Guest Column | September 30, 2026

AI Is Already Entering The Water Sector. Here Is How We Use It Without Losing Control

By Gigi Karmous-Edwards, Andy Bochman, Kevin Morley, Barry Liner, Lisa McFadden, and Ashwin Dhanasekar

clean, safe water with AI-GettyImages-1314144773

Moving beyond both GenAI hype and Agentic AI fear toward more informed and responsible adoption

There is a strange conversation happening around artificial intelligence in the water sector. On one side, GenAI is sometimes presented as if it is going to transform virtually everything we do: operations, engineering, customer service, asset management, planning, cybersecurity, and workforce productivity. On the other side, we hear increasingly serious warnings about cybersecurity, hallucinations, sensitive data, prompt injection, autonomous GenAI agents, and the possibility of connecting probabilistic GenAI, as well as agentic AI processing systems to critical infrastructure. Both conversations contain some truth. But neither extreme is particularly helpful to a utility trying to answer a much more practical question:

What should we actually be doing with GenAI today?

That is the question behind our forthcoming paper titled: “The Water Sector Guide to Safe, Secure, and Responsible Use of Artificial Intelligence.” We did not write it to convince utilities to adopt AI. And we certainly did not write it to scare them away from it. We wrote it because GenAI adoption, as well as agentic AI processes are already happening. Employees are using GenAI to summarize documents, draft reports, research regulations, analyze information, create training materials, assist with customer communications, and automate pieces of everyday work. The paper begins with that reality: GenAI is entering water organizations whether leadership has formally created an AI useprogram or not.

So perhaps the question is no longer, “Should we use AI?” The better questions are: Where does GenAI and agentic AI make sense? What data can we safely give it? What should it never be allowed to do? Who remains accountable? And how do the answers change as we move from a chatbot that gives us information to an AI agent that can actually take action? Those are very different questions. They require the water sector to find a middle ground between fear and blind optimism. We hope that the paper will help inform organizations and individuals towards a deep understanding of what the technology actually can and cannot do, and how to use it safely.

First, Not All AI Is the Same

An easy way to remember the difference is: traditional AI often predicts or classifies, GenAI creates, and Agentic AI can act. Artificial intelligence is not new to the water sector. Utilities have used forms of traditional AI, including machine learning (ML) and deep learning (DL), for years to recognize patterns, make predictions, detect anomalies, and optimize specific tasks. Think about your email identifying spam, your phone recognizing a face in a photograph, or a utility model predicting pipe failure. These systems are generally built and trained to perform a defined task, some call that narrow AI. They are very different from the newer GenAI tools that have captured so much attention.

GenAI creates new content. It can summarize a 50-page report, draft a customer letter, explain a regulation, write computer code, or develop training materials. Many of today's GenAI tools are powered by large language models, or LLMs, which have been trained on very large amounts of text to learn patterns and relationships in language. Rather than simply retrieving a predetermined answer, an LLM generates a response based on those learned patterns and the context it is given. That is why GenAI output is probabilistic: the answer can vary and, importantly, can sound convincing while still being wrong. The guide makes this distinction because probabilistic GenAI requires different expectations for verification and human review.

We also have Agentic AI, and this is where the conversation changes again. GenAI agents typically use LLMs as their reasoning and language engine, but instead of simply generating an answer, they can be given tools, access, permissions, and a goal. They might search files, retrieve information, call another application, run code, send a message, or complete a sequence of steps on a user's behalf.

Ten Rules People Can Actually Remember

We wanted part of the guide to be useful not just to a CISO, CIO, utility director, or engineer, but to any employee who opens a GenAI application tomorrow morning. So we distilled much of the guidance into ten simple rules.

The detailed version appears in the guide, but the ideas are deliberately straightforward: know your data, use approved tools, protect restricted information, remember that GenAI drafts while humans decide, keep humans in control of operations, verify important answers, apply stronger oversight to AI agents, report problems, understand where your information goes, and keep learning. The point is not to make every employee a GenAI security expert.

The point is to give every employee enough understanding to recognize when an ordinary GenAI interaction has become a security or operational decision.

We Are Already Seeing Real Utility Applications

This discussion is not theoretical. Across the sector, utilities of very different sizes are beginning to explore practical applications of AI. We know this because utilities are already experimenting. Through WRF Project 5321, “GenAI for the Global Water Sector”, utilities of very different sizes tested real applications of GenAI. The project's final report was published in September 2026. Hampton Roads Sanitation District explored and agent utilizing computer vision for safety and asset monitoring. Houston Water explored AI-supported capital planning and a locally deployed WaterGPT. Smaller systems participated too, including pilots around rate planning and digitization of handwritten data. Another, called “What Would Jerry Do?” captures expert knowledge about chlorine residual management so that small-system operators can query that knowledge conversationally. Importantly, this is decision support for trained operators, not autonomous control of chlorine dosing. These experiences matter because they move the conversation from “What could AI someday do?” to three much better questions:

  1. What problem are we solving?
  2. What information does the AI need?
  3. What guardrails belong around this use?

But Water Is Not Just Another Industry

The water sector has a complication that cannot be ignored. We operate physical infrastructure responsible for public health. A hallucinated sentence in an internal memo is inconvenient. A hallucinated recommendation that influences chemical dosing, pump operation, or another treatment decision can have consequences for public health and safety. That is why one principle runs throughout our guide: AI can advise. Qualified humans decide.

