ASUG News + Views
ASUG Util­i­ty Voice: Why SAP’s Autonomous Enter­prise Vision Is the Right Move for Utilities
Marc Rosson May 27, 2026
Bookmark
Share Article:

The fol­low­ing Util­i­ty Voice was authored by Marc Rosson, Com­mu­ni­ty Con­nec­tor at Utility.Community.

For those of us who have spent careers in reg­u­lat­ed util­i­ty envi­ron­ments, the con­cepts of secu­ri­ty, gov­er­nance, com­pli­ance, and per­for­mance are not aspi­ra­tional; they are pre­req­ui­sites. Those were the table stakes: the assump­tion was always that noth­ing moved to pro­duc­tion until those box­es were checked.

Then came the exu­ber­ance of AI.

Across our indus­try, teams have built impres­sive proofs of con­cept: pre­dic­tive main­te­nance mod­els, DER dis­patch opti­miza­tion tools, out­age ana­lyt­ics dash­boards, and intel­li­gent meter­ing pipelines. The demos were com­pelling. The busi­ness cas­es were sound. And then, one by one, many of these projects stalled. The tech­nol­o­gy worked fine, but when secu­ri­ty, per­for­mance, and gov­er­nance ques­tions were final­ly raised in earnest, the answers weren’t ready.

We had the inno­va­tion: what we’d for­got­ten was the infra­struc­ture that makes inno­va­tion safe.

This is not a fail­ure of ambi­tion. It is a nat­ur­al con­se­quence of mov­ing fast in an indus­try where we are not accus­tomed to mov­ing fast. And this is pre­cise­ly what makes SAP’s announce­ment at Sap­phire 2026 sig­nif­i­cant: it estab­lish­es the foun­da­tion that’s been missing.

What SAP Actu­al­ly Announced

At Sap­phire 2026, SAP unveiled what it calls the Autonomous Enter­prise — a uni­fied plat­form built around three pil­lars: the SAP Busi­ness AI Plat­form (con­text, build, and gov­er­nance lay­ers), the SAP Autonomous Suite (50+ domain-spe­cif­ic Joule Assis­tants orches­trat­ing 200+ spe­cial­ized agents), and a new user expe­ri­ence designed for human-AI collaboration.

For util­i­ties specif­i­cal­ly, SAP and Anthrop­ic announced a part­ner­ship to build cus­tom agents and agen­tic work­flows tar­get­ing the util­i­ties sec­tor, cov­er­ing asset man­age­ment, field oper­a­tions, and the inte­gra­tion of oper­a­tional and trans­ac­tion­al data that has long been our holy grail.

Ahead of Sap­phire, SAP also updat­ed its API Pol­i­cy (v4/​2026), restrict­ing the use of SAP APIs for unsanc­tioned agen­tic AI inte­gra­tions, specif­i­cal­ly those involv­ing autonomous sys­tems that exe­cute sequences of API calls, and large-scale data extrac­tion out­side endorsed archi­tec­tures. This pol­i­cy update has gen­er­at­ed sig­nif­i­cant com­mu­ni­ty debate.

We believe that debate, while valid, is miss­ing the larg­er point.

Why the API Pol­i­cy Is the Right Move — Even If the Com­mu­ni­ca­tion Was Not

Let us be hon­est about some­thing: the AI inte­gra­tions many of us have pro­to­typed involve third-par­ty tools call­ing SAP direct­ly, often via undoc­u­ment­ed inter­faces, often at scale, often with­out for­mal gov­er­nance frame­works. Some of these have been enor­mous­ly valu­able as demon­stra­tions. Very few have been ready for production.

The rea­son they were not ready for pro­duc­tion is exact­ly what SAP’s new pol­i­cy and Autonomous Enter­prise frame­work are designed to address.

Secu­ri­ty

Agen­tic AI sys­tems that can read — and increas­ing­ly write — to pro­duc­tion sys­tems rep­re­sent a cat­e­gor­i­cal­ly dif­fer­ent secu­ri­ty sur­face than tra­di­tion­al inte­gra­tions. A human makes one deci­sion at a time. An AI agent can exe­cute thou­sands of actions in the time it takes a secu­ri­ty team to be noti­fied. SAP’s Agent Gate­way and endorsed archi­tec­ture mod­el cre­ate a con­trolled, auditable chan­nel for agent activ­i­ty. For util­i­ty CISOs who have been reluc­tant to approve any agen­tic AI in pro­duc­tion, this is the secu­ri­ty perime­ter they’ve been wait­ing for.

Gov­er­nance and Compliance

We oper­ate in one of the most reg­u­lat­ed indus­tries in the world. NERC CIP, state PUC require­ments, FERC over­sight, and an evolv­ing land­scape of data pri­va­cy and cyber­se­cu­ri­ty man­dates all touch our sys­tems. SAP’s gov­er­nance lay­er, built on LeanIX, Sig­navio, and Cloud ALM, pro­vides auditable agent teleme­try, ver­i­fied agent enforce­ment, and work­force impact map­ping. These are not nice-to-haves for util­i­ties. They are pre­req­ui­sites for any reg­u­la­tor con­ver­sa­tion about autonomous AI in production.

