Databricks iconDatabricksSep 15, 2026 ~6 min source read

Turning theft detection into governed action: how energy teams use Databricks to close the loop

Machine learning flags theft risk, but value requires a governed, end-to-end workflow that moves cases from a score to safe, recovered outcomes. Databricks components — Databricks App, Lakebase, Unity Catalog, Genie One, Unity Gateway, and Agent Bricks — combine detection, investigation, dispatch, and executive reporting on one platform.

How energy teams turn theft detection into governed action with Genie and AI business processes

Share this story

Send the public story page.

Useful takeaways from this story.

Detection is an input, not an outcome: a risk score must feed a governed workflow that interprets, prioritizes, dispatches, recovers revenue, and records results.

Databricks App + Lakebase keep live case state and recovery totals in the lakehouse so investigations update in real time and models can be swapped without re-engineering the workflow.

Genie One, Unity Catalog, Unity Gateway, and Agent Bricks provide consistent metric definitions, governed AI access, and automated executive reporting.

The useful part

A Databricks App connects risk interpretation, investigation prioritization, dispatch-ready reporting, and recovery workflows, with Lakebase maintaining live case state and recovery totals. Genie One, Unity Catalog, Unity Gateway, and Agent Bricks provide trusted metrics, governed AI usage, and automated executive reporting on a single platform. Energy theft is the deliberate use of gas or electricity without paying for it, typically by tampering with a meter or supply so consumption goes unrecorded.

How it works

  • Teams need to be able to interpret signals, prioritize investigations, prepare field teams, recover losses, and give leaders trusted metrics in a timely manner.
  • An ML insight is not yet a business outcome Most organizations can train models that generate useful predictions, such as a churn probability, fraud score, failure forecast, or theft risk score.
  • On Databricks, that loop runs in a Databricks App, with live case state held in Lakebase and business logic running in the same lakehouse as the underlying data, governed end to end by Unity Catalog.
  • Watch Daniel Zoccali, an Energy Solutions Architect at Databricks, demonstrate how Databricks can help detect and operationalize energy theft investigations.
  • The analyst triaging a flagged account is not a data scientist, and even an accurate composite risk score may not explain what to do next.

What to take from it

The challenge is no longer simply detecting more theft, as most companies already have ML models that can flag suspicious accounts. Every day a genuine case waits means more stolen energy and a prolonged safety risk. A bare number can send crews toward false positives and consume scarce field capacity.

Example or evidence

  • When models, serving endpoints, and datasets are registered in Unity Catalog with fields labeled as PII, teams can trace data lineage through to the models that consume it, audit usage, and apply...
  • Unlike a billing error or an unpaid bill, it involves physically modifying the connection, making it difficult to detect and potentially dangerous.
  • For revenue protection teams, theft is both a financial and a safety issue.
  • Energy theft costs energy consumers in Great Britain alone over £1.4 billion a year, with only 40% of target cases being detected.

Details worth keeping

How energy teams turn theft detection into governed action with Genie and AI business processes | Databricks Blog Skip to main content Summary ML can flag suspicious accounts, but providers need a governed business process to turn those insights into investigation, recovery, and measurable action. Tampered meters and wiring can cause fires and gas leaks. The insight lands in a dashboard, while someone still has to translate it into action.

Related coverage

  • Databricks: S&P Global's goal was to fundamentally improve how customers discover and consume...
  • Databricks: Most marketing teams aspire to be data-driven. In practice, getting a trusted answer,...
  • Databricks: At Data and AI Summit, we announced the evolution of Genie Spaces to Genie Agents,...
  • Amazon: After talking with enterprise security leaders over the past year, one thing has become clear: the rise of autonomous AI agents is the most significant shift in security posture since the move to cloud.
  • Databricks: Business leaders often have access to plenty of data, but still can't get a reliable...

More context around this story.

Agentic security: Detection and response at machine speed
Amazon iconAmazonSep 2, 2026

Agentic security: Detection and response at machine speed

After talking with enterprise security leaders over the past year, one thing has become clear: the rise of autonomous AI agents is the most significant shift in security posture since the move to cloud. Organizations across every industry are adopting AI agents that authenticate on behalf of users, execute multistep wo

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app