Energy & UtilitiesAI-Driven Disruptions & Innovations
AI-driven lights-out power plants: what unattended generation really takes in energy and utilities
A lights-out power plant is a generating site whose normal operating cycle — start, load, respond, shut down — runs with nobody on site, inside a written unattended-operations basis. AI supplies detection and diagnosis. Whether anyone can actually leave is decided by instrumentation, remote actuation, isolation and fire cover.

Key takeaways
- Lights-out is an attendance property, not an intelligence property. A site becomes unattended when its remaining manual tasks have been instrumented, actuated or designed out — and when a written unattended-operations basis says under what conditions nobody needs to be there. The model is the last and cheapest component.
- Unattended generation is already routine in one half of the fleet and structurally blocked in the other. Wind, utility solar, batteries and much hydro run without permanent crews today. High-hazard thermal plant, fuel handling and licensed nuclear do not, and the constraint is fire cover, isolation and staffing conditions rather than software.
- Time-to-human is the governing design parameter. Every automatic response has to hold the plant in a safe state for at least as long as it takes a competent person to arrive — so drive time, road closures and on-call rosters set the autonomy envelope more tightly than any confidence threshold.
- Remote monitoring is attendance-neutral. A read-only link to a remote centre buys earlier diagnosis and zero reduction in crewing, because every remote diagnosis still terminates in a callout. The step that changes the roster is remote actuation and isolation, which is a controls, protection and cyber project.
- The credible near-term prize is the night, not the plant. Removing a permanently staffed night shift from sites that do three real interventions a month is achievable, measurable and reversible; removing the day crew from a combined-cycle plant is not, and pretending otherwise is how these programmes lose their sponsor.
Abbreviations used on this page
- DCS
- Distributed control system — the plant's own control and interlock logic
- SCADA
- Supervisory control and data acquisition
- ROC
- Remote operations centre (also renewable or fleet control centre)
- BOP
- Balance of plant — everything outside the main generating unit
- CCGT
- Combined-cycle gas turbine
- OCGT
- Open-cycle gas turbine, typically a peaking plant
- BESS
- Battery energy storage system
- AGC
- Automatic generation control — the system operator's set-point signal
- LOTO
- Lock-out / tag-out: physical isolation of hazardous energy for maintenance
- PTW
- Permit to work — the authorisation controlling work on plant
- EFOR
- Equivalent forced outage rate, the standard generation reliability metric
- NERC CIP
- North American Electric Reliability Corporation Critical Infrastructure Protection standards
Free · 8 questions · ~3 minutes
Score one site on the attendance ladder
Eight questions about one generating site, one at a time, about three minutes. Answer them and we build your personalised readiness report — the site's rung on the attendance ladder, its score on each of the four dimensions, and the specific constraint standing between it and the next rung — and send it to your inbox. Score the site you would most like to stop staffing at night.
0 of 8 answered
Pick an option to continue
Report ready
Your personalised readiness report is ready
Tell us where to send it. The site's rung appears on screen straight away, and the full report — dimension scores, the constraint that caps this site, comparable sites of the same asset class, and a 90-day plan for the weakest dimension — arrives in your inbox.
Your result
Your full report is on its way to your inbox.
Stage 1 · Continuously attended
A crew is on site around the clock because the plant cannot be sensed, actuated or diagnosed from anywhere else.
Your next moveWrite the night task inventory: every task the night shift performs across a month, each mapped to the instrument, actuator or design change that would remove it.
Stage 2 · Remotely monitored
Plant data reaches a remote centre and gets analysed there, but every action still requires someone on site.
Your next moveDefine the smallest set of remotely writable actions worth having — safe-state, runback, changeover, start inhibit — and build the segmented, logged cyber path that makes them defensible.
Stage 3 · Remotely operated
The plant can be started, loaded, run back and isolated from a remote operations centre; site staff work days and cover nights on call.
Your next moveAttack the callout list: instrument, automate or design out the five most common reasons somebody drives to site at night, and re-measure before touching the roster.
Stage 4 · Routinely unattended
The site runs with nobody present for defined periods under a written unattended-operations basis, with people arriving for planned work and exceptions.
Your next movePut the basis under change control: every plant modification, roster change and market-rule change re-tests the conditions and the pre-approved response catalogue.
Stage 5 · Lights-out within an envelope
The normal operating cycle runs with nobody on site inside a stated envelope, and everything outside that envelope escalates to a person.
Your next moveVersion the envelope like code and give it review triggers — every plant modification, roster change, market-rule change and seasonal transition.
0 / 24
Sensing and field dependence
— / 6
Remote control and isolation
— / 6
Detection and response autonomy
— / 6
Unattended basis and time-to-human
— / 6
Your score maps to a rung on the attendance ladder. The dimension breakdown matters more than the total: the lowest dimension is the one that actually caps the site, and on most sites it is not the one the programme is currently funding. Your lowest-scoring dimension is —, and that is where the next investment belongs.
Your score maps to a rung on the attendance ladder. The dimension breakdown matters more than the total: the lowest dimension is the one that actually caps the site, and on most sites it is not the one the programme is currently funding.Your four dimensions score evenly, so there is no single weak link to attack — follow the stage’s next move above rather than picking a dimension.
Want this checked against the plant rather than the questionnaire?
We walk the site with your operations and control engineers, count the local-only indications and the hand-operated devices on the night round, pull the callout log, and leave you with a costed removal list ordered by what it actually buys in attendance. No obligation, and you keep the list either way.