Per­for­mance

Our pro­duc­tion sys­tems — IS‑U billing, out­age man­age­ment, Plant Main­te­nance, PSCD — were designed for human-paced trans­ac­tion­al work­loads. Agen­tic AI cre­ates a fun­da­men­tal­ly dif­fer­ent load pro­file: high-fre­quen­cy, par­al­lel, poten­tial­ly recur­sive API calls that can desta­bi­lize sys­tems not designed for them. SAP’s con­cern here is legit­i­mate and prac­ti­cal. The endorsed archi­tec­ture mod­el is as much about sys­tem sta­bil­i­ty as it is about com­mer­cial interests.

Audit

When an AI agent acts on pro­duc­tion data — clos­es a work order, adjusts a rate sched­ule, dis­patch­es a field crew — who is account­able? Under cur­rent third-par­ty inte­gra­tion mod­els, the answer is often unclear. SAP’s frame­work, with its agent activ­i­ty logs, pol­i­cy enforce­ment lay­ers, and com­pa­ny mem­o­ry audit trails, cre­ates the account­abil­i­ty chain that reg­u­la­tors will even­tu­al­ly demand and that our inter­nal audit func­tions need today.

The Ven­dor Lock-In Ques­tion Deserves an Hon­est Answer

The con­cern about ven­dor lock-in is real and should not be dis­missed. But it deserves a more com­plete analy­sis than it has received in the com­mu­ni­ty con­ver­sa­tion so far.

Every AI ven­dor is build­ing a pro­pri­etary moat. What mat­ters is whether you’re choos­ing yours deliberately.

Con­sid­er what is hap­pen­ing across the AI land­scape right now. Microsoft Copi­lot cap­tures your employ­ees’ inter­ac­tion pat­terns, doc­u­ment work­flows, and deci­sion log­ic in its mem­o­ry lay­er. Google’s Gem­i­ni Enter­prise builds orga­ni­za­tion­al knowl­edge graphs from your work­space activ­i­ty. Anthropic’s Claude, used at scale, accu­mu­lates com­pa­ny-spe­cif­ic con­text through mem­o­ry sys­tems that are not portable across ven­dors. While open stan­dards like MCP (Mod­el Con­text Pro­to­col) and A2A (Agent-to-Agent) pro­to­cols enable inter­op­er­abil­i­ty at the inte­gra­tion lay­er, the com­pa­ny mem­o­ry is pro­pri­etary to each ven­dor. The cap­tured trib­al knowl­edge, the learned pref­er­ences, the insti­tu­tion­al process con­text that makes an AI gen­uine­ly use­ful: none of that is portable.

That isn’t a crit­i­cism of those com­pa­nies; it’s sim­ply how val­ue gets cre­at­ed in AI sys­tems. The more your peo­ple inter­act with an AI plat­form, the more con­tex­tu­al­ly valu­able it becomes to your orga­ni­za­tion, and the more embed­ded it becomes. SAP is doing exact­ly what every oth­er AI ven­dor is doing. The dif­fer­ence is that SAP is doing it with 50 years of util­i­ty indus­try process knowl­edge already embed­ded in the platform.

The lock-in ship has sailed indus­try-wide. The ques­tion worth ask­ing now is: With which part­ner do we want to build our insti­tu­tion­al AI knowl­edge, and do they have the indus­try depth, gov­er­nance frame­work, and reg­u­la­to­ry aware­ness that our busi­ness requires?”

And for many util­i­ties already deeply invest­ed in SAP, the answer may well be SAP’s Autonomous Enter­prise. Its util­i­ty-spe­cif­ic agent roadmap, Anthrop­ic part­ner­ship tar­get­ing the util­i­ties ver­ti­cal, and gov­er­nance frame­work make it the most defen­si­ble path to pro­duc­tion AI.

The Data Archi­tec­ture Shift We Can­not Ignore

For many util­i­ties, we have spent a decade build­ing robust ana­lyt­i­cal archi­tec­tures: repli­cat­ing SAP data into BW, data marts, and data lakes, then run­ning read-only dash­boards and deci­sion-sup­port tools on top. This mod­el has served us well. It is also insuf­fi­cient for the agen­tic AI era.

Tra­di­tion­al AI rec­om­mends. Agen­tic AI acts. That dis­tinc­tion comes down to write access to pro­duc­tion sys­tems. An AI agent that can update a main­te­nance work order, adjust a demand response sig­nal, or mod­i­fy a billing account is not oper­at­ing on a read-only copy of your data. It is oper­at­ing on your pro­duc­tion sys­tem. That requires an entire­ly dif­fer­ent lev­el of secu­ri­ty, gov­er­nance, and per­for­mance infra­struc­ture than we have his­tor­i­cal­ly built around our ana­lyt­ics layers.

