Energy companies are deploying AI in safety-critical environments — from predictive maintenance and drilling optimisation to smart grid management and autonomous inspection. This benchmark — measured against ISO 42001 — reveals where the energy sector stands and what gaps remain between operational excellence and structured AI governance.
Four major regulatory and safety frameworks are converging on the energy sector simultaneously — creating the most urgent AI governance compliance window the industry has ever faced. Every day without a structured governance framework increases exposure to penalties, safety incidents, and reputational risk.
—
Days Until EU AI Act
Critical infrastructure AI · Aug 2, 2026
ACTIVE
IEC Functional Safety
IEC 61508/61511 — complementary to ISO 42001
—
KSA PDPL
Full enforcement · Sep 2025
ACTIVE
UAE Energy Strategy 2050
National mandate in effect
01 — EXECUTIVE SUMMARY
The Energy AI Governance Gap
Energy and oil & gas organisations are, on average, 40% ready for ISO 42001 certification — positioning them alongside the lowest-governed sectors for AI. This is a dangerous paradox: energy is deploying AI in safety-critical, physically consequential environments — wellhead operations, grid management, refinery process control, autonomous inspection — while operating with AI governance frameworks designed for spreadsheets and dashboards. When an AI system fails in financial services, money is lost. When an AI system fails in energy, equipment is damaged, environments are contaminated, and people can be killed.
Four forces are converging: safety-critical AI proliferation into operational technology environments, ESG and sustainability mandates requiring disclosure of AI governance practices, the energy transition introducing entirely new AI applications (solar forecasting, grid balancing, carbon capture monitoring), and GCC strategic positioning as ADNOC, Saudi Aramco, DEWA, and Masdar deploy AI at massive scale under national energy strategies.
The gap isn't governance discipline — energy companies have world-class Health, Safety & Environment (HSE) culture. Decades of managing hazardous operations have created HAZOP studies, Management of Change processes, and incident investigation methodologies that map directly to ISO 42001 requirements. The gap is extending that discipline to AI systems. ISO 42001 certification bridges this gap, ensuring AI receives the same systematic governance that physical operations have received for decades.
€35M
Max EU AI Act Penalty
Or 7% of global turnover
80%
Lack Mature AI Governance
Deloitte State of AI, 2026
80+
Jurisdictions with AI Policy
OECD AI Policy Observatory, 2026
IEC 61508
Safety ≠ AI Governance
Functional safety doesn't cover algorithmic risk
Benchmark scores are directional estimates derived from regulatory analysis, ISO adoption research, and industry governance maturity patterns. They reflect expected readiness levels based on published data and are updated periodically as the market matures.
02 — AI GOVERNANCE LANDSCAPE
Approaches to AI Governance
AI governance is not a single framework — it's a discipline with multiple approaches, each with distinct strengths and limitations. Understanding the full landscape is essential before choosing a path, and helps explain why ISO 42001 has emerged as the leading certifiable option for organizations serious about structured AI governance.
Approach
What It Is
Strengths
Limitations
Internal AI Policies
Self-defined governance frameworks developed in-house
Flexible, quick to implement, tailored to organization
No external validation, inconsistent across teams, not recognized by regulators or clients as proof of governance
EU AI Act Compliance
Meeting requirements of Regulation 2024/1689
Mandatory in EU, clear penalties create urgency, detailed requirements for high-risk AI
Jurisdiction-specific, not certifiable, reactive (compliance ≠ governance), doesn't cover full management lifecycle
NIST AI RMF 1.0
Voluntary US framework: GOVERN, MAP, MEASURE, MANAGE functions Source: NIST AI 100-1, January 2023
Well-structured, free, aligns with ISO 42001 concepts
Voluntary only — no certification, no audit mechanism, US-centric, no enforcement
IEEE Ethically Aligned Design
Ethics-focused standards for autonomous systems Source: IEEE P7000 series
Strong on fairness, transparency, and human rights
Narrow scope (ethics, not full governance), not widely adopted, not a management system
Industry-Specific Frameworks
IEC 61508/61511 (functional safety), API RP 754, IOGP Standards Source: IEC 61508:2010, API RP 754 (3rd ed.)
Deep domain expertise, regulatory weight in energy operations
Cover functional safety, not AI governance. Can't certify AI management against them. Don't address bias, transparency, or lifecycle governance.
ISO/IEC 42001:2023
International standard for AI Management Systems (AIMS) Source: ISO/IEC 42001:2023, published December 2023
Certifiable by accredited bodies worldwide. Covers full lifecycle (Clauses 4–10 + 39 Annex A controls). Compatible with ISO 27001/9001/14001/45001. Satisfies multiple regulations simultaneously. Continuous improvement built in.
Relatively new (27 months old). Certification body capacity still scaling. Requires genuine organizational commitment.
03 — WHY ISO 42001
The Case for ISO 42001
ISO 42001 is not the only approach to AI governance — but for organizations seeking a structured, certifiable, and internationally recognized framework that covers the full AI lifecycle from leadership accountability through operational controls to continuous improvement, it is the strongest available option. Here's why it stands apart from other approaches.