How the score maps to a stage
- 0–5 — Stage 1, Continuously attended. A crew is on site around the clock because the plant cannot be sensed, actuated or diagnosed from anywhere else.
- 6–11 — Stage 2, Remotely monitored. Plant data reaches a remote centre and gets analysed there, but every action still requires someone on site.
- 12–16 — Stage 3, Remotely operated. The plant can be started, loaded, run back and isolated from a remote operations centre; site staff work days and cover nights on call.
- 17–21 — Stage 4, Routinely unattended. The site runs with nobody present for defined periods under a written unattended-operations basis, with people arriving for planned work and exceptions.
- 22–24 — Stage 5, Lights-out within an envelope. The normal operating cycle runs with nobody on site inside a stated envelope, and everything outside that envelope escalates to a person.
What a lights-out power plant is — and what it is not
A definition, the three things that actually decide attendance, and the same 03:00 alarm followed through three different plants.
A lights-out power plant is a generating site whose normal operating cycle — start, load, respond to dispatch, shut down — runs with nobody on site, under a written unattended-operations basis that states the conditions, the automatic responses and the maximum time before a competent person arrives. The phrase describes an attendance model, not a technology. A site is lights-out when the work that used to require a body has been instrumented, actuated, designed out or scheduled into attended windows.
It is not a plant that thinks. Nothing in a credible unattended arrangement lets a model improvise on plant: the responses that move equipment are deterministic control logic, interlocked and tested, and the AI layer sits upstream of them doing detection, diagnosis, triage and evidence assembly. It is also not a plant that nobody ever visits — unattended means no permanent crew, not no humans. Maintenance, isolation, statutory inspections and consumables all still bring people to site on a schedule.
Three things decide whether a given site can go unattended, and none of them is model quality. First, sensing: can the plant be seen without a person walking it. Second, actuation and isolation: can it be moved to a safe state and held there from somewhere else. Third, the basis: is there a defensible written case, agreed with the people who carry the consequences — safety, insurer, fire service, system operator — for running without anyone present. The rest of this page is about those three, in that order.
One high-vibration alarm at 03:00, three endings
The same event on three sites at different rungs of the attendance ladder. What differs is not the alarm and not the model — it is what the plant can be made to do without a person, and what evidence exists afterwards. Most sites are in the top lane.
- Data & feeds
- Where value leaks
- Human in the loop
- AI / model
- System-of-record action
The process, in words
- On a continuously attended site, the vibration probe reports to a local panel, the alarm arrives inside a flood of others, and an operator walks the unit and forms a judgement. The judgement is often right and leaves almost no record — the site's knowledge of the event is one person's recollection at the end of a night shift.
- On a remotely operated site, the same signal is historised alongside temperatures and load, a diagnostic model ranks probable causes with supporting evidence, and the remote operator runs the unit back and holds it. The event is diagnosed sooner and recorded properly, and it still ends in a callout, because the corrective work needs hands and drive time bounds everything.
- On a routinely unattended site, the response was decided in advance: a pre-approved, interlocked DCS action runs the unit back or trips it, the plant holds a defined safe state, and the escalation carries an evidence pack — signals, model output, actions taken and the time remaining before someone must arrive.
Step-by-step insights
- The local-only signal is the whole argument for a night shift
- Instrumentation is where unattended operation is won or lost, and it is unglamorous. A vibration probe with a local panel and no historian connection means the plant's condition is observable only by a person standing in front of it, which means someone stands in front of it every night for the remaining life of the asset. The removal cost is a transmitter, a marshalling change and a point in the historian — trivial next to a permanent roster line. Programmes routinely spend more on analytics for the instrumented 40% of a plant than it would cost to instrument the other 60%.
- Alarm floods make autonomy undecidable, not just unpleasant
- Unattended operation depends on an alarm meaning something. Where a single event produces forty alarms in ninety seconds, no operator and no model can be given a defensible response, because the signal that should trigger the response is indistinguishable from consequence alarms. Long-standing alarm-management practice treats a steady-state rate above roughly one alarm every ten minutes per operator as unmanageable, and rationalising to something near that is a prerequisite for any pre-approved response catalogue rather than an optional tidy-up.
- The model's job is evidence, not action
- In the middle lane the model earns its place by turning a raw alarm into a ranked hypothesis with supporting signals: which bearing, what trend, what changed in the last four hours, which comparable events look similar. That is decision support with a clean audit story. The moment the model is allowed to move plant directly, the safety argument, the insurance conversation and the incident investigation all become materially harder — which is why mature unattended sites keep the acting layer deterministic and put the intelligence upstream of it.
- Remote runback is the action that changes the roster
- The single most valuable remotely writable capability is not remote start; it is the ability to take the unit somewhere safe and hold it. A remote runback converts an event that requires immediate presence into an event that requires eventual presence, and 'eventual' is what allows a night shift to become an on-call arrangement. Scope the safe-state path before the convenience functions: it is the one that carries the attendance benefit and the one the protection engineer will scrutinise hardest.
- Drive time is a design parameter, not a logistics detail
- In the middle lane the callout is the ending, and its duration bounds everything upstream. If a competent person is ninety minutes away in good weather and three hours away in February, then every automatic response has to hold the plant safely for three hours, or the site cannot be left in that condition at all. Operators who write time-to-human into the design brief end up with a much shorter and more honest list of unattended candidate sites than those who treat travel as an operational afterthought.
