Blue Prysm · Analysis3 minutes from change to outage

Analysis · AI in operations · part 5 of 5

Where the kill gate goes

We went looking for a regulator’s fine against an operator for its own AI and did not find one. What we found instead were two failures of automated change. At Rogers a risk algorithm rated a national core change Low. At AT&T a network element was loaded without the review the operator’s own rules required. Those are the precedents. The rules that bind today are about voices and disclosure, and the European duties for AI in critical digital infrastructure now start on 2 December 2027.

Sources: FCC 24-17, the 24-84 notice as published in the Federal Register, 24-104 and the Bureau’s report on the AT&T outage (22 July 2024); CyberScoop on Lingo Telecom; Xona Partners’ assessment of Rogers for the CRTC (4 July 2024); the ACMA on Optus; The Register, The Nightly and Optus’s FY26 release; Light Reading on Verizon and Comcast; the Wisconsin Examiner on the Senate vote; Executive Order 14365; the FTC (1 July 2026); Colorado SB25B-004 and SB26-189, with the law firms Seyfarth and McDermott; Regulations (EU) 2024/1689 and 2026/1744 and Directive 2022/2557; NIST AI 100-1; the trackers Governome and The Political Group; Bain (10 September 2026). Read 7 Oct 2026.

Three of the four big outages were changes a control should have stopped

None of the network failures in the public record was caused by AI. Three of them were changes that a control should have stopped, and at Rogers the control that failed was itself a piece of automation (Exhibit 1).

Exhibit 1Four outages since 2022 cut off tens of millions of customers, and in each one where a cause is published a change got past a control
OutageScaleWhat the control missedRecord
Rogers, 8 Jul 2022Over 12 million customers, about 26 hoursA risk algorithm rated phase 6 of a 7-phase core change Low, down from High; scrutiny and lab tests were skippedXona Partners for the CRTC
AT&T, 22 Feb 2024Over 125 million devices; over 92 million calls and over 25,000 calls to 911 blocked; at least 12 hoursAn element was loaded without the peer review AT&T’s procedures required; an automated protection mode then shut connections downFCC report; referred to the Enforcement Bureau
Optus, 18 Sep 2025About 14 hours; 455 Triple Zero calls failed; two deathsThe contractor used the wrong 2022 procedure and classed the job no-impact; Optus classed it urgent, skipping review; the post-change check was “not sufficiently granular”Independent review; ACMA court action
Verizon, 14 Jan 2026Up to 10 hours; 1.5 million outage reportsA “software issue”; no root cause publishedPress; no FCC report yet

Source: Xona Partners executive summary, published by the CRTC (4 July 2024); FCC DOC-404150A1 (22 July 2024) (Filed). The Register (19 December 2025) and The Nightly (30 July 2026) on Optus; Light Reading on Verizon (Reported).

Optus adds the check that comes after the change. Its 2:40 AM check missed rising call failures because “This data was not sufficiently granular to enable detection of the emerging problem”. Its board has since accepted all 21 recommendations of the independent review and expanded its automated testing of Triple Zero calls.

It would be easy to read these as cases against automation, and that would be the wrong lesson. Comcast says “99.7% of the software changes that we are making are fully automated”, and Verizon made more than 70 million configuration changes autonomously in 2025. Automation at that scale is normal. The failure in each case is a control that a change, or a tool, could get past (Exhibit 2).

Exhibit 2The Rogers, AT&T and Optus outages each got past a different step of the change process, and the controls now called for cover the steps an AI would occupy
Where an AI that scores, approves or loads a change sitsRogers 2022AT&T 2024Optus 2025Method ofprocedureRiskclassPeerreviewLabtestLoadPost-changecheckRollbackA changeCalled forno tool maylower itunapprovedcannot loadlocal KPIs,call testsautomatic,fallback setwhere the record says the control faileda control the record now calls forRisk class: Xona for the CRTC. Load: FCC, para. 29. Post-change check: Optus review and board.Rollback: Xona; 3GPP TS 28.105 Rel-19 degradation thresholds and fallback actions.

Source: Xona Partners assessment for the CRTC (4 July 2024); FCC PSHSB report on the 22 February 2024 AT&T outage (22 July 2024); the Optus independent review as reported by The Register (19 December 2025); 3GPP TS 28.105 Release 19 per TR 21.919 (Filed and Reported as marked). Note: a cross marks a step the record says failed; a dot marks a control the record now calls for. Compiled by Blue Prysm.

