Regulation Neutral 5

1 Utility Filing Could Redefine Regulatory Data Security

Evergy's July 30 request to the Kansas Corporation Commission would bar confidential utility docket information from open AI tools while allowing closed systems. For security teams, the filing frames authorized insiders as a data-exposure vector and raises questions about data loss prevention in regulated workflows.

· 4 min read ·

Cybersecurity briefing

Key takeaways

5 impact
Neutralsentiment
4min read
  1. Evergy's July 30 request to the Kansas Corporation Commission would bar confidential utility docket information from open AI tools while allowing closed systems.
  2. For security teams, the filing frames authorized insiders as a data-exposure vector and raises questions about data loss prevention in regulated workflows.

In this briefing

Mentioned

Key Intelligence

Key Facts

  1. 1Evergy filed a request with the Kansas Corporation Commission on July 30, 2026, to amend the standard protective order for regulatory cases.
  2. 2The proposed amendment would prohibit confidential case information from being used in open AI tools while allowing secure, closed AI systems with appropriate safeguards.
  3. 3Evergy spokesman Matt Lucht said the company must protect business, customer and infrastructure-related information from disclosure.
  4. 4KCC Director of Utilities Justin Grady warned that someone could dump confidential files into a large language model and ask it to identify weaknesses or deficiencies in a filing.
  5. 5The filing was reported by the Great Bend Post and Hays Post on August 13, 2026, highlighting the rapid growth of generative AI in professional use.
  6. 6Evergy does not allege a specific breach; the request is a preventive governance measure aimed at future AI-related disclosure risk.

dump all of their files into some new large language model and say what were the weaknesses or the deficiencies that were in this filing

Justin Grady Director of Utilities, Kansas Corporation Commission

Describing generative AI risk to confidential regulatory documents

Analysis

For security practitioners, Evergy's filing is not about an external breach but about an insider-risk path: a staffer, intervenor, or attorney with legitimate access to a confidential docket could paste it into an open AI tool and lose control of the data. The utility wants protective orders to close that gap before customer, business, or infrastructure information leaks through model training or reuse.

Evergy filed a request with the Kansas Corporation Commission on July 30, 2026, asking utility regulators to amend the standard protective order used in contested dockets so confidential case information cannot be uploaded into open artificial intelligence tools. The filing, first reported by the Great Bend Post and Hays Post on August 13, would permit the use of secure, closed AI systems with appropriate safeguards while prohibiting open AI tools from ingesting protected material. It represents one of the earliest utility-sector efforts to preempt generative AI as a data-exposure risk in regulatory proceedings, not in response to a known breach but as a prospective governance measure.

The filing, first reported by the Great Bend Post and Hays Post on August 13, would permit the use of secure, closed AI systems with appropriate safeguards while prohibiting open AI tools from ingesting protected material.

Matt Lucht, Evergy spokesman, said confidential information is regularly given to regulators to help stakeholders in the decision-making process, but the company must also protect business, customer and infrastructure-related information from disclosure. He added that Evergy wants to ensure it can continue to openly share information with regulators and case intervenors while maintaining appropriate confidentiality. The filing is less about restricting access to regulators and more about controlling what happens to sensitive documents once authorized users possess them.

The concern reflects how quickly generative AI has entered professional workflows. Artificial intelligence tools now transcribe meeting notes, summarize emails and write letters for the general public. In business settings, the same tools are developing strategic plans, helping attorneys draft court documents and assessing competition. That shift creates a gap in legal instruments written before large language models became widely available. A standard protective order may bind human users to confidentiality, but it does not necessarily address the automated retention, reuse or training exposure that can occur when a user pastes protected text into a consumer AI platform.

Justin Grady, KCC director of utilities, described the risk in stark terms. He said "the sky's the limit" regarding how people could use confidential information with generative AI tools. Grady outlined a scenario in which an individual with access to a confidential regulatory document could "dump all of their files into some new large language model and say what were the weaknesses or the deficiencies that were in this filing." Generative AI creates new content by drawing from large datasets and learning as it goes, which means input data may not be reliably contained or forgotten. For a regulated utility, that could expose trade secrets, customer data or critical infrastructure details through an ordinary workflow action.

The filing draws a meaningful distinction between open and closed AI systems. Open tools are widely accessible and easy to use, but their data handling practices may be opaque or include training on user inputs. Closed systems, by contrast, can be controlled, audited and potentially isolated from external model training. Evergy's proposed amendment would allow the latter with safeguards while blocking the former. This distinction is likely to become a recurring theme in enterprise and regulatory data governance because it offers a practical compromise: confidentiality can be preserved without prohibiting AI-assisted analysis altogether.

From a cybersecurity perspective, the filing frames an insider-risk issue rather than a classic external intrusion. A staff member, attorney or intervenor with legitimate access to a confidential docket could bypass traditional data loss prevention controls simply by pasting content into an open AI tool. No network compromise is required for sensitive information to leave the controlled environment. That makes the protective order amendment a governance control designed to reduce an accidental or careless disclosure path that is difficult to detect after the fact.

What to Watch

The Kansas Corporation Commission now faces the harder task of defining terms such as "open AI tools" and "appropriate safeguards" in a legal instrument that may be applied across many future cases. If the commission adopts Evergy's request, it could set a precedent for other state utility commissions and for regulated industries such as insurance, banking and health care, where similar protective orders govern the exchange of confidential evidence among parties.

Looking ahead, the KCC's response will be watched closely by utilities, intervenors and AI governance professionals. The decision may shape whether protective orders across the country are updated to address generative AI directly, and whether open versus closed AI becomes a standard clause in regulatory data-sharing agreements. Evergy's filing is narrow in scope, but it addresses a broad and rapidly evolving risk that regulators have only begun to confront.

Timeline

Timeline

  1. Evergy files protective order amendment request

  2. Kansas outlets report on the filing

Cite This Page

"1 Utility Filing Could Redefine Regulatory Data Security." Cyber Intelligence Brief, August 14, 2026. https://getcyberbrief.com/story/evergy-kansas-regulators-ai-confidential-data-security

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.