Start Free Trial
Home/Regulations/NRC Nuclear Safety Regulations (10 CFR) — Regulatory Reference
Regulatory Reference
Energy Federal (US) critical

NRC Nuclear Safety Regulations (10 CFR) — Regulatory Reference

Nuclear facility access controls and security data — critical sensitivity floor; AutoPIL key scoping and need-to-know directly apply.

Key Provisions
  • 10 CFR Part 73 — physical protection of plants and materials
  • 10 CFR Part 95 — facility security clearance and safeguarding of classified information
  • Safeguards information (SGI) — classified sub-category
  • Cyber Security Plan requirements under 10 CFR 73.54
How AutoPIL Enforces It
  • Safeguards information classified at CRITICAL — unregistered AI agents denied by default
  • Key scoping enforces personnel and cleared-AI access boundaries
  • Audit chain provides the inalterable record nuclear security inspections expect
Policy EngineAudit LogSensitivity LabelsAgent RegistryKey ScopingAlert Rules
AutoPIL Policy IDs
ENG-NRC-P73-001Safeguards Information AI Access Control
ENG-NRC-7354-001Cyber Security Plan Implementation
Official Sources

This page is a working reference and not a substitute for qualified legal review. Verify against official sources before use in compliance artifacts.

Frequently Asked Questions
What does 10 CFR Part 73.54 require for AI agent deployments at nuclear facilities?
10 CFR 73.54 requires licensees to protect digital computer and communication systems from cyber attacks that could adversely affect safety, security, or emergency preparedness functions. A Cyber Security Plan must identify and protect critical digital assets (CDAs). For AI agents, this means any system that can access, process, or influence CDA-adjacent data — including AI-assisted monitoring, analysis, or control workflows — must operate under documented access controls, continuous monitoring, and an auditable record of every access decision. Uncontrolled AI agent access to nuclear operational data is inconsistent with these requirements. AutoPIL policy ENG-NRC-7354-001 maps directly to these Cyber Security Plan controls.
What is Safeguards Information (SGI) and how does it affect AI system access at nuclear sites?
Safeguards Information is a regulated category of sensitive nuclear security data defined under 10 CFR Part 73. It describes the security measures protecting nuclear facilities and materials — including guard deployment, intrusion detection, and vulnerability assessments. SGI is not classified as national security information, but its unauthorized disclosure carries civil penalties and potential criminal liability. Any AI agent that can query, retrieve, or summarize SGI-adjacent records must be bound to strict need-to-know controls. AutoPIL classifies SGI data sources at the CRITICAL sensitivity tier and, under policy ENG-NRC-P73-001, denies access to any unregistered or improperly scoped AI agent before the data enters the agent's context window.
How does AutoPIL help nuclear operators meet NRC audit and inspection record requirements?
NRC security inspections require demonstrating that access to Safeguards Information and critical digital assets was properly controlled and that an accurate, unaltered record of that control exists. AutoPIL writes a tamper-evident cryptographic audit chain for every policy evaluation — each record is hash-chained to the previous one, making retroactive alteration detectable. Inspectors can review exactly which AI agent requested access, which data source was involved, the policy version that governed the decision, and whether access was granted or denied — and why. This satisfies the inalterable record expectation NRC security reviewers apply during 10 CFR Part 73 compliance audits without requiring custom logging infrastructure.
When does NRC cybersecurity regulation apply to AI tools used at nuclear power plants?
10 CFR 73.54 applies to all NRC-licensed nuclear power reactors. It covers digital systems that could impact safety, security, or emergency preparedness functions — broadly interpreted by the NRC to include any system with a networked path to a critical digital asset. AI tools used for predictive maintenance, radiation monitoring analysis, security video review, or operational data queries may fall within scope depending on their integration architecture. The NRC's Cyber Security Plan requirements do not carve out an exception for AI or machine learning systems. Any AI agent with data access paths that touch CDAs or SGI-classified sources should be governed under a documented access control framework aligned with the approved Cyber Security Plan.
What are the enforcement risks for nuclear licensees that fail to control AI agent access under 10 CFR?
NRC enforcement follows a graduated severity scale. Violations involving Safeguards Information access failures or Cyber Security Plan deficiencies can reach Severity Level I or II, with civil penalties up to $1 million per violation per day of noncompliance under 10 CFR Part 2, Subpart B. The NRC also has authority to issue Confirmatory Action Letters, Orders, or — in extreme cases — modify or revoke operating licenses. Beyond financial penalties, unauthorized SGI disclosure can trigger referral to the Department of Justice. For AI-driven access scenarios, the primary risk is an undocumented agent accessing restricted data with no audit trail, which the NRC would treat as a control failure under the Cyber Security Plan rather than an isolated incident.
Covered Industries

NRC nuclear safety regulations under 10 CFR apply to NRC-licensed nuclear power reactor operators and fuel cycle facilities in the United States. As AI agents are introduced into operational monitoring, security review, and data analysis workflows at these facilities, they become subject to the same Cyber Security Plan and Safeguards Information access control requirements that govern all other digital systems touching critical nuclear assets.

AutoPIL Governance Platform

Enforce this regulation today

AutoPIL intercepts every AI agent data access call, enforces your policy, and writes a tamper-evident audit record — before sensitive data enters the agent context window.

Start Free Trial View All Industries