An AI that scores, approves or executes network changes would occupy the steps where these failures happened. So the first kill gate goes in change control, and we would write it in one sentence: no automated tool, AI or otherwise, may lower a change’s risk class or load a change that has not passed review.

The rules in force today are about voices and disclosure, and the infrastructure duties come with a date

The rules that bind an operator’s AI today are about voices and disclosure. The duties for AI that runs critical infrastructure are written and dated, and the date has already moved once (Exhibit 3).

United States: voices. In February 2024 the FCC ruled in FCC 24-17 that AI-generated voices “are ‘artificial’ voice messages because a person is not speaking them”. From that it follows that “callers that use such technologies must obtain the prior express consent of the called party”. That reaches an outbound AI agent making renewal, collections or retention calls. Inbound AI care is not a TCPA call, so it does not. In August 2024 the FCC proposed that AI-generated calls disclose it “at the beginning of each call”, and the trackers we read reported no final rule as of 5 October 2026.

The FCC’s enforcement so far has been against traffic rather than operators. It levied a $6 million forfeiture for the cloned-voice Biden robocalls of January 2024. CyberScoop reported a $1 million consent decree with Lingo Telecom, the carrier that passed those calls with A-level caller-ID attestation.

United States: preemption. Federal preemption of state AI law has been tried and has not happened. The Senate struck a moratorium out of the 2025 budget bill by 99 votes to 1. Executive Order 14365 of 11 December 2025 directed the FCC to “initiate a proceeding to determine whether to adopt a Federal reporting and disclosure standard for AI models”. A tracker reported that proceeding not yet opened as of 5 October 2026. The FTC proposed on 1 July 2026 that a law like Colorado’s is “impliedly preempted to the extent it conflicts with a federal regulatory scheme”. That is a proposal, and not yet a decision.

Colorado. Colorado pushed its AI Act back to 30 June 2026 in SB25B-004, then saw enforcement held in April 2026 after a challenge the Justice Department joined. The law firms Seyfarth and McDermott report that SB 26-189, which replaces it, was signed on 14 May 2026 and takes effect on 1 January 2027. It brings notice duties for automated decision-making in consequential decisions. The legislature’s own bill page listed only the bill’s introduction, on 1 May 2026, when we read it. For an operator the law reaches credit and eligibility decisions in sales, and not the network.

European Union. Annex III of the AI Act lists “AI systems intended to be used as safety components in the management and operation of critical digital infrastructure”, and that takes in “Providers of public electronic communications networks”. Then came Regulation (EU) 2026/1744 of 8 July 2026, in force from 27 July. It moved the high-risk duties for Annex III systems to 2 December 2027 and narrowed what counts as a safety function. Its recital 7 says the term “does not include AI systems which are intended to solely fulfil functions related to user assistance, performance optimisation, service efficiency, automation, convenience”. The amended definition keeps the second test, though. A safety component is still one “the failure or malfunctioning of which endangers the health and safety of persons or property”.

The chatbot duty did not move. Under Article 50(1) a system that talks to people has to tell them it is an AI “unless this is obvious”, and that duty has applied since 2 August 2026. Most breaches can be fined up to €15 million or 3% of worldwide turnover. The NIST AI Risk Management Framework, for completeness, is voluntary and under revision.

Exhibit 3The rules binding an operator’s AI arrived between February 2024 and August 2026; the EU’s infrastructure duties follow in December 2027
20242025202620272028Feb 2024 FCC 24-17: AI voices need prior express consentAug 2024 FCC 24-84 proposed: disclose AI at the start of each callSep 2024 FCC 24-104: $6 million forfeiture for the cloned-voice robocallsJul 2025 Senate strikes the state-law moratorium, 99 to 1Aug 2025 Colorado SB25B-004 delays its AI Act to 30 June 2026Dec 2025 EO 14365: FCC to weigh a disclosure standardApr 2026Colorado enforcement held after a federal challengeMay 2026SB 26-189 signed, per law firms; effective 1 Jan 2027Jul 2026FTC proposes that conflicting state AI laws are preemptedJul 2026 Regulation 2026/1744 moves Annex III duties to 2 Dec 2027Aug 2026 AI Act Article 50(1): chatbots must say they are AIJan 2027 Colorado SB 26-189 takes effectDec 2027 AI Act high-risk duties for critical digital infrastructure

Source: FCC 24-17 (8 February 2024), 24-84 (Federal Register, 10 September 2024) and 24-104 (30 September 2024); Executive Order 14365 (11 December 2025); FTC release (1 July 2026); Regulations (EU) 2024/1689 and 2026/1744 (Filed). Wisconsin Examiner on the Senate vote; Seyfarth and McDermott on Colorado; Governome and The Political Group on the FCC items (Reported). Note: the Colorado dates are as reported by law firms.