- The evidence pack is what makes the third lane repeatable
- An escalation from an unattended site should arrive as a package: the triggering signals, the model's assessment, the response that executed, the plant's current state, the time remaining in that state and the conditions that would end it. This is not documentation overhead — it is what lets the arriving engineer act immediately, what lets the insurer price the arrangement, and what lets the next review decide whether the envelope was correct. Sites that escalate with a phone call and a screenshot cannot sustain unattended operation past their first serious event.
The five rungs of the attendance ladder
For each rung: what it looks like on the ground, the diagnostic signals a reviewer can check in an afternoon, the anti-pattern that traps sites there, and what leaving costs.
The ladder measures one thing: how much of the plant's work still requires a human body on site. It deliberately does not measure how autonomous the control logic is, because a plant can run a fully automatic start sequence and still need three people for the balance of plant — and because the reverse is common too, with heavily crewed sites whose crews spend the night reading dials that could have been transmitters.
Each rung below is written for a practitioner. The hallmarks describe observable conditions on a real site, the diagnostic signals are checks you can run against your own plant and logs this week, and the anti-pattern is the specific mistake most often made trying to leave that rung. Score sites individually — a fleet has a distribution, not a level.
Select a rung
Every rung's full detail is in the page source — the selector only changes which panel is visible, so nothing here depends on JavaScript to exist.
Stage 1
Continuously attended
24% of operators sit here
A crew is on site around the clock because the plant cannot be sensed, actuated or diagnosed from anywhere else.
Stage 1 sites are almost never attended because of a hazard assessment. They are attended because of a design vintage: the plant was commissioned when a person walking a route with a clipboard was the cheapest instrument available, and nothing since has changed the assumption. Ask why the night shift exists and the honest answer is usually that it always has.
The tell is the local indicator. Count the gauges, sight glasses, local panels and hand-operated valves that a night operator physically looks at or touches during a normal shift, and you have measured the site's distance from unattended operation in units that can be costed. A dial with no transmitter behind it is a person on site, permanently, for the life of the plant.
This is an expensive stage to sit in and a cheap one to leave, because the first move costs almost nothing. Nobody can price the removal of work that has never been enumerated, so the enumeration is the project. Operators who skip it end up buying analytics for data that does not leave the turbine hall.
In practice
The night list nobody has written down
A 60 MW run-of-river hydro station runs two operators every night. Asked what the night shift does, the plant manager describes rounds, log readings and 'being there if something happens'. A month of shift logs shows 190 completed rounds, four local resets, one trash-rack clearance and no interventions that could not have waited until 07:00. Nothing about that month argues for a night crew; nothing about the plant's instrumentation allows one to be removed.
What it looks like
- Key readings exist only on local gauges and local panels
- Starting, synchronising or isolating the unit requires hands on plant
- The night shift's work has never been written down as a task list
- Remote access, where it exists, is an engineer's laptop and a VPN
Diagnostic signals you can check this week
- Ask for the night task list. If it does not exist as a document, you are here
- Walk the round with an operator and count readings that exist only locally
- Count hand-operated valves and local switches in the normal start sequence
- Ask who physically resets the lube-oil or seal-water pump after a trip, and how long that takes
Anti-pattern · Buying the AI before the transmitters
The instinctive first move is a condition-monitoring pilot, because it is procurable and demonstrable. It fails quietly at stage 1 for a mundane reason: the signals the model needs — bearing temperatures, differential pressures, tank levels, vibration on the balance of plant — are on local gauges, sampled by a human once a shift, or not measured at all. Instrument the twenty points the night round actually depends on first; the analytics are then a weekend, not a programme.
What holds you here
The work the crew actually does has never been enumerated, so nobody can price removing it or prove it is safe to.
Highest-leverage next move
Write the night task inventory: every task the night shift performs across a month, each mapped to the instrument, actuator or design change that would remove it.
Cost of leaving
- Effort
- 2–4 months
- Team
- One control engineer, the shift supervisor, part-time
- Risk
- Low — the work is documentation and survey; nothing in the plant changes yet
- To next stage
- 3–6 months
If this is you, the next step is
A two-week exercise: one site, one month of logs, a costed removal list per task.
Stage 2
Remotely monitored
38% of operators sit here
Plant data reaches a remote centre and gets analysed there, but every action still requires someone on site.
Stage 2 is where most of the fleet sits, and it is genuinely valuable — early detection of a failing bearing or a fouling heat exchanger is worth real money in avoided forced outages. It is also, on its own, completely attendance-neutral. Monitoring is read-only by construction, so every remote diagnosis terminates in the same sentence: somebody has to go.
The read-only decision is usually a cyber decision, taken deliberately and for good reasons, and it is the actual ceiling on the stage. That matters because it means the path out of stage 2 is not a data-science path. It runs through control engineering, protection philosophy and a defensible remote-access architecture — zones and conduits in the sense of the IEC 62443 series, with logging, supervision and a tested break-glass route.
Time spent here is not neutral either. Every year at stage 2 accumulates monitoring coverage that flatters the programme in slides and never appears in the roster or in the operations budget. When the sponsor eventually asks what the monitoring centre changed about how the fleet is run, the honest answer is 'the timing of callouts', and that is a much smaller answer than the one that funded it.
In practice
The diagnosis that still needed a van
A fleet monitoring centre identifies a rising boiler feed-pump bearing temperature at a peaking site and correctly calls a developing failure eleven days out. The corrective action is a changeover to the standby pump — which requires a local valve lineup and a local start, because neither the suction valves nor the pump control are remotely writable. An operator drives seventy minutes. The catch was excellent; the attendance model did not move by an hour.
