Predictive and generative AI are already making a major impact in mining, especially in areas like mineral processing – where it is possible to not just forecast maintenance related issues based on learning from past data, but also to optimise processes based on changing ore feed in real time, revolutionising short interval control. In autonomous haulage, thanks to sensor fusion and greater environment perception, onboard AI intelligence is now enabling mining trucks to anticipate more complex scenarios and respond to obstacles or mixed fleet traffic in real time without stoppages.
But there is a third area of AI that has enormous potential in mining – that is agentic AI, which acts as an independent assistant that can independently navigate multi-step workflows. These systems are capable of planning, making decisions, and taking autonomous actions to achieve specific goals with minimal human intervention – which has huge potential in a remote operations centre type environment – effectively removing siloes and achieving decision making in real time from pit to port.
Ahead of the inaugural edition of The AI Mine conference, being held September 7-8, 2027 in Singapore, IM Editorial Director Paul Moore set out to understand agentic AI better in a mining context, and spoke to Fatimah Abdulghafur, Co-Founder and CEO of agentic AI company Tolun AI. She has spent nearly 20 years as a geoscientist across all three earth-science disciplines – geology, geochemistry, and geophysics – on four continents, from remote field sites to boardrooms. Most recently she was Principal Specialist Geophysicist at Ma’aden and before that, an exploration geoscientist at Fleet Space Technologies. Tolun AI is building one agentic system that spans the mining lifecycle – exploration, resource, development, operations and closure – with 48 services published in three tiers, based on who runs it: the platform, its team, or a Competent Person.
Fatimah Abdulghafur, Co-Founder and CEO of agentic AI company Tolun AI

Q What is agentic AI, and why is it significant in mining beyond the predictive and generative AI tools the industry is already using?
The difference is where the system stops. Predictive AI tells you a bearing will fail. Generative AI writes you a paragraph about the bearing. Both hand you back a recommendation, and a person still has to do the work. That’s the ceiling, and most of what the industry calls AI today sits under it. An agentic system doesn’t stop at the recommendation. It recognises that something needs doing, proposes the action, asks your consent, then carries it out and hands you the finished result. Our own shorthand for it is: turn every “here’s what you should do” into “shall I do it?” Your own industry already wrote this distinction down, for machines. EMESRT’s performance requirement for vehicle interaction systems separates Level 8, advisory controls, which give “a specific instruction to the operator to intervene,” from Level 9, intervention controls, which give “a specific instruction to the machine to intervene”. South Africa made Level 9 law in 2022. Mining has understood the difference between recommending and acting for years – it just applied it to proximity braking rather than to decisions. You’ve also covered one shape of it recently – Applied Intuition’s Dana, which Komatsu is using to bring agentic capability into its engineering workflows. That’s agents helping build the machines, and it’s real. Ours is the other lane: agents pointed at the decisions. Where to drill, what the ground is, whether the resource stands up, what closure is going to cost. Same idea, different half of the mine, and the two will meet.
In mining that difference is worth more than it sounds, because our problem is rarely a shortage of insight. It’s that insight arrives in fragments – the geophysicist has one piece, the geochemist has another, the geologist has a third – and someone senior spends weeks assembling them into a decision. An agent can read the data, choose the method, run it, check its own result and tell you what it couldn’t resolve. That collapses the assembly time. Not by being cleverer than the geoscientist. By not needing the geoscientist for the twenty steps that never required judgment in the first place. And the shape of it is not what people picture. An agentic system isn’t one clever model that knows a little about everything. It’s a team. Each agent holds a goal instead of waiting to be prompted, and each is trained deep in one speciality the way you’d hire people – a geologist, a geochemist, a geophysicist, a data manager, a QA/QC lead, a drilling engineer, a resource estimator. Any seat on a mining company’s org chart. They work in concert, and they argue: Pascal Bornet and his co-authors – who have built agentic systems in other industries, not ours – put it well in Agentic Artificial Intelligence, that a panel of experts in structured debate reaches better conclusions than any one of them alone. When the geophysics agent and the geochemistry agent disagree about what a body is, I want that surfaced, not averaged away. And they learn from the Competent Person: every time you overrule one and say why, that judgment goes back into what the team knows. Working agentically feels less like using software and more like having hired the team you always wanted and could never justify.
