This is Icebreaker One’s response to Ofgem’s Call for Input on AI Assurance in the Energy Sector. It can be published openly.
Please note that throughout this consultation, Icebreaker One (IB1) uses the terms Open, Shared and Closed data as defined here.
If you have any questions about our submission or require clarifications please do not hesitate to contact us via policy@ib1.org. We have omitted questions which we did not answer.
Thank you for considering our submission.
Call for input response:
As stated in IB1’s response to Ofgem’s AI in the Energy Sector Guidance Consultation, AI presents immense opportunities for delivering customer benefits, driving economic growth, accelerating the transition to net zero, and enhancing financial and regulatory frameworks. However, AI must be deployed responsibly – ensuring trust, transparency, and interoperability across sectors.
The questions in this consultation lean towards gathering information on what individual organisations are doing to assure themselves about their own use of AI. This is a necessary first step, but covers only a part of today’s interconnected energy sector services. To have real impact, assurance must be extended to cover AI-mediated data that is shared and used across organisations, sectors and use cases. It is in that context of data sharing governance that IB1 is responding to the consultation.
IB1 highlights two key points about data assurance:
- Assurance is evaluated in the context of the entity using the data, not the entity providing it. What is adequate for one usage situation may not be enough for another. Consequently, data sharing assurance can only be established by convening data users and publishers and developing their assurance needs and options around clearly defined use cases
- Assurance is a journey, not a destination. As available data, data users and use cases proliferate, so do their assurance needs. A sector approach to assurance must establish an agile process for determining assurance needs, and encoding and enforcing them so that machines (AI or otherwise) can rely on them at scale.
These requirements for data sharing assurance existed before recent AI advances. AI hasn’t changed them, but the opacity of inference and the non-deterministic nature of outputs that are features of Generative Pretrained Transformer (GPT) models bring new challenges compared to deterministic and probabilistic approaches. A distinction between “Narrow AI” (AI designed for a specific task such as weather forecasting) and “General AI” (AI with human-like performance at different task types) may prove useful in assurance. Despite the rapid uptake of both types of AI, governance is still nascent within organisations, and even more so between them. These factors amplify the need and shorten the timelines for determining what “fit for purpose” means.
Over the past six years, IB1 has developed and openly published co-design processes (Icebreaking) and Trust Framework-based approaches to enable rapid decision-making and implementation of governance of data sharing. These apply equally when AI is in the mix. Trusted use of AI demands well-understood, open governance with agile co-design by market participants delivered at ecosystem scale. The importance of these factors multiply as AI capacity and independence grows, with oversight often taking time to catch up.
IB1 recommends that, at the end of this information-gathering phase of its AI work, Ofgem ensures that the proposed Digitalisation Coordination Function is tasked with convening data stakeholders and working at pace to uncover, elucidate and specify assurance standards within a governance framework.
Question 1: Current AI assurance practices
- How do organisations evidence that AI systems are operating as intended and delivering safe, fair and effective outcomes?
No response
- What AI assurance approaches are currently used or under development, including in-house and third-party?
No response
- What tools and technical capabilities are available to support AI assurance in practice, how mature and effective are they, and where are there gaps or opportunities for shared or sector-wide approaches?
A range of tools are available to support AI assurance, including model testing, performance monitoring, explainability techniques, audit logging and cybersecurity controls. While these approaches are becoming increasingly mature for assuring AI within individual organisations, there is much less maturity in assessing AI operating across organisational boundaries and shared data ecosystems. A lack of trusted data flows into AI systems could lead to poor, potentially unaccountable, decisions made or informed by machines and human-machine systems.
Effective AI assurance depends on trusted data flows. Capabilities such as provenance and lineage metadata, verifiable signatures, machine-readable licenses and organisational identity provide confidence in where data originated, how it has been processed and who is accountable.
However, the characterisation and verification of AI models and their applications within data-sharing remains immature. More work is needed to identify and develop use cases that surface assurance requirements. Developing assurance around real-world use cases will help establish reusable assurance ontologies, with lessons drawn from more mature sectors such as autonomous vehicles or medical diagnostics.
- How are AI governance frameworks translated into operational practice?
No response
- Which assurance or governance practices are most effective in supporting reliable outcomes?
The most effective assurance and governance practices are those that provide clear, proportionate evidence that data and AI systems are fit for their intended purpose. Assurance should be assessed in the context of how AI-mediated data will be used, recognising that while assurance signals originate from the data publisher, the decision to trust and use that data ultimately sits with the data user.
IB1’s work on data assurance is a good starting point to adapt for AI-mediated data. Organisational and dataset assurance can be extended to provide consistent, machine-readable signals relating to provenance, quality, governance, licensing and accountability. As AI becomes more prevalent, these assurance signals become increasingly important for establishing credibility, compliance, quality and usability across organisational boundaries.