The Only Certifiable AI Framework
You cannot get a certificate for NIST AI RMF compliance. You cannot certify against the EU AI Act. IEC 61508 certifies functional safety, not AI governance. ISO 42001 is the only AI governance framework where an accredited third-party auditor can verify your implementation and issue an internationally recognized certificate.
ISO 42001 follows the Annex SL management system structure used by ISO 27001, ISO 9001, ISO 14001, and ISO 45001. Energy companies already certified to these standards can integrate ISO 42001 into their existing management system — extending governance infrastructure rather than building it from scratch.
Source: ISO/IEC 42001:2023 follows the ISO Harmonized Structure (Annex SL) for management system standards.
The Regulatory Multiplier
A single ISO 42001 implementation addresses requirements across the EU AI Act (critical infrastructure AI), DORA (ICT risk), IEC 62443 (industrial cybersecurity governance), ESG disclosure requirements, and regional data protection laws. Instead of five separate compliance projects, energy companies can build one governance system.
Source: EU AI Act Recital 40 references harmonized standards; ISO 42001 submitted for harmonization under the EU AI Act framework.
Compatible with Existing ISO Systems
Energy companies already certified to ISO 14001 (environmental), ISO 45001 (occupational health & safety), ISO 55001 (asset management), or ISO 27001 (information security) can integrate ISO 42001. The shared Annex SL structure means common elements need only be extended. ISO estimates 30–40% reduction in implementation effort for organizations with existing certifications.
Source: ISO Annex SL harmonized structure; ISO/IEC 42001:2023 Annex D (informative) on relationship to other standards.
39 Controls Across the Full AI Lifecycle
Annex A provides 39 specific controls covering data governance (A.4), transparency (A.5), accountability (A.6), bias and fairness (A.7), reliability (A.8), security (A.9), privacy (A.10), human oversight (A.11), documentation (A.12), and third-party AI management (A.13). No other framework provides this breadth of AI-specific controls in a single, auditable structure.
Source: ISO/IEC 42001:2023, Annex A — Reference control objectives and controls.
What ISO 42001 Does Not Cover
Functional safety certification. ISO 42001 governs AI management systems. IEC 61508/61511 govern functional safety of safety-instrumented systems. They are complementary — ISO 42001 does not replace functional safety certification, but fills the AI governance gap that functional safety standards do not address.
Technical AI safety. The standard covers governance and management of AI risks, but does not prescribe specific technical solutions for model testing, adversarial robustness, or algorithmic fairness. Organizations must select appropriate technical approaches within the governance framework.
Our position: ISO 42001 is not a silver bullet — no single framework can solve AI governance in isolation. But for energy organizations seeking to extend their world-class HSE governance discipline to AI systems, it is the strongest available option. The benchmarks in this report measure readiness against this standard specifically.
The Benchmark
The energy sector averages 40% readiness. The certification threshold is 75%.
Here's the clause-by-clause breakdown of where that gap lives.
04 — CLAUSE ANALYSIS
Clause-by-Clause Benchmark
How energy, oil & gas, and utilities organizations score across each of the 7 mandatory ISO 42001 management system clauses — from context and leadership through planning, support, and operations to performance evaluation and improvement. Scores reflect the degree to which current industry practices align with each clause's specific requirements. Click any clause to see the detailed analysis, key gaps, and recommendations.
Estimated readiness based on regulatory analysis, ISO Survey certification adoption data (2019–2024), published AI governance maturity research, and industry-specific compliance infrastructure patterns across energy, oil & gas, and utilities entities.
When an AI system fails in energy, equipment is damaged, environments are contaminated, and people can be killed.
05 — ANNEX A CONTROLS
Control Maturity by Domain
ISO 42001 Annex A defines 39 controls across 12 groups, which we organize into 5 operational domains for clarity. Each domain is scored on a 1–5 maturity scale based on typical implementation patterns observed across energy, oil & gas, and utilities organizations. The industry's deepest vulnerability — third-party AI governance at just 1.4/5.0 maturity — reflects the critical gap between vendor-supplied AI in safety-critical OT environments and the operator's governance visibility.
Maturity scores estimated from regulatory compliance patterns, published AI governance research, and industry-specific control implementation analysis across energy, oil & gas, and utilities entities.
Energy companies have the strongest safety culture of any sector — the gap is extending that discipline to AI systems.
06 — CRITICAL GAPS
Top 5 Gaps in Energy & Oil & Gas
The most significant AI governance gaps we consistently identify across energy, oil & gas, and utilities organizations — ranked by severity, with ISO 42001 clause references and estimated remediation timelines for each.
The first energy company to achieve ISO 42001 bridges the gap between operational safety and algorithmic governance.
07 — REGULATORY LANDSCAPE
Energy & Oil & Gas AI Regulations
A comprehensive reference of every regulation and safety standard affecting AI governance in the energy sector — current status, enforcement dates, penalty structures, and the specific impact on energy operations. Use this as a quick reference when assessing your organization's regulatory exposure.