Each of those rules reaches a different candidate from part 3 (Exhibit 4). The narrowed EU definition takes AI built solely for efficiency out of the safety-function test altogether. What it leaves is the failure test, and that catches automated change which could, if it went wrong, cut emergency calling: the very change the AT&T, Rogers and Optus records describe. So an operator has until 2 December 2027 for that class of system, and no time at all for chatbot disclosure.

Exhibit 4Consent and disclosure duties bind now; the EU’s high-risk duties for automated change that could endanger safety start on 2 December 2027
CandidateRuleFromWhat it requires
Outbound AI voice: retention, collections, renewalsTCPA, as read in FCC 24-178 Feb 2024Prior express consent of the person called
Chatbots and voice agents in the EUAI Act, Article 50(1)2 Aug 2026Tell people they are dealing with an AI, unless obvious
Automated network change whose failure could endanger safety, such as emergency calling, in the EUAI Act, Annex III point 2, as amended2 Dec 2027High-risk duties
Energy saving, RAN optimisation, AIOps built for efficiency, in the EURegulation 2026/1744, recital 7n/aOutside the safety function where the purpose is solely efficiency
Credit and eligibility decisions in ColoradoSB 26-189, as reported by law firms1 Jan 2027Notice duties for automated decisions
AI-generated callsFCC 24-84, proposedNot adoptedDisclosure at the start of each call

Source: the instruments named in each row (Filed); the mapping of candidates to rules is our reading and not legal advice (Judgement).

Each pilot measures value net of run cost, with a guardrail beside it

The AI opportunity portfolio model, which also exists as a framework workbench, runs a monthly kill gate with six triggers. It stops a pilot when the falsifier fires, when the decision owner leaves or when the data turns out not to exist. It stops or rescopes when the proof runs past twice its plan, re-ranks when the cost to prove doubles, and promotes what works, with an owner and a date. 3GPP’s TS 28.105 asks a model learning on a live network for “tolerable degradation thresholds” and “fallback actions”, and TS 28.100 gives a human decision “the highest authority in each level”. Between them those cover a good deal. What the failure record adds is what they leave open. A guardrail has to be measured beside the value, and some of the rules come from outside the business.

Every pilot therefore measures its value in a unit the business already tracks, net of what the AI costs to run, and beside it measures whatever gets worse if the AI is wrong (Exhibit 5). Bain’s advice in September 2026 was to “Measure cost per task on one workflow”, as a “cost per resolved customer issue, network incident, proposal generated, or software release”. Its scenario puts AI agent and token costs at 20% to 30% of the total, and a fifth to a third is a share worth netting off. Vodafone, for what it is worth, states its €100 million in part 2 as a net figure.

Exhibit 5Each candidate has a value measure in a unit the business tracks, a guardrail that worsens if the AI is wrong, and a control
CandidateValue, inGuardrail beside itControl
Energy savingkWh metered at the siteUser throughput and access delay at low loadMatched sites
Agent assistCost per resolved contactFollow-up contact; complaintsAgent groups split at random
DeflectionContacts resolved without a person, defined in publicRepeat contact; time to reach a personCustomers split at random
RAN optimisationSpectral efficiency; throughputDrops and access failures, neighbours includedMatched clusters
AIOpsRepair time on matched incident classesCritical alarms missed in a shadow runShadow run
Fraud and scamLosses avoidedLegitimate traffic blockedLabelled holdout
Churn and offersChurn and marginOffer cost; complaintsHoldout
SoftwareCycle time; defects and rollbacksIncidents from generated codeComparable teams
Automated changeChanges completed without a personRollback time; local post-change KPIsStaged rollout

Source: our pairing, from Bain (10 September 2026), Verizon’s customer survey, 3GPP TR 38.864, the FCC report on AT&T and the Optus review (Judgement).

