Atoms
Join the Praxis beta

Sector · Oil and gas

Physical AI for oil and gas

Wells, terminals and plants hold safety, inventory and process data in systems that were never joined, often on sites where the data may not leave the country. These are the questions engineers ask first, answered from 2 published CodeNinja Atoms reference architectures.

  1. What does a physical AI system for oil and gas look like?
  2. Which AI models can an oil and gas operator run on its own hardware?
  3. How much compute and hardware does AI in oil and gas need?
  4. Is it cheaper to own AI hardware or rent cloud GPUs in oil and gas?
  5. What ontology or object model does an oil and gas AI system need?
  6. Who approves the decisions an AI system makes in oil and gas?

What does a physical AI system for oil and gas look like?

A complete physical AI design for oil and gas names what to sense, which existing systems to join, the object model that joins them, the models and hardware, the three-year cost and the person who approves every action. CodeNinja Atoms has published 2 such reference architectures for oil and gas, each free to reuse under CC BY 4.0.

DesignCountryWhat it does
Sovereign HSE WatchPakistanAn open reference architecture for predicting HSE incidents at an oil and gas operator in Pakistan, on the operator's own hardware, with no data leaving the country and no third-party AI service in the serving path.
Loop Integrity WatchPakistanfield hardware that rebuilds the signal path on three Modbus loops, and a governed inventory ontology that catches a flatlined or swapped radar gauge reading before the central inventory picture misleads anyone.

Which AI models can an oil and gas operator run on its own hardware?

Each published oil and gas design names its models and why, and every model is open-weight or no model is used at all, so the operator can run it on hardware it owns.

DesignModels
Sovereign HSE Watch6 self-hosted open-weight models, including GLM 5.3 (reasoning), Chronos-2 (forecasting), RF-DETR (vision), BGE-M3 (retrieval in English and Urdu) and PaddleOCR-VL 1.6 (scans)
Loop Integrity WatchNone: every integrity check (stuck value, swap, distortion) is deterministic
DesignChoiceWhat was pickedWhy
Sovereign HSE WatchFrontier reasoning modelGLM 5.3 open weights at FP8, self-hostedStrongest open agentic model; the bespoke license exempts purely internal use from the model-as-a-service security-review trigger
Sovereign HSE WatchDetectorRF-DETR, Apache-2.0 Nano to Large checkpoints, BF16The practical sovereign answer to the AGPL gate; Plus XL and 2XL excluded from the serving path
Sovereign HSE WatchForecasterChronos-2, Apache-2.0, about 0.48 GB at 32 bitZero-shot multivariate forecasting with no field-of-use restriction; weights may be held, fine tuned and redistributed
Sovereign HSE WatchEmbeddingsBGE-M3, MIT, FP16Dense plus sparse plus multi-vector retrieval in one pass with an 8,192-token window
Sovereign HSE WatchDocument parsingPaddleOCR-VL 1.6, Apache-2.0, about 0.9B parameters, BF16Strong on degraded multilingual scans; no user or revenue threshold; fine tuning permitted
Sovereign HSE WatchTrackingRoboflow trackers, Apache-2.0Stable identity across frames without reintroducing copyleft after an Apache detector
Sovereign HSE WatchFrontier node classOne node of 8 x 141 GB HBM GPUs (H200 class)1,128 GB holds the 904 GB FP8 footprint with KV cache headroom
Sovereign HSE WatchEdge compute classThe operator's NPU/GPU accelerators, sized from measured stream and decode loadSizing is stated as a requirement and verified at the phase-one survey
Sovereign HSE WatchCameras reused subject to ONVIF reuse gatesThe existing Vision AI IP camera estate, stream evidence, with gaps priced as newReuse on measured density, angle and class purchases
Sovereign HSE WatchTime synchronization holdover, driving linuxptp and chronyOCP Time Card GNSS grandmaster with cameras and process tagsOne defensible chronology across detectors,
Sovereign HSE WatchEdge orchestration disconnected installRed Hat OpenShift AI self-managed, model serving, registry, pipelines andDocumented disconnected procedure for workbenches
Sovereign HSE WatchServing runtimes nodeKServe at the edge, vLLM on the centralModel serving matched to each tier's load
Loop Integrity WatchModel registerZero entries; all integrity logic is deterministic thresholds and rulesThe failure modes are physical and protocol-level, so no learned model is needed, no weights are held and no license question arises
Loop Integrity WatchHardware classFlameproof enclosure disciplineThe junction boxes sit in the classified area, so the enclosure class is chosen against the zone at each exact position, not by part number
Loop Integrity WatchHardware classArea classification as the gating documentThe zone, gas group and temperature class are read from the operator's current classification drawing before any hardware is specified, and the position list is countersigned
Loop Integrity WatchHardware classReading an Ex certification markingThe Eex'n' marking is a Zone 2 restricted-breathing class, so a Zone 1 position would force a different, heavier enclosure and must be caught before ordering
Loop Integrity WatchHardware classEquipment protection levels drive the purchaseProtection levels, not catalog convenience, decide the explosion proof junction boxes, 24VDC power supplies, breakers and M20 Exd glands
Loop Integrity WatchSensingradar tank gauges on all 13 tanksThese are the field devices whose readings must arrive continuous, undistorted and unswapped; the design improves their signal path without modifying them
Loop Integrity WatchSensing24VDC field power suppliesThey power the boosters and the loop electronics, and their health is a named failure mode with its own degraded status
Loop Integrity WatchSensing3-core 2.5 sq.mm CU/PVC/SWA/PVC loop cablingThe loop cabling is the medium the distortion travels in, so its schedule is recorded in the as-built against each loop
Loop Integrity WatchSensingModbus RTU loop polling via the boostersThe polling cycle is the pace of truth for every check, and the boosters are what make the three loops readable end to end
Loop Integrity WatchPatternSystem of Context, primaryThe central inventory picture is an ontology projection over the gauging host, never a shadow copy, so there is one place where tank truth lives
Loop Integrity WatchGroundThe operator's own site application server, on-premisesThe two containers run inside the operational technology boundary on the operator's own hardware, consistent with the Pakistani Cloud First posture, so nothing about tank truth depends on a link leaving the site

