Redefining Technology

Energy & UtilitiesAI-Driven Disruptions & Innovations

AI-driven lights-out power plants: what unattended generation really takes in energy and utilities

A lights-out power plant is a generating site whose normal operating cycle — start, load, respond, shut down — runs with nobody on site, inside a written unattended-operations basis. AI supplies detection and diagnosis. Whether anyone can actually leave is decided by instrumentation, remote actuation, isolation and fire cover.

Scene: an unstaffed generating hall lit only by equipment indicators, with a remote operations centre screen wall in the background
Energy & Utilities · AI-Driven Disruptions & Innovations

Key takeaways

  1. Lights-out is an attendance property, not an intelligence property. A site becomes unattended when its remaining manual tasks have been instrumented, actuated or designed out — and when a written unattended-operations basis says under what conditions nobody needs to be there. The model is the last and cheapest component.
  2. Unattended generation is already routine in one half of the fleet and structurally blocked in the other. Wind, utility solar, batteries and much hydro run without permanent crews today. High-hazard thermal plant, fuel handling and licensed nuclear do not, and the constraint is fire cover, isolation and staffing conditions rather than software.
  3. Time-to-human is the governing design parameter. Every automatic response has to hold the plant in a safe state for at least as long as it takes a competent person to arrive — so drive time, road closures and on-call rosters set the autonomy envelope more tightly than any confidence threshold.
  4. Remote monitoring is attendance-neutral. A read-only link to a remote centre buys earlier diagnosis and zero reduction in crewing, because every remote diagnosis still terminates in a callout. The step that changes the roster is remote actuation and isolation, which is a controls, protection and cyber project.
  5. The credible near-term prize is the night, not the plant. Removing a permanently staffed night shift from sites that do three real interventions a month is achievable, measurable and reversible; removing the day crew from a combined-cycle plant is not, and pretending otherwise is how these programmes lose their sponsor.

Abbreviations used on this page

DCS
Distributed control system — the plant's own control and interlock logic
SCADA
Supervisory control and data acquisition
ROC
Remote operations centre (also renewable or fleet control centre)
BOP
Balance of plant — everything outside the main generating unit
CCGT
Combined-cycle gas turbine
OCGT
Open-cycle gas turbine, typically a peaking plant
BESS
Battery energy storage system
AGC
Automatic generation control — the system operator's set-point signal
LOTO
Lock-out / tag-out: physical isolation of hazardous energy for maintenance
PTW
Permit to work — the authorisation controlling work on plant
EFOR
Equivalent forced outage rate, the standard generation reliability metric
NERC CIP
North American Electric Reliability Corporation Critical Infrastructure Protection standards

Free · 8 questions · ~3 minutes

Score one site on the attendance ladder

Eight questions about one generating site, one at a time, about three minutes. Answer them and we build your personalised readiness report — the site's rung on the attendance ladder, its score on each of the four dimensions, and the specific constraint standing between it and the next rung — and send it to your inbox. Score the site you would most like to stop staffing at night.

0 of 8 answered

Question 1 of 8Sensing and field dependence

How much of what a night operator looks at exists only as a local indication?

Every local-only gauge, sight glass or panel is a permanent argument for a person on site. This is the cheapest constraint to remove and the one most often skipped.

How the score maps to a stage
  • 05 — Stage 1, Continuously attended. A crew is on site around the clock because the plant cannot be sensed, actuated or diagnosed from anywhere else.
  • 611 — Stage 2, Remotely monitored. Plant data reaches a remote centre and gets analysed there, but every action still requires someone on site.
  • 1216 — Stage 3, Remotely operated. The plant can be started, loaded, run back and isolated from a remote operations centre; site staff work days and cover nights on call.
  • 1721 — Stage 4, Routinely unattended. The site runs with nobody present for defined periods under a written unattended-operations basis, with people arriving for planned work and exceptions.
  • 2224 — Stage 5, Lights-out within an envelope. The normal operating cycle runs with nobody on site inside a stated envelope, and everything outside that envelope escalates to a person.

What a lights-out power plant is — and what it is not

A definition, the three things that actually decide attendance, and the same 03:00 alarm followed through three different plants.

A lights-out power plant is a generating site whose normal operating cycle — start, load, respond to dispatch, shut down — runs with nobody on site, under a written unattended-operations basis that states the conditions, the automatic responses and the maximum time before a competent person arrives. The phrase describes an attendance model, not a technology. A site is lights-out when the work that used to require a body has been instrumented, actuated, designed out or scheduled into attended windows.

It is not a plant that thinks. Nothing in a credible unattended arrangement lets a model improvise on plant: the responses that move equipment are deterministic control logic, interlocked and tested, and the AI layer sits upstream of them doing detection, diagnosis, triage and evidence assembly. It is also not a plant that nobody ever visits — unattended means no permanent crew, not no humans. Maintenance, isolation, statutory inspections and consumables all still bring people to site on a schedule.

Three things decide whether a given site can go unattended, and none of them is model quality. First, sensing: can the plant be seen without a person walking it. Second, actuation and isolation: can it be moved to a safe state and held there from somewhere else. Third, the basis: is there a defensible written case, agreed with the people who carry the consequences — safety, insurer, fire service, system operator — for running without anyone present. The rest of this page is about those three, in that order.

One high-vibration alarm at 03:00, three endings

The same event on three sites at different rungs of the attendance ladder. What differs is not the alarm and not the model — it is what the plant can be made to do without a person, and what evidence exists afterwards. Most sites are in the top lane.

  • Data & feeds
  • Where value leaks
  • Human in the loop
  • AI / model
  • System-of-record action

The process, in words

  • On a continuously attended site, the vibration probe reports to a local panel, the alarm arrives inside a flood of others, and an operator walks the unit and forms a judgement. The judgement is often right and leaves almost no record — the site's knowledge of the event is one person's recollection at the end of a night shift.
  • On a remotely operated site, the same signal is historised alongside temperatures and load, a diagnostic model ranks probable causes with supporting evidence, and the remote operator runs the unit back and holds it. The event is diagnosed sooner and recorded properly, and it still ends in a callout, because the corrective work needs hands and drive time bounds everything.
  • On a routinely unattended site, the response was decided in advance: a pre-approved, interlocked DCS action runs the unit back or trips it, the plant holds a defined safe state, and the escalation carries an evidence pack — signals, model output, actions taken and the time remaining before someone must arrive.
Step-by-step insights
The local-only signal is the whole argument for a night shift
Instrumentation is where unattended operation is won or lost, and it is unglamorous. A vibration probe with a local panel and no historian connection means the plant's condition is observable only by a person standing in front of it, which means someone stands in front of it every night for the remaining life of the asset. The removal cost is a transmitter, a marshalling change and a point in the historian — trivial next to a permanent roster line. Programmes routinely spend more on analytics for the instrumented 40% of a plant than it would cost to instrument the other 60%.
Alarm floods make autonomy undecidable, not just unpleasant
Unattended operation depends on an alarm meaning something. Where a single event produces forty alarms in ninety seconds, no operator and no model can be given a defensible response, because the signal that should trigger the response is indistinguishable from consequence alarms. Long-standing alarm-management practice treats a steady-state rate above roughly one alarm every ten minutes per operator as unmanageable, and rationalising to something near that is a prerequisite for any pre-approved response catalogue rather than an optional tidy-up.
The model's job is evidence, not action
In the middle lane the model earns its place by turning a raw alarm into a ranked hypothesis with supporting signals: which bearing, what trend, what changed in the last four hours, which comparable events look similar. That is decision support with a clean audit story. The moment the model is allowed to move plant directly, the safety argument, the insurance conversation and the incident investigation all become materially harder — which is why mature unattended sites keep the acting layer deterministic and put the intelligence upstream of it.
Remote runback is the action that changes the roster
The single most valuable remotely writable capability is not remote start; it is the ability to take the unit somewhere safe and hold it. A remote runback converts an event that requires immediate presence into an event that requires eventual presence, and 'eventual' is what allows a night shift to become an on-call arrangement. Scope the safe-state path before the convenience functions: it is the one that carries the attendance benefit and the one the protection engineer will scrutinise hardest.
Drive time is a design parameter, not a logistics detail
In the middle lane the callout is the ending, and its duration bounds everything upstream. If a competent person is ninety minutes away in good weather and three hours away in February, then every automatic response has to hold the plant safely for three hours, or the site cannot be left in that condition at all. Operators who write time-to-human into the design brief end up with a much shorter and more honest list of unattended candidate sites than those who treat travel as an operational afterthought.
The evidence pack is what makes the third lane repeatable
An escalation from an unattended site should arrive as a package: the triggering signals, the model's assessment, the response that executed, the plant's current state, the time remaining in that state and the conditions that would end it. This is not documentation overhead — it is what lets the arriving engineer act immediately, what lets the insurer price the arrangement, and what lets the next review decide whether the envelope was correct. Sites that escalate with a phone call and a screenshot cannot sustain unattended operation past their first serious event.