What it looks like
- A historian streams plant data to a monitoring and diagnostics centre
- Condition models flag developing faults days or weeks ahead
- The OT link is deliberately read-only, and everyone treats that as settled
- Site crewing is unchanged since the monitoring centre opened
Diagnostic signals you can check this week
- Ask whether the remote link can write anything at all, and to how many points
- Compare telemetry coverage with actuation coverage — the second number is usually near zero
- Count callouts per month whose cause was already known remotely before the call
- Ask whether the ROC can put the unit in a defined safe state without anyone on site
Anti-pattern · Confusing monitoring coverage with autonomy
Programmes report telemetry coverage — points connected, sites onboarded, models deployed — and read it as progress towards autonomy. It is not the same axis. A site can be at 100% telemetry coverage and 0% remote actuation coverage, and the second number is the one attendance responds to. Report both from the first month, side by side, and the roadmap corrects itself.
What holds you here
The remote link is read-only, so remote diagnosis always terminates in a callout and the roster never changes.
Highest-leverage next move
Define the smallest set of remotely writable actions worth having — safe-state, runback, changeover, start inhibit — and build the segmented, logged cyber path that makes them defensible.
Cost of leaving
- Effort
- 6–12 months
- Team
- Controls engineer, OT security lead, protection engineer, ops owner
- Risk
- Medium — the first remote write into a plant needs a protection review and a rollback
- To next stage
- 9–18 months
If this is you, the next step is
Which actions, which interlocks, which cyber path — one site, four weeks.
Stage 3
Remotely operated
24% of operators sit here
The plant can be started, loaded, run back and isolated from a remote operations centre; site staff work days and cover nights on call.
Stage 3 is where the economics start to work, because span of control changes. One room can hold a large number of sites, and the cost of watching the hundredth site is close to the cost of watching the tenth. This is the stage most large renewable and hydro fleets already occupy, and it is the stage where the first real staffing decisions get made.
The constraint moves, though, rather than disappearing. Once the plant is remotely operable, what still brings a person to site is maintenance, consumables, isolation for work, local resets and physical faults — the callout list. Operators consistently discover that the control system was the easy half and that the on-call roster, drive time and overtime bill are the half that decides whether the business case holds.
The other change at stage 3 is legal rather than technical. Someone has to be the competent person for the plant at 03:00, and the arrangements for lone working, callout and emergency response have to be real rather than assumed — the same territory the HSE's lone-working guidance covers for any remote site. Stage 3 programmes that skip that conversation get stopped by it later, usually after an incident that was survivable and badly handled.
In practice
The peaker that starts itself but cannot be left alone
An OCGT site takes its dispatch instruction remotely, purges, starts, synchronises and loads without anyone present — a sequence the DCS has run reliably for years. It still carries a resident technician because the fuel-gas filter change, the weekly fire-pump test, the lube-oil top-up and the monthly black-start proving all need hands. The unit is autonomous; the site is not. Attendance is set by the balance of plant, not the turbine.
What it looks like
- The ROC can start, synchronise, load and stop the unit
- There is a defined remote safe state and a tested route to it
- Site staff are on day shift with an on-call rota at night
- A named competent person is accountable for the plant at all hours
Diagnostic signals you can check this week
- Ask the ROC to demonstrate a start and a synchronisation with nobody on site
- Ask for the callout log for the last quarter, sorted by cause and by hour
- Check who is named as the competent person overnight, and whether they are reachable and trained
- Ask what the plant does automatically if telemetry to the ROC is lost for thirty minutes
Anti-pattern · Cutting the roster before counting the callouts
Remote operation reads like a headcount saving, so the roster is cut on the strength of the control-system capability alone. The callouts then arrive at overtime rates, the on-call burden lands on a smaller group, and within two quarters the site is informally re-crewed by exhausted people. Count and cost the callout list first; remove its top five causes; then change the roster. The order is the whole difference between a saving and a churn problem.
What holds you here
The plant is remotely operable but not remotely maintainable, so the callout rate — not the control system — sets the crewing.
Highest-leverage next move
Attack the callout list: instrument, automate or design out the five most common reasons somebody drives to site at night, and re-measure before touching the roster.
Cost of leaving
- Effort
- 12–24 months
- Team
- Control system project, protection engineer, ROC operations model, HR and union consultation
- Risk
- Medium to high — protection philosophy changes and industrial relations both sit on the critical path
- To next stage
- 12–24 months
If this is you, the next step is
Which actions leave the site, which stay, and what the interlocks have to prove.
Stage 4
Routinely unattended
11% of operators sit here
The site runs with nobody present for defined periods under a written unattended-operations basis, with people arriving for planned work and exceptions.
The artefact that defines stage 4 is not software. It is a document: the unattended-operations basis, which states under what conditions the site may run with nobody on it, what ends that condition, what the plant does automatically in each named event, how long it can hold that state, and who arrives when it cannot. Everything else at this stage exists to satisfy a line in that document.
AI's role becomes precise here, and smaller than the marketing suggests. Models do detection, diagnosis and triage: is this a real event, what is the probable cause, which of the pre-approved responses applies, what evidence goes with the escalation. The response that actually moves plant is DCS logic — deterministic, interlocked, testable and, crucially, explainable to a regulator, an insurer and an investigation. Keeping that boundary sharp is what lets the basis be written at all.
