Chapter 3:
Risks of AI integration and policy recommendations
AI brings clear benefits to the power sector, but it also comes with challenges and risks. To use it safely and efficiently, the right policies need to be in place.
3.1
AI challenges and risks
Although AI could play a big role in the energy transition, it is a probabilistic approach and should not be viewed as the silver bullet. Many existing systems in the region were not designed for AI integration, meaning deployment may require significant upgrades or redesign. It is important to note that AI facilitates the resolution of grid challenges associated with the energy transition but cannot, on its own, resolve them all completely.
At the same time, AI is driving rapid growth of data centres, further complicating the landscape as it stresses existing power grids. By 2030, data centres could account for 2–30% of national electricity demand across ASEAN (excluding Viet Nam). In addition, these facilities require stable and continuous loads, a demand profile renewables can only partially meet today. As a result, many rely on natural gas now, substantially increasing emissions.
Beyond these systemic pressures, AI deployment in power systems could introduce additional technical, operational, and governance risks.
Data limitation can lead to unintentional AI failures
The effectiveness of AI in the power sector is fundamentally constrained by data availability, accessibility, and quality. Levels of digitalisation vary widely across regions and segments of the power system, placing less-digitalised utilities and operators at a disadvantage in capturing AI’s potential benefits.
Even where data exist, access remains a major barrier. Energy systems are highly fragmented, often built and enhanced over many decades with data non-standardised and distributed across multiple companies and organisations that may be unwilling or unable to share information due to confidentiality, regulatory, or competitive concerns.
Data quality further compounds these challenges. High quality data characterised by completeness, accuracy, coverage, and timeliness are essential for reliable AI performance, yet they are costly and resource-intensive to produce. The lack of quality data results in models trained and validated on synthetic or simulated data, which may not capture the full spectrum of variability and noise present in live grid conditions.
These data limitations directly increase the risk of unintentional AI failure modes. Incomplete or unrepresentative datasets can lead to bias, where AI decisions systematically deviate from intended objectives. Limited or narrow training data raise the risk of extrapolation errors, causing models to behave unpredictably when exposed to conditions outside their training experience, an especially critical concern in safety critical power system operations.
Finally, ambiguous objectives or misaligned training signals can result in model misalignment, where AI actions diverge from the goals of system operators or policymakers.
Regulatory uncertainty and liability risks
Power systems are traditionally engineered as deterministic and highly reliable infrastructures, while AI models are inherently probabilistic. Integrating AI into real time and critical operations can therefore introduce uncertainty, complicate validation and verification, and challenge existing reliability standards. Utilities therefore rely on extensive offline testing, digital twins and virtual commissioning to validate AI behaviour before deployment.
A digital twin is a virtual replica of a physical grid asset (generators, transformers, or transmission lines) that uses real-time data and machine learning to simulate, analyse, and predict behaviour while virtual commissioning uses digital twins to test, validate, and optimise new control logic, automation systems, and infrastructure before physical installation.
AI adoption also raises complex liability and accountability questions. When AI tools are used for forecasting, dispatch, protection, or autonomous control, responsibility for system failures may be unclear. Accountability can span utilities, system operators, AI developers, software vendors, and data providers. The unclear nature of many AI models further complicates accountability attribution, as it can be difficult to trace how a specific decision was made.
In addition, existing power system regulations and grid codes were not designed to address AI decision-making, creating legal uncertainty and discouraging large scale adoption. Without clearly defined liability frameworks and market standards, utilities may face increased legal risk, while regulators struggle to enforce compliance and ensure system reliability.
One of the solutions is to implement human-in-the-loop systems where AI can suggest actions but operators approve final decisions. Also, explainable AI models are more interpretable and will be easier to audit, justify and eventually improve trust in AI. The implementation of AI solutions will face regulatory hurdles. The desire to preserve some element of human control is likely to persist.
Rising cybersecurity vulnerabilities in a digitalised grid
ASEAN’s transition toward a more decentralised energy system is expected to drive rapid growth in DERs alongside cross-border electricity trade through the ASEAN Power Grid (APG). These developments will require secure and trusted data sharing including sensitive operational information, which underscores the critical importance of robust cybersecurity.
Cybersecurity readiness remains uneven across the region. While Singapore and Malaysia rank high in cybersecurity capacity, and the Philippines’ government issued the 2023-2028 National Cybersecurity Plan in 2024, other countries, including Cambodia, Myanmar, and Lao PDR are below world average and thus require additional support to strengthen cybersecurity. Poor measures in several member states can pose risks to regional data security and could hinder cross-border energy collaboration.
Cyber threats to the energy sector have intensified significantly in recent years. Analysis shows that a typical gas and electricity utility faced over 1500 attacks per week in 2024, triple the number four years earlier. Between 2021 and 2022, the number of “cyber threats” in the region, including data breaches, increased by more than 80 per cent. In 2023, Southeast Asian businesses reportedly experienced more than 36,000 online attacks on a daily basis.