The five rungs of the attendance ladder

For each rung: what it looks like on the ground, the diagnostic signals a reviewer can check in an afternoon, the anti-pattern that traps sites there, and what leaving costs.

The ladder measures one thing: how much of the plant's work still requires a human body on site. It deliberately does not measure how autonomous the control logic is, because a plant can run a fully automatic start sequence and still need three people for the balance of plant — and because the reverse is common too, with heavily crewed sites whose crews spend the night reading dials that could have been transmitters.

Each rung below is written for a practitioner. The hallmarks describe observable conditions on a real site, the diagnostic signals are checks you can run against your own plant and logs this week, and the anti-pattern is the specific mistake most often made trying to leave that rung. Score sites individually — a fleet has a distribution, not a level.

Select a rung

Every rung's full detail is in the page source — the selector only changes which panel is visible, so nothing here depends on JavaScript to exist.

Stage 1

Continuously attended

24% of operators sit here

A crew is on site around the clock because the plant cannot be sensed, actuated or diagnosed from anywhere else.

Stage 1 sites are almost never attended because of a hazard assessment. They are attended because of a design vintage: the plant was commissioned when a person walking a route with a clipboard was the cheapest instrument available, and nothing since has changed the assumption. Ask why the night shift exists and the honest answer is usually that it always has.

The tell is the local indicator. Count the gauges, sight glasses, local panels and hand-operated valves that a night operator physically looks at or touches during a normal shift, and you have measured the site's distance from unattended operation in units that can be costed. A dial with no transmitter behind it is a person on site, permanently, for the life of the plant.

This is an expensive stage to sit in and a cheap one to leave, because the first move costs almost nothing. Nobody can price the removal of work that has never been enumerated, so the enumeration is the project. Operators who skip it end up buying analytics for data that does not leave the turbine hall.

In practice

The night list nobody has written down

A 60 MW run-of-river hydro station runs two operators every night. Asked what the night shift does, the plant manager describes rounds, log readings and 'being there if something happens'. A month of shift logs shows 190 completed rounds, four local resets, one trash-rack clearance and no interventions that could not have waited until 07:00. Nothing about that month argues for a night crew; nothing about the plant's instrumentation allows one to be removed.

What it looks like

  • Key readings exist only on local gauges and local panels
  • Starting, synchronising or isolating the unit requires hands on plant
  • The night shift's work has never been written down as a task list
  • Remote access, where it exists, is an engineer's laptop and a VPN

Diagnostic signals you can check this week

  • Ask for the night task list. If it does not exist as a document, you are here
  • Walk the round with an operator and count readings that exist only locally
  • Count hand-operated valves and local switches in the normal start sequence
  • Ask who physically resets the lube-oil or seal-water pump after a trip, and how long that takes

Anti-pattern · Buying the AI before the transmitters

The instinctive first move is a condition-monitoring pilot, because it is procurable and demonstrable. It fails quietly at stage 1 for a mundane reason: the signals the model needs — bearing temperatures, differential pressures, tank levels, vibration on the balance of plant — are on local gauges, sampled by a human once a shift, or not measured at all. Instrument the twenty points the night round actually depends on first; the analytics are then a weekend, not a programme.

What holds you here

The work the crew actually does has never been enumerated, so nobody can price removing it or prove it is safe to.

Highest-leverage next move

Write the night task inventory: every task the night shift performs across a month, each mapped to the instrument, actuator or design change that would remove it.

Cost of leaving

Effort
2–4 months
Team
One control engineer, the shift supervisor, part-time
Risk
Low — the work is documentation and survey; nothing in the plant changes yet
To next stage
3–6 months

If this is you, the next step is

A two-week exercise: one site, one month of logs, a costed removal list per task.

Get your night task inventory written

Stage 2

Remotely monitored

38% of operators sit here

Plant data reaches a remote centre and gets analysed there, but every action still requires someone on site.

Stage 2 is where most of the fleet sits, and it is genuinely valuable — early detection of a failing bearing or a fouling heat exchanger is worth real money in avoided forced outages. It is also, on its own, completely attendance-neutral. Monitoring is read-only by construction, so every remote diagnosis terminates in the same sentence: somebody has to go.

The read-only decision is usually a cyber decision, taken deliberately and for good reasons, and it is the actual ceiling on the stage. That matters because it means the path out of stage 2 is not a data-science path. It runs through control engineering, protection philosophy and a defensible remote-access architecture — zones and conduits in the sense of the IEC 62443 series, with logging, supervision and a tested break-glass route.

Time spent here is not neutral either. Every year at stage 2 accumulates monitoring coverage that flatters the programme in slides and never appears in the roster or in the operations budget. When the sponsor eventually asks what the monitoring centre changed about how the fleet is run, the honest answer is 'the timing of callouts', and that is a much smaller answer than the one that funded it.

In practice

The diagnosis that still needed a van

A fleet monitoring centre identifies a rising boiler feed-pump bearing temperature at a peaking site and correctly calls a developing failure eleven days out. The corrective action is a changeover to the standby pump — which requires a local valve lineup and a local start, because neither the suction valves nor the pump control are remotely writable. An operator drives seventy minutes. The catch was excellent; the attendance model did not move by an hour.

What it looks like

  • A historian streams plant data to a monitoring and diagnostics centre
  • Condition models flag developing faults days or weeks ahead
  • The OT link is deliberately read-only, and everyone treats that as settled
  • Site crewing is unchanged since the monitoring centre opened

Diagnostic signals you can check this week

  • Ask whether the remote link can write anything at all, and to how many points
  • Compare telemetry coverage with actuation coverage — the second number is usually near zero
  • Count callouts per month whose cause was already known remotely before the call
  • Ask whether the ROC can put the unit in a defined safe state without anyone on site

Anti-pattern · Confusing monitoring coverage with autonomy

Programmes report telemetry coverage — points connected, sites onboarded, models deployed — and read it as progress towards autonomy. It is not the same axis. A site can be at 100% telemetry coverage and 0% remote actuation coverage, and the second number is the one attendance responds to. Report both from the first month, side by side, and the roadmap corrects itself.

What holds you here

The remote link is read-only, so remote diagnosis always terminates in a callout and the roster never changes.

Highest-leverage next move

Define the smallest set of remotely writable actions worth having — safe-state, runback, changeover, start inhibit — and build the segmented, logged cyber path that makes them defensible.

Cost of leaving

Effort
6–12 months
Team
Controls engineer, OT security lead, protection engineer, ops owner
Risk
Medium — the first remote write into a plant needs a protection review and a rollback
To next stage
9–18 months

If this is you, the next step is

Which actions, which interlocks, which cyber path — one site, four weeks.

Scope the first remotely writable envelope

Stage 3

Remotely operated

24% of operators sit here

The plant can be started, loaded, run back and isolated from a remote operations centre; site staff work days and cover nights on call.

Stage 3 is where the economics start to work, because span of control changes. One room can hold a large number of sites, and the cost of watching the hundredth site is close to the cost of watching the tenth. This is the stage most large renewable and hydro fleets already occupy, and it is the stage where the first real staffing decisions get made.

The constraint moves, though, rather than disappearing. Once the plant is remotely operable, what still brings a person to site is maintenance, consumables, isolation for work, local resets and physical faults — the callout list. Operators consistently discover that the control system was the easy half and that the on-call roster, drive time and overtime bill are the half that decides whether the business case holds.

The other change at stage 3 is legal rather than technical. Someone has to be the competent person for the plant at 03:00, and the arrangements for lone working, callout and emergency response have to be real rather than assumed — the same territory the HSE's lone-working guidance covers for any remote site. Stage 3 programmes that skip that conversation get stopped by it later, usually after an incident that was survivable and badly handled.