The parties who have to agree are the ones most programmes meet late. Fire and life-safety arrangements for a generating station — the territory NFPA 850 covers as recommended practice — assume a response, and the response changes when nobody is on site. Insurers price the change. The local fire service should walk the site. Where a generating licence, connection agreement or grid code obligation implies availability of competent staff, that obligation has to be read carefully rather than hoped over.
In practice
Four nights a week, and the fourteen conditions that end them
A hydro station runs unattended from 22:00 to 06:00 on Sunday through Wednesday. Its basis lists fourteen conditions that end unattended operation and return the site to attended status: fire-detection fault, loss of the primary telemetry path for more than fifteen minutes, forecast lightning within a set radius, river level above a stated threshold, any protection operation, any fire-pump unavailability, and so on. Nine of the fourteen are weather or river conditions. None of them is about the model.
What it looks like
- A written unattended-operations basis states the conditions and their owner
- Time-to-human is measured, contracted and seasonally tested
- A versioned catalogue of pre-approved automatic responses exists
- Fire, security and insurance arrangements were rewritten for the unattended case
Diagnostic signals you can check this week
- Ask to see the unattended-operations basis, its owner, its version and its review date
- Ask when time-to-human was last measured rather than estimated — and in which season
- Check whether the local fire service has attended the site and agreed the arrangements
- Check whether the last three plant modifications were tested against the response catalogue
Anti-pattern · Treating the basis as a document rather than a control
The basis gets written once, signed, and filed. Then the plant changes: a pump is replaced with a different starting characteristic, a detection head is isolated for building work, an on-call engineer moves house forty minutes further away. Each change is individually reasonable and none triggers a review, so the site drifts out of the conditions under which unattended operation was justified. Put the basis under management of change and make it a required check on every plant modification and roster change.
What holds you here
The written basis and the physical plant diverge, so the justification for unattended operation quietly expires without anyone noticing.
Highest-leverage next move
Put the basis under change control: every plant modification, roster change and market-rule change re-tests the conditions and the pre-approved response catalogue.
Cost of leaving
- Effort
- 12–24 months
- Team
- Operations, safety case owner, control engineering, insurer and fire-service liaison
- Risk
- Concentrated — low frequency, high consequence, and evidence-driven
- To next stage
- 18+ months
If this is you, the next step is
We run the basis against real events and your last twelve plant modifications.
Stage 5
Lights-out within an envelope
3% of operators sit here
The normal operating cycle runs with nobody on site inside a stated envelope, and everything outside that envelope escalates to a person.
Stage 5 is narrower than the phrase 'lights-out' implies, and the narrowness is the point. It is not an autonomous power station in the science-fiction sense; it is a specific asset class, running a specific cycle, inside a stated envelope, with everything outside the envelope escalating. Utility solar, wind, batteries and small hydro qualify routinely. Fuel handling, high-pressure steam plant and licensed nuclear do not, and saying so plainly is what makes the rest of the claim credible.
Some of this frontier was never a human job to begin with. A grid-scale battery providing fast frequency response acts in tens of milliseconds and a grid-forming unit responds to a system disturbance faster than an operator can register that one has occurred. There is no version of that service with a person in the loop, which is a useful reminder that autonomy in generation is often set by physics and market products rather than by how clever the software has become.
Sustaining the stage is a governance discipline, and it is the stage most likely to regress. Envelopes are written for a plant configuration, a roster, a road network, a market design and a season, and all five move. The operators who hold stage 5 treat the envelope as a live artefact with an owner, a version history and a review trigger, and they watch the escalation rate the way a stage-3 operator watches the callout list.
In practice
The envelope, written on one page
A battery site's envelope states the market products it may respond to autonomously, the state-of-charge and temperature bounds within which it does so, the actions it takes on any excursion, the maximum period it may hold that state, and the four events that summon a person. The bidding policy behind it is reviewed weekly by humans who never touch the plant. The site has no permanent staff and no ambiguity about who is accountable.
What it looks like
- Start, dispatch, response and shutdown all execute without anyone present
- The envelope fits on one page and is versioned like code
- Escalation rate and time-to-human are monitored as leading indicators
- Any automated action can be reconstructed from logs months later
Diagnostic signals you can check this week
- Ask for the envelope on one page. If it takes a workshop to reconstruct, it is not being governed
- Check the escalation-rate trend over four quarters, not the last month
- Ask when time-to-human was last tested in winter, with a road closure assumed
- Pick one automated action from six months ago and try to reconstruct it end to end from logs
Anti-pattern · Generalising the envelope across asset classes
An envelope proven on a solar and battery portfolio gets extended to a hydro station or a peaker on the argument that the control platform is the same. The control platform is the same; the hazard inventory, the fire load, the isolation requirements and the failure modes are not. Envelopes are earned per asset class from that class's own operating evidence, and inheriting one is the fastest route to the incident that ends the whole programme.
What holds you here
Holding lights-out is a change-control and evidence problem: plant, roster, roads, market rules and weather all move underneath a fixed envelope.
Highest-leverage next move
Version the envelope like code and give it review triggers — every plant modification, roster change, market-rule change and seasonal transition.
Cost of leaving
- Effort
- Continuous
- Team
- Standing governance forum, control engineering, ops assurance
- Risk
- Concentrated and regulatory — rare events with public consequences
If this is you, the next step is
We test the envelope, the evidence trail and the escalation path against a real scenario.
Where generating sites actually sit today
The distribution across the ladder, why it is bimodal by asset class, and why the second rung is where most of the fleet has settled.
