Sector · Oil and gas
Physical AI for oil and gas
Wells, terminals and plants hold safety, inventory and process data in systems that were never joined, often on sites where the data may not leave the country. These are the questions engineers ask first, answered from 2 published CodeNinja Atoms reference architectures.
- What does a physical AI system for oil and gas look like?
- Which AI models can an oil and gas operator run on its own hardware?
- How much compute and hardware does AI in oil and gas need?
- Is it cheaper to own AI hardware or rent cloud GPUs in oil and gas?
- What ontology or object model does an oil and gas AI system need?
- Who approves the decisions an AI system makes in oil and gas?
What does a physical AI system for oil and gas look like?
A complete physical AI design for oil and gas names what to sense, which existing systems to join, the object model that joins them, the models and hardware, the three-year cost and the person who approves every action. CodeNinja Atoms has published 2 such reference architectures for oil and gas, each free to reuse under CC BY 4.0.
| Design | Country | What it does |
|---|---|---|
| Sovereign HSE Watch | Pakistan | An open reference architecture for predicting HSE incidents at an oil and gas operator in Pakistan, on the operator's own hardware, with no data leaving the country and no third-party AI service in the serving path. |
| Loop Integrity Watch | Pakistan | field hardware that rebuilds the signal path on three Modbus loops, and a governed inventory ontology that catches a flatlined or swapped radar gauge reading before the central inventory picture misleads anyone. |
Which AI models can an oil and gas operator run on its own hardware?
Each published oil and gas design names its models and why, and every model is open-weight or no model is used at all, so the operator can run it on hardware it owns.
| Design | Models |
|---|---|
| Sovereign HSE Watch | 6 self-hosted open-weight models, including GLM 5.3 (reasoning), Chronos-2 (forecasting), RF-DETR (vision), BGE-M3 (retrieval in English and Urdu) and PaddleOCR-VL 1.6 (scans) |
| Loop Integrity Watch | None: every integrity check (stuck value, swap, distortion) is deterministic |
| Design | Choice | What was picked | Why |
|---|---|---|---|
| Sovereign HSE Watch | Frontier reasoning model | GLM 5.3 open weights at FP8, self-hosted | Strongest open agentic model; the bespoke license exempts purely internal use from the model-as-a-service security-review trigger |
| Sovereign HSE Watch | Detector | RF-DETR, Apache-2.0 Nano to Large checkpoints, BF16 | The practical sovereign answer to the AGPL gate; Plus XL and 2XL excluded from the serving path |
| Sovereign HSE Watch | Forecaster | Chronos-2, Apache-2.0, about 0.48 GB at 32 bit | Zero-shot multivariate forecasting with no field-of-use restriction; weights may be held, fine tuned and redistributed |
| Sovereign HSE Watch | Embeddings | BGE-M3, MIT, FP16 | Dense plus sparse plus multi-vector retrieval in one pass with an 8,192-token window |
| Sovereign HSE Watch | Document parsing | PaddleOCR-VL 1.6, Apache-2.0, about 0.9B parameters, BF16 | Strong on degraded multilingual scans; no user or revenue threshold; fine tuning permitted |
| Sovereign HSE Watch | Tracking | Roboflow trackers, Apache-2.0 | Stable identity across frames without reintroducing copyleft after an Apache detector |
| Sovereign HSE Watch | Frontier node class | One node of 8 x 141 GB HBM GPUs (H200 class) | 1,128 GB holds the 904 GB FP8 footprint with KV cache headroom |
| Sovereign HSE Watch | Edge compute class | The operator's NPU/GPU accelerators, sized from measured stream and decode load | Sizing is stated as a requirement and verified at the phase-one survey |
| Sovereign HSE Watch | Cameras reused subject to ONVIF reuse gates | The existing Vision AI IP camera estate, stream evidence, with gaps priced as new | Reuse on measured density, angle and class purchases |
| Sovereign HSE Watch | Time synchronization holdover, driving linuxptp and chrony | OCP Time Card GNSS grandmaster with cameras and process tags | One defensible chronology across detectors, |
| Sovereign HSE Watch | Edge orchestration disconnected install | Red Hat OpenShift AI self-managed, model serving, registry, pipelines and | Documented disconnected procedure for workbenches |
| Sovereign HSE Watch | Serving runtimes node | KServe at the edge, vLLM on the central | Model serving matched to each tier's load |
| Loop Integrity Watch | Model register | Zero entries; all integrity logic is deterministic thresholds and rules | The failure modes are physical and protocol-level, so no learned model is needed, no weights are held and no license question arises |
| Loop Integrity Watch | Hardware class | Flameproof enclosure discipline | The junction boxes sit in the classified area, so the enclosure class is chosen against the zone at each exact position, not by part number |
| Loop Integrity Watch | Hardware class | Area classification as the gating document | The zone, gas group and temperature class are read from the operator's current classification drawing before any hardware is specified, and the position list is countersigned |