Regulation
Jurisdiction
Status
Penalties
Impact on Energy
ISO 42001 Alignment
EU AI Act
EU/EEA
High-risk: Aug 2026
€35M / 7%
Critical infrastructure AI (Annex III §2): grid management, gas/heating/electricity supply = high-risk. Obligations effective Aug 2, 2026.
Cl.6 · Cl.8 · A.5 · A.8 · A.11
EU CSRD
EU/EEA
Phased (2025-26)
Supervisory enforcement
Corporate sustainability reporting includes technology governance. AI environmental impact disclosure emerging.
Cl.4 · A.2.3 · Cl.7.4
IEC 61508/61511
Global
In force
Regulatory varies
Functional safety for safety-instrumented systems. Does NOT cover AI governance — complementary to ISO 42001.
Cl.8 · A.8 · A.3
IEC 62443
Global
In force
Industry requirement
Industrial cybersecurity. Covers OT security but not AI-specific threats (adversarial, poisoning, extraction).
A.9 · A.13
UAE Data Protection
UAE
In force
AED 5M (~$1.36M)
Personal data processing requirements for employee/contractor data in AI systems.
A.4 · A.10
KSA PDPL
Saudi Arabia
Full: Sep 2025
SAR 5M
Data localisation. Consent and purpose limitation for AI using worker data.
A.4 · A.9 · A.10
ADNOC HSE Standards
Abu Dhabi
Corporate
Operational compliance
HSE management system requirements — AI governance extension opportunity.
Cl.5 · Cl.8 · A.11
NIST AI RMF 1.0
United States
Voluntary
No direct penalties
GOVERN, MAP, MEASURE, MANAGE. EO 14110 rescinded Jan 20, 2025.
Cl.6 · Cl.9 · A.3 · A.8
DORA
EU/EEA
Live since Jan 2025
€10M / 5%
ICT risk for energy companies' financial operations and third-party AI.
Cl.8 · A.8 · A.9 · A.13
The regulatory multiplier: Every regulation and safety standard in the table above maps to specific ISO 42001 clauses and controls. For energy companies, ISO 42001 bridges the gap between functional safety standards (IEC 61508/61511) and AI governance — while simultaneously addressing regulatory requirements from the EU AI Act, CSRD, and regional data protection laws. A single governance framework addresses all of these overlapping requirements.
08 — METHODOLOGY
How This Benchmark Was Built
Scores were derived by mapping each ISO 42001 clause requirement against known industry practices, regulatory compliance maturity data from ISO Survey certifications, and published AI governance maturity research. Each clause score reflects the estimated degree to which organizations of that size typically demonstrate alignment with the clause's specific requirements, adjusted for industry-specific factors such as HSE maturity, existing compliance infrastructure, and AI deployment patterns across IT and OT environments.
Data Sources
› ISO Survey of Management System Certifications (2019–2024)
› EU AI Act (Regulation 2024/1689) — Annex III §2 critical infrastructure
› IEC 61508/61511 functional safety standards
› IEC 62443 industrial cybersecurity
› DNV Global Energy Transition Outlook 2025
› Deloitte State of AI in the Enterprise 2026 (3,235 leaders)
› NIST AI RMF 1.0 (January 2023)
Important Caveats
› ISO 42001 published December 2023 — no energy company has certified yet
› HSE culture is an advantage — implementation should be faster than other sectors
› IT/OT split affects scores — IT AI may score 60%, OT AI may score 20%
› Certification typically requires 70–75% readiness to engage and 80–85% to certify
› These benchmarks will be updated as the market matures
09 — ABOUT THE AUTHOR
Mike Merdinian
Founder · Digital North Associates
Mike Merdinian works at the intersection of governance and AI, helping organizations scale decision-making at machine speed without losing control.
He is a transformation leader specializing in governance, large-scale change, and AI-driven operating models, with over 20 years of experience across North America, Europe, and the GCC. He has led complex transformation and M&A initiatives across banking, supply chain, retail, and the public sector — working both as a strategic advisor and as an internal transformation leader.
He has advised members of parliament from more than 20 Commonwealth countries on technology and governance strategy, and teaches emerging technologies at leading international universities. He holds an AI Strategy and Leadership certification from MIT and is currently pursuing Applied Agentic AI for Organizational Transformation (MIT, expected May 2026).
He is the founder of Digital North Associates, an AI governance and transformation firm focused on enabling organizations to operate at machine speed while maintaining control through policy-driven governance. The firm transitioned to an AI-first model in March 2026, with a clear principle: keep humans at the core, using AI to amplify expertise rather than replace it.
Under his leadership, DNA is on track to become a fully AI-augmented organization by May 2026, with intelligent systems embedded across sales, marketing, advisory, operations, delivery, and finance.
Mike Merdinian
Founder · March 2026
Digital North Associates
AI Governance & Digital Transformation · Strategic Advisory & Purpose-Built Technology