Most generating sites are remotely monitored and locally operated — rung two. The distribution below is bimodal by design rather than by accident: newer wind, solar and storage sites were built with no control room at all and start life at rung three or four, while thermal plant and older hydro carry crewing models inherited from commissioning. Fleet-level averages therefore mislead badly, and the useful unit of analysis is the site.
Distribution of generating sites across the attendance ladder
Illustrative distribution across a mixed generating fleet, synthesised from published operator control-centre disclosures and IEA digitalisation research — not a survey. The shape is the argument: the mode sits at remote monitoring, which is the rung that changes diagnosis and does not change crewing.
Share of generating sites
- 24% — 1 · Continuously attended
- 38% — 2 · Remotely monitored (the attendance-neutral plateau)
- 24% — 3 · Remotely operated
- 11% — 4 · Routinely unattended
- 3% — 5 · Lights-out in envelope
The fleet is also moving under the question. The large majority of new generating capacity added worldwide each year is now wind, solar and battery storage — see IRENA's Renewable Capacity Statistics (opens in a new tab) — and those asset classes are built with remote operation as the default rather than as a retrofit. That means the fleet-wide attendance picture improves partly through new build rather than through any operator changing anything, and it makes the retrofit question sharper: the sites you already own are the ones where the work is.
There is a demand-side pressure too. Reliability bodies are documenting tighter margins and steeper ramps as the resource mix changes — NERC's Long-Term Reliability Assessment (opens in a new tab) runs this analysis annually across the United States and Canada over a ten-year horizon, and the IEA's electricity analysis (opens in a new tab) tracks the same trends globally. Plants that used to run baseload now start and stop far more often, and start reliability at 04:00 on a site with nobody present is a different engineering problem from start reliability with a crew standing by.
What still needs hands: the field-task ledger
The page's centrepiece. Attendance is decided task by task — so here is the ledger of what still requires a body, what removes each item, and what cannot be removed at any price.
Attendance is decided task by task, not plant by plant. Every permanently staffed site is staffed because of a specific list of physical tasks, and the only reliable way to change the crewing model is to take that list apart item by item: what is the task, why does it need a body today, what specific instrument, actuator, robot, contract or design change removes it, and is it removable at all. The ledger below is that analysis in general form; the version that matters is the one written for your site.
| Field task | Why a body is on site today | What actually removes it | Removable? |
|---|---|---|---|
| Operator rounds and local readings | Key values exist only on local gauges, sight glasses and local panels | Transmitters on the twenty-odd points the round depends on, plus fixed thermal and acoustic imaging on the assets people listen to | Yes — instrumentation capex |
| Manual valve lineups, draining and venting | Hand-operated valves in the start, changeover and drain sequences | Motorised valves and automated drain sequences on the critical path only; the rest scheduled into attended windows | Partly — plant modification |
| Grab sampling and chemistry | Water, steam and oil chemistry sampled and analysed by a person | Online analysers with auto-calibration, drift detection and health alarms; manual verification on a longer cycle | Partly — and the analysers themselves need maintenance |
| Local resets and breaker racking | Devices resettable only at the panel; arc-flash procedures require presence | Remotely resettable protection under supervision, remote racking where the switchgear supports it, and a protection philosophy that says which resets may ever be remote | Partly — protection review required |
| Lubrication, filters and consumables | Greasing, top-ups and filter changes on a calendar | Auto-lubrication systems, extended-interval filters, larger reservoirs, condition-based intervals | Partly — mostly a scheduling win |
| Isolation for maintenance (PTW / LOTO) | Physical isolation and verification is a legal and safety requirement | Nothing. It is scheduled into attended windows and planned around | No — by design |
| First-response fire and emergency | Fire code, insurer expectations and local fire-service response assumptions | Fixed detection and suppression, agreed fire-service arrangements, and a stated time-to-human that bounds the automatic responses | No — but need not be plant staff |
| Security and intrusion response | Site security presence and physical response | Hardened perimeter, camera analytics, monitored alarms and a patrol contract | Yes — usually transferable |
| Black start and manual synchronising | Local switching sequences and manual synchronising on older units | Automatic synchronisers, remote-capable black-start schemes, periodic proving runs during attended windows | Partly — proving stays manual |
| Physical fouling: screens, racks, snow, debris | Trash racks, intakes, filters and panels foul physically | Automated rakes and washing where the layout allows; otherwise a visit frequency, not an automation target | Partly — site-specific |
Two conclusions fall out of the ledger every time it is written honestly. The first is that most of the removable cost is instrumentation and small plant modifications rather than software — which is good news, because those are known quantities with contractors who price them. The second is that the irreducible items are irreducible for legal and physical reasons: nobody isolates plant for maintenance over a network, and the control of hazardous energy (opens in a new tab) is a hands-on discipline in every jurisdiction. Unattended operation works around those items by scheduling, not by automating them.