How much compute and hardware does AI in oil and gas need?

The compute follows from the models: the published oil and gas designs size it as follows, from no new hardware to a full GPU node.

DesignPartThe design
Sovereign HSE WatchFrontier computeOne node of eight 141 GB HBM-class GPUs holds GLM 5.3 at FP8 (753 GB of weights, 904 GB with headroom)
Sovereign HSE WatchThe hard dependency141 GB-class accelerators need a US export licence for Pakistan (Country Group D:4); the rollout's first gate confirms installed hardware first
Loop Integrity WatchComputeTwo containers on the operator's own site application server, inside its OT boundary
Loop Integrity WatchField scope13 fuel tanks on 3 Modbus RTU loops; 3 booster installations engineered from a measured signal survey inside explosion proof junction boxes

Is it cheaper to own AI hardware or rent cloud GPUs in oil and gas?

Each oil and gas design prices three years of ownership in its Appendix A, with every price cited, against renting the same capacity from a cloud region at its deepest three-year commitment where hardware is bought.

DesignLineThree years
Sovereign HSE WatchThree-year cost, ownedAbout 670,000 US dollars with support and power at Pakistan's industrial tariff
Sovereign HSE WatchThree-year cost, rented1.1 to 2.8 million US dollars for the same GPUs in the nearest cloud region; no hyperscaler runs a region in Pakistan
Loop Integrity WatchThree-year costNo compute to price; the field equipment is priced by OEM quotation against the survey (Appendix A)

What ontology or object model does an oil and gas AI system need?

The object model is the part that makes the system an ontology rather than a pipeline: typed objects for the things in the oil and gas operation, with properties, status values and typed links. Every published design ships its object model as hyper-ontology/1 JSON that loads into Hyper Ontology.

DesignSizeObjectsDownload
Sovereign HSE Watch12 objects, 14 linksOperating Facility / Site, HSE Equipment, HSE Incident, Near Miss Report, Corrective Action, Inspection / Audit Record, HSE Document, Sensor Reading, Anomaly Event, Agent Recommendation, HSE Person, HSE Roleobjects.json
Loop Integrity Watch15 objects, 15 linksFuel Tank, Radar Tank Gauge (RTG), RTG Communication Loop, Modbus Booster (Repeater), Explosion Proof Junction Box, Gauge Reading, Data Quality Event, Central Inventory Picture, Loop Wiring As-Built, Service Order, Warranty and Support Record, OEM Authorization Letter, HSE Work Permit, Instrumentation Technician, Location Engineerobjects.json

Who approves the decisions an AI system makes in oil and gas?

In every published oil and gas design a named person makes the decision that changes the physical world; the system prepares it.

DesignHuman control
Sovereign HSE WatchEvery recommendation is approved or rejected by a named person; nothing executes on equipment
Loop Integrity WatchEvery data quality event is acknowledged and resolved by a named person; the location engineer signs acceptance

Every answer on this page is drawn from the papers linked in it: each paper's At a glance table, model register and cost appendix. Full text for agents: llms-full.txt. Designed on Praxis; object models load into Hyper Ontology.