Predictive maintenance, seismic data analysis, drones inspecting offshore platforms, and systems capable of anticipating equipment failures. Artificial intelligence is no longer just a promise; it is already becoming part of the oil and gas industry’s day-to-day operations. But as algorithms move closer to physical assets and operational decision-making, a question arises that goes far beyond technology: who is liable when AI gets it wrong?
An industry no longer asking “Whether” to use AI, but “How”
The pursuit of operational efficiency, lower costs, and improved asset performance has accelerated the sector’s digital transformation. Deloitte’s 2026 Oil & Gas Industry Outlook identifies technological advancement as one of the forces expected to shape the industry in the coming years and notes that advanced maintenance solutions, combined with sensors, drones, and robotics, can reduce equipment failures by up to 40%, generating annual savings of up to US$10 million for certain highly complex assets.
In Brazil, this trend receives additional impetus from the Research, Development and Innovation (R&D&I) policy of the National Agency of Petroleum, Natural Gas and Biofuels (ANP). Exploration and production contracts provide for mandatory R&D&I investments: under concession contracts, the obligation is equal to 1% of the gross production revenue from fields subject to Special Participation payments; under production-sharing contracts, 1%; and under transfer-of-rights contracts, 0.5%.
This environment helps explain why digital transformation already holds a prominent place on the industry’s agenda. A survey conducted by Deloitte with support from the Brazilian Petroleum and Gas Institute (IBP) found that 87% of the companies surveyed prioritize innovation projects. The main reported gains are precisely in the areas where their effects are felt most strongly across the industry: efficiency, performance, and operational safety.
From the field to data: where AI is already at work
In exploration and production, machine-learning algorithms process large volumes of seismic and geological data, helping to reduce uncertainty and support drilling decisions. In a country that ranks among the world’s leaders in deepwater and ultra-deepwater operations, the potential is clear.
In maintenance, sensors paired with predictive models can identify abnormal patterns before a failure causes an unplanned shutdown. Drones and computer vision systems expand the capacity to inspect structures and equipment. In corporate functions, meanwhile, generative AI tools are beginning to support procurement, compliance, and legal work, from document analysis to contract review and supplier assessment.
The adoption of these technologies is not without concerns. The Deloitte and IBP study shows that, although innovation is widespread, benefits related to intellectual property creation and cybersecurity still rank below other outcomes perceived by companies.
That is precisely where the discussion ceases to be purely technological.
Even before a specific law, a mosaic of rules already applies
Brazil does not yet have a comprehensive artificial intelligence law in force. Bill No. 2,338/2023, approved by the Senate in December 2024, remains under consideration in the Chamber of Deputies. In 2025, the Executive Branch also introduced Bill No. 6,237/2025, which proposes the creation of the National System for the Development, Regulation, and Governance of Artificial Intelligence (SIA); in 2026, the proposal was attached to Bill No. 2,338/2023 for joint consideration.
The absence of a specific legal framework, however, does not mean an absence of regulation.
Depending on the application, AI systems used in the industry may already be subject to Brazil’s General Data Protection Law (LGPD), operational safety standards and other sector-specific rules, environmental legislation, intellectual property law, and, of course, the contracts entered into by operators, service providers, and technology suppliers.
The distinction among types of data is particularly important. Seismic information, well parameters, and production or maintenance data are not automatically subject to the LGPD, which protects data relating to natural persons. This does not mean that operational data are unprotected: their use may involve confidentiality obligations, trade secrets, intellectual property rights, contractual provisions, and sector-specific regulations.
Brazil’s National Data Protection Authority itself included artificial intelligence and emerging technologies, when related to the processing of personal data, among its enforcement priorities for the 2026–2027 period.
When the algorithm leaves the office and moves into operations
Perhaps the key distinguishing feature of artificial intelligence in the oil and gas industry lies in the distance between two seemingly similar uses.
A generative tool that produces an inaccurate summary of a report may create rework. A model that fails to properly detect an anomaly in critical equipment may contribute to far more serious operational, environmental, and human consequences.
The closer AI moves from the administrative environment to the well, offshore platform, pipeline, or control room, the greater the need to define who makes decisions, who supervises them, and who is held accountable.
Imagine a system that recommends continuing an operation despite certain signs of abnormality. If the human operator follows the recommendation and an incident occurs, the legal debate quickly becomes complex: did the model fail? Were the data provided adequate? Was the system merely intended to support the decision, or was operational reliance placed on its recommendation? Who had the duty to validate the outcome?
There is another factor: rarely is there only one company involved. The operator, service provider, equipment manufacturer, software developer, cloud infrastructure provider, and AI model provider may all be part of the same technology chain.
In this scenario, the question is no longer simply “who is liable for the AI?” but “how was risk allocated among all those involved?”
Data, intellectual property, and cybersecurity
The same complexity arises in intellectual property.
If a technology company receives years’ worth of drilling data from an operator to develop a predictive model, who owns the resulting system? May the supplier use the knowledge gained to serve competitors? Who will own the improvements developed during the contract? And what happens to the trained model when the commercial relationship ends?
These questions show why it is no longer enough to define ownership of the original data alone. Technology contracts must also address the use of data for training, the models developed, derived information, and the outputs produced by AI.
At the same time, concern over cybersecurity, an issue inseparable from digitalization, is growing. Offshore platforms, refineries, pipelines, and other industrial facilities increasingly combine digital systems with physical infrastructure. The greater the integration of artificial intelligence, sensors, and operational technology, the larger the potential attack surface for cyberattacks, data manipulation, system compromise, and disruption.
In a high-risk industry, cybersecurity and operational safety are therefore beginning to occupy the same territory.
Contracts take center stage
While Brazil’s artificial intelligence legislation remains under development, much of the industry’s legal certainty will depend on the governance adopted by companies and, above all, on the quality of their contracts.
Clauses that might once have seemed overly technical are beginning to take on strategic importance: who may use the data and for what purpose; whether the data may be used to train other models; who owns the outputs and improvements; which cybersecurity standards must be met; when a decision requires human oversight; how systems will be audited; who must report incidents; and how liability, indemnification, insurance, and limitations of liability will be allocated between the parties.
Technology suppliers themselves will also require close scrutiny. Many companies will not develop their systems in-house but will instead procure third-party platforms, models, and infrastructure. In these cases, issues such as information storage, subcontracting, the use of data for training, audit rights, and service continuity cease to be mere details of the technology contract and become part of the risk management framework for the operation itself.
Artificial intelligence promises to make the oil and gas industry more efficient, predictable, and safe. But the same technology that reduces technical uncertainty can create new legal uncertainties when responsibilities, data, and decisions are not clearly defined.
The challenge in the years ahead, therefore, may not simply be to adopt more artificial intelligence. It will be to know when to trust the algorithm, when to require human intervention, and how to allocate risk from a legal standpoint when machines begin to take part in decisions that were once made exclusively by people.
By Julia Borges da Mota and Thiago Bandeira
<hr>
Source: Eixos
Photo: Canva
Recent Comments