| Asset class | Decisions worth automating first | System of record | KPI it moves | Attendance ceiling today |
|---|---|---|---|---|
| Utility-scale solar | Inverter fault triage, curtailment response, soiling and string diagnostics | SCADA + CMMS | Availability, performance ratio | Unattended, periodic visits |
| Onshore and offshore wind | Turbine fault triage, icing detection, crew and vessel dispatch | Turbine SCADA + CMMS | Availability, capacity factor | Unattended, campaign maintenance |
| Battery storage (BESS) | Dispatch and bidding policy, thermal management, state-of-charge policy | EMS + market gateway | Response accuracy, round-trip efficiency | Lights-out within an envelope |
| Run-of-river and small hydro | Unit start and stop, rack cleaning cycles, spill and level management | DCS + SCADA | EFOR, starts per day, spill volume | Unattended nights, periodic visits |
| Large storage hydro and pumped storage | Mode changes, governor tuning, dewatering scheduling | DCS + SCADA + AGC | EFOR, mode-change reliability | Remotely operated, reduced crew |
| OCGT peaking plant | Remote start on dispatch, purge and ignition supervision, start-failure diagnosis | DCS + AGC | Start reliability, time to full load | Unattended start, attended maintenance |
| CCGT | Steam-cycle chemistry, HRSG transient management, runback supervision | DCS + historian | EFOR, heat rate, starts per year | Reduced night crew, attended |
| Biomass and waste-to-energy | Fuel-handling jam prediction, combustion tuning, emissions compliance | DCS + CMMS | Availability, emissions excursions | Attended — fuel handling |
| Licensed nuclear | Advisory only: condition monitoring, procedure support, outage planning | Plant computer + DCS | Capacity factor, unplanned scrams | Attended by licence condition |
Which attendance model a site can support
Plot the site's on-site hazard inventory against its remote actuation and isolation coverage. The quadrant tells you what to do next — and in three of the four, the next investment is not AI.
Correctly attended
- High hazard, nothing reachable remotely
- CCGT, biomass, most large thermal plant
- Next move: automate the round, not the crew
Unattended on a written basis
- High hazard, safe state reachable and held
- The real frontier — large hydro, peakers, some CCGT nights
- Next move: the unattended-operations basis and time-to-human
Attended by inertia
- Low hazard, low actuation — staffed by habit
- Older small hydro, legacy solar and standby sites
- Next move: instrument the night round; this is the cheapest win on the page
Already lights-out
- Low hazard, remotely controllable
- Wind, utility solar, batteries
- Next move: govern the envelope and watch the escalation rate
The bottom-left quadrant is where most of the recoverable money sits, and it is the least discussed, because a small hydro station staffed by habit is nobody's transformation story. It is also the quadrant where a programme can produce an attributable result inside two quarters, which is what buys permission to attempt the top-right one. Sequence accordingly: prove the mechanism where the hazard is low, then spend the credibility on plant where the basis has to be argued.
Separating what runs today from what is research and what is speculation
Six claims you will hear about autonomous power plants, sorted into in-service, published research and speculation — with what would have to be true for each to move up.
The honest position is that lights-out generation is partly ordinary and partly decades away, and the line between them is sharp enough to draw. Remote and unattended operation of low-hazard generation is unremarkable engineering practice, deployed at scale, with published operator disclosures behind it. Autonomous response inside a written envelope is real but narrow. Everything involving a machine forming a novel judgement about a hazardous process, or repairing itself, is speculation — and treating it as imminent is what makes energy audiences discount the credible parts.
| Claim you will hear | What is actually the case | Status | What would have to be true |
|---|---|---|---|
| "Power plants already run themselves" | Large renewable and hydro fleets run without permanent site crews, controlled from remote centres, with humans on call. The control that acts is conventional DCS and protection logic | In service | Nothing — this is current practice for low-hazard asset classes |
| "AI decides what the plant does" | AI does detection, diagnosis, triage and evidence assembly. The acting layer is deterministic and interlocked, because the safety case and the incident investigation both depend on it being so | In service, bounded | A certification route for non-deterministic control on hazardous plant, which does not currently exist |
| "Nobody visits an unattended site" | Unattended means no permanent crew. Maintenance, isolation, statutory inspection, sampling and consumables all bring people to site on a schedule | In service, widely misunderstood | Nothing — the claim is simply wrong as usually stated |
| "Plants will inspect and repair themselves" | Robotic inspection is real and expanding — drones, crawlers, submersibles for waterways and confined spaces. Autonomous repair of rotating plant or pressure systems is not | Split: inspection in service, repair speculative | Manipulation and qualification standards for robotic work on live plant under a permit regime |
| "Digital twins remove the need for instruments" | Physics-based models are genuinely useful for performance, life consumption and what-if analysis. They interpolate between measurements; they do not replace missing ones | In service, over-claimed | Nothing — the physics does not permit it. Instrument the gap instead |
| "Nuclear will go lights-out" | The operating fleet is staffed under licence conditions with minimum crewing. Advanced reactor concepts propose reduced staffing, and any change runs through the regulator over years | Speculative, licence-bound | A regulator accepting a reduced-staffing case for a specific design, with operating evidence behind it |
Digital data and analytics can reduce power system costs in at least four ways: by reducing operations and maintenance costs; improving power plant and network efficiency; reducing unplanned outages and downtime; and extending the operational lifetime of assets.
What the research bodies actually publish
The IEA's Energy and AI (opens in a new tab) report surveys AI across the energy system, including generation operations and maintenance, and is explicit that data availability and skills are the binding constraints rather than model capability. EPRI's generation research (opens in a new tab) covers condition monitoring, plant flexibility and asset management for operating fleets, and its Open Power AI Consortium (opens in a new tab) exists because sector-specific models need sector-specific data that no single operator holds. None of that literature promises an unattended thermal plant.
What the governance frameworks add
Unattended operation shifts the burden of proof onto documentation. NIST's AI Risk Management Framework (opens in a new tab) gives a usable vocabulary for characterising and monitoring risk in the model layer, and ISO/IEC 42001 (opens in a new tab) defines an AI management system in the same shape as the quality and safety management systems energy operators already run. Neither is a substitute for the unattended-operations basis; both make it easier to write one an auditor will accept.