Q To what extent are mining companies already using agentic AI – are there any initial examples of use cases?
Honestly: much less than the conference programmes suggest. Plenty of pilots, plenty of copilots bolted onto existing software, very little running unattended against production data. Most of what gets called agentic is a chat window in front of a database – and once you’ve been shown that, it’s easy to conclude there’s nothing here. I went looking properly before answering you, and the examples that exist are real but small. BHP used Microsoft’s agents to screen more than half a million molecules for a copper-leaching reagent – genuinely agentic, and BHP’s own words are that the candidates “could one day be deployed,” so it’s research, not operations. Vale has AI that predicts dust conditions and fires mist cannons by itself: three cannons at one port complex, and as far as I can tell that is the only unattended AI action any miner has published. Rio Tinto runs an assistant built on Amazon’s agent infrastructure that answers questions about a thirty-year-old plant system and changes nothing in it. That last one is the whole pattern in miniature – agent infrastructure is being counted as agentic deployment.
If you want the blunt version: across the sixteen large miners that file with the SEC, the words “agentic” and “AI agent” have never appeared in a single filing. Not once, ever. Those same companies mention artificial intelligence dozens of times, so it isn’t that they don’t file on the subject. So I’ll say it plainly, because I don’t think it’s a close call. Agentic AI is the future of this industry. Not a tool it adds on the side – the way its decisions get made. The companies that get there first will be making better calls on the same ground, with the same data, than the ones that don’t.
Here’s what it looks like on the ground. An exploration manager with a licence, a room full of legacy data, and one question: is there anything here worth drilling Today that comes back slowly, through separate consultancies working to separate briefs, and the decision gets made on whichever two datasets were in the last presentation. Agentic AI doesn’t make each step faster – it removes the seams. The system we’re building reads everything the company already owns, runs the physics, checks the chemistry, ground-truths the geology, integrates the assays, argues with its own result, tells you where the evidence is thin, and comes back with ranked targets and the reasoning attached. Not a report you commission. A question you ask – with a Competent Person at the end of it, signing. Exploration is where I started because it’s where my heart is, but the same is true of resource estimation, of the studies, of closure. Anywhere a decision waits on someone assembling evidence by hand.
We’re building that in the open. Twenty-four blind, pre-registered studies on public data – eight countries, seventeen deposit types – with the pass/fail bar written into version-controlled code before each study runs, so it can never quietly move afterwards to flatter the result. Of 36 metrics committed in advance, 11 came in met, 18 did not, and 7 are open. Nine studies are recorded as fail, with the reason published beside each one. It’s all at tolun.ai/validation, and three are published in full – Winu, Pilgangoora and the NSW Macquarie Arc. I put that in front of clients on purpose, and the reason is personal. As a principal geophysicist, I was the client on the other side of a technical report more than once, signing off on a result I had no practical way to check. If a vendor can’t show you a case where their system failed, that isn’t a track record. It’s a brochure.
A live 2D gravity inversion on the Tolun AI platform with the interpretation the agent wrote underneath it. The agent refuses its own result: it says the solve isn’t usable, that the cross-section is regularisation rather than geology, and that the headline density number is sitting on the constraint bound rather than coming from the data. The input is public data – Bouguer anomaly grid of Finland © Geological Survey of Finland, GTK Open Licence

Q Looking at areas like mineral consultancy and the EPC/EPCM part of the industry – is there potential to use agentic AI in areas like mineral exploration reporting, or collation of prefeasibility, feasibility and technical reports?
This is where it lands first, and faster than most people expect. A technical report is a long chain of small, evidence-bound steps. Pull the assays, check the QA/QC, reconcile the drillhole database against the model, chase the one hole that doesn’t tie, assemble the figures, make sure every number in the text matches the number in the table. Almost none of that is judgment. All of it is expensive, and it’s where the errors get in. Not from bad geology – from a stale figure nobody re checked after the resource was updated. That work is close to ideal for agents because every step is checkable -the agent can be made to show its source for every number it prints.