AI governance in the energy sector must also be codified to require a demonstrable contribution to net zero targets and consumer outcomes. This should be supported by appropriate explainability standards that are needed for AI-driven decisions, such as pricing and grid management, alongside regulatory monitoring to prevent AI-driven market monopolisation.
- What skills, expertise and resources are required for effective AI assurance, and where are the main capability gaps?
Effective AI assurance requires a combination of technical expertise, governance, and stakeholder engagement. While AI introduces new technical considerations, many of the core capabilities are the same as those required for trusted data sharing.
Core capabilities include:
- Stakeholder engagement to understand ecosystem needs and develop proportionate, useful assurance to meet those needs
- Appropriate model and process selection
- Risk characterisation and management
- Data annotation (metadata) using appropriate standards
- Quality control and verification
AI’s potential to unlock data-driven innovation must be balanced with privacy, security, and ethical considerations. Therefore, IB1 advocates for AI models that:
- Respect consumer consent and data sovereignty, using decentralised identity frameworks
- Support open standards to ensure interoperability between AI-driven systems
- Embed transparency and explainability to mitigate AI biases and prevent regulatory fragmentation
Organisations using AI must possess relevant expertise that encompasses the above bullet points to ensure their solutions provide, secure, fair and sustainable AI.
Question 2: Risks and challenges
- What are the main barriers to implementing effective AI assurance?
The fundamental barriers to effective assurance of AI-mediated data are structural and cultural. Organisations tend to work in siloes, which limits the sharing of both data and assurance practice. There is no accepted standard for AI explainability or verification, making it hard to establish a common baseline for what “good” assurance looks like. This is compounded by the pace of change in the underlying technology – rapidly evolving models and increasingly agentic processes make static assurance frameworks quickly outdated.
Stemming from this, the data which AI requires is also fragmented, held in inconsistent formats across organisations, and subject to different consent regimes to access. System-wide data that would support assurance work, such as LV feeder loads, flexibility capacity, and network constraints, often exists but remains inaccessible or non-interoperable between organisations.
Privacy-preserving technology and synthetic data are effective methods to enable innovation without creating data protection issues. While good work is being done to provide this for smart meters, such as via the Faraday project, there is a need for similar efforts on other datasets, such as flexibility assets and behind-the-meter energy use.
Finally, there is a lack of structured methods to evaluate and communicate assurance for data processing, including using AI, across organisational boundaries, so even where individual organisations assure their own systems, that assurance doesn’t travel or compound across the sector. This is worsened by a general lack of consideration by data publishers about appropriate AI use by the downstream applications of data users. For instance, no mechanism exists to signal which models are appropriate for which specific applications, leaving adopters to make that judgement without guidance.
- What are the key risks associated with AI use in the energy system (including system reliability, market functioning and consumer outcomes)?
The key risks associated with AI in the energy system extend beyond performance of individual AI models to the governance of the data ecosystems on which they depend. Focusing solely on AI assurance for organisations’ use of their own AI systems risks overlooking compounding risks for data sharing scenarios across organisations, use cases and sectors.
Without clear, actionable assurance signals describing the provenance, quality, licensing and appropriate use of AI-mediated data, downstream users may be unable to assess whether the data is fit for purpose. Similarly, without the use of open and shared access frameworks, AI capabilities will consolidate in the hands of large incumbents who already hold proprietary datasets, creating market concentration risks that undermine innovation, consumer, and environmental benefits.
We anticipate that cost, usage and IP conditions will hamper otherwise technically possible uses of the data. We recommend early surfacing of this information to mitigate five risks:
1. Regulatory and compliance complexity: Data licensing must align with compliance rules around grid data, market data, and critical infrastructure. It is important to ensure data inputs to AI systems, and the outputs of the AI, remain compliant.
2. Third-party data dependencies AI models in energy often rely on weather feeds, satellite imagery, market pricing, and sensor data from multiple vendors. Each source carries its own licensing terms around permitted use, commercial exploitation, and AI training rights. Identifying these dependencies early prevents data supply chain disruptions during development, or worse, after deployment.
3. Intellectual property and model ownership: Who owns the AI model trained on licensed data? Many data providers now include clauses that restrict or claim rights over derivative works, including trained models.
4. Onward data publishing and monetisation: Energy sector companies typically want to share or sell AI-derived insights. Licensing terms set upstream can block valuable downstream opportunities.
5. Long-term data access and continuity risk: Many foreseeable AI systems in the energy sector (e.g. predictive maintenance, load forecasting) need consistent, long-term data access. Identifying long-term data rights is critical to operational resilience.
- Which risks are most difficult to assess, evidence, or link to real-world outcomes?
Risk assessment must be based on concrete use cases. These allow the counter-assessment of the risks of not using AI or not sharing the data created. The hardest risks to assess are those where there is insufficient information for a data user to make an informed judgement.