What the codes and connection rules constrain
A generating site is not free to define its own behaviour. Connection and performance obligations — the European requirements for generators (opens in a new tab) network code, and in Great Britain the obligations in the Grid Code (opens in a new tab) — specify frequency and voltage response, availability declarations and communications with the system operator. An unattended site still has to answer the phone, declare its availability and respond to instruction, which is an operating-model design constraint before it is a technical one.
What the cyber standards make non-optional
Unattended operation concentrates a site's entire controllability into a network path, which changes the threat model rather than merely adding to it. The ISA/IEC 62443 series (opens in a new tab) is the reference architecture for segmenting that path, and for North American bulk-electric assets NERC CIP (opens in a new tab) turns much of it into compliance obligation. Loss-of-communications behaviour is part of the safety case: what the plant does when the ROC goes dark has to be a designed answer, not an emergent one.
What sits genuinely on the horizon
Three things are plausibly changing within a planning horizon rather than a fantasy one: robotic inspection displacing a meaningful share of routine rounds; sensing costs falling far enough that instrumenting an old plant stops being a capital argument; and standardised unattended-operation cases for common asset classes, so each operator stops writing one from scratch. All three are engineering and paperwork. None requires a breakthrough in artificial intelligence.
What unattended generation looks like in public
Three publicly reported operations read against the ladder. None is an Atomic Loops engagement — each links to the operator's own published material.
The best public evidence for the attendance thesis is in what large operators actually built, and it is consistent: the differentiator is never a model, it is span of control plus the physical ability to act remotely. Read the three below against the ladder rather than as marketing. Each is a case where an operator published the numbers themselves; verify the figures against the linked source before reusing them.
Three operations, read against the attendance ladder
Outcomes as reported by the operators themselves. The images are generated industry scenes from our media library, not photographs of the named operators' sites, and imply no endorsement.
Duke EnergyUS investor-owned utility · regulated renewable and hydro fleet13
- Challenge
- A large, geographically dispersed fleet of hydro stations, solar sites and batteries had historically been operated the way such plant always was: Duke Energy notes that each hydro station was staffed around the clock until operations were consolidated in 2000.
- Approach
- Consolidation into central operations centres. Duke Energy describes a Regulated Renewable Operations Center covering 76 hydro units, 33 solar sites and battery systems, with several hundred thousand alarms and almost 500 cameras, and a separate Renewable Control Center in Charlotte where around 30 employees on 12-hour shifts monitor and control wind, solar and batteries across 22 states — remotely starting and stopping equipment, forecasting generation, dispatching field technicians and supporting reliability compliance.
- Reported outcome
- Duke Energy reports operating roughly 5,500 MW from the regulated renewable centre, with quicker response to emerging issues and reduced operating costs, and describes the portfolio growing substantially by 2030 and 2035 without a proportional operations centre.
- What it shows about the curveThis is rung three done properly, and the economics are span of control: the cost of watching the hundredth site is close to the cost of watching the tenth. Note what did not change — field technicians are still dispatched, because remote operation moves the work, it does not delete it.
Duke Energy — what it takes to operate 5,500 MW of renewable energy (opens in a new tab)
Enel Green PowerGlobal renewable generator · multi-country control-room network24
- Challenge
- A renewable portfolio spread across many countries and technologies, where per-site staffing would never amortise and per-country tooling would fragment the operating model.
- Approach
- A network of regional control and monitoring rooms rather than site control rooms, with plant digitalisation making it possible, in Enel Green Power's own words, to connect and control the renewable generation mix from a single point.
- Reported outcome
- Enel Green Power reports that its control room in Greece alone manages 481 MW of installed capacity across 59 plants, describing it as one of the largest and most modern of its kind.
- What it shows about the curveThe number to take from this is 59 plants per room, not 481 MW. Span of control is the metric that decides whether unattended operation pays, and it is set by how much of each site can be acted on remotely — not by how many megawatts it holds.
Enel Green Power — control and monitoring room, Greece (opens in a new tab)
Hornsdale Power ReserveSouth Australia · grid-scale battery, 150 MW45
- Challenge
- Delivering frequency and system-strength services on timescales where a human decision loop is physically impossible, while remaining accountable to the market operator for every response.
- Approach
- The site reports being built in two stages — 100 MW / 129 MWh completed in November 2017 and a 50 MW / 64.5 MWh expansion in September 2020 — with the full 150 MW subsequently upgraded to include Tesla's Virtual Machine Mode, enabling the battery to provide inertia support services to the grid. Human involvement sits in bidding policy, envelope design and market compliance rather than in any individual response.
- Reported outcome
- Hornsdale Power Reserve reports that in its first two years of operation it confirmed the benefits associated with grid-scale batteries in the National Electricity Market and saved South Australian consumers over $150 million.
- What it shows about the curveThis is the clearest illustration that autonomy in generation is often set by physics rather than by ambition. Nobody debated whether to put an operator in this loop; the response times made it impossible. What was debated — and written down — is the envelope the plant is allowed to act within.
Hornsdale Power Reserve — about the project (opens in a new tab)
Read together, the three make a single point. The operators who removed permanent site crews did so on low-hazard asset classes, with conventional control systems, by building span of control and remote actuation — and they kept field technicians, callout rosters and maintenance visits. Nothing in the public record supports the stronger version of the lights-out story, and nothing in the public record is needed to justify the achievable version.