In practice

The peaker that starts itself but cannot be left alone

An OCGT site takes its dispatch instruction remotely, purges, starts, synchronises and loads without anyone present — a sequence the DCS has run reliably for years. It still carries a resident technician because the fuel-gas filter change, the weekly fire-pump test, the lube-oil top-up and the monthly black-start proving all need hands. The unit is autonomous; the site is not. Attendance is set by the balance of plant, not the turbine.

What it looks like

  • The ROC can start, synchronise, load and stop the unit
  • There is a defined remote safe state and a tested route to it
  • Site staff are on day shift with an on-call rota at night
  • A named competent person is accountable for the plant at all hours

Diagnostic signals you can check this week

  • Ask the ROC to demonstrate a start and a synchronisation with nobody on site
  • Ask for the callout log for the last quarter, sorted by cause and by hour
  • Check who is named as the competent person overnight, and whether they are reachable and trained
  • Ask what the plant does automatically if telemetry to the ROC is lost for thirty minutes

Anti-pattern · Cutting the roster before counting the callouts

Remote operation reads like a headcount saving, so the roster is cut on the strength of the control-system capability alone. The callouts then arrive at overtime rates, the on-call burden lands on a smaller group, and within two quarters the site is informally re-crewed by exhausted people. Count and cost the callout list first; remove its top five causes; then change the roster. The order is the whole difference between a saving and a churn problem.

What holds you here

The plant is remotely operable but not remotely maintainable, so the callout rate — not the control system — sets the crewing.

Highest-leverage next move

Attack the callout list: instrument, automate or design out the five most common reasons somebody drives to site at night, and re-measure before touching the roster.

Cost of leaving

Effort
12–24 months
Team
Control system project, protection engineer, ROC operations model, HR and union consultation
Risk
Medium to high — protection philosophy changes and industrial relations both sit on the critical path
To next stage
12–24 months

If this is you, the next step is

Which actions leave the site, which stay, and what the interlocks have to prove.

Design your remote-operation envelope

Stage 4

Routinely unattended

11% of operators sit here

The site runs with nobody present for defined periods under a written unattended-operations basis, with people arriving for planned work and exceptions.

The artefact that defines stage 4 is not software. It is a document: the unattended-operations basis, which states under what conditions the site may run with nobody on it, what ends that condition, what the plant does automatically in each named event, how long it can hold that state, and who arrives when it cannot. Everything else at this stage exists to satisfy a line in that document.

AI's role becomes precise here, and smaller than the marketing suggests. Models do detection, diagnosis and triage: is this a real event, what is the probable cause, which of the pre-approved responses applies, what evidence goes with the escalation. The response that actually moves plant is DCS logic — deterministic, interlocked, testable and, crucially, explainable to a regulator, an insurer and an investigation. Keeping that boundary sharp is what lets the basis be written at all.

The parties who have to agree are the ones most programmes meet late. Fire and life-safety arrangements for a generating station — the territory NFPA 850 covers as recommended practice — assume a response, and the response changes when nobody is on site. Insurers price the change. The local fire service should walk the site. Where a generating licence, connection agreement or grid code obligation implies availability of competent staff, that obligation has to be read carefully rather than hoped over.

In practice

Four nights a week, and the fourteen conditions that end them

A hydro station runs unattended from 22:00 to 06:00 on Sunday through Wednesday. Its basis lists fourteen conditions that end unattended operation and return the site to attended status: fire-detection fault, loss of the primary telemetry path for more than fifteen minutes, forecast lightning within a set radius, river level above a stated threshold, any protection operation, any fire-pump unavailability, and so on. Nine of the fourteen are weather or river conditions. None of them is about the model.

What it looks like

  • A written unattended-operations basis states the conditions and their owner
  • Time-to-human is measured, contracted and seasonally tested
  • A versioned catalogue of pre-approved automatic responses exists
  • Fire, security and insurance arrangements were rewritten for the unattended case

Diagnostic signals you can check this week

  • Ask to see the unattended-operations basis, its owner, its version and its review date
  • Ask when time-to-human was last measured rather than estimated — and in which season
  • Check whether the local fire service has attended the site and agreed the arrangements
  • Check whether the last three plant modifications were tested against the response catalogue

Anti-pattern · Treating the basis as a document rather than a control

The basis gets written once, signed, and filed. Then the plant changes: a pump is replaced with a different starting characteristic, a detection head is isolated for building work, an on-call engineer moves house forty minutes further away. Each change is individually reasonable and none triggers a review, so the site drifts out of the conditions under which unattended operation was justified. Put the basis under management of change and make it a required check on every plant modification and roster change.

What holds you here

The written basis and the physical plant diverge, so the justification for unattended operation quietly expires without anyone noticing.

Highest-leverage next move

Put the basis under change control: every plant modification, roster change and market-rule change re-tests the conditions and the pre-approved response catalogue.

Cost of leaving

Effort
12–24 months
Team
Operations, safety case owner, control engineering, insurer and fire-service liaison
Risk
Concentrated — low frequency, high consequence, and evidence-driven
To next stage
18+ months

If this is you, the next step is

We run the basis against real events and your last twelve plant modifications.

Stress-test your unattended-operations basis

Stage 5

Lights-out within an envelope

3% of operators sit here

The normal operating cycle runs with nobody on site inside a stated envelope, and everything outside that envelope escalates to a person.

Stage 5 is narrower than the phrase 'lights-out' implies, and the narrowness is the point. It is not an autonomous power station in the science-fiction sense; it is a specific asset class, running a specific cycle, inside a stated envelope, with everything outside the envelope escalating. Utility solar, wind, batteries and small hydro qualify routinely. Fuel handling, high-pressure steam plant and licensed nuclear do not, and saying so plainly is what makes the rest of the claim credible.

Some of this frontier was never a human job to begin with. A grid-scale battery providing fast frequency response acts in tens of milliseconds and a grid-forming unit responds to a system disturbance faster than an operator can register that one has occurred. There is no version of that service with a person in the loop, which is a useful reminder that autonomy in generation is often set by physics and market products rather than by how clever the software has become.

Sustaining the stage is a governance discipline, and it is the stage most likely to regress. Envelopes are written for a plant configuration, a roster, a road network, a market design and a season, and all five move. The operators who hold stage 5 treat the envelope as a live artefact with an owner, a version history and a review trigger, and they watch the escalation rate the way a stage-3 operator watches the callout list.

In practice

The envelope, written on one page

A battery site's envelope states the market products it may respond to autonomously, the state-of-charge and temperature bounds within which it does so, the actions it takes on any excursion, the maximum period it may hold that state, and the four events that summon a person. The bidding policy behind it is reviewed weekly by humans who never touch the plant. The site has no permanent staff and no ambiguity about who is accountable.

What it looks like

  • Start, dispatch, response and shutdown all execute without anyone present
  • The envelope fits on one page and is versioned like code
  • Escalation rate and time-to-human are monitored as leading indicators
  • Any automated action can be reconstructed from logs months later

Diagnostic signals you can check this week

  • Ask for the envelope on one page. If it takes a workshop to reconstruct, it is not being governed
  • Check the escalation-rate trend over four quarters, not the last month
  • Ask when time-to-human was last tested in winter, with a road closure assumed
  • Pick one automated action from six months ago and try to reconstruct it end to end from logs

Anti-pattern · Generalising the envelope across asset classes

An envelope proven on a solar and battery portfolio gets extended to a hydro station or a peaker on the argument that the control platform is the same. The control platform is the same; the hazard inventory, the fire load, the isolation requirements and the failure modes are not. Envelopes are earned per asset class from that class's own operating evidence, and inheriting one is the fastest route to the incident that ends the whole programme.

What holds you here

Holding lights-out is a change-control and evidence problem: plant, roster, roads, market rules and weather all move underneath a fixed envelope.

Highest-leverage next move

Version the envelope like code and give it review triggers — every plant modification, roster change, market-rule change and seasonal transition.

Cost of leaving

Effort
Continuous
Team
Standing governance forum, control engineering, ops assurance
Risk
Concentrated and regulatory — rare events with public consequences

If this is you, the next step is

We test the envelope, the evidence trail and the escalation path against a real scenario.

Audit an unattended envelope

Where generating sites actually sit today

The distribution across the ladder, why it is bimodal by asset class, and why the second rung is where most of the fleet has settled.

Most generating sites are remotely monitored and locally operated — rung two. The distribution below is bimodal by design rather than by accident: newer wind, solar and storage sites were built with no control room at all and start life at rung three or four, while thermal plant and older hydro carry crewing models inherited from commissioning. Fleet-level averages therefore mislead badly, and the useful unit of analysis is the site.