- Where are current AI assurance approaches most limited in practice?
Data assurance, whether the data was generated by AI or otherwise, is unevenly applied in the UK energy sector. There is a lack of attention to the data foundations and their transparency and accountability. A coherent, well-governed trust framework with standards for assurance signals is required, along with processes to develop and monitor them.
As discussed in 1c, the characterisation and verification of AI models and their applications within data-sharing remains immature. More work is needed to identify and develop use cases that surface assurance requirements. Developing assurance around real-world use cases will help establish reusable assurance ontologies that can be implemented within trust frameworks.
Question 3: Critical infrastructure considerations
- How should AI assurance reflect the criticality of energy systems as national infrastructure?
No response
- What level of rigour is appropriate for high-impact or safety-critical AI use cases?
An appropriate level of rigour can only be determined on a use case by use case basis.
Question 4: Consumer protection and fairness
- How can AI assurance support fair treatment of consumers, including vulnerable groups?
AI assurance can support fair treatment of consumers by ensuring that AI-enabled decisions are transparent, accountable and designed around the needs of those affected, including vulnerable groups. This requires more than assessing technical performance; it requires governance arrangements that consider social impacts, consumer rights and the ability for individuals to understand and challenge decisions that affect them.
IB1 advocates that data governance should establish clear principles, structures, roles and responsibilities, agreed by market participants, to enable accurate and timely data sharing at market-wide scale. These principles extend to AI assurance, ensuring that approaches are developed with cross-sector collaboration and learning rather than imposed through a purely top-down process.
- What risks arise from AI-driven pricing, segmentation or prioritisation, e.g. fairness, transparency, consumer outcomes?
We strongly advocate for the adoption of a broader concept of social sustainability in defining fairness. This must conceptualise people in a manner beyond their economic roles and should also be capable of viewing people in terms of groups. This approach is vital to assessing a more holistic range of AI impacts beyond the individualised economic sphere.
As stated by Which? “consumers [must] have the right to challenge decisions that are made about them by computers alone. This right is particularly important because it forces transparency and accountability in systems, making sure companies can be held to account if things go wrong”. Transparency and accountability are precisely what assurance seeks to bring.
Question 5: Cyber security and resilience
- How should AI assurance align with existing cyber and operational security frameworks, e.g. NIS Regulations?
Assurance must align entirely.
- How can AI assurance support system resilience, including identifying and mitigating cyber, operational and AI-specific risks?
IB1’s 2025 Positioning Paper on AI set out five dimensions of resilience for consideration with AI, going beyond the purely technical. The benefits of assurance to each are below:
- Economic Resilience
- Assurance enhances the likelihood that AI-driven data-sharing infrastructure (e.g. smart data initiatives) is interoperable and equitable, preventing market concentration and boosting innovation and SME growth
- Sustainability and Environmental Resilience
- Assurance can increase confidence in the use of AI to optimise energy efficiency, emissions tracking, and climate risk modelling, helping industries and governments meet net zero goals.
- Assurance can be used to evidence that AI contributes to the UK’s net zero targets, enabling the requirement to be open to monitoring and audit
- Regulatory and Governance Resilience
- Consistent, well-understood assurance signals enable AI-driven compliance automation, reducing administrative burden and maintaining public trust in AI-enabled services
- Digital and Cyber Resilience
- Open and interoperable digital identity frameworks alongside clear governance and accountability enable data users to be assured about the provenance of the information being relied upon to make operational decisions
- Robust data governance policies, evidenced as part of assurance, ensure AI systems remain secure, transparent, and resistant to manipulation
- Social and Community Resilience
- Well-understood, structured assurance enables confident deployment of data-driven AI interventions to novel scenarios, including emergency responses and disaster preparedness
- AI assurance can demonstrate that inferences and decisions are free from bias and discrimination, ensuring fair access to economic opportunities, financial services, and public resources.
Question 6: Proportionality
- What does proportionate AI assurance look like across different use cases and risk levels?
The use cases drive both the assurance and the proportionality. Potential aspects of the assurance include:
- The identity of the assuring party
- Information about the training data
- Information about the contextual data used for a specific inference
- Model choice and use
- Explainability
- Verification
- Data protection
- Liability and redress
- Prompts for appropriate use
- Reports from other users
- Monitoring reports and incident logging
- Reproducibility
- Reliability of data availability and comparability in the long term
- How can assurance approaches be tailored while remaining effective and practical, including for smaller organisations?
Clarity on the data use case, by both data producer and data user, greatly assists in identifying appropriate, proportionate assurance. Over time, informed by modelling and in-use analysis, individual use cases may well cluster into categories, further simplifying decision-making. Case studies, automated compliance, and effective, transparent monitoring and verification all lead to building greater confidence amongst stakeholders.