But the bigger prize isn’t a cheaper report. It’s a different kind of report. A prefeasibility study today is a snapshot that starts decaying the day it’s issued – new drilling arrives, a price moves, a recovery assumption changes, and the document is out of date long before anyone can justify rebuilding it. If a study is assembled by agents from live evidence, you stop reading it and start asking it questions. What does the schedule do if this hole comes back barren? Which of these conclusions depend on the assumption that just changed? That’s the version I want to build – a study that stays current, and tells you when it has stopped being true.
I’d expect the same to be true on the EPC and EPCM side, where the documents are bigger and the reconciliation is worse, though that’s further from my own bench than the resource side is. What’s striking is that nobody is doing it yet. I went through the major consultancies and EPCM firms looking for anyone claiming agentic AI on resource reports, competent person’s reports, feasibility studies or design-basis documents, and found no public claim anywhere. The closest, Ausenco, states its own constraint plainly – every critical decision keeps a human in the loop. So the lane with the most obvious drudgery and the clearest fee pool is the one where this has arrived least.
What doesn’t move is the signature. A Competent Person under JORC, or a Qualified Person under NI 43-101 – and the same holds under SAMREC and PERC – signs because a named human is accountable, and no amount of automation changes that. It shouldn’t. The goal isn’t to remove the CP. It’s to make it cheap for the CP to sign honestly, because the evidence behind every claim is one click away instead of three weeks away. On our side that’s literal: every result carries a signed provenance record anyone holding the hash can check at tolun.ai/verify. The codes haven’t caught up yet. The current NI 43-101 rewrite and the JORC revision materials contain no mention of artificial intelligence at all – and there’s a question sitting under that which the industry hasn’t answered.
Kapageridis and his co-authors put it directly a few years ago: how can a Competent Person make their assumptions transparent when they can’t understand the system that produced them? That’s the right question, and the answer isn’t to ban the system. It’s to build one whose reasoning a CP can actually inspect. I think this makes the reporting codes stronger. It doesn’t threaten them.
Q In what ways are the AI agents still using LLMs, and do they require additional learning mechanisms to react to mining’s dynamic environment – how is this achieved in practice?
The language model is the part that reasons and plans. It isn’t the part that knows the physics, and it never computes an answer. When our system inverts a gravity survey, no language model touches the arithmetic. That’s a forward model and a regularised inversion – the same mathematics we’d run without any of this. What the language model does is understand what was asked, set the job up, read the result and explain it. Keeping those two apart is deliberate. The model can reason about the physics. It can’t invent it. So it can’t hallucinate a density contrast.
On learning, and this is where people expect the wrong answer: the base model isn’t retrained on mining, and deliberately so. I don’t want a model that has quietly absorbed one region’s habits and applies them to another, and I don’t want anyone’s data ending up in a training set as a side effect of simply using the system. What adapts is everything around it. A curated knowledge base the agents read from, which we correct when it’s wrong. A library of deposit signatures and regional context. The corrections themselves – when a Competent Person overrules an agent and says why, that reasoning goes into what the agents read, so the team is sharper next time without a single weight being changed. And an evaluation harness that runs as a gate on every code change, enforcing the standing rules of honesty – that an inversion reports uncertainty rather than a bare point estimate, that a cell with no prior comes back unresolved instead of asserted, that the provenance stamp reproduces. That’s the learning mechanism that matters in a dynamic environment: not a bigger model, a tighter feedback loop with humans in it.
The rest of the machinery is mostly about restraint rather than capability. Gates that refuse – the design rule is that if the data can’t support a result, the answer is “I can’t resolve this,” not a picture, and where we’ve found the engine returning a confident answer it hadn’t earned, that’s the bug we fix first, not a rounding error. Calibrated confidence, because a number the system reports as 70% has to be right about 70% of the time or it’s decoration. And earned autonomy, which is the part I’d argue hardest for. Mining’s own functional-safety work says plainly that non-deterministic systems can’t be analysed by the established methods, and that a safety performance level claim may not be possible for them at all. You cannot certify a probabilistic system the way you certify a brake.