Distribution of generating sites across the attendance ladder

Illustrative distribution across a mixed generating fleet, synthesised from published operator control-centre disclosures and IEA digitalisation research — not a survey. The shape is the argument: the mode sits at remote monitoring, which is the rung that changes diagnosis and does not change crewing.

Share of generating sites

  • 24% — 1 · Continuously attended
  • 38% — 2 · Remotely monitored (the attendance-neutral plateau)
  • 24% — 3 · Remotely operated
  • 11% — 4 · Routinely unattended
  • 3% — 5 · Lights-out in envelope

Source: Illustrative, anchored to IEA digitalisation research and published operator control-centre disclosures

The fleet is also moving under the question. The large majority of new generating capacity added worldwide each year is now wind, solar and battery storage — see IRENA's Renewable Capacity Statistics (opens in a new tab) — and those asset classes are built with remote operation as the default rather than as a retrofit. That means the fleet-wide attendance picture improves partly through new build rather than through any operator changing anything, and it makes the retrofit question sharper: the sites you already own are the ones where the work is.

There is a demand-side pressure too. Reliability bodies are documenting tighter margins and steeper ramps as the resource mix changes — NERC's Long-Term Reliability Assessment (opens in a new tab) runs this analysis annually across the United States and Canada over a ten-year horizon, and the IEA's electricity analysis (opens in a new tab) tracks the same trends globally. Plants that used to run baseload now start and stop far more often, and start reliability at 04:00 on a site with nobody present is a different engineering problem from start reliability with a crew standing by.

What still needs hands: the field-task ledger

The page's centrepiece. Attendance is decided task by task — so here is the ledger of what still requires a body, what removes each item, and what cannot be removed at any price.

Attendance is decided task by task, not plant by plant. Every permanently staffed site is staffed because of a specific list of physical tasks, and the only reliable way to change the crewing model is to take that list apart item by item: what is the task, why does it need a body today, what specific instrument, actuator, robot, contract or design change removes it, and is it removable at all. The ledger below is that analysis in general form; the version that matters is the one written for your site.

Field taskWhy a body is on site todayWhat actually removes itRemovable?
Operator rounds and local readingsKey values exist only on local gauges, sight glasses and local panelsTransmitters on the twenty-odd points the round depends on, plus fixed thermal and acoustic imaging on the assets people listen toYes — instrumentation capex
Manual valve lineups, draining and ventingHand-operated valves in the start, changeover and drain sequencesMotorised valves and automated drain sequences on the critical path only; the rest scheduled into attended windowsPartly — plant modification
Grab sampling and chemistryWater, steam and oil chemistry sampled and analysed by a personOnline analysers with auto-calibration, drift detection and health alarms; manual verification on a longer cyclePartly — and the analysers themselves need maintenance
Local resets and breaker rackingDevices resettable only at the panel; arc-flash procedures require presenceRemotely resettable protection under supervision, remote racking where the switchgear supports it, and a protection philosophy that says which resets may ever be remotePartly — protection review required
Lubrication, filters and consumablesGreasing, top-ups and filter changes on a calendarAuto-lubrication systems, extended-interval filters, larger reservoirs, condition-based intervalsPartly — mostly a scheduling win
Isolation for maintenance (PTW / LOTO)Physical isolation and verification is a legal and safety requirementNothing. It is scheduled into attended windows and planned aroundNo — by design
First-response fire and emergencyFire code, insurer expectations and local fire-service response assumptionsFixed detection and suppression, agreed fire-service arrangements, and a stated time-to-human that bounds the automatic responsesNo — but need not be plant staff
Security and intrusion responseSite security presence and physical responseHardened perimeter, camera analytics, monitored alarms and a patrol contractYes — usually transferable
Black start and manual synchronisingLocal switching sequences and manual synchronising on older unitsAutomatic synchronisers, remote-capable black-start schemes, periodic proving runs during attended windowsPartly — proving stays manual
Physical fouling: screens, racks, snow, debrisTrash racks, intakes, filters and panels foul physicallyAutomated rakes and washing where the layout allows; otherwise a visit frequency, not an automation targetPartly — site-specific
The field-task ledger. 'Removable' is an engineering judgement about the task, not about a particular site — the site-specific answer depends on plant vintage, layout and hazard inventory. Items marked 'No' do not block unattended operation; they get scheduled into attended windows instead.

Two conclusions fall out of the ledger every time it is written honestly. The first is that most of the removable cost is instrumentation and small plant modifications rather than software — which is good news, because those are known quantities with contractors who price them. The second is that the irreducible items are irreducible for legal and physical reasons: nobody isolates plant for maintenance over a network, and the control of hazardous energy (opens in a new tab) is a hands-on discipline in every jurisdiction. Unattended operation works around those items by scheduling, not by automating them.

Asset classDecisions worth automating firstSystem of recordKPI it movesAttendance ceiling today
Utility-scale solarInverter fault triage, curtailment response, soiling and string diagnosticsSCADA + CMMSAvailability, performance ratioUnattended, periodic visits
Onshore and offshore windTurbine fault triage, icing detection, crew and vessel dispatchTurbine SCADA + CMMSAvailability, capacity factorUnattended, campaign maintenance
Battery storage (BESS)Dispatch and bidding policy, thermal management, state-of-charge policyEMS + market gatewayResponse accuracy, round-trip efficiencyLights-out within an envelope
Run-of-river and small hydroUnit start and stop, rack cleaning cycles, spill and level managementDCS + SCADAEFOR, starts per day, spill volumeUnattended nights, periodic visits
Large storage hydro and pumped storageMode changes, governor tuning, dewatering schedulingDCS + SCADA + AGCEFOR, mode-change reliabilityRemotely operated, reduced crew
OCGT peaking plantRemote start on dispatch, purge and ignition supervision, start-failure diagnosisDCS + AGCStart reliability, time to full loadUnattended start, attended maintenance
CCGTSteam-cycle chemistry, HRSG transient management, runback supervisionDCS + historianEFOR, heat rate, starts per yearReduced night crew, attended
Biomass and waste-to-energyFuel-handling jam prediction, combustion tuning, emissions complianceDCS + CMMSAvailability, emissions excursionsAttended — fuel handling
Licensed nuclearAdvisory only: condition monitoring, procedure support, outage planningPlant computer + DCSCapacity factor, unplanned scramsAttended by licence condition
Where unattended operation lands by asset class, and what the binding constraint actually is. 'Attendance ceiling' is what today's engineering, codes and licensing realistically support — not a prediction about what may become possible later.

Which attendance model a site can support

Plot the site's on-site hazard inventory against its remote actuation and isolation coverage. The quadrant tells you what to do next — and in three of the four, the next investment is not AI.

Correctly attended

  • High hazard, nothing reachable remotely
  • CCGT, biomass, most large thermal plant
  • Next move: automate the round, not the crew

Unattended on a written basis

  • High hazard, safe state reachable and held
  • The real frontier — large hydro, peakers, some CCGT nights
  • Next move: the unattended-operations basis and time-to-human

Attended by inertia

  • Low hazard, low actuation — staffed by habit
  • Older small hydro, legacy solar and standby sites
  • Next move: instrument the night round; this is the cheapest win on the page

Already lights-out

  • Low hazard, remotely controllable
  • Wind, utility solar, batteries
  • Next move: govern the envelope and watch the escalation rate
On-site hazard inventory — top: Gas, high-pressure steam, hydrogen, large cell stacks, bottom: No fuel, no pressure, low fire load
Remote actuation and isolation coverage — left: Read-only telemetry, right: Safe state reachable remotely

The bottom-left quadrant is where most of the recoverable money sits, and it is the least discussed, because a small hydro station staffed by habit is nobody's transformation story. It is also the quadrant where a programme can produce an attributable result inside two quarters, which is what buys permission to attempt the top-right one. Sequence accordingly: prove the mechanism where the hazard is low, then spend the credibility on plant where the basis has to be argued.

Separating what runs today from what is research and what is speculation

Six claims you will hear about autonomous power plants, sorted into in-service, published research and speculation — with what would have to be true for each to move up.

The honest position is that lights-out generation is partly ordinary and partly decades away, and the line between them is sharp enough to draw. Remote and unattended operation of low-hazard generation is unremarkable engineering practice, deployed at scale, with published operator disclosures behind it. Autonomous response inside a written envelope is real but narrow. Everything involving a machine forming a novel judgement about a hazardous process, or repairing itself, is speculation — and treating it as imminent is what makes energy audiences discount the credible parts.

