Steve Dawson is the founder and CEO at POWERCONNECT.AI.
It doesn’t matter whether I’m meeting with a utility CEO, speaking at a conference or sitting in a customer workshop. The conversation almost always turns to one topic: AI. At first, everyone wanted to know what AI could do. Could it summarize customer calls? Could it search thousands of documents? Could it help agents answer questions faster? Those were the conversations a year ago.
Today the conversation is different. The first question I usually hear isn’t about features anymore. It’s, “How do we make sure this doesn’t become our next cybersecurity problem?”
I think that’s exactly the question organizations should be asking. A few months ago, I was demonstrating one of our AI applications for a utility. We had connected it to their customer information system, knowledge base and internal documents. The AI answered questions almost instantly. It found procedures employees normally spent several minutes searching for. The room was quiet for a second. Then one of the managers asked, “What happens if someone tricks the AI into giving the wrong answer?”
Honestly, I was glad he asked. Too many conversations about AI focus on how smart the technology has become. Not enough focus on how it should be controlled. Building AI for utilities has changed the way I think about cybersecurity. Traditional cybersecurity is still incredibly important. Firewalls, endpoint protection, identity management, backups and employee training aren’t going away.
But AI introduces a completely different challenge. Instead of protecting only people and computers, we’re now protecting systems that interpret information, make recommendations and sometimes perform actions on behalf of employees. That’s a different security model.
AI Shouldn’t Have Unlimited Access
It’s also why I don’t think an AI assistant should ever be treated like another employee. One mistake I see organizations making is assuming AI should inherit all of the permissions of the person using it. I disagree with that approach. If we build an AI assistant whose only job is helping customer service representatives answer billing questions, why should it have access to engineering drawings, HR files, payroll records or financial systems?
It shouldn’t. Every AI application should have its own identity, its own credentials and access only to the information required to perform a specific task. That isn’t just good security. It’s common sense.
AI Isn’t The Source Of Truth
Another lesson we’ve learned while integrating AI with utility systems is that AI should never become the source of truth. Our customers rely on Oracle, SAP, Harris, Jomar and other enterprise systems to manage critical operational data. AI can retrieve that information, explain it, summarize it and even point employees in the right direction, but those enterprise applications remain the authority.
Whenever someone asks me if AI will replace those systems, my answer is simple: No. AI makes those systems easier to use. It doesn’t replace them.
Attackers Are Using AI Too
One thing that has surprised me over the last year is how quickly attackers have adopted AI themselves. According to the FBI’s 2024 Internet Crime Report, reported cybercrime losses reached $16.6 billion, the highest amount ever recorded. At the same time, CISA and the NSA have warned that criminals are increasingly using AI to improve phishing emails, impersonation attempts, and social engineering attacks.
We’ve seen our own share of suspicious activity. My company has received fake inquiries, suspicious emails and attempts to manipulate our AI systems. None of those attempts were successful, but they reinforced something I’ve been telling customers for months: If you’re investing in AI, you also need to invest in protecting it.
Trust Comes From Responsible AI
One recommendation I give almost every utility is to test their AI the same way they test everything else. Try to confuse it. Feed it bad information. Ask it questions it shouldn’t answer. See how it behaves when someone intentionally tries to misuse it. You’ll learn far more from those exercises than from watching a perfect product demonstration.
I’ve also become a big believer in keeping humans involved when decisions actually matter. AI can recommend, summarize and identify patterns. But when it comes to financial decisions, customer account changes, regulatory compliance or critical infrastructure, someone should still be accountable.
Technology should support good judgement, not replace it. I honestly believe AI is going to transform the utility industry. I’m already watching it happen. Customer service teams are resolving issues faster. Employees are spending less time searching for information. Customers are getting better experiences.
Those are real improvements. But after spending the last couple of years building these systems, I’ve come to one conclusion: The companies that succeed with AI won’t be the ones that deploy it first. They’ll be the ones their customers trust the most. In my experience, trust has never come from having the newest technology. It comes from building technology responsibly.
That’s true for utilities. And I think it’s going to be even more important as AI becomes part of the critical infrastructure we all depend on.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


