All insights

PSU & CPSE

Energy Sector PSUs: Regulatory Constraints

· 10 minute read

Energy CPSEs do not have an 'AI Act'. They have CERC and SERC duties, CEA safety, grid-code confidentiality, DPDP and a hard OT boundary. Hedge every overlay. Do not invent a circular.

A generating company's board note said the plant copilot was 'compliant with power-sector AI norms'. The company secretary asked for the citation. The consultant produced a European blog and a slide with a transmission-tower watermark. There was no Indian instrument with that title. The CVO asked that the sentence be deleted before the note travelled.

This explainer is for compliance and regulatory-affairs leads in generation, transmission, distribution and oil-and-gas CPSEs. It is deliberately hedged. As of 17 August 2026 we have not found a single Indian statute or CERC regulation that can honestly be nicknamed an energy AI Act. What you have is a stack: sector regulators, safety bodies, grid and market codes, company law, DPDP, CERT-In, and your own OT standards. An agent has to be placed against the stack, not against a slogan.

CERC at the Centre and SERCs in the states regulate tariffs, markets, licensing and a thicket of information duties. They do not, by virtue of existing, certify your model. CEA writes technical and safety standards that plant engineers actually fear. Those standards were not drafted for a chatbot. Do not pretend they were. Do not pretend they are irrelevant when the chatbot can see a protection setting.

Not legal advice and not a substitute for your regulatory cell. Confirm every overlay against the live regulation, the current grid code, the plant's safety case, and counsel. Circulars move. This article will lag.

The stack, not the slogan

Write the stack on one page before you write the use case. Typical rows for a generating CPSE: Electricity Act licensing and tariff context; CERC or the relevant SERC information and market-conduct duties that apply to you; CEA safety and technical standards; the grid code and any RLNG or SLDC confidentiality practice you actually follow; PESO or factories-act overlays if they touch the site; DPDP for personal data; CERT-In for ICT logs; DPE and CVC for the CPSE file; the company's OT and IS policy.

If a row does not apply, say why. A pure trading desk and a pit-head plant do not share a stack. A city discom under a SERC has duties a central generating station does not. Copy-pasting 'CERC compliant' onto a state discom note is how you look unprepared in a review.

MeitY's India AI Governance Guidelines (5 November 2025) are horizontal sutras. They are useful culture. They are not a CERC order. DPDP is the personal-data statute, commencing in phases. Neither document relocates a protection setting.

Place the agent on the stack. Inventing a sector AI Act is a finding, not a shortcut.
OverlayWhat it actually gives youHow an agent typically fails it
CERC / SERC dutiesMarket, tariff, licensing, specified informationA chat that leaks a bid, a outage plan, or a consumer list into a vendor tenant
CEA / plant safetyTechnical and safety standards for apparatus and operationAn agent that can see or suggest protection settings from a laptop on Wi-Fi
Grid code / SLDC-RLDC practiceOperational confidentiality and dispatch disciplineA copilot trained on yesterday's despatch in a public model
DPDP + CERT-InPersonal data purpose; ICT log floorConsumer or employee data in a foreign prompt; no packet

OT is the hard stop

The companion field note on OT networks exists because energy buyers keep asking the same unsafe question. Agents belong on the business network, on documents, on ERP extracts, on regulatory correspondence. They do not belong on the DCS, the SCADA, the protection LAN, or the historian's control path. If you need a tag, use the export path the plant already approves, on a one-way or mediated basis the OT owner initials.

Safety cases are conservative for a reason. A wrong suggestion about a valve is not a wrong footnote. Until a competent plant authority writes a different rule, the default is stay out. Hedge: we are not telling you that no future instrument will ever allow assisted analytics on a mirrored historian. We are telling you not to invent that instrument in a 2026 pilot note.

Market data and consumer data are different animals

A bid, a forced-outage notice, or an unreleased tariff working is commercially and sometimes regulatorily sensitive. Treat it as a purpose-tagged corpus with a small access list. Do not put it in the same index as the CSR brochure.

A discom's consumer list is personal data under DPDP and often a SERC conduct issue. An agent that drafts disconnection notices is a rights-affecting workflow. It needs a named officer, a reconstructable packet, and a grievance path. It is not a 'customer experience copilot' until those exist.

What to write when the board wants a 'norm'

Write: we have not identified a dedicated energy-sector AI regulation that certifies this tool. We have mapped the live overlays (list). The agent is confined to (corpus). It cannot reach OT. Personal and consumer data carry purposes. Market-sensitive text does not leave the perimeter. The regulatory cell will re-read this map if CERC, the SERC, CEA or MeitY issues a later instrument.

