AAIGF-E: An AI and Agentic Intelligence Governance Framework for Electric-Sector Smart-City Infrastructure
AI is being deployed in smart-grid and smart-city energy infrastructure faster than governance frameworks can validate it. Existing instruments—NERC CIP, NIST AI RMF 1.0, and ISA/IEC 62443—address cybersecurity compliance and AI trustworthiness principles but do not provide operational control architecture for AI systems influencing grid stability, distributed energy resource (DER) dispatch, or real-time reliability decisions. Compliance with these instruments is not equivalent to operational assurance: their requirements do not by themselves establish validated input integrity controls, adversarial robustness testing, or bounded autonomy architecture for every AI-enabled operational use case. This paper presents the AI and Agentic Intelligence Governance Framework, Electric Sector (AAIGF-E): 111 controls across seven lifecycle phases (Govern, Design, Implement, Assure, Monitor, Respond, Recover), mapped to existing electric-sector compliance obligations. A defining structural feature of AAIGF-E is its dual-narrative control architecture, in which each control carries both an AI governance rationale and a parallel electric-sector operational translation, enabling the framework to serve AI governance stakeholders and operational technology (OT) engineering teams within the same control set without requiring cross-discipline translation. Scenario-driven validation tests the framework against three operationally relevant failure modes: adversarial manipulation of DER dispatch AI, unauthorized autonomous action execution by an agentic AI system in an OT environment, and silent model drift in grid stability forecasting. Validation confirms structural coverage across prevention, detection, and response phases and identifies residual implementation and assurance gaps while identifying a residual prompt-injection pathway in which technically valid operational content may manipulate agent task scope or apparent authority before downstream actuation controls activate. The 111-control register is further characterized through quantitative analysis of standards coverage, lifecycle and governance-domain distribution, cross-framework convergence, and sector-specific translation. A separate independent coding reproducibility check samples 35 controls across five reference frameworks, producing 175 binary mapping decisions; 155 decisions agree with the internal coding key (88.6% raw agreement; Cohen’s κ=0.742). To reduce reliance on author-led validation, a representative operational scenario is also evaluated by independent AI governance, cybersecurity, and ICS/OT experts who derive their judgments before reviewing the AAIGF-E reference assessment. Their domain selections and governance recommendations show strong overall convergence with the framework assessment. AAIGF-E is designed for electric utilities and smart-city operators within North American regulatory frameworks who need governance architecture that connects AI lifecycle risk management to existing compliance cycles rather than replacing them.
Authors
- Dinara Kozhamzharova (ORCID: https://orcid.org/0000-0002-4320-9774)
- Seunghwan Myeong (ORCID: https://orcid.org/0000-0002-6730-2770)
- Suhail Ahmad Rana (ORCID: https://orcid.org/0009-0008-5460-5001)
Institutions
- Inha University (KR)
- Satbayev University (KZ)
- University of Jeddah (SA)
- University of Business and Technology (SA)
Publication Details
- Journal
- Smart Cities
- Published
- 2026-09-24
- DOI
- https://doi.org/10.3390/smartcities9100161
- Primary Topic
- Smart Grid Security and Resilience
- Type
- article
- Field-Weighted Citation Impact
- 0.00