Claim you will hearWhat is actually the caseStatusWhat would have to be true
"Power plants already run themselves"Large renewable and hydro fleets run without permanent site crews, controlled from remote centres, with humans on call. The control that acts is conventional DCS and protection logicIn serviceNothing — this is current practice for low-hazard asset classes
"AI decides what the plant does"AI does detection, diagnosis, triage and evidence assembly. The acting layer is deterministic and interlocked, because the safety case and the incident investigation both depend on it being soIn service, boundedA certification route for non-deterministic control on hazardous plant, which does not currently exist
"Nobody visits an unattended site"Unattended means no permanent crew. Maintenance, isolation, statutory inspection, sampling and consumables all bring people to site on a scheduleIn service, widely misunderstoodNothing — the claim is simply wrong as usually stated
"Plants will inspect and repair themselves"Robotic inspection is real and expanding — drones, crawlers, submersibles for waterways and confined spaces. Autonomous repair of rotating plant or pressure systems is notSplit: inspection in service, repair speculativeManipulation and qualification standards for robotic work on live plant under a permit regime
"Digital twins remove the need for instruments"Physics-based models are genuinely useful for performance, life consumption and what-if analysis. They interpolate between measurements; they do not replace missing onesIn service, over-claimedNothing — the physics does not permit it. Instrument the gap instead
"Nuclear will go lights-out"The operating fleet is staffed under licence conditions with minimum crewing. Advanced reactor concepts propose reduced staffing, and any change runs through the regulator over yearsSpeculative, licence-boundA regulator accepting a reduced-staffing case for a specific design, with operating evidence behind it
Claim, status and the condition that would move it up a class. 'In service' means publicly documented in operating plant; 'published research' means a named body has published work on it; 'speculation' means no operating evidence and no certification route today.

Digital data and analytics can reduce power system costs in at least four ways: by reducing operations and maintenance costs; improving power plant and network efficiency; reducing unplanned outages and downtime; and extending the operational lifetime of assets.

  • What the research bodies actually publish

    The IEA's Energy and AI (opens in a new tab) report surveys AI across the energy system, including generation operations and maintenance, and is explicit that data availability and skills are the binding constraints rather than model capability. EPRI's generation research (opens in a new tab) covers condition monitoring, plant flexibility and asset management for operating fleets, and its Open Power AI Consortium (opens in a new tab) exists because sector-specific models need sector-specific data that no single operator holds. None of that literature promises an unattended thermal plant.

  • What the governance frameworks add

    Unattended operation shifts the burden of proof onto documentation. NIST's AI Risk Management Framework (opens in a new tab) gives a usable vocabulary for characterising and monitoring risk in the model layer, and ISO/IEC 42001 (opens in a new tab) defines an AI management system in the same shape as the quality and safety management systems energy operators already run. Neither is a substitute for the unattended-operations basis; both make it easier to write one an auditor will accept.

  • What the codes and connection rules constrain

    A generating site is not free to define its own behaviour. Connection and performance obligations — the European requirements for generators (opens in a new tab) network code, and in Great Britain the obligations in the Grid Code (opens in a new tab) — specify frequency and voltage response, availability declarations and communications with the system operator. An unattended site still has to answer the phone, declare its availability and respond to instruction, which is an operating-model design constraint before it is a technical one.

  • What the cyber standards make non-optional

    Unattended operation concentrates a site's entire controllability into a network path, which changes the threat model rather than merely adding to it. The ISA/IEC 62443 series (opens in a new tab) is the reference architecture for segmenting that path, and for North American bulk-electric assets NERC CIP (opens in a new tab) turns much of it into compliance obligation. Loss-of-communications behaviour is part of the safety case: what the plant does when the ROC goes dark has to be a designed answer, not an emergent one.

  • What sits genuinely on the horizon

    Three things are plausibly changing within a planning horizon rather than a fantasy one: robotic inspection displacing a meaningful share of routine rounds; sensing costs falling far enough that instrumenting an old plant stops being a capital argument; and standardised unattended-operation cases for common asset classes, so each operator stops writing one from scratch. All three are engineering and paperwork. None requires a breakthrough in artificial intelligence.

What unattended generation looks like in public

Three publicly reported operations read against the ladder. None is an Atomic Loops engagement — each links to the operator's own published material.

The best public evidence for the attendance thesis is in what large operators actually built, and it is consistent: the differentiator is never a model, it is span of control plus the physical ability to act remotely. Read the three below against the ladder rather than as marketing. Each is a case where an operator published the numbers themselves; verify the figures against the linked source before reusing them.

Three operations, read against the attendance ladder

Outcomes as reported by the operators themselves. The images are generated industry scenes from our media library, not photographs of the named operators' sites, and imply no endorsement.

Scene: a utility fleet control room with a wall of generation and weather displays (illustrative, not a photograph of Duke Energy)Duke EnergyUS investor-owned utility · regulated renewable and hydro fleet13
Challenge
A large, geographically dispersed fleet of hydro stations, solar sites and batteries had historically been operated the way such plant always was: Duke Energy notes that each hydro station was staffed around the clock until operations were consolidated in 2000.
Approach
Consolidation into central operations centres. Duke Energy describes a Regulated Renewable Operations Center covering 76 hydro units, 33 solar sites and battery systems, with several hundred thousand alarms and almost 500 cameras, and a separate Renewable Control Center in Charlotte where around 30 employees on 12-hour shifts monitor and control wind, solar and batteries across 22 states — remotely starting and stopping equipment, forecasting generation, dispatching field technicians and supporting reliability compliance.
Reported outcome
Duke Energy reports operating roughly 5,500 MW from the regulated renewable centre, with quicker response to emerging issues and reduced operating costs, and describes the portfolio growing substantially by 2030 and 2035 without a proportional operations centre.
What it shows about the curveThis is rung three done properly, and the economics are span of control: the cost of watching the hundredth site is close to the cost of watching the tenth. Note what did not change — field technicians are still dispatched, because remote operation moves the work, it does not delete it.

Duke Energy — what it takes to operate 5,500 MW of renewable energy (opens in a new tab)

Scene: renewable generation assets with a remote monitoring overlay (illustrative, not a photograph of an Enel site)Enel Green PowerGlobal renewable generator · multi-country control-room network24
Challenge
A renewable portfolio spread across many countries and technologies, where per-site staffing would never amortise and per-country tooling would fragment the operating model.
Approach
A network of regional control and monitoring rooms rather than site control rooms, with plant digitalisation making it possible, in Enel Green Power's own words, to connect and control the renewable generation mix from a single point.
Reported outcome
Enel Green Power reports that its control room in Greece alone manages 481 MW of installed capacity across 59 plants, describing it as one of the largest and most modern of its kind.
What it shows about the curveThe number to take from this is 59 plants per room, not 481 MW. Span of control is the metric that decides whether unattended operation pays, and it is set by how much of each site can be acted on remotely — not by how many megawatts it holds.

Enel Green Power — control and monitoring room, Greece (opens in a new tab)

Scene: a utility-scale battery storage installation at dusk (illustrative, not a photograph of Hornsdale Power Reserve)Hornsdale Power ReserveSouth Australia · grid-scale battery, 150 MW45
Challenge
Delivering frequency and system-strength services on timescales where a human decision loop is physically impossible, while remaining accountable to the market operator for every response.
Approach
The site reports being built in two stages — 100 MW / 129 MWh completed in November 2017 and a 50 MW / 64.5 MWh expansion in September 2020 — with the full 150 MW subsequently upgraded to include Tesla's Virtual Machine Mode, enabling the battery to provide inertia support services to the grid. Human involvement sits in bidding policy, envelope design and market compliance rather than in any individual response.
Reported outcome
Hornsdale Power Reserve reports that in its first two years of operation it confirmed the benefits associated with grid-scale batteries in the National Electricity Market and saved South Australian consumers over $150 million.
What it shows about the curveThis is the clearest illustration that autonomy in generation is often set by physics rather than by ambition. Nobody debated whether to put an operator in this loop; the response times made it impossible. What was debated — and written down — is the envelope the plant is allowed to act within.