Question 7: External assurance and standards
- Are existing frameworks and standards sufficient, or is sector-specific AI assurance guidance needed?
Existing standards are not sufficient, especially in data sharing ecosystems involving LLMs and agents. Governance concepts, structures and implementations are nascent, both within organisations and and between them.
Ideally, the UK would have cross-sector guidance and standards for AI assurance to enable assured data flows throughout the economy. Ofgem would then build on this where further refinement is needed, for example regarding critical national infrastructure and energy supply considerations.
In the absence of UK-wide guidance, approaches taken by Ofgem should be designed to be replicable elsewhere by adopting existing standards where available, and openly publishing governance processes, data standards, and ontologies.
- What role should independent assurance (e.g. audits, certification) play?
The role of independent assurance is use case specific. It is likely to be required for scenarios involving personal/customer data and where decision-making affects customers.
Audits may be applied to both parties sharing data: the AI-mediated data provider to ensure their assurance signals are correct, and the data user to ensure they are not using AI-mediated data for unintended purposes.
- What are the benefits and risks of external assurance approaches?
No response
Question 8: Future guidance
- What would be most useful in future AI assurance guidance for the energy sector?
Future AI assurance guidance for the energy sector should focus on supporting practical decision-making rather than prescribing a single approach. Guidance should help organisations identify their AI use cases, understand the level of assurance required for the intended purpose and apply proportionate governance measures based on risk and impact.
A key priority should be the development and adoption of open standards for representing assurance information, enabling organisations to communicate. Similar to the role of standards like Dublin Core in describing metadata, common assurance standards would support interoperability, transparency, and more efficient trust decisions across AI-enabled data ecosystems.
Guidance should also support cross-sector collaboration, engagement and knowledge sharing through forums where organisations can exchange approaches. IB1’s own experience with collaborative governance models and Trust Frameworks demonstrates the value of bringing participants together to establish shared principles, standards and assurance approaches.
- What types of evidence are most useful in demonstrating outcomes in practice?
Useful evidence should demonstrate that assurance requirements are being met and that they lead to reliable outcomes in practice. This could include:
- Membership of data sharing Schemes
- Volume and continuity of data transactions
- New products and services enabled by AI-intermediated data
- Evidence of exceptions, “Red Flags,” when assured data hasn’t proven to be as reliable as asserted
- Audit reports
- What examples or case studies would be valuable?
Assured Open Data
With input from Open Energy members, IB1 developed the Assured Open Data (AOD) scheme in the Energy Sector Trust Framework in order to provide a standard externally credible mechanism for organisations to demonstrate their implementation of Data Best Practice Guidance (DBPG).
In the scheme, progressive assurance levels operate at both organisational and dataset level. Organisational assurance verifies identity, governance, and accountability. Dataset assurance covers metadata quality, format, provenance, licensing, accessibility, and update cadence. Four cumulative levels run from minimum DBPG-aligned entry expectations through to comprehensive, machine-readable cross-market reuse. Assurance is signalled through metadata that maps to human-readable badges.
SSEN-D was the first organisation to adopt AOD and has assured many datasets on its portal (e.g. SSEN Substation Data). AOD is in the process of implementation by other UK regulated energy sector companies.
Perseus Assurability Framework
Perseus is a UK-led Smart Data Scheme for SMEs to embed sustainable finance with trusted, automated carbon emissions reporting. In it, SMEs give permission for their energy consumption data to be processed securely by carbon accounting platforms in order to provide emissions data to financial service providers to evidence carbon reductions.
In order for financial service providers to reach reasonable assurance in the data they receive under the scheme, an assurability framework was developed, implemented by signed provenance records provided at each data exchange. These capture the identity of the sending and receiving parties within the trust framework, specify the data’s origins, codify the processing that has taken place, and make clear the permission and licence that covered the processing and transfer. Provenance records are chained as data is shared onwards, providing a verifiable record of assurance claims by processing parties.
While the assurance information carried is use case specific, the building blocks of provenance records – identity, origin, licence, permission, processing, transfer, receipt – are broadly applicable. This enables assurance requirements, once defined, to be deployed within trust frameworks very rapidly.
Question 9: Communication
- How should organisations communicate AI assurance to different audiences?
By working in collaboration with the users of AI-mediated data to identify use cases and the assurance they require, organisations can design and communicate assurance in terms that are meaningful to those users. Open publication of the purpose and rationale for the assurance signals provided allows for a rapid adopt-and-adapt approach for new scenarios.
To support this, well-defined frameworks and guidance should be established, facilitating open standards, clear ontologies and machine readable formats for interoperability among people and systems.
- What information is most useful for consumers, boards, senior management and affected groups?
The type and usefulness of information is use case specific, and should be developed alongside the assurance needs for each use case.