AI adoption in OT security outpaces governance controls

Share This Post

Industrial organisations are adopting artificial intelligence for threat detection, network monitoring, and security operations, but formal controls governing its use in operational technology environments remain limited, according to a new industry survey.

The State of AI in OT Cybersecurity 2026 report found that 87.7% of respondents are using, evaluating, piloting, or planning to adopt AI for OT cybersecurity. Only 7.9% have deployed the technology across multiple security functions.

Almost one-third of respondents, 30.8%, have deployed AI for at least one OT cybersecurity function, while 37.1% are evaluating or piloting the technology. A further 19.9% expect to begin implementation within the next 12 months, while 12.3% reported no current plans.

AI is already being used for threat detection and alerting by 33.8% of respondents, network monitoring and anomaly detection by 31.5%, and security operations centre support by 24.5%. However, only 15.6% reported having an enforced AI policy specifically covering OT or industrial environments.

AI use centres on monitoring and detection

AI use is concentrated in monitoring and analyst-support functions. Threat detection and alerting was the most common application, followed by network monitoring and anomaly detection.

Another 22.2% of respondents apply AI to incident response and triage. Although these uses generally support security analysis rather than direct industrial control, they can affect how alerts are classified, prioritised, and investigated.

An incorrect classification, suppressed warning, or unsuitable response recommendation can influence decisions involving equipment availability, operational continuity, and safety controls.

Use was lower in vulnerability management, cited by 19.5% of respondents, risk assessment and prioritisation at 17.5%, and predictive maintenance or asset health at 12.9%.

The report also found a gap between reported benefits and formal measurement. While 32.4% of respondents said AI had delivered a quantifiable or observed improvement, only 8.6% could demonstrate a formally measured result.

Most respondents viewed AI positively, with 69.9% saying its benefits in industrial cybersecurity outweigh its risks. However, only 20.9% said the benefits were clearly greater than the risks.

The largest group, 49%, took a more qualified position and identified concerns involving reliability, data integrity, model manipulation, and the need for human oversight.

“These findings indicate a clear interest in deploying AI systems, but OT and ICS organisations struggle with how to implement AI safely, effectively, and with operational control,” Jonathon Gordon, directing analyst at Takepoint Research, said.

Broader deployment remains uncommon. While 45.7% of respondents have formally evaluated, piloted, or deployed agentic AI for an OT cybersecurity function, only 21.2% have moved the technology into an active pilot, proof of concept, or production environment.

Of that group, 16.2% are conducting pilots or proofs of concept. Production deployment stands at 5%.

Agentic AI refers to systems that can take actions without step-by-step human instruction. In OT environments, the level of authority granted to these systems determines whether they remain advisory tools or can influence actions affecting industrial processes.

Although 78.7% reported some form of human oversight for applicable AI-driven decisions, most relied on informal practices. Among the 183 respondents for whom the question applied, 55.7% had oversight that was not formally codified, while only 23% had a documented and enforced human-in-the-loop protocol.

A further 18.6% reported no defined protocol, while 2.7% said AI-driven decisions were largely automated.

Documented oversight was closely associated with consequence mapping. Among the 42 respondents with an enforced human-in-the-loop protocol, 90.5% had completed at least some assessment of the AI-driven decisions that could affect physical processes.

Implementation challenges were concentrated in data and existing infrastructure. Data quality, availability, and labelling was the most commonly cited barrier at 45.4%, followed by integration with legacy OT systems at 42.4% and reliability concerns in safety-critical environments at 38.7%.

AI failures carry physical risks

Concerns also extend to the physical consequences of attacks against AI systems or operational data. Around 20.5% of respondents classified such attacks as a top operational risk, while 43.4% described them as an emerging priority.

Overall, 87.7% acknowledged at least some possibility that an AI-related cyberattack could contribute to downtime, equipment damage, or a safety event. Concern was higher among organisations already using AI, with 79.2% placing the issue in one of the two highest concern categories, compared with 37.3% of non-users.

The report said the risk is not limited to autonomous systems. A compromised AI tool could suppress an alert, misclassify an incident, recommend an inappropriate response, or corrupt information used in an operational decision.

Nozomi Networks CEO Edgard Capdeveille said attackers are also using AI to support cyber operations. “Adversaries are increasingly using AI to augment their attacks, heightening the speed and sophistication of threats,” Capdeveille said.

He said industrial defenders are introducing AI into their security operations in response. The survey, however, found that technical safeguards around those tools remain limited.

Just over one-third of respondents, 35.1%, said they have controls designed to protect AI tools and models against manipulation, adversarial inputs, or supply chain compromise.

Only 7.6% said those safeguards had been tested sufficiently to support high confidence, while 27.5% had introduced controls that were not yet fully validated.

The report identified training and operational data, model behaviour, manipulated inputs, third-party components, and AI-generated outputs as areas requiring assurance. These risks extend beyond conventional network and endpoint protection because altered inputs or outputs can affect how security teams interpret activity within an OT environment.

BlastWave CEO and co-founder Tom Sego said organisations should assume attackers have access to the same technology. “Embrace AI for everything it can do in OT, but deploy it behind a perimeter that assumes the adversary has AI too,” Sego said.

OT-specific governance remains limited

OT-specific governance policies remain uncommon. Only 15.6% of respondents reported having an enforced policy governing the use of AI in operational environments.

Another 34.8% were developing an OT-specific AI policy, bringing the share with an enforced policy or one in development to 50.3%.

A further 30.8% relied on general IT or cybersecurity policies. The report said such policies may not account for AI-related operational, safety, and physical-process risks in industrial environments.

Governance activity was more common among organisations that had already deployed AI. Among respondents using AI for at least one OT cybersecurity function, 81.7% had either enforced an OT-specific policy or were developing one.

A written policy did not always correspond with tested controls. Of the 47 organisations with an enforced OT-specific AI policy, only 17 had tested the safeguards protecting their AI tools and models.

The report also found that only 11.9% had formally identified and reviewed AI-driven decisions that could directly affect physical processes, safety systems, or operational continuity. Another 25.2% had assessed selected systems.

Consequence mapping links an AI-generated output to the operational decision it informs, the action that may follow, and the control available to stop an unsafe outcome.

Among the 176 respondents for whom consequence mapping applied, 63.6% had completed at least some form of assessment. However, only one in five had established a formal, reviewed process.

All 36 respondents with a formally mapped and reviewed process also reported having an enforced OT-specific AI policy. The report said this association indicates that formal governance and consequence mapping tend to develop together.

More than half of respondents, 54.3%, were monitoring or preparing for AI-related regulations, frameworks, or sector guidance, but only 17.9% had established a formal initiative.

“Over the next six to 12 months, the organisations that progress furthest are likely to be those that expand AI use without granting it more authority than their controls, evidence, and operating models can support,” Gordon said.

(Photo by Homa Appliances)

See also: Anthropic and Nozomi bring AI vulnerability research to OT security

Banner for IoT Tech Expo by TechEx events.

Want to learn more about the IoT from industry leaders? Check out IoT Tech Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including AI & Big Data Expo and the Cyber Security Expo. Click here for more information.

IoT News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

Adblock test (Why?)

More To Explore

  • About
  • Smart Tech
  • Solutions
  • Join Us
  • Contact
  • Contractor’s Hub