The stop rules

The stop rules are written before the pilot starts, so that stopping is arithmetic rather than argument. Each of the eight comes from an outage, a regulation or a 3GPP control described above (Exhibit 6).

Exhibit 6Eight stop rules, each drawn from an outage, a regulation or a 3GPP control
  1. Change control. Stop any tool, AI or otherwise, that can lower a change’s risk class or load a change that has not passed review. Rogers’ algorithm rated its change Low, and the FCC wrote that loading such a change “should not be possible”.
  2. Degradation. Roll back when a guardrail crosses the threshold set before the pilot, which is what TS 28.105 asks of models learning live. Roll back too when the post-change check cannot see the local measure, as happened at Optus.
  3. Care. Stop a deflection pilot when repeat contacts or complaints rise above the control, whatever the containment rate says.
  4. Consent and disclosure. Stop an outbound AI voice campaign that lacks documented prior express consent, and stop an EU-facing agent that does not say it is an AI.
  5. Net value. Stop when value net of model, token and integration cost falls below the bar set before scoring; the portfolio model’s bar is three times the cost of proof in a year. Vodafone turned off hundreds of use cases whose value did not justify their cost, and it is better to do that early.
  6. Energy. Stop a sleep policy when user throughput at low load falls below its threshold, however many kilowatt-hours it is saving. TR 38.864 records a user-throughput loss of up to 62.4% in one source’s simulation of one technique.
  7. The model’s gate. Stop when the falsifier fires, the owner leaves or the data is not there. Rescope when the proof runs past twice its plan, and re-rank when its cost doubles.
  8. Dates. Re-check any credit or eligibility use in Colorado before 1 January 2027, and the classification of any automated-change system before 2 December 2027.

Source: the outages, rules and 3GPP controls cited in Exhibits 1 to 4 and the AI opportunity portfolio model; the rules themselves are ours (Judgement).

The terms, briefly

  • TCPA. The Telephone Consumer Protection Act, which restricts calls that use an artificial or prerecorded voice.
  • Annex III, safety component. The AI Act’s list of high-risk uses, and the part of a system whose failure endangers people or property.
  • Method of procedure. The written steps for a network change, which a peer reviews before the change is loaded.
  • Falsifier. In the portfolio model, the result written down before a pilot starts that will stop it.

Implications

Carrier strategist

Put the gate in change control before you choose a model. No AI that touches configuration may lower a risk class or load an unreviewed change, and rollback is automatic, because those are the steps where Rogers, AT&T and Optus failed. Then write each pilot’s falsifier and guardrail before it starts, and not after.

Investor

Price the precedents as outages rather than as AI fines, because no regulator has fined an operator for its own AI. The dates to hold are 1 January 2027 in Colorado and 2 December 2027 in the EU, with chatbot disclosure in force since August 2026. The question to ask a carrier is which of its AI systems can change the network without a person, and what stops them.

Vendor

Ship the controls with the model: TS 28.105 degradation thresholds and fallback actions, change records a peer can review, and post-change measures at the level of the cell. A product the customer’s change process cannot stop will not get through that process.

Method and limits

How this was built

We read the rules from the instruments themselves: the FCC’s ruling, notice and forfeiture order, the executive order, the Colorado bill pages and the EU regulations in the Official Journal. Law-firm summaries and trackers fill in where the primary record lags behind. We read the failure record from regulators’ reports, from the consultant’s report the CRTC published on Rogers and, where no report has been published, from the press. The measures and the stop rules are ours. We built them from that record, from 3GPP TS 28.105 and TS 28.100 and from the portfolio model’s kill gate.

What it does not show

This is a reading of the public record and not legal advice. Whether a system is high-risk under the AI Act turns on its intended purpose, which only its owner can state. The FCC’s proposed disclosure rule, the executive order’s deliverables and the FTC’s policy statement were all still pending at the trackers’ last report. Only law firms report Colorado SB 26-189’s signing and effective date; the legislature’s own page showed nothing beyond its introduction, on 1 May 2026, when we read it. We found no FCC report on Verizon’s January 2026 outage and no enforcement outcome for AT&T’s of February 2024.

Data as of: rules, regulators’ reports and trackers as read 7 Oct 2026 · Method version 1.0.

Found an error? Tell us. Corrections are published on the piece that carried them.