Hornsdale Power Reserve — about the project (opens in a new tab)

Read together, the three make a single point. The operators who removed permanent site crews did so on low-hazard asset classes, with conventional control systems, by building span of control and remote actuation — and they kept field technicians, callout rosters and maintenance visits. Nothing in the public record supports the stronger version of the lights-out story, and nothing in the public record is needed to justify the achievable version.

The unattended-operations stack, layer by layer

What has to exist for each rung, in build order — and why the top layer is a document rather than a system.

Unattended operation needs five layers, and the order in which you build them decides whether the programme converts into attendance or into slides. The stack below is deliberately vendor-neutral: every layer is defined by what it must guarantee, not by what product provides it, and each is annotated with the rung that first requires it. Nothing above a layer works reliably if the layer beneath it is partial.

Layers required by rung

Read bottom-up as a build order. A programme buying decision support before it has actuation and isolation is buying a better description of a site it still cannot act on.

  1. Plant and field

    Stage 1+

    • Instrumentation coverageTransmitters on every point the night round depended on
    • ActuationMotorised valves and drives on the critical path
    • Fixed detectionFire, gas, smoke, flood and intrusion, with health monitoring
  2. Control and protection

    Stage 2+

    • DCS logic and interlocksThe layer that is allowed to move plant
    • Protection philosophyWhich resets may ever be remote, and under what supervision
    • Safe-state and runback schemesA defined state the unit can be held in
  3. Connectivity and cyber

    Stage 3+

    • Segmented remote accessZones and conduits, logged, with break-glass
    • Redundant telemetryA second independent path, and a designed loss-of-comms behaviour
    • Identity and supervisionNamed operators, session recording, dual authorisation for high-consequence actions
  4. Detection and decision

    Stage 3+

    • Condition and anomaly modelsDetection and diagnosis, upstream of the acting layer
    • Alarm rationalisationA manageable steady-state rate, or no response can be pre-approved
    • Evidence assemblyEvery escalation arrives as a package, not a phone call
  5. Unattended-operations basis

    Stage 4+

    • Conditions and ownerWhen unattended operation applies, what ends it, who owns it
    • Time-to-humanMeasured, contracted, seasonal, and binding on every response
    • Response catalogueVersioned, reviewed, tested against real events
    • External agreementsInsurer, fire service, system operator, regulator where applicable

Pipeline described

  1. Plant and field (stage 1+) — Instrumentation coverage: Transmitters on every point the night round depended on; Actuation: Motorised valves and drives on the critical path; Fixed detection: Fire, gas, smoke, flood and intrusion, with health monitoring
  2. Control and protection (stage 2+) — DCS logic and interlocks: The layer that is allowed to move plant; Protection philosophy: Which resets may ever be remote, and under what supervision; Safe-state and runback schemes: A defined state the unit can be held in
  3. Connectivity and cyber (stage 3+) — Segmented remote access: Zones and conduits, logged, with break-glass; Redundant telemetry: A second independent path, and a designed loss-of-comms behaviour; Identity and supervision: Named operators, session recording, dual authorisation for high-consequence actions
  4. Detection and decision (stage 3+) — Condition and anomaly models: Detection and diagnosis, upstream of the acting layer; Alarm rationalisation: A manageable steady-state rate, or no response can be pre-approved; Evidence assembly: Every escalation arrives as a package, not a phone call
  5. Unattended-operations basis (stage 4+) — Conditions and owner: When unattended operation applies, what ends it, who owns it; Time-to-human: Measured, contracted, seasonal, and binding on every response; Response catalogue: Versioned, reviewed, tested against real events; External agreements: Insurer, fire service, system operator, regulator where applicable
Step-by-step insights
Plant and field — the layer that decides the budget
Almost every unattended programme is priced wrongly at the start because this layer is assumed to be adequate. It rarely is: the main unit is well instrumented and the balance of plant — cooling water, compressed air, fire systems, drainage, standby supplies — is where the local gauges and hand-operated valves live, and where the night round actually spends its time. Survey the balance of plant before committing to a date. Fixed thermal and acoustic imaging deserves specific attention, because it replaces the sensory judgements experienced operators make on walkdowns and that no point-value transmitter captures.
Control and protection — the boundary that keeps the case defensible
This is the only layer permitted to move plant, and keeping that true is what makes the safety case writable. The hard conversation is protection reset: which protection operations may be reset remotely, under what supervision, with what evidence that the cause has cleared. Get a protection engineer to write that policy explicitly, because the default answer inherited from an attended era is 'none', and an unattended site whose every protection operation requires a drive is not unattended in any useful sense.
Connectivity and cyber — design the dark case first
Unattended operation concentrates a site's whole controllability into a network path, so the interesting design question is not how the path works but what the plant does when it fails. Loss-of-comms behaviour must be an explicit, tested design decision — hold, run back, shut down, or continue for a defined period — and it belongs in the unattended basis, not in a configuration file. Segmentation along ISA/IEC 62443 lines and, for North American bulk-electric assets, NERC CIP obligations, then determine how remote access is granted, recorded and revoked.
Detection and decision — where the AI actually earns its place
This layer converts signals into decisions a human or a pre-approved response can act on: anomaly detection against normal operating envelopes, diagnosis ranked by probable cause, triage that distinguishes a real event from an instrument failure, and evidence assembled for escalation. Its value is measured in two currencies — callouts avoided and time-to-diagnosis on real events — and both are readable from logs. Note the dependency: without alarm rationalisation beneath it, this layer inherits the flood and produces confident nonsense.
The unattended-operations basis — the artefact everything else serves
The top layer is a document, and it is the deliverable that distinguishes an unattended site from a site with nobody on it. It states the conditions, the responses, the time-to-human, the escalation path, the external agreements and the review triggers. Treat it as a control rather than a record: put it under management of change, give it an owner with the authority to end unattended operation, and require every plant modification, roster change and market-rule change to test it. Sites that skip this layer are not at rung four; they are at rung three with an unrecorded risk transfer.

The layer most often skipped is the second, and skipping it is why so many programmes stall with excellent dashboards. Remote visibility without a remote safe state produces better-informed callouts, which is a real but small benefit. The step change comes from being able to put the unit somewhere safe and hold it there long enough for a person to arrive — everything the attendance model depends on is downstream of that single capability.

A 90-day plan: unattended nights at one hydro station

The rung two to rung four transition made concrete on one problem — removing the permanent night shift from a small hydro station. Contains no model development.

Ninety days is enough to make one site's nights unattended, and nowhere near enough to change a fleet's crewing model. The plan below therefore runs the transition on a single, common Energy & Utilities problem: a small run-of-river hydro station carrying two operators every night to perform rounds that a month of logs shows produce almost no interventions. It contains no model development, because at rung two the detection capability usually already exists and the constraint is field dependence, actuation and the basis.

From attended nights to four unattended nights a week, in one quarter

One station, one shift pattern, one named owner. If a phase overruns, narrow the scope — fewer nights, a shorter window — rather than extending the plan. The end state is deliberately partial: four nights, not seven.

  1. Days 1–15

    Write the night task inventory and baseline the callouts

    Shadow the night shift for two weeks and record every task performed, with the instrument, actuator or design change that would remove it. Pull twelve months of callout logs, alarm counts per hour, EFOR and unit trips. Measure time-to-human properly: drive it, at night, in the worst season you have data for. Name the operations owner — this is their number, not the project's.

    A costed removal list and a measured time-to-human

  2. Days 16–45

    Close the sensing and actuation gaps the night list depends on

    Instrument the local-only points the round actually reads — typically twenty to forty transmitters, plus fixed thermal imaging on the assets operators listen to and touch. Motorise the two or three valves in the safe-state path. Verify fire and intrusion detection health monitoring. Nothing here is AI work, and this phase is where most of the money and most of the schedule risk sits.

    The night round is observable and the safe state is reachable

  3. Days 46–70

    Rationalise alarms and write the pre-approved response catalogue

    Rationalise the alarms that would reach a remote operator until the steady-state rate is manageable, then write the response catalogue: for each credible night event, what the plant does automatically, how long it can hold that state, and what triggers escalation. Have the ROC run the nights with the site crew present, so the catalogue is tested with a safety net. Drill the runback and the trip deliberately, on a quiet night.

    A reviewed response catalogue, exercised with cover

  4. Days 71–90

    Sign the basis and run four unattended nights

    Complete the unattended-operations basis: conditions, responses, time-to-human, escalation, review triggers and owner. Walk the site with the local fire service and confirm the insurer has the arrangement in writing. Then run four unattended nights a week for a month and report against the baseline — callouts, alarm rate, trips, EFOR, and any condition that ended unattended operation and why.

