The warning was on file: why we built uc2c.ai

Major industrial accidents are investigated in depth, and the investigations keep finding the same thing: the warning signs were already on file. This is why that happens, and what we built to change it.

Risk hides between the records

Every high-hazard plant (chemicals, refining, oil and gas, pharmaceuticals) runs on a written record of its own risk: hazard studies, change records, drawings, maintenance history and incident reports. Each team keeps its piece carefully. Operations knows which safeguard is bypassed tonight. Engineering knows which line was modified last spring. Process safety knows what the hazard study assumed.

The dangerous risk is rarely in any one of those records. It sits between them. A change the hazard study never caught up with. A safeguard that is credited on paper but out of service in the field. An incident at a sister site involving the same equipment as yours. No one person holds all the pieces, so no one sees the whole picture in time.

The stakes could not be higher. When this goes wrong, it costs lives, damages communities and destroys assets worth billions. Short of catastrophe, the same gaps drive unplanned shutdowns and lost production. Siemens estimates that unplanned downtime costs the world’s 500 largest companies almost $1.4 trillion a year (The True Cost of Downtime 2024).

The dangerous risk is rarely in any one of those records. It sits between them.

Why it hasn’t been solved before

It isn’t for lack of rigor. This industry built some of the most careful safety disciplines in the world. Three things stood in the way.

  • The knowledge lives in documents, not databases. Hazard studies, change records, drawings and investigation reports are written for people to read. They come as PDFs, scans and spreadsheets, in decades of different formats. Software could store them, but it could not read them.

  • No team can read all of it. Checking every change and every incident against every hazard scenario at a single facility comes to millions of comparisons. So the work happens in snapshots: a hazard study every five years, a review when a change is proposed, an investigation after something goes wrong.

  • Generic AI isn’t trustworthy enough. Language models can now read engineering documents. But a fluent answer that can’t show its evidence has no place in a safety decision, and in this industry an answer you can’t trace is worse than no answer at all.

What we built

uc2c.ai builds Hazard Navigator. It reads a plant’s own records as they are, in whatever format they already exist, and connects them into one living picture of the plant’s risk. It then shows where that risk hides: documents that disagree, changes and incidents that affect a hazard scenario, safeguards credited in one place but not in another. Everything is ranked by consequence, so the team sees what matters most first.

What makes it different:

  • It connects what already exists. Other tools help write the next study. Hazard Navigator connects every study, change and incident a site already has.

  • Every result is traced to its source. Each finding links to the document and passage behind it, so an engineer can check it in minutes rather than take it on trust.

  • It works with engineering judgment, not around it. It reads but never writes to plant systems, and a qualified engineer decides what happens to every finding.

  • It is grounded in how plants actually fail. It was built by people who have run plants and led hazard studies, on a structured understanding of equipment, failure modes and safeguards, not on generic text.

  • It stays current. As changes and incidents arrive, the picture updates, so risk doesn’t drift unseen between studies.

Other tools help write the next hazard study. We connect every study, change and incident a site already has.

Who it helps, and why today’s tools fall short

Hazard Navigator serves the people who carry responsibility for a plant’s risk. Each of them is doing careful work with tools that can’t see across the whole record.

  • Process safety engineers rebuild hazard studies every five years in long workshops. That takes weeks of senior time, and the study starts going out of date as soon as the plant changes.

  • Operations leaders make restart and bypass calls under pressure, from memory and whoever is on shift. The relevant change or past incident is buried in a shared drive.

  • Engineers reviewing changes check each change against the documents someone remembers to pull. But changes interact, and nobody reviews them together.

  • Site and company leaders rely on audits and lagging indicators. Too often, they learn about the gap after the incident.

What changes on the plant floor

The difference shows up in the decisions people make every week. For five of them, here is the current state, and where we are headed with Hazard Navigator.

Bypassing a critical safety device

Current state
A high-pressure trip has to be bypassed for maintenance. The shift team writes a compensating measure, often an extra operator round, based on what they remember and what the permit template suggests. They rarely see every scenario the trip was protecting against, or how reliable the alternatives really are.
Where we’re headed with Hazard Navigator
They see every scenario that depends on that trip, both those in the hazard studies and those Hazard Navigator has found since. For each one they see which other safeguards act on it, whether each is available right now, and how reliable each has proven, based on the plant’s own history and industry data. They choose the compensating measure that best covers the real risk, with the evidence in front of them.

Reviewing a change

Current state
An engineer reviews a proposed change against the documents they know to pull. Earlier changes to the same equipment, and the scenarios those changes affected, are rarely in view.
Where we’re headed with Hazard Navigator
The change arrives with every scenario it touches, every earlier change to the same equipment, and every related incident, so the review covers the real cumulative effect rather than one change in isolation.

Restarting after a trip

Current state
The unit is down and the control room is full. The team pieces together what has changed since the last study by phone and shared drive, while every hour costs production.
Where we’re headed with Hazard Navigator
What has changed since the last study, which safeguards are impaired, and which past incidents match the situation are in one view within minutes, so the restart decision rests on the full picture.

Learning from someone else’s incident

Current state
An incident at a peer site goes round as a lessons-learned email. Whether it could happen here depends on someone recognizing the equipment.
Where we’re headed with Hazard Navigator
The incident is matched against your own equipment and scenarios. You see where your plant is exposed and which safeguards stand in the way.

Revalidating a hazard study

Current state
Every five years, the hazard study is rebuilt in weeks of workshops, starting from the old binder.
Where we’re headed with Hazard Navigator
The team walks in with the cross-checks already done: changes since the last study, scenarios that need revisiting, and safeguards credited inconsistently. The workshop spends its time on judgment, not paperwork.