| Loop Integrity Watch | Hardware class | Reading an Ex certification marking | The Eex'n' marking is a Zone 2 restricted-breathing class, so a Zone 1 position would force a different, heavier enclosure and must be caught before ordering |
| Loop Integrity Watch | Hardware class | Equipment protection levels drive the purchase | Protection levels, not catalog convenience, decide the explosion proof junction boxes, 24VDC power supplies, breakers and M20 Exd glands |
| Loop Integrity Watch | Sensing | radar tank gauges on all 13 tanks | These are the field devices whose readings must arrive continuous, undistorted and unswapped; the design improves their signal path without modifying them |
| Loop Integrity Watch | Sensing | 24VDC field power supplies | They power the boosters and the loop electronics, and their health is a named failure mode with its own degraded status |
| Loop Integrity Watch | Sensing | 3-core 2.5 sq.mm CU/PVC/SWA/PVC loop cabling | The loop cabling is the medium the distortion travels in, so its schedule is recorded in the as-built against each loop |
| Loop Integrity Watch | Sensing | Modbus RTU loop polling via the boosters | The polling cycle is the pace of truth for every check, and the boosters are what make the three loops readable end to end |
| Loop Integrity Watch | Pattern | System of Context, primary | The central inventory picture is an ontology projection over the gauging host, never a shadow copy, so there is one place where tank truth lives |
| Loop Integrity Watch | Ground | The operator's own site application server, on-premises | The two containers run inside the operational technology boundary on the operator's own hardware, consistent with the Pakistani Cloud First posture, so nothing about tank truth depends on a link leaving the site |
How much compute and hardware does AI in oil and gas need?
The compute follows from the models: the published oil and gas designs size it as follows, from no new hardware to a full GPU node.
| Design | Part | The design |
|---|---|---|
| Sovereign HSE Watch | Frontier compute | One node of eight 141 GB HBM-class GPUs holds GLM 5.3 at FP8 (753 GB of weights, 904 GB with headroom) |
| Sovereign HSE Watch | The hard dependency | 141 GB-class accelerators need a US export licence for Pakistan (Country Group D:4); the rollout's first gate confirms installed hardware first |
| Loop Integrity Watch | Compute | Two containers on the operator's own site application server, inside its OT boundary |
| Loop Integrity Watch | Field scope | 13 fuel tanks on 3 Modbus RTU loops; 3 booster installations engineered from a measured signal survey inside explosion proof junction boxes |
Is it cheaper to own AI hardware or rent cloud GPUs in oil and gas?
Each oil and gas design prices three years of ownership in its Appendix A, with every price cited, against renting the same capacity from a cloud region at its deepest three-year commitment where hardware is bought.
| Design | Line | Three years |
|---|---|---|
| Sovereign HSE Watch | Three-year cost, owned | About 670,000 US dollars with support and power at Pakistan's industrial tariff |
| Sovereign HSE Watch | Three-year cost, rented | 1.1 to 2.8 million US dollars for the same GPUs in the nearest cloud region; no hyperscaler runs a region in Pakistan |
| Loop Integrity Watch | Three-year cost | No compute to price; the field equipment is priced by OEM quotation against the survey (Appendix A) |
What ontology or object model does an oil and gas AI system need?
The object model is the part that makes the system an ontology rather than a pipeline: typed objects for the things in the oil and gas operation, with properties, status values and typed links. Every published design ships its object model as hyper-ontology/1 JSON that loads into Hyper Ontology.
| Design | Size | Objects | Download |
|---|---|---|---|
| Sovereign HSE Watch | 12 objects, 14 links | Operating Facility / Site, HSE Equipment, HSE Incident, Near Miss Report, Corrective Action, Inspection / Audit Record, HSE Document, Sensor Reading, Anomaly Event, Agent Recommendation, HSE Person, HSE Role | objects.json |
| Loop Integrity Watch | 15 objects, 15 links | Fuel Tank, Radar Tank Gauge (RTG), RTG Communication Loop, Modbus Booster (Repeater), Explosion Proof Junction Box, Gauge Reading, Data Quality Event, Central Inventory Picture, Loop Wiring As-Built, Service Order, Warranty and Support Record, OEM Authorization Letter, HSE Work Permit, Instrumentation Technician, Location Engineer | objects.json |
Who approves the decisions an AI system makes in oil and gas?
In every published oil and gas design a named person makes the decision that changes the physical world; the system prepares it.
| Design | Human control |
|---|---|
| Sovereign HSE Watch | Every recommendation is approved or rejected by a named person; nothing executes on equipment |
| Loop Integrity Watch | Every data quality event is acknowledged and resolved by a named person; the location engineer signs acceptance |
Every answer on this page is drawn from the papers linked in it: each paper's At a glance table, model register and cost appendix. Full text for agents: llms-full.txt. Designed on Praxis; object models load into Hyper Ontology.