AI systems also face additional risks from adversarial attacks, including data poisoning, evasion, and model extraction, which exploit vulnerabilities unique to machine-learning systems.
Organisational and cultural barriers to adoption
AI adoption in the power sector is often slowed by institutional caution and limited trust. Power systems are complex, safety-critical infrastructures where reliability and regulatory compliance take precedence over rapid innovation. Operators are therefore reluctant to deploy new technologies without clear evidence that system stability will not be compromised.
Tight control over operational data further limits experimentation, while workforce concerns about job security can create internal resistance. In safety-critical environments, acceptance also depends on transparency. Without explainability, auditability, and clear accountability, “black-box” AI systems are unlikely to gain the confidence of engineers, regulators, or system operators.
3.2
Key recommendations
AI is a powerful catalyst for overcoming VRE integration constraints, offering one of the fastest, simplest, and lowest-cost options available. It is not a future technology but a proven set of tools that remain under-utilised across ASEAN, making it a clear low-hanging fruit to accelerate the energy transition while reducing system costs and emissions. Even though risks exist, they are largely policy-manageable.
Align regulation with accurate VRE forecasting
An effective regulatory framework should incentivise accurate VRE generation forecasting. Grid codes need to define data standards and transparency requirements, including regulations that mandate the deployment of weather sensing and monitoring infrastructure to ensure the availability of high quality, real time meteorological data. Such data are essential for training and operating AI forecasting models.
Where electricity markets exist, mechanisms that reward forecasting accuracy and penalise significant deviations between scheduled and actual generation can incentivise AI adoption, driving both operational efficiency and market performance.
Strengthen data foundations and model governance
AI can significantly improve weather and VRE generation forecasting, but this technique requires extensive, diverse, and reliable datasets. Establishing decentralised, secure and collaborative data ecosystems such as data spaces will help improve data interoperability, trust, value and governance.
ASEAN governments should therefore build and improve these data frameworks for power system operations. Secure data sharing platforms between system operators, utilities, and regulators are essential to unlock AI applications in forecasting, dispatch, and flexibility management.
Public investment and concessional financing should support digital grid infrastructure, including advanced metering, sensors, and communication systems. It is because AI benefits depend critically on digitalisation and real-time visibility of the power system.
Embed data protection and cyber security by design
AI deployment in power systems must safeguard sensitive utility data and comply with established cybersecurity standards. A secure data foundation is essential, incorporating robust access controls for data integrations.
Advanced technologies, for instance post-quantum cryptography, can defend against potential cyberattacks on AI models. Additionally, decentralised machine learning techniques such as federated learning can enhance user privacy and reduce data transmission costs.
Besides that, since AI models are sensitive to input data, adversarial data manipulation or poisoning can deliberately disrupt model performance and lead to unsafe or misleading outcomes. This risk underscores the importance of integrating Machine Learning Operations (MLOps) practices that support continuous data monitoring, anomaly detection, and model performance validation.
On top of that, developing collective legislation on the ethics of AI – such as the EU AI Act 2024, the world’s first comprehensive, risk-based framework for AI regulation – is essential to ensure the safe use of AI.
Build AI-ready institutions and workforces
Successful AI adoption in utilities requires leadership commitment and a workforce equipped with the necessary digital and analytical skills. Utilities should systematically map AI and digital competencies across operational domains to identify and address skill gaps in high value use cases such as predictive grid maintenance, load forecasting, and DERs optimisation.
Targeted training and upskilling programmes are essential to reduce organisational resistance and position AI as an augmentation of human expertise rather than a replacement. Also, partnerships between governments, private sector organisations, and educational institutions can play a critical role in designing and delivering relevant AI skill-development initiatives, ensuring alignment with industry needs and labour market demands, particularly in ASEAN countries.
Phased roll-out, close monitoring and plan additional budget
AI deployment should be prioritised in power system operations and planning where near-term impact is greatest. AI sandboxes can further manage risks by enabling utilities and generators to experiment and pilot applications in controlled environments with defined risk parameters while accelerating learning, innovation, and scaling.
AI sandbox environments for power systems are secure, controlled, and isolated digital spaces designed to test and validate artificial intelligence models, algorithms and applications for energy infrastructure without impacting real-world operations.
Utility adoption should follow a phased, impact-focused rollout designed for long-term resilience. For example, initial pilot programmes on predictive maintenance should be for a limited set of critical assets only, and should clearly define priority failure modes and assess vendors based on the relevance of their training data to local equipment types, in-service age and operating conditions.
Performance evaluation should link technical metrics to business outcomes through cost-benefit analyses, ensuring that AI deployments deliver measurable value while maintaining operational reliability.
In addition, given the long lifecycles of utility assets relative to AI vendors and sensor technologies, deployments should plan for equipment replacement, documentation, and internal capability building. Budgets and timelines should realistically account for integration challenges, sensor upgrades, and the complexity of connecting AI systems to legacy infrastructure.
Related Content