Why no team can do this by hand. At one representative facility, using real customer data, fully cross-checking the hazard study, change records and incident history came to about 13.4 million comparisons. At a minute each, that is roughly 110 years of an engineer’s working time.

Now try to fit that into a typical hazard study, which runs two to four weeks. You would need roughly 1,400 to 2,750 engineers working full time, instead of the handful of specialists who normally sit in the room. And they can’t be just any engineers. Risk assessment draws on a plant’s most experienced people.

Price them accordingly. The top 10% of chemical engineers earn more than $182,880 a year (BLS, May 2025). Benefits add the other 30% of what an employer pays (BLS, June 2026). That puts each senior engineer-year at more than $261,000, and the full effort at about $29 million, spent in a single month. That is before travel, facilities, or the cost of pulling more than a thousand senior engineers off their day jobs. No plant does that, which is why the connections that matter most so often go unseen.

One facility, cross-checked by hand
13.4M
cross-checks at one representative facility
~110
engineer-years of work, at a minute per check
1,400–2,750
senior engineers to fit it into a 2–4 week hazard study
$29M
their pay alone, spent in a single month

Can new software win in a conservative industry?

It is a fair question. Process industries are slow to adopt new software, and for good reason: they have been burned by tools that promised a lot and mostly added work.

But the same companies spend heavily, every year, on the one thing they never cut: keeping their people, assets and communities safe. They pay for hazard studies, consultants, safety systems and inspections, because a single catastrophic failure can cost lives, billions of dollars and the license to operate.

Hazard Navigator doesn’t ask them to take on a new priority. It serves the one they already have, the most important one, and it earns trust the way this industry expects: it reads but never writes, it shows the evidence for every result, and it leaves every decision with their engineers.

The accidents we remember

Much of today’s process safety practice was written in the aftermath of disasters. Each was investigated in depth, and each investigation found that warning signs existed beforehand.

Timeline of five major accidents: Flixborough 1974, Bhopal 1984, Piper Alpha 1988, Texas City 2005 and Deepwater Horizon 2010, each with the warning sign that was already there beforehand.
  • 1974, Flixborough, UK. A cyclohexane release and explosion killed 28 people. Already there: a temporary bypass pipe had been installed with no engineering assessment or pressure test.

  • 1984, Bhopal, India. A methyl isocyanate release killed thousands and exposed more than 500,000 people. Already there: the refrigeration, scrubber and flare meant to contain such a release were shut down, on standby or undersized.

  • 1988, Piper Alpha, North Sea. Explosions and fire destroyed the platform and killed 167 people. Already there: a pump was restarted while its pressure safety valve was out for maintenance, and the permit recording it was not found at shift change.

  • 2005, Texas City, US. An explosion during a unit restart killed 15 people and injured 180. Already there: similar vapor releases from the same vent system had occurred at least eight times in the decade before.

  • 2010, Deepwater Horizon, Gulf of Mexico. A well blowout killed 11 people and spilled millions of barrels of oil over 87 days. Already there: pressure test readings that showed the well was not secure were misread.

Each of these is remembered for what it cost. In each, the signs were there in a record, on an instrument or in someone’s memory, but no one connected them in time.

That is the problem we started uc2c.ai to solve. Somewhere, the next major accident is already taking shape in records that don’t yet talk to each other. Our aim is to find it first.

Somewhere, the next major accident is already taking shape in records that don’t yet talk to each other.

Frequently asked questions

What does uc2c.ai do?

uc2c.ai builds Hazard Navigator, software that helps high-hazard plants find the risk hidden between their records. It connects hazard studies, change records, drawings and incident history into one living picture of plant risk, and ranks what to address first. Every result is traced to its source.

What problem does Hazard Navigator solve?

In high-hazard plants, the most dangerous risks sit between records held by different teams: a change the hazard study never caught up with, or a safeguard credited on paper but out of service. Hazard Navigator connects those records so the warning signs are seen before an incident, not after it.

Why hasn’t this problem been solved before?

Plant knowledge lives in documents written for people, such as PDFs, scans and spreadsheets, which software could store but not read. Checking all of it by hand comes to millions of comparisons per facility. Generic AI can read documents, but it cannot show the evidence a safety decision requires.

Who uses Hazard Navigator?

Process safety engineers, operations leaders, engineers reviewing changes, and site and company leaders in chemicals, refining, oil and gas, and pharmaceuticals.

Does Hazard Navigator make safety decisions?

No. Hazard Navigator is decision support. It reads a plant’s records but never writes to plant systems, traces every result to its source, and leaves every decision to a qualified engineer.

Why would a conservative industry adopt new software?

Process industries are cautious about software that adds work, but they invest every year in keeping people, assets and communities safe. Hazard Navigator serves that priority directly, and it earns trust by showing the evidence for every result.

David Parham

David Parham is Co-Founder and Chief Product Officer of uc2c.ai, building Hazard Navigator — Comprehensive Hazard Intelligence for energy and industrial operations. A chemical engineer, he spent nine years at Chevron, leading topside process design for a major offshore production facility and then running processing operations on a 120,000-barrel-per-day FPSO offshore Brazil. He went on to co-lead the research team that developed the SASB Standards, working with companies, investors and global standard-setters, and to lead product at C3 AI and Fiùtur, launching AI and generative AI products deployed at multinational companies. He holds an MBA from UC Berkeley's Haas School of Business and B.S. degrees in Chemical Engineering and Materials Science and Engineering from UC Berkeley.

https://www.linkedin.com/in/david-w-parham/
Next
Next

Fail-Closed by Design: Why Auditable AI Can’t Depend on Unconstrained Agency