Water utilities operate IT systems alongside operational technology including SCADA, PLCs, sensors, pumps, valves, chemical feed systems, and treatment processes. As these environments become more connected, an AI security problem can potentially become a cyber-physical problem. GenAI can be extremely useful for analysis, knowledge retrieval, anomaly identification, drafting, scenario exploration, and decision support. But consequential decisions affecting operations, compliance, safety, or public health require qualified human review.

Agentic AI Changes the Equation: More Autonomy Requires More Control

For many employees, GenAI still means typing a question into a chatbot and receiving an answer. Instead of simply answering a question, an AI agent can be given a goal and potentially access files, interact with applications, run code, communicate with external services, and carry out a sequence of actions.  A simple analogy we use in the guide is this:  GenAI is like an assistant sitting across the desk from you. Agentic AI can be more like giving that assistant a badge, credentials, and access to the building. The security question therefore changes dramatically. It is no longer simply, can I trust this answer, but rather it becomes:

  • What can this agent access?
  • What credentials does it have?
  • What actions can it take?
  • What happens if it misunderstands its goal?
  • What happens if someone manipulates the information it reads?
  • And can a human stop it?

The forthcoming guide digs into issues such as prompt injection, indirect prompt injection, data and tool poisoning, identity and privilege, third-party tools, agent memory, logging, monitoring, least privilege, human approval, and kill mechanisms.

Your First Line of AI Defense Is an Informed Workforce

We can purchase sophisticated cybersecurity technology and still create risk if employees do not understand what happens when they upload a spreadsheet, paste information into a chatbot, connect a GenAI tool to email, or authorize an agent to access a file repository.

Every interaction with GenAI can involve a data decision. That means GenAI literacy is becoming part of cybersecurity literacy. Utilities need policies that clearly distinguish public, internal, confidential, and restricted information. Employees need to know which GenAI tools have been approved. They need to understand where information may go, whether it is retained, and what a GenAI provider is permitted to do with it. It is important to create a safe environment for employees to ask questions and report mistakes rather than hiding them. An organization cannot govern GenAI effectively if employees are quietly using tools because the official policy is simply don't use AI.

That is why training, culture, governance, and leadership occupy as much attention in our guide as the technology itself. The paper argues that GenAI readiness is fundamentally an organizational challenge: people need to know what to do, policies need to tell them how to do it safely, technology needs to support those policies, and leadership needs to make the system work.

What Should Utilities Do Monday Morning?

A utility does not need a 100-page GenAI strategy before anyone can safely use GenAI. But it does need some basics.

Perhaps the most important point is this: start with the problem, not the technology. A utility does not need a GenAI project. It needs a problem worth solving. Maybe operators spend hours searching SOPs. Maybe engineers repeatedly search hundreds of pages of standards. Maybe customer-service representatives answer the same questions thousands of times. Maybe experienced employees are retiring and taking decades of institutional knowledge with them. Once the employees have identified a set of problems, then ask whether GenAI is an appropriate part of the solution.

The second basic is knowing where your organization actually stands today. The guide also includes a five-level AI maturity model, from ad hoc experimentation to mature, adaptive AI governance. Many utilities may recognize themselves in Levels 1 or 2 today, and that is not unusual this early in the journey. Before deploying agents with meaningful access to organizational systems or data, our guide recommends establishing at least Level 3 foundations: approved tools, data classification, governance, cybersecurity controls, and standard human review.

Cybersecurity Is Not Being Replaced

One of the reassuring lessons from our research is that utilities do not need to throw away everything they already know about cybersecurity, rather they need to expand on it. Identity management still matters. Least privilege still matters. Network segmentation still matters. Vendor management still matters. Logging, monitoring, incident response, data governance, employee training, and executive accountability still matter. GenAI and Agentic AI adds new questions and new attack paths, but many of the foundations remain familiar.

We did not invent these security concerns. Our guide draws from the most current multinational guidance on the subject: in April 2026, the NSA, CISA, and Five Eyes partner agencies jointly published “Careful Adoption of Agentic AI Services”, the cybersecurity focused specifically on Agentic AI.  The forthcoming guide translates that guidance, alongside frameworks from NIST, CISA, EPA, FBI, ISO, WaterISAC, and AWWA, into language and action steps appropriate for water utilities.  The full guide explores these risks in detail, including prompt injection, data and tool manipulation, identity and permissions, third-party access, agent memory, monitoring, human approval, and how to stop an agent when something goes wrong. The manuscript itself is intentionally written for everyone from operators and plant managers to executives, engineers, cybersecurity professionals, administrative staff, consultants, and technology providers. That translation matters because guidance that nobody outside the security team understands does not protect a utility very well.

The Goal Is Informed Adoption

There is a temptation whenever a powerful new technology appears to divide ourselves into camps. Optimists talk about possibilities. Security professionals talk about risks. We believe that utilities need both conversations happening at the same table. The real choice is not between innovation and security. It is between uninformed adoption and informed adoption.

We believe the water sector should experiment. We should run pilots, learn from utilities of every size, train our workforce, and explore how GenAI can preserve institutional knowledge, improve customer service, accelerate engineering work, strengthen planning, and reduce administrative burden.

But we should do it knowing what data we are giving the technology, where that information goes, what the system is allowed to do, how its answers will be verified, and which decisions must remain firmly in human hands.

That is the philosophy behind our forthcoming publication, The Water Sector Guide to Safe, Secure, and Responsible Use of Artificial Intelligence.

This is not blind optimism about GenAI, and it is not fear of Agentic AI. It is informed adoption.

AI does not replace cybersecurity. It extends it. And it does not eliminate the need for human expertise. It makes informed human judgment more important than ever.