So the response isn’t to pretend you can – it’s to tier autonomy by how reversible the action is, and let an agent earn more of it on demonstrated track record. Toil gets delegated freely. Anything a person can’t easily undo stops and asks. That last one is the whole design. The scarce thing isn’t an agent that can act. It’s an agent whose confidence you can trust.
Q Why did you opt to focus Tolun AI on the mining sector, and how much of that is based on your experiences at companies like Ma’aden
Almost all of it. I’ve worked across all three earth-science disciplines – geology, geochemistry, geophysics – on four continents since 2004. It means I’ve sat in the geophysics chair, the geochemistry chair and the geology chair on the same deposit, and watched three competent people reach three partial answers because nobody owned the whole picture. That’s not anyone’s fault. It’s how the industry is built, and I’ve never been happy with it.
And I mean that personally, not as a market observation. I’ve spent a lot of my career watching highly trained people spend their days on work that didn’t need them, and watching good ground get walked past because nobody had the time to look at it properly. The second is expensive. The first is the one I couldn’t let go of. There’s no dignity in spending a trained person’s working life on clicking, downloading and redrawing a plot for the fourth time – and I didn’t want to spend mine that way either. Reducing both is why I started this company, more than any market I could point at.
At Ma’aden, as Principal Geophysicist, thin-plate modelling was what found the copper, not a new instrument and not a bigger survey, but a better interpretation of data the company already held. I was responsible for the geophysics across early and advanced exploration, and on the other side of the same job I spent six months supervising an airborne contractor, watching the acquisition end of the same problem. The pattern was the same at every scale I saw it: the industry spends enormous sums acquiring data it never fully uses. That stopped being an observation and became the thing I couldn’t stop thinking about. That gap – between the data mining companies already own and the decisions they actually extract from it – is the business. It isn’t a mining-software problem. It’s an intelligence problem that happens to sit in mining, and mining is where I can see it clearly enough to build for it.
Q How do you see Tolun AI’s trajectory and roadmap – would your agentic AI be added as another layer into the AI platforms mining companies are already using?
I want to push back gently on the framing, because it’s the question we get most and the answer matters. We are not a layer. A layer sits on top of someone else’s system and makes its output prettier – and when the answer is wrong, a layer has nobody to blame and nothing to sign. We’re the intelligence core – the part that reads the data, decides what to do, does it, and stands behind the result. We integrate happily with what a client already owns. Data comes in from their systems, results go back out to them. And for a large operator with its own secure environment, the whole thing can run inside it. But the reasoning isn’t borrowed, and it isn’t a plug-in to somebody else’s brain.
On trajectory, since that’s the actual question: I’m not building a better tool for geoscientists. I’m building the system a mining company runs its technical decisions through – where the data lands, where the analysis happens, where the argument gets had, and where the recommendation arrives with its evidence attached and a name signed at the bottom. Exploration first, because that’s where I can prove it fastest. Then resource, the studies, operations, closure. The end state is that a company stops commissioning this work in pieces from four different firms and reconciling it themselves.
On what exists today, the real shape rather than a headline number. Our catalogue carries 48 services across the mining lifecycle in three tiers – 14 built into the platform itself, 17 we run for a client, 17 a Competent Person delivers – and those tiers are generated from the code rather than from a marketing decision, which means the catalogue occasionally catches us and corrects itself. It did that a few weeks ago, and I want it to keep doing that. Underneath, eleven forward models are wired into the engine and published on our own public capabilities endpoint – from gravity and gradiometry through magnetics and magnetotellurics to surface waves, receiver functions, heat flow, geoid and elevation. You can fetch the full list yourself without an account. More are validated in the core than have a client route yet, and I’d rather you check the endpoint than take my number.
