Win and keep energy customers on an AI-native experience, on data that stays sovereign.
In energy retail, the customer is up for grabs as never before: switching is easy, loyalty is thin, and AI-native challengers are winning on experience, personalised tariffs, proactive service, and real-time consumption insight. That runs on granular household data, which is why the customer stack stays sovereign, even as the grid it connects to remains critical infrastructure.
The shifts our research is tracking, named, current, cited.
Octopus Energy's Kraken platform now runs customer operations for utilities including EDF and E.ON Next, and was spun off in 2025 as a business of its own. An AI-native customer operating system is the sector's growth engine; the incumbents' choice is to match it or rent it.
Octopus Energy / Kraken →About 35% of Octopus Energy customer emails are now written with Kraken's Magic Ink generative-AI tool, and those AI-assisted replies score higher customer satisfaction (around 70%) than those without.
techUK →Iberdrola launched 'niba' in 2025 as a fully digital 'neo-energy' brand, using AI for a hyper-personalised single-app experience, real-time consumption analytics, and tailored savings, with no branches. Incumbents are being out-experienced.
Iberdrola →NIS2 and the Critical Entities Resilience directive classify energy as critical infrastructure, so a third-country AI dependency in your stack is a supply-chain exposure, and Gartner names energy and utilities among the core buyers already moving to sovereign European cloud.
Gartner →In energy, the retail customer is won on AI-native experience and kept on trust, and the household data behind it stays sovereign, as does the grid it powers.
Energy retail has become a customer-experience business: switching is frictionless, loyalty is thin, and AI-native challengers, Octopus's Kraken operating system, Iberdrola's fully digital 'niba' brand, are winning on personalised tariffs, proactive service, and real-time consumption insight. The experience runs on granular household data: a diary of how every family lives.
Personalise acquisition, switching, and retention on sovereign, first-party consumption data and you win and keep customers on the experience, while grid and trading data stay inside the critical-infrastructure perimeter NIS2 requires. Run the customer stack on an opaque US API and you have leaked how every household lives.
We build the sovereign customer stack and pick the right model for each job: acquisition and retention decisioned on EU compute, agentic service where frontier reasoning helps and identity stays home, grid and trading workloads sovereign by mandate. In energy, experience wins the customer and sovereignty keeps both them and the lights on.
| Workload | Placement | Rationale |
|---|---|---|
| Customer acquisition & switching | Sovereign | Household consumption data; belongs on EU compute. |
| Retention & personalised tariffs | Sovereign | Behavioural signal that must not leak. |
| Agentic customer service | Hybrid | Frontier reasoning; customer identity kept sovereign. |
| Grid & trading operations | Sovereign | Critical-infrastructure data under NIS2. |
Before any platform decision, one question settles the rest: how much of what your organisation knows can be written down precisely enough for a machine to act on it, and who ends up owning that writing. We run a short engagement to answer it, and it produces working artefacts rather than a report.
Two artefacts come out of this. An operating ontology, the nouns: the entities, relationships, and states your business actually runs on, described once and precisely. And agentic skills, the verbs: the procedures, thresholds, and judgments your best people apply, written down, versioned, and testable instead of retold.
A placement map addressed to the CTO or CIO office: what runs on your compute, what is bought, what is rented, who holds the keys, and what each costs. One test cuts through most of the debate. If a supplier vanished on a Friday, what stops working on Monday, and how long would it take you to replace it?
Where an open-weight model fine-tuned or adapted on your own corpus beats a frontier call, where a small purpose-built model for one narrow task beats both, and where the frontier still earns its fee. Geographic sovereignty falls out of that answer rather than having to be argued for on its own.
Half-hourly consumption and asset telemetry are yours alone. A purpose-built small model forecasts on them locally, in a control room or a van, with no link to anywhere.
This is a CTO and CIO office engagement, not a procurement exercise. Your own people have to end up running it, because the moment the encoding is delegated, the thing being encoded quietly stops being yours.
Palantir calls this layer an ontology, and the idea is right: a governed model of your objects, links, and actions that agents can act on. It lives inside their platform. 8090 will design, build, host, and maintain the software around it for you. Both are serious, and both leave the same question open. At the end of it, who owns the layer that holds your judgment? We build the same artefacts in open formats, on compute you control, and hand your CTO the keys.
The same four layers we ship in legal, instantiated for an energy retailer or network, where meter data reveals the private life of a household half-hour by half-hour.
A household energy advisor grounded in the customer's own consumption, tariff and flexibility decisioning that can explain itself to a regulator, and a field and asset copilot that works where the signal does not.
Tariff mechanics, switching and billing rules, vulnerable-customer safeguarding, and field procedures compiled into skills, so automated advice is auditable against a position the business has actually agreed.
Half-hourly meter and in-home device data stays on sovereign compute by architecture. Grid and asset models run where the assets are, and the frontier is reserved for work that carries no household in it.
In your own estate, on a managed instance on sovereign infrastructure, or on hardware at the site itself for control-room and field work that cannot depend on a link staying up.
The application layer here is built for you, not bought. The pattern is the one we already ship, as a product, in legal.
The same software in every posture, so a team can start hosted and end up air-gapped without a migration project. You move along the ladder when you decide to, not when a contract renews.
Your stack stood up on our infrastructure in days and pointed at real work, so it is judged on your matters rather than on a demo. The pilot fee credits against the hardware when you migrate.
Teams that want proof before capital expenditure.
The open-source cores installed on a machine you own, by a script anyone can read first. No account with us, no telemetry, no phone-home. Code flows one way, from us to you, and only when you ask for it.
Small teams, and anyone who wants to inspect the source before trusting it.
An isolated instance per client on sovereign infrastructure, European by default, run, patched, and monitored by us, with the security and backup credentials in your hands rather than ours.
Organisations without an infrastructure team to spare.
Dedicated AI hardware inside your building, with the applications and the open-weight models you choose installed and tested before it ships. It runs with the network unplugged, and it keeps working whatever happens to us.
In energy the appliance earns its place wherever connectivity is the weak link: it keeps working in a substation, a control room, or a van.
Work that cannot leave the building, ever.
Not promises. Consequences of the architecture: your keys and your data are generated on your machine and stay there, and nothing calls home.
We send a sector-specific brief with workload-by-workload placement guidance and a reference architecture for sovereign deployment.