Most energy operators can now tell you which AI tools they use. Far fewer can tell you what those tools decided last quarter, who reviewed the output, and on whose authority the company acted on it.
That second question is the one that matters in 2026, because it is the one a regulator, a partner, or opposing counsel will actually ask. “Defensible AI” is the shorthand for being able to answer it. It has nothing to do with how advanced your models are and everything to do with whether your decisions leave a record.
What does “defensible AI” actually mean?
An AI-influenced decision is defensible when you can reconstruct it after the fact: what the system recommended, what information it worked from, who reviewed that recommendation, and why the company acted the way it did.
Notice what is missing from that list. There is no requirement that the model be correct, because models are wrong sometimes and that is survivable; what is not survivable is being unable to show how a wrong call was made, who reviewed it, and on what basis it was approved. A documented decision that turned out badly is a business loss. An undocumented one is an exposure.
This is the distinction most AI policies miss. They govern the tool. Defensibility governs the decision.
Why the usual governance stack does not cover it
Most operators already run three programs that sound like they should cover this, and none of them quite do.
Data governance tracks where information came from and who may access it. It answers questions about the input, not the judgment. Information governance handles retention, classification, and disposal, largely a records discipline built before models started making recommendations. AI governance, as it is usually implemented, is a procurement and risk exercise: which tools are approved, which use cases are permitted, which vendors have been assessed.
All three are necessary, and none of them capture the moment a human took a machine’s recommendation and turned it into an operational or financial commitment, which is precisely where the accountability lives and, in most organizations, the least documented link in the entire chain.
The discipline that sits on top of those three and captures the decision itself is what I have been calling Digital Information Governance: keeping AI-influenced decisions traceable, the company’s information accurately represented, and its AI use provable. The label matters less than the gap it names. Whatever you call it, the gap is real and most operators have it.
Where AI already makes decisions in an energy business
The exposure is rarely where leadership expects it. It is almost never the flagship pilot with the steering committee and the quarterly readout, but the accumulated small stuff that arrived inside a procurement bundle, or through no process at all.
- Maintenance and integrity. Models ranking which assets get attention this cycle, and which wait.
- Subsurface and reserves work. Model-assisted interpretation feeding numbers that eventually reach a disclosure.
- Procurement and vendor screening. Automated scoring that quietly decides who never makes the shortlist.
- Trading and scheduling. Recommendation engines shaping positions on a timescale no human reviews individually.
- Hiring. Screening tools that filter candidates before any person reads a resume.
- External representation. How AI systems describe your company to a counterparty researching you, which you did not choose and may never see.
The last one is the one operators tend to dismiss, and it is worth a second look. When an AI system misstates what your company does, that description becomes something a partner, a regulator, or a court can point to. It is a control surface whether or not you treat it as one.
What the regulation actually requires
Three frameworks matter for a US energy operator right now, and they converge on the same demand.
The NIST AI Risk Management Framework is voluntary, and it has become the reference point everyone else borrows from. Its four functions (Govern, Map, Measure, Manage) are organized around documented, repeatable process rather than any particular technology.
Texas passed the Texas Responsible AI Governance Act (HB 149) in the 89th Legislature, which matters directly for operators headquartered here. The EU AI Act reaches any company with meaningful European exposure, which for most energy firms means partners, buyers, or an EU-domiciled entity somewhere in the structure.
Read them together and the common requirement turns out not to be a technical control at all, but a documented, defensible account of how AI-influenced decisions get made and who stays answerable for them. That is a records and process problem long before it is an engineering one. The good news follows: you can start without hiring a data scientist.
A defensibility checklist you can run this quarter
None of this requires new software. It requires deciding that the answers should exist.
- Inventory the AI you inherited. Not the tools you bought deliberately, but the ones that arrived inside software you already licensed. Most operators find more than they expect.
- Identify decisions with physical or financial weight. Where does a model recommendation turn into money moving, equipment operating, or a person being hired or not hired?
- Name an accountable human for each one. Not a committee. A person who can explain the call and who remains answerable for it.
- Capture the decision, not just the data. Record what the model recommended, who reviewed it, on what authority, and why they acted. Capture it at decision time, because reconstructing it later is exactly the thing you cannot do.
- Check how AI describes your company. Ask the major assistants what your firm does. Ask more than once, on more than one day. The answers vary considerably, and the variation itself is worth knowing about.
- Set the board reporting line. Decide who reports on AI decisions, how often, and in what format, before an incident forces the question.
An operator who can work through those six items has most of what a regulator would ask for. An operator who cannot is carrying an exposure that no amount of model accuracy will offset.
The practical test
Here is the question worth taking into your next leadership meeting: if a significant AI-influenced decision from last quarter were challenged tomorrow, could you produce the record of how it was made, within a day, without a scramble?
If the answer is yes, your governance is real. If the answer is “we would have to go ask around,” then what you have is a policy rather than a control, and the distance between those two things is where defensibility actually lives. Closing it is mostly organizational discipline, not technology spend.
The operators who sort this out in 2026 will not be the ones with the most advanced AI. They will be the ones who can show their work.
Matthew Bertram is involved in AI visibility, digital transformation, and industrial AI governance initiatives across the energy sector through OGGN, ModalPoint, and EWR Digital.
