Who Approved It? AI Governance for Bulk Liquids Operators

Over the past two years, I have had a version of the same conversation many times: in board presentations, in AI strategy and planning workshops, and in trading and risk management assessments and benchmarking engagements for refiners, fuel distributors, and retail fuel operators. 

When I ask where artificial intelligence is currently running in the organization's commercial and operations environment, I typically get at (at least!) three different answers. 

  • IT describes the officially sanctioned tooling that went through the procurement process, the architecture review, etc.
  • Commercial and scheduling teams describe something considerably broader.
  • Risk, describes very little, not because risk is absent, but because the question was never routed to them. 

The gap between these three answers is the ordinary consequence of a technology that entered through vendor release notes and individual initiative rather than through a procurement and approval sequence.  It closes only when someone decides to address it purposefully.

The Regulatory Picture Is Thinner Than Most Assume

The reasonable next question from a risk officer or a CIO is whether any of this is actually required yet. For a US bulk liquids operator, the honest answer is that direct mandates remain sparse, which makes the convergence across various frameworks all the more interesting. 

  • Federal Guidance: NIST published its AI Risk Management Framework in January 2023 as voluntary guidance, and it remains voluntary, which means its value lies in giving an organization a defensible structure it can adopt on its own terms and at its own pace.
  • The European Union's AI Act: This applies to a Gulf Coast refiner only to the extent that the organization or its trading affiliates place systems on the EU market or serve EU users, and the timeline most people memorized in 2025 has since been moved. Under the Digital Omnibus approved by the European Parliament and Council in June 2026, obligations for stand-alone high-risk systems shift from August 2026 to December 2, 2027, and systems embedded in regulated products move to August 2028, while August 2, 2026 remains the date the Commission's enforcement powers over general-purpose AI models switch on and the Article 50 transparency duties become applicable.
  • State-Level Legislation: Closer to home, the Texas Responsible Artificial Intelligence Governance Act has been in force since January 1, 2026, though the enacted version is considerably narrower than the draft that circulated in 2024. It establishes intent-based liability for a defined set of prohibited practices, reserves enforcement to the Attorney General, provides a sixty-day cure period, and creates no private right of action. A document-extraction model reading bills of lading does not come anywhere near the prohibitions.

Why Convergence Matters More Than Compliance

The compliance case at this time may be a bit thin, but the convergence case is not. Four bodies with unrelated mandates and very different enforcement postures have arrived at substantially the same expectations: 

  1. Classify systems according to the consequence of their failure
  2. Govern the data that feeds them
  3. Document system functions and who owns them
  4. Keep a named human accountable for consequential outcomes
  5. Monitor performance after deployment and retain the ability to stop a system quickly. 

When guidance converges consistently across jurisdictions, it gradually stops functioning as guidance and starts functioning as the industry standard of care that auditors, insurers, counterparties, and eventually opposing counsel will use to evaluate whether an organization behaved reasonably.

Where the CCRO Paper Fits

This is where the Committee of Chief Risk Officers (CCRO) AI Risk Governance paper earns its place on the shelf. 

Published in November 2025, the paper does the translation work that the general frameworks leave undone, because it was written for commodity market participants rather than for consumer lending, employment screening, and the other domains that tend to dominate regulatory drafting. It addresses the risk taxonomy in terms a trading organization recognizes; it treats vendor-delivered AI as a governance problem in its own right, and it speaks directly to the segregation of duties question that any risk function will confront the first time it tries to validate a model built by the same team that wants to deploy it. It is essential reading for anyone carrying risk or technology accountability in this space.

Two Places to Look First

In a bulk liquids environment, two everyday situations illustrate why an AI inventory matters more than an abstract policy. 

Embedded Document Extraction

Confirmations, bills of lading, inspection reports, and compliance notices arrive as PDFs and email text in volumes that make manual entry a persistent source of both lag and error. Extraction models handle that work well enough that they are now appearing inside CTRM releases and adjacent vendor products as standard functionality. While the capability is genuinely useful, and I am not suggesting anyone turn it off, the governance questions are narrow and specific: 

  • Who validated extraction accuracy against a known sample of your own documents?
  • What error rate was accepted, and who is named as the owner of that error rate?
  • What happens operationally when a misread quantity or a transposed date reaches a position report or an invoice?

A capability that arrives enabled by default in a quarterly release has usually answered none of those questions, and the fact that it was delivered rather than procured does nothing to change the fact that the organization is now accountable for its output.

Commercial Use of General-Purpose AI

Analysts, schedulers, and originators are pasting contract language, counterparty names, cargo details, and position data into public chat tools, and they are doing it because the tools are useful and because nobody has told them where the boundaries sit. The exposures compound quietly: 

  • Violations of confidentiality obligations under supply, terminaling, and exchange agreements that were negotiated long before anyone got to this point
  • No audit trail of inputs or logic, such as what was asked or what came back
  • Inability to reconstruct what informed a commercial recommendation if a counterparty or a regulator later asks

I have yet to see an organization solve this with a prohibition, because prohibitions push the activity further out of view (i.e., shadow AI) rather than ending it. Organizations making real progress provide a sanctioned tool under an enterprise agreement, state plainly what may or may not go into it, and treat the resulting usage as something to be monitored rather than assumed away.

Start with the Inventory

If you take one thing from this, let it be the sequencing. You do not need a governance program before you need an AI inventory. 

Step

Action

Practical Outcome

1. Poll the Enterprise

Ask IT, Commercial, and Risk the same inventory question.

Captures sanctioned, vendor-native, and shadow tools without internal friction.

2. Catalog & Classify

Document every tool and assess the impact if its output were wrong and uncorrected.

Establishes a baseline risk profile based on operational consequence.

3. Apply Reference Frameworks

Map findings against the CCRO paper and NIST guidelines.

Replaces theoretical policy gaps with practical, targeted controls.

About the Author
Kent Landrum
A Partner – Process & Technology at Opportune LLP, Kent has more than 20 years of diversified information technology experience with an emphasis on solution delivery for the energy industry. He has a proven track record of managing full life cycle software implementation and process improvement projects for downstream and utilities companies, including ETRM, ERP, BI, MDM, and CRM solutions.

Our experts are here for you.

When you choose Opportune, you gain access to seasoned professionals who not only listen to your needs, but who will work hand in hand with you to achieve established goals. With a sense of urgency and a can-do mindset, we focus on taking the steps necessary to create a higher impact and achieve maximum results for your organization.

Learn More Contact Us