industries · Energy & utilities

NIS2 in OT environments, working with no route to the internet

AI for critical infrastructure that can live inside your OT network: open models on-premise, with operational data never leaving the perimeter.

compliance

Compliance, built into the stack.

Every regulatory demand mapped to a platform capability that ships built in, with nothing to configure.

NIS2

Directive (EU) 2022/2555 · national transposition under way in Spain

RequiresEnergy is a highly critical sector: cybersecurity risk management, resilience and supply-chain control, the AI provider included.

HelmcodeOn-premise or edge deployment with an auditable stack: the AI provider stops being an external dependency.

OT segregation

IT/OT separation for operational technology

RequiresOperational data in OT environments cannot leave the operations network.

HelmcodeThe same models run on-premise, and Gemma 4 fits on a single GPU at the edge, inside your OT perimeter.

Sovereignty

EU infrastructure over critical assets

RequiresCritical infrastructure should not depend on foreign-controlled inference.

HelmcodeOpen weights on European infrastructure or fully on-premise, with no external dependency.

This page is an informational overview, not legal advice. For your obligations and the risk classification of each system, consult qualified legal counsel. AI Act Guide →

how the sector measures scope

What the electricity network code adds to NIS2.

Electricity has its own cybersecurity rulebook on top of NIS2: a network code for the cybersecurity aspects of cross-border flows, adopted in March 2024. It decides who is in scope by measured power, and it has something to say about your ICT providers.

01

Scope is measured in megawatts

ENTSO-E and the EU DSO entity published the provisional impact index: in Spain, 1,000 MW for high impact and 3,000 MW for critical impact, and the same thresholds apply to entities and to processes. Both bodies state the figures are a recommendation to the competent authorities and are not legally binding.

02

The perimeter is yours to draw

Before any of it applies you have to determine your high- and critical-impact perimeters, through a business impact assessment of each business process supporting the ones on the Union-wide list. That is analysis work inside your own operation, and no supplier can hand it to you.

03

A provider can be declared critical

The code carries the notion of a critical ICT service provider, reported as such to the competent authority. Whoever runs inference over your operational data is a candidate, which is a reason to prefer a dependency you can describe, audit and, if it comes to it, replace.

Commission Delegated Regulation (EU) 2024/1366 · Network Code on Cybersecurity Network code on sector-specific rules for cybersecurity aspects of cross-border electricity flows, 11 March 2024, with the critical ICT service provider in Articles 24 and 27 as corrected by the Council corrigendum. The thresholds and the perimeter steps come from the "Provisional Electricity Cybersecurity Impact Index" published by ENTSO-E and the EU DSO entity under Article 48(2), which is explicit that it is a non-binding recommendation to the competent authorities. read the report →

use cases

Your most common use cases.

The cases with the most traction in the sector, each with its own page in detail.

Recommended open models.

A starting point per task type. The full guide maps 80 cases to the open model for each one.

DeepSeek V4 FlashMIT · 1M ctx in Helmcode
Volume workhorse for documentation, extraction and support.
Gemma 4 12BGemma · 128K ctx · 1 GPU
Fits on one GPU at the edge, the realistic option inside an OT environment.
GLM-5.2MIT · 1M ctx
Reasoning for incident and root-cause analysis over the full record.

in progressWe are distilling and quantizing these open models into small, tightly specialised versions, trained for one task rather than for all of them. A model like that runs on less hardware, answers faster and fits where the big one does not, your own datacenter included. If you have a process with volume and stable criteria, that is the conversation we want to have with you.

// faq

Questions, answered.

What the sector's technical, compliance and business teams ask.

What does NIS2 mean for a utility?

NIS2 (Directive (EU) 2022/2555) classes energy as a highly critical sector, with cybersecurity risk management, resilience and supply-chain obligations; its Spanish transposition is still under way. Running inference on-premise or at the edge, on an auditable stack, removes the AI provider as an external dependency; the concrete national obligations firm up as the transposing law is enacted.

Can it run inside an OT network?

Yes. The on-premise deployment runs the same models and API inside your perimeter, and Gemma 4 fits on a single GPU at the edge, so operational data never leaves the operations network.

What is the entry use case?

A copilot over plant and technical documentation: high value, low risk, and deployable at the edge on modest hardware.

Can we analyse incidents over the full record?

Yes. GLM-5.2 offers strong reasoning with 1M of context for root-cause analysis over long operational histories, and can run on-premise for confidential logs.

How does it integrate with our current stack?

The API is OpenAI-compatible: change the base URL and key and existing tools keep working unchanged.

// get started

START BURNING TOKENS

Skip the AI infra work. Deploy your first private inference endpoint today.

Flat rate. EU data. OpenAI API compatible.