techUK's final response to Ofgem's Call for Input on AI assurance in the energy sector: what we contributed
Ofgem asked how AI in the energy system should be assured. techUK coordinated a member response, and we contributed. The final submission went in on 12 August 2026, and it is now public. Here is the final version, and the parts we put in that are reflected in the text.
Ofgem's Call for Input: AI assurance in the energy sector (ofgem.gov.uk)
What Ofgem asked, and what techUK did
Ofgem's Call for Input on AI assurance in the energy sector asks a practical question: as AI moves from proof of concept into live grid operations, forecasting, optimisation and control, how do we know it is operating safely, fairly and effectively? techUK drafted a collective member response and ran two comment rounds. The final submission was made on 12 August 2026, the closing date of the consultation.
We responded to the first draft. Two sections had no answer text at all: Question 3 on critical infrastructure and the right level of rigour, and Question 7 on external assurance and standards. Both are squarely our subject, so we offered to help fill them and added three comments on the text as it stood.
What we contributed, and where it sits in the final text
The final submission takes our points forward in substance. The parts we care about most:
- Questions 3 and 7 are answered, and the answers are ours in substance. The critical-infrastructure section scales rigour by the operational authority, consequence and reversibility of the action the AI can influence or execute, and requires bounded authority, independent validation of the execution context immediately before action, governance controls that can allow, constrain, pause, deny or escalate, proportionate human override, tested degraded-mode and safe-state behaviour, and reassessment after material change. The external-assurance section explains the value of independent evaluation and warns against false confidence from certification and one-off audits.
- The ISO/IEC 42001 distinction is explicit. The final text states plainly that ISO 42001 certifies the organisation, not the product, and that certification "assures governance, not deployment risk". That single distinction does a lot of work, because a certificate alone tells a regulator nothing about the system that actually runs.
- Independent assurance is treated as different from self-attestation. An independent verdict against a common sector standard is "more portable and trustworthy than organisations self-certifying against frameworks they've each interpreted differently".
- A system of record for inference. The final text requires that every AI-supported decision generates an immutable, queryable record of the data, model state and reasoning behind it, not just the final output, so a significant operational event can be reconstructed after the fact.
Our two recommendations, now in the final text
We put two recommendations to techUK during the consultation, and both are reflected in the final submission.
1. Make the evidence requirement concrete. The final text says evidence is most useful to a later reader when it records what was and was not established, and the conditions under which it should be re-checked, and that this applies to model cards, test reports, third-party audit statements and bought-in product assurance alike. It calls for standardised metrics, common reporting templates and audit trails mapped to recognised frameworks, and, for higher-impact uses, evidence that preserves the relationship between the AI recommendation, the live execution context, the governance controls applied, any human intervention and the resulting operational outcome.
2. Say what a credible assurance record must contain. The final text requires that sign-off of an AI system captures the scope of what was assessed, the period for which the assessment is expected to hold, and the material changes that would prompt reassessment, so assumptions do not have to be reconstructed after an incident. It also states that "a favourable result does not by itself demonstrate that the underlying process was safe", and that assurance should evaluate the governed process behind a decision, not only the outcome it happened to produce.
Why this matters
Energy is a high-consequence setting. An AI recommendation that is sound when generated can be wrong by the time it is executed, because operating conditions, network state, demand or cyber posture have moved. Assurance that only checks the model once, at launch, misses the part that actually fails. That is true in energy, and it is true in the diagnostic and predictive clinical AI we test every day: a model that performs well in the lab can quietly degrade at a new site, on an under-served subgroup, or as the data shifts.
The lesson travels across sectors. Assurance has to be continuous, versioned and independently checkable, not a certificate filed at deployment.
A note on independence
The final submission is a collective techUK member response, and the trade association does not name individual contributing members in it. We are comfortable with that: the value for us is that our positions on critical infrastructure rigour, independent assurance and concrete evidence requirements are now on the record with a regulator, in the final text of a submission we can point to. UK AI Evaluation is an independent AI assurance company, a techUK member, and we engaged with this Call for Input in that capacity. We are aligned with the direction of Ofgem, the UK AI Security Institute and the clinical safety frameworks we work to, but we are not affiliated with, certified by, or endorsed by any regulator or government body. Our interest is straightforward: better, checkable assurance standards benefit everyone who builds, buys or regulates AI in high-consequence settings.
Building or regulating high-consequence AI?
We test, evaluate and red-team diagnostic and predictive AI for transferability, calibration, subgroup performance and drift, then map the evidence to the standards buyers and regulators trust.