The joint inversion is the part I care most about – 3D gravity-magnetics run on real field data at Sudbury, and 3D geochemistry-with-geophysics so far only on known-truth synthetics. I’ll always say which is which. The roadmap is the movement between those tiers: methods migrating from “we run it for you” to “you run it,” and agents earning wider autonomy as their track record justifies it. The engine is domain-agnostic by construction, and we’re deliberately proving that outside mining as well as inside it. I’ll name where when there’s something signed to name.
One thing worth saying plainly, because it’s part of the argument rather than a footnote to it. There are two of us at the centre of it, with support from people in this industry whose judgment I trust. I’m in Riyadh; my co-founder, Dr Alim Polat, is in Stockholm, and he builds the platform end to end. We have never once been in the same room. A company this size claiming it could cover a mining lifecycle would have been absurd three years ago. That it isn’t absurd now is the whole point of the thing I’m describing. They ask, and the answer comes back whole.
Q How are mining companies ensuring cybersecurity in terms of protecting the data their AI systems use — are there additional cybersecurity aspects to using agentic AI?
There are, and they’re different in kind, which I don’t think the industry has fully absorbed yet. Conventional data security asks: who can read this? Agentic security has to ask a second question – what is the system allowed to do? An agent holds tools. It can run jobs, write results, reach other systems. So the boundary that matters is no longer only around the data. It’s around the actions. On the first half of your question, the industry’s honest problem is that nobody really knows how it’s doing. Rob Labbé, who runs the Mining and Metals ISAC, has said plainly that there is massive under-reporting of cyber incidents in this sector – and you cannot manage a risk you are not counting.
And there’s a genuinely new attack surface that I don’t think the industry has priced in yet. An agent reads things – your files, your logs, a vendor’s report. Anything it reads can carry instructions, not just information. A line buried in a CSV or a PDF can try to tell the agent what to do, and the agent has tools. That class of attack is not solved anywhere in this field, by us or by anyone selling to you, and I’d treat a vendor who tells you otherwise with suspicion. What you can do is contain it: every tool call is treated as an untrusted request rather than a trusted one, unknown arguments are rejected instead of quietly dropped, the tenant is derived by the server rather than taken from the request, and nothing irreversible happens without a person. The honest position is that the blast radius is engineered, not that the attack is prevented.
What that means on our side. Each client’s data is isolated at the database level and enforced there rather than in application code, so an application bug isn’t the thing standing between one client and another. Agents get an explicit allowlist of tools: anything not on it fails closed, and a malformed declaration resolves to no tools at all rather than to all of them. Irreversible actions don’t happen without a person. And every result carries a signed provenance record – which data, which parameters, which version of the code – signed with a key whose public half we publish openly, no account needed.
That last one is worth spelling out, because I think it’s the part of this that should become normal and hasn’t. If you hold a result of ours, you can check three things without asking us anything at all. That it’s genuinely ours, because the signature validates against a key you fetch yourself. That nobody has altered it since, because changing a single digit breaks the signature. And that it’s the result we actually produced, because the fingerprints of the data and the parameters are inside the record. You don’t need our cooperation for any of that, which is the point – a verification that depends on the vendor being helpful isn’t verification. There’s a live one at tolun.ai/verify if you’d rather try it than take my word for it.
I wouldn’t tell you the surface is closed. I’d tell you where the boundary is drawn and who checks it. I’d also say what we don’t do: we’re not in the control room, and we don’t touch anything with a safety interlock on it. The question I’d put back to any vendor – and I’d want to be asked it myself – is the blunt one: is my data used to train your models? It’s the concern I hear most and the one most often answered vaguely, so let me answer it properly rather than just ask it.
Today the answer is no. Our models are built from your own ground at the moment you run them, and nothing accumulates behind them. If that ever changes – if a foundation model is going to learn from a client’s data – it happens only with that client’s explicit consent, asked plainly and separately, never buried in terms of service. And one thing every provider should be asked, us included: what the underlying model vendor does with whatever passes through. On that you’re relying on somebody else’s contract, and you should know whose.
