A consultation on 21 proposed changes points to a narrower compliance debate with a wider goal: keeping critical infrastructure rules relevant as AI changes how cyber risk is measured.