That paragraph is dull. Dull is how energy files survive a later order that did not exist when you bought the tool.

Objections you will hear — and what to do with them

These are the lines that stall the file. Answer them in the room, then put the answer in the note. A spoken answer without paper will be forgotten by the next officer.

CERC will issue an AI regulation soon, so we should wait.

Waiting for a hypothetical instrument is how you also skip DPDP purpose, CERT-In logs and the OT boundary — which already exist. Build the stack you can cite. Re-read when a real order lands.

Our OEM's cloud historian is already abroad.

That is an existing risk to put on the map. It is not a licence to add prompts, embeddings and traces to the same path. Do not stack a new transfer on an old exception without a fresh note.

SERC asked us to be citizen-friendly, so the chatbot must be live.

Citizen-facing answers can run on public tariff orders and published outage notices. They do not need the billing corpus or the control room. Split the systems.

The vendor is 'power-sector specialised'.

Specialisation is a reference list, not a regulation. Ask which overlay they mapped. If they say 'we follow CERC AI norms' and cannot produce the instrument, they are selling a watermark.

A four-week overlay map

Do this on paper before anyone plugs a laptop into a plant VLAN.

  1. Week 1: regulatory cell lists live CERC/SERC, CEA, grid-code and safety instruments that actually apply to this unit. Hedge what is unclear. Do not invent titles.
  2. Week 2: mark the OT boundary and the approved export paths. Get the plant head and the CISO to initial the drawing.
  3. Week 3: classify corpora — public, market-sensitive, consumer-personal, employee-personal, safety. Separate indexes.
  4. Week 4: write the board paragraph that admits there is no sector AI Act and lists the overlays. Tabletop a leak of an unreleased outage plan.

How this shows up in the file

Subject: Agent use in an energy CPSE — overlay map, no invented AI regulation.

This company has not identified a dedicated CERC or SERC instrument that certifies artificial-intelligence agents. The pilot is placed against (list overlays). The agent cannot reach OT networks. Market-sensitive and consumer-personal data are purpose-tagged and do not leave the approved perimeter. The map will be re-read if a later instrument is issued.

This note is not regulatory advice.

This article is informational field guidance for Indian public sector undertakings and their vendors, not legal, audit, labour, energy-regulatory, banking-regulatory or procurement advice. Confirm the live circular, DPE guideline, CVC instruction, sector regulator text, purchase manual and your counsel before you file it.

How this clears vigilance and the board

A P6 Compliance/DPO in a PSU will meet CVC-shaped questions even when there is no special 'AI circular'. “Energy Sector PSUs: Regulatory Constraints” has to survive a technical committee, a cost centre, and a union conversation if jobs appear threatened.

Energy CPSEs do not have an 'AI Act'. They have CERC and SERC duties, CEA safety, grid-code confidentiality, DPDP and a hard OT boundary. Hedge every overlay. Do not invent a circular. OT networks stay off-limits. Navratna autonomy speeds buying; it does not waive DPDP or data classification. IREPS is not GeM. RBI-shaped rules still localise payment data.

  • Classify data before the POC.
  • Keep agents off OT.
  • Write the board memo with residual risk.
  • Engage unions on retrieval vs replacement.

Close this loop before the next CAB

Put “Energy Sector PSUs: Regulatory Constraints” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P6 Compliance/DPO, not “the vendor.”

Revisit the item when the model, the GeM term, the region, or the SI changes. “energy PSU AI regulation” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.

Questions this usually raises

Is there an Indian energy-sector AI Act?
As of 17 August 2026 we have not found a statute or CERC regulation that can honestly be cited that way. Place the agent against the live overlay stack. Re-read when an instrument actually issues.
Does a SERC consumer-service standard require a chatbot?
Not that we can see as a general rule. Standards about service and information can often be met with published data and human desks. Do not stretch a service standard into an OT or billing-corpus permission.
Can we use live SCADA tags in a copilot?
Default no. Keep agents off the control path. Any exception needs a competent plant authority, a mediated export, and a safety review. Do not invent the exception in a vendor SOW.
Where does DPDP fit for a discom?
Consumer and employee personal data. Purpose, processor, security, rights path. Sector duties sit on top, they do not replace DPDP.
What should a generating company cite in the board note?
The overlay list, the OT boundary, the corpus classes, the training ban, and the promise to re-read if CERC, CEA or MeitY issues a later instrument. Not a fictional 'power AI norm'.

Sources