Q The fear with AI, especially agentic AI, is that a lot of technology-related roles in mining will become redundant – is that the case, or will it create new roles such as in human oversight?
Some of both. I’ll take the uncomfortable half first, and I’ll be specific, because vague answers to this question are how the industry lost people’s trust on automation. Work does disappear, and I can name it because I’m building the thing that does it. Reformatting data between systems. Rebuilding the same plot for the fourth time. Re-reading a table to confirm it agrees with the paragraph above it. And the big one for my own discipline: a geologist sitting with reams of drilling data, decoding by hand whether there is something there or not.
Brandon Craig, now BHP’s Chief Executive, described that task publicly in 2025 and said AI interprets that data more reliably. I think he’s right, and I’d finish the sentence he stopped short of: that particular way of spending a geologist’s week is going away. I’ll give you the moment that started the company. A Vice-President came to my desk and said, Fatimah, can you find me this report? He was a VP. His time was expensive. I was a principal geophysicist, so was mine. And between us we spent it on something that needed no geophysics at all – finding a document, then downloading a dataset from a public survey portal. Neither of us should have been anywhere near it. That work is so low-level it isn’t a person’s job at all.
I won’t give you the comfortable version of the second half, because there’s a serious argument against it. The usual reassurance is that automation always creates new jobs to replace the ones it takes. Dario Amodei, who runs the AI lab Anthropic, has made the case that this time is different – that because AI matches the general shape of human cognition, it will also be good at the new jobs that would ordinarily appear. That deserves an answer rather than a slogan, and mine is narrower than the optimists’ and less bleak than his.
Here’s what I’d point at. Across aviation, nuclear, rail, shipping and medicine, automation has deleted job titles – fireman, brakeman, flight engineer, radio officer, engine-room watchkeeper – and in not one of those industries did it delete accountability. It moved to a differently-named human, or regulation held it in place until the technology could prove itself. Shipping went furthest: a rule written in 1993 requires every company to designate, in writing, a person ashore whose job is to monitor whether the safety system is actually working, with a guaranteed line to the top of the company. That is the oversight role people speculate about. It’s thirty-three years old and it has case law behind it.
Our own code says the same thing more bluntly than we usually notice. JORC requires a Competent Person to belong to a professional body with the power to suspend or expel a member. You cannot expel an algorithm. Whatever the software does, the accountability has nowhere else to go. Two caveats, because I’ve watched this industry promise otherwise. Those roles are fewer than the ones they replace, and they often sit somewhere else – a control room in a capital city is not a job in Newman or Moranbah, and pretending otherwise is the move that cost mining its credibility on automation. And the way this arrives is quieter than redundancy. It’s doors that stop opening – the graduate position that isn’t posted – which is harder to see and harder to argue with than a layoff.
The question I’d actually put to a working geoscientist isn’t whether they’ll be employed. It’s whether they’ll still be able to do this in five years. That’s not my worry, it’s an old one: Lisanne Bainbridge wrote in 1983 that someone who has been monitoring an automated process for years may have become an inexperienced operator, and that automation therefore needs people who are more skilled, not less. Aviation published the same finding about its own pilots in 2013. Skill fades when it isn’t used, and nobody gets an exemption. So if I’m asked what to protect, it isn’t headcount. It’s the currency of the people who sign. What I’d say to anyone worried about their own role is that the burden of proof runs the other way, and it hasn’t been discharged. When American rail regulators mandated two-person crews in 2024, their reasoning was that no railroad had yet made the case that its technology was good enough to remove one. Nobody has made that case for the Competent Person either — not in mining, not anywhere. When producing a result becomes cheap, the scarce thing is the person willing to put their name on it, and that person has to understand what the system did well enough to defend it. That’s a capability an organisation has to build deliberately. It doesn’t arrive with the software.
A full list of sources for every external claim in the answers above, with where it comes from, is available from Fatimah Abdulghafur, Tolun AI Co-Founder and CEO at fatimah@tolun.ai