    Four unattended nights a week, with evidence

The order matters

  1. Sensing before autonomy

    A modest detection model on a fully instrumented plant is worth far more than an excellent one on a plant whose critical values sit on local gauges. Instrument the twenty points the night round depends on before buying anything that analyses them.

  2. Isolation before absence

    Nobody signs off unattended operation on a site that cannot be driven to a safe state and held there from somewhere else. Build the safe-state path and drill it before the roster conversation starts, not as a follow-up work package.

  3. Time-to-human before headcount

    Measure the real arrival time — at night, in winter, with the usual road closed — and let that number bound every automatic response. A site whose worst-case time-to-human is three hours needs responses that hold for three hours, or it is not a candidate this year.

  4. Four nights before seven

    Partial unattended operation is a legitimate and durable end state. It banks most of the roster benefit, keeps the hardest nights attended, and gives the basis a season of real operating evidence before anyone asks it to cover the whole week.

Proving it: the metrics that survive scrutiny

What to instrument so the attendance claim is telemetry rather than testimony — formula, source system and the rung at which each becomes honest.

The claim that a site runs unattended has to be provable from logs, because the people who will test it — an insurer after a loss, a regulator after an event, a finance director during a budget cycle — do not accept testimony. Every metric below reduces to timestamps and counts that the DCS, historian, SCADA, CMMS and callout system already record. The instrumentation work is joining them and agreeing definitions, not creating new data.

MetricFormula / readSourceCadenceHonest from
Local-only indication countPoints a night round reads that are not historisedWalkdown survey + historian point listPer site, per reviewRung 1
Remote actuation coverageRemotely writable actions ÷ actions in the normal cycleDCS point list + remote-access policyPer site, per changeRung 2
Callout rateCallouts per site per month, split by cause and hourCallout / on-call systemMonthlyRung 2
Time-to-diagnosisFirst alarm timestamp → cause identified in the logHistorian + ROC logPer eventRung 2
Time-to-humanEscalation timestamp → competent person on siteCallout system, measured not estimatedPer escalation, seasonal reviewRung 3
Safe-state reachabilityDrills reaching the defined safe state ÷ drills attemptedDCS event logQuarterly drillRung 3
Unattended hoursHours with nobody on site, within basis conditionsAccess control + rosterWeeklyRung 4
Response-catalogue coverageReal events matched by a pre-approved response ÷ real eventsEvent reviewMonthlyRung 4
Escalation rateEscalations ÷ unattended hoursROC logWeeklyRung 4
EFOR deltaForced outage rate vs the attended baseline, same seasonGeneration reportingQuarterlyRung 4
Build sheet for the core unattended-operation metrics. 'Honest from' is the rung at which the metric first measures something real — reporting it earlier produces a number with no referent.

Two disciplines make the whole sheet trustworthy. First, attendance metrics and reliability metrics are always reported as a pair: unattended hours without an EFOR comparison is a cost story with the risk deleted, and a reliability number without an attendance number does not tell you what was bought. Second, every comparison is seasonal — a station that ran unattended beautifully through August has demonstrated nothing about February, which is when time-to-human, access and fault rates all move together.

Unattended-night readiness checklist

Eight conditions. If you cannot tick all eight, the site is not ready for unattended nights regardless of how good the monitoring is. Tick as you go — this list works without JavaScript.

0 of 8 ticked

Nothing ticked yet — start with the walkdown, not the tooling

A blank list is the normal starting point for an attended site, and it is not a bad position. The first move costs almost nothing: shadow the night shift for two weeks, write the task inventory, and count the local-only indications. Everything on this list becomes a costed line once that document exists.

How unattended sites get re-crewed

Attendance gains are not permanent. Four regressions account for almost all of the ground that gets given back.

Sites regress, and they usually regress quietly, because the conditions that justified unattended operation stopped holding without anyone declaring it. The four failure modes below account for almost all of the ground given back, and three of the four are organisational rather than technical — which is also why they are cheap to prevent and embarrassing to explain afterwards.

Likelihood: highImpact: high

The basis expires without anyone noticing

A pump is replaced with a different starting characteristic, a detection head is isolated for building work, a valve is left in manual after an outage. Each change is individually reasonable and none triggers a review, so the site drifts out of the conditions under which unattended operation was justified — and the drift is discovered during an event, in front of people asking why.

PreventionMake the unattended basis a mandatory check in management of change, with the same status as a safety-critical drawing.

Likelihood: highImpact: high

Time-to-human degrades underneath a fixed envelope

The on-call group shrinks, an engineer moves further away, a depot closes, a bridge goes under repair for a season. The automatic responses were designed to hold the plant for ninety minutes and now the nearest competent person is three hours out, which nobody recalculated because arrival time is not on anybody's dashboard.

PreventionMeasure time-to-human quarterly and on every roster change; make the envelope explicitly conditional on it.

Likelihood: mediumImpact: high

The first real upset arrives as an alarm flood

Rationalisation was descoped to hit a date, so the ROC operator covering forty sites meets a genuine event as ninety alarms in two minutes with no ranking. The pre-approved response either does not fire or fires on the wrong cause, and the organisational conclusion is that unattended operation is unsafe rather than that the alarm system was never finished.

PreventionTreat a manageable steady-state alarm rate as a gate for unattended status, not as a nice-to-have work package.

Likelihood: lowImpact: high

The envelope is inherited by an asset class that never earned it

An arrangement proven on solar and batteries gets extended to a hydro station or a peaker because the control platform is shared. The platform is shared; the fire load, isolation requirements, hazard inventory and failure modes are not, and the first serious event on the new asset class typically ends unattended operation everywhere.

PreventionEach asset class earns its own basis from its own operating evidence — no inheritance, no exceptions.

The pattern across all four is that unattended operation is a claim about a set of conditions, and conditions decay. Operators who hold the gains treat the basis, the envelope and time-to-human the way they treat protection settings — owned, versioned, reviewed on a schedule and re-proven after change. That discipline sits closer to sector governance practice (opens in a new tab) and to the regulatory expectations set out by bodies such as Ofgem (opens in a new tab) than to anything in a machine-learning workflow, and it is the part of the programme that has to outlast its sponsor.

Glossary

Hover a term for its definition — or expand the map full screen. The full definitions are written out below.

Unattended operation
Running a generating site with nobody present for defined periods under a written basis. It does not mean nobody visits — maintenance, isolation, sampling and statutory inspection all still bring people to site on a schedule.
Unattended-operations basis
The written case stating the conditions under which a site may run with nobody present, what ends those conditions, what the plant does automatically in each named event, how long it holds that state, and who arrives when it cannot. The defining artefact of rung four.
Time-to-human
The measured elapsed time from an escalation to a competent person being on site, in the worst credible season and traffic conditions. It bounds every automatic response, because a response must hold the plant safely until someone arrives.
Remote actuation coverage
The share of the actions in a site's normal operating cycle that can be performed from a remote operations centre. The counterpart to telemetry coverage, and the number that attendance actually responds to.
Safe state
A defined plant condition — typically a reduced load, a controlled shutdown or an isolated standstill — that the unit can be driven to and held in without a person present, for a stated duration.
Runback
An automatic or commanded reduction in unit output in response to a plant limitation, holding the unit online at a lower load rather than tripping it. The most attendance-relevant remote capability on most thermal and hydro plant.
Alarm rationalisation
Systematically reviewing every alarm for purpose, priority, response and setpoint so that alarms indicate causes rather than consequences. A prerequisite for any pre-approved response catalogue, because floods make responses undecidable.
Pre-approved response catalogue
The versioned list of automatic actions the plant may take on its own for named events, with the hold duration and escalation trigger for each. Reviewed by operations and safety, and tested against real events rather than assumed.
EFOR
Equivalent forced outage rate: the proportion of demanded operating time lost to forced outages and forced deratings. The standard generation reliability metric, and the one that has to be compared against an attended baseline in the same season.
Permit to work and LOTO
The authorisation and physical isolation regime controlling work on plant. Isolation and its verification are hands-on by law and by physics, so unattended sites schedule maintenance into attended windows rather than automating around it.
Balance of plant
Everything outside the main generating unit — cooling water, compressed air, fire systems, drainage, standby supplies, fuel handling. The usual home of local-only indications and hand-operated valves, and therefore of most attendance.
Grid-forming inverter
An inverter that establishes voltage and frequency rather than following an existing waveform, allowing storage or renewables to provide inertia-like system support. Its response is faster than any human loop, which is why some autonomy in generation is set by physics rather than by policy.