SAP’s Autonomous Enter­prise frame­work, with its Agent Gate­way and endorsed archi­tec­ture mod­el, is the first cred­i­ble indus­try-spe­cif­ic answer to the ques­tion: How do we give AI agents safe, gov­erned, auditable write access to our pro­duc­tion util­i­ty sys­tems?” We should engage with that answer seri­ous­ly, even as we push to improve it.

What We Still Need to Influence

Embrac­ing SAP’s strate­gic direc­tion does not mean accept­ing it with­out ques­tion. As a com­mu­ni­ty, we have both the stand­ing and the respon­si­bil­i­ty to shape how this vision is imple­ment­ed. Here are the areas where our voice mat­ters most:

  • Real-time oper­a­tional data inte­gra­tion: Our DER man­age­ment, grid edge ana­lyt­ics, and demand response pro­grams require sub-sec­ond data from SCA­DA, AMI, and OMS sys­tems that live out­side SAP’s trans­ac­tion perime­ter. We need SAP’s agent frame­work to con­nect clean­ly with real-time oper­a­tional data, not just SAP trans­ac­tion­al data.
  • Pric­ing trans­paren­cy and con­trac­tu­al pro­tec­tions: The DSAG user group has for­mal­ly demand­ed that SAP pro­vide clear con­trac­tu­al def­i­n­i­tions, tran­si­tion time­lines, and pro­tec­tion for exist­ing inte­gra­tions. Our com­mu­ni­ty should align with and ampli­fy these demands, par­tic­u­lar­ly around con­tract renew­al implications.
  • Exist­ing AI invest­ment pro­tec­tion: Many of our mem­bers have built valu­able AI pipelines and data prod­ucts that cur­rent­ly access SAP via inter­faces that may be affect­ed by the new API pol­i­cy. We need grace peri­ods, migra­tion sup­port, and clear endorsed-archi­tec­ture path­ways that pro­tect these investments.
  • Asset man­age­ment with embed­ded ana­lyt­ics: Pre­dic­tive main­te­nance, fail­ure prob­a­bil­i­ty mod­el­ing, and main­te­nance plan opti­miza­tion that con­nects SAP PM data with oper­a­tional sen­sor data is one of our high­est-val­ue use cas­es. We need SAP’s util­i­ty agent roadmap to pri­or­i­tize this.
  • 2027 pric­ing clar­i­ty: The Joule agent run­time is free through Decem­ber 2026. No post-pro­mo­tion pric­ing has been dis­closed. We need com­mit­ments, not pro­mo­tions, before we build pro­duc­tion AI infra­struc­ture on this platform.

A Call to Our Community

Before dis­miss­ing SAP’s API changes and Autonomous Enter­prise vision as unwel­come con­straints, I ask each of you to sit with a hard­er ques­tion: If not SAP’s gov­er­nance frame­work, then what? How are you plan­ning to oper­a­tional­ize agen­tic AI, with true write access to your pro­duc­tion util­i­ty sys­tems, in a way that sat­is­fies your secu­ri­ty team, your com­pli­ance func­tion, your inter­nal audit, and your regulator?

If you have a bet­ter answer, please bring it for­ward. Our com­mu­ni­ty is stronger when good ideas com­pete. But we’ll fig­ure out gov­er­nance lat­er” is not a plan. It is the rea­son our proofs of con­cept have not become pro­duc­tion systems.

AI is here to stay, and so are our reg­u­la­to­ry oblig­a­tions. The goal is not to choose between them — it is to build a frame­work where both can coexist.

SAP has put for­ward a strate­gic vision for doing exact­ly that. It is imper­fect, it rais­es legit­i­mate con­cerns, and it will require sig­nif­i­cant com­mu­ni­ty engage­ment to shape into some­thing that ful­ly serves our needs. But the direc­tion is cor­rect: gov­er­nance, secu­ri­ty, and per­for­mance as the foun­da­tion for pro­duc­tion AI, not as afterthoughts.

Read the details. Ask the hard ques­tions. Engage SAP through ASUG and your direct rela­tion­ships to influ­ence the roadmap, and do it with the recog­ni­tion that for reg­u­lat­ed indus­tries, the hard­est part of the AI jour­ney was always going to be oper­a­tional­iza­tion, not inno­va­tion. That’s the chal­lenge in front of us now, and it’s one worth meet­ing together.

To learn more in-depth about the Autonomous Enter­prise, I encour­age you to check out SAP’s upcom­ing, 11-part webi­nar series. To get involved and keep up with the lat­est, join ASUG’s Util­i­ties Com­mu­ni­ty.

You Might Be Interested In


Insights Included in Membership
View All Insights
Bookmark
Bookmark
Bookmark
Bookmark