needs a work address and one click.