Frequently asked questions

The questions operators ask most often when working out whether a site can stop being staffed.

What is a lights-out power plant?

A lights-out power plant is a generating site whose normal operating cycle runs with nobody present, under a written unattended-operations basis. The basis states the conditions under which unattended operation applies, what the plant does automatically in each named event, how long it can hold that state, and who arrives when it cannot. The phrase describes an attendance model, not a technology: sites qualify by having their manual tasks instrumented, actuated, designed out or scheduled into attended windows, and by having a defensible written case behind the arrangement.

Are there unattended power plants operating today?

Yes, and they are unremarkable. Utility-scale solar, wind, battery storage and much small hydro run without permanent site crews, controlled from remote operations centres, with technicians dispatched for maintenance and faults. Duke Energy publicly describes operating around 5,500 MW of hydro, solar and batteries from a single regulated renewable operations centre, and Enel Green Power reports managing 59 plants from one control room in Greece. What is new is not the practice but its extension towards higher-hazard plant, which is where the constraints bind.

Does AI actually control an unattended plant, or just advise?

In every credible arrangement, AI advises and deterministic control logic acts. Models perform detection, diagnosis, triage and evidence assembly; the actions that move plant are DCS logic and protection functions that are interlocked, tested and explainable. That boundary is not conservatism for its own sake — the unattended-operations basis, the insurance position and any subsequent investigation all depend on being able to state exactly why the plant did what it did. Blurring the boundary makes the safety case substantially harder to write and to defend.

Why can a combined-cycle plant not run unattended overnight?

Usually because of the balance of plant rather than the turbine. A CCGT carries a large on-site hazard inventory — gas, high-pressure steam, hydrogen cooling, chemical storage — and a long list of tasks that need hands: chemistry sampling, local valve operations, filter and lubrication work, local resets and first-response fire duties. Fire and life-safety arrangements assume a response, and insurers price that assumption. Several of those constraints can be reduced with instrumentation and design change; some cannot, which is why reduced night crewing is a more realistic target than an empty site.

What is time-to-human and how should we set it?

Time-to-human is the measured time from an escalation to a competent person being on site. Set it by measuring, not estimating: drive it at night, in the worst season you have data for, with the usual route closed. It then becomes a hard design constraint, because every automatic response must hold the plant in a safe state for at least that long. Sites whose worst-case time-to-human exceeds what the plant can safely hold are not unattended candidates in the current configuration, however good the monitoring is.

Does remote monitoring reduce staffing on its own?

No. Remote monitoring is read-only by construction, so every remote diagnosis ends with someone driving to site. It genuinely improves reliability — developing faults are caught days or weeks earlier — but it does not change a roster, and programmes that report telemetry coverage as progress towards autonomy are measuring the wrong axis. The step that changes attendance is remote actuation and isolation: the ability to put the unit in a defined safe state and hold it there without anybody present.

Do cyber security rules prevent remote operation?

No, but they shape the architecture and belong in the design from the start. The ISA/IEC 62443 series provides the segmentation model — zones, conduits, controlled access — and for North American bulk-electric assets, NERC CIP turns much of that into compliance obligation. The specific requirement unattended operation adds is a designed loss-of-communications behaviour: what the plant does when the remote centre goes dark must be an explicit, tested decision recorded in the unattended basis, alongside a second independent telemetry path where the consequence justifies it.

How do you handle maintenance isolation at an unattended site?

You schedule it into attended windows. Physical isolation and its verification are hands-on requirements in every jurisdiction — control of hazardous energy is a hands-on discipline and no permit regime accepts a remote substitute. Unattended sites therefore plan planned work into periods when people are present, batch it to reduce visits, and design the maintenance strategy around visit frequency rather than trying to automate isolation. This is a scheduling problem with a well-understood answer, not a barrier to unattended operation.

Does unattended operation make reliability worse?

It can go either way, and the only honest answer comes from measurement. Unattended sites lose the informal recovery an on-site operator provides — the local reset, the nudge that avoids a trip — and gain earlier detection, faster diagnosis and consistent pre-approved responses. Report equivalent forced outage rate against an attended baseline in the same season, alongside unattended hours, and treat any deterioration as a signal that the response catalogue is incomplete rather than as proof the model was wrong.

Could a nuclear plant ever run lights-out?

Not the operating fleet, and not on any timescale worth planning around. Licensed nuclear plants are staffed under licence conditions with minimum crewing requirements, and changing those requires a regulator to accept a reduced-staffing case supported by operating evidence — a multi-year process tied to a specific design. Some advanced reactor concepts propose smaller operating crews, but that is a licensing question rather than an AI question. AI in nuclear today is advisory: condition monitoring, procedure support and outage planning, all with a human accountable.

Where should a mixed fleet start?

Start where the hazard is low and attendance is habitual — typically older small hydro, legacy solar and standby sites staffed by inheritance rather than by risk assessment. Those sites produce an attributable attendance result inside two quarters, and the mechanism they prove is the same one that higher-hazard plant will need. Spend that credibility on the harder cases afterwards. Sequencing the other way round, starting with the thermal site that has the biggest roster, is the most reliable way to stall the programme in a safety-case argument.

What does an unattended-operations basis actually contain?

Six things: the conditions under which unattended operation applies, the events that end it, the pre-approved automatic responses with their hold durations, the measured time-to-human, the escalation path and evidence requirements, and the external agreements covering fire, security and insurance. It also names an owner with authority to suspend unattended operation, and states its review triggers. Treat it as a control document under management of change rather than as a report — a basis that is not re-tested after plant modifications expires silently.

About the author

Atomic Loops Engineering

Industrial AI practice

Atomic Loops builds production AI systems for energy, manufacturing and logistics operators — condition monitoring, forecasting, anomaly detection and decision support running against live plant data, integrated into the DCS, historian and work-management layer rather than delivered as dashboards.

  • · Condition-monitoring and anomaly-detection systems on generating plant
  • · Integration-first delivery: historian, DCS boundary, CMMS write-back, rollback
  • · Readiness reviews run jointly with operations, control and safety engineers
  • · 23 cited sources on this page

Sources

  1. International Energy AgencyDigitalisation and Energy (opens in a new tab)
  2. International Energy AgencyEnergy and AI (opens in a new tab)
  3. International Energy AgencyElectricity system analysis (opens in a new tab)
  4. IRENARenewable Capacity Statistics 2025 (opens in a new tab)
  5. U.S. Energy Information AdministrationElectricity data and analysis (opens in a new tab)
  6. NERCLong-Term Reliability Assessments (opens in a new tab)
  7. NERCCIP standards (opens in a new tab)
  8. EPRIGeneration sector research (opens in a new tab)
  9. EPRIOpen Power AI Consortium (opens in a new tab)
  10. NISTAI Risk Management Framework (opens in a new tab)
  11. International Society of AutomationISA/IEC 62443 series (opens in a new tab)
  12. ISOISO/IEC 42001 — AI management systems (opens in a new tab)
  13. UK Health and Safety ExecutiveLone working guidance (opens in a new tab)
  14. OSHAControl of hazardous energy (lockout/tagout) (opens in a new tab)
  15. NFPACodes and standards (incl. NFPA 850) (opens in a new tab)
  16. NESOThe Grid Code (opens in a new tab)
  17. ENTSO-ERequirements for Generators network code (opens in a new tab)
  18. OfgemEnergy policy and regulation (opens in a new tab)
  19. EurelectricEuropean electricity industry association (opens in a new tab)
  20. Duke EnergyWhat it takes to operate 5,500 MW of renewable energy (opens in a new tab)
  21. Duke EnergyLook inside Duke Energy's Renewable Control Center (opens in a new tab)
  22. Enel Green PowerControl and monitoring room, Greece (opens in a new tab)
  23. Hornsdale Power Reserve (Neoen)Hornsdale Power Reserve (opens in a new tab)

Find out which of your sites can actually stop being staffed

We walk one site with your operations and control engineers, write the field-task ledger, measure time-to-human, and leave you with a costed sequence from where the site is now to unattended nights. You keep the ledger and the sequence whether or not we build anything.

Published · Last updated

Benchmark request

Tell us where to send it

Benchmark for this page

Used once, to send this benchmark and follow it up personally. No newsletter, no automated sequences.