Artificial intelligence is no longer confined to pilot projects on the factory floor. It is moving into the control room. Predictive maintenance models flag failing pumps before a technician notices a vibration change. Vision systems inspect welds faster than any human eye. And a new generation of agentic AI tools is beginning to recommend and, in some cases, initiate operational actions once reserved for human operators.
That shift is now drawing official attention. In May, CISA and international partners issued joint guidance on the secure adoption of agentic AI, warning that these systems expand the attack surface and introduce risks such as privilege escalation, behavioral misalignment and limited auditability as they take on operational roles in critical infrastructure.
Weeks earlier, NIST released a concept note for an AI Risk Management Framework profile on trustworthy AI in critical infrastructure. For CISOs, OT security leaders, and risk and audit professionals, the question is no longer whether AI will scale across industrial operations, but whether governance can scale with it.
Why the Pace Is Accelerating
Three forces are converging. First, industrial digital transformation has matured to the point where the data needed to train useful models, sensor telemetry, historian records and maintenance logs finally exists in usable form.
Second, IT/OT convergence has created the network and data pathways that make centralized AI platforms technically feasible across plants and sites.
Third, competitive pressure is real: organizations that use AI to reduce downtime and extend asset life are gaining a measurable cost advantage and boards are asking why their organization isn’t moving faster.
Why OT Is Not the Same Problem as IT
Scaling AI in IT and scaling it in operational technology are fundamentally different exercises. In IT, a flawed model output rarely has physical consequences. In OT, a flawed recommendation can affect physical safety, product quality or critical infrastructure reliability. OT environments also run on legacy protocols and equipment with multi-decade lifecycles, alongside safety systems that cannot tolerate the rapid iteration AI teams take for granted in IT. An IT-style “move fast” deployment model is a mismatch that governance has to correct before it becomes an incident.
The Risks Leaders Need to Govern
A handful of risks deserve explicit attention as AI expands across operations:
- Model drift: a model trained on last year’s process conditions can quietly degrade as equipment ages or parameters shift, producing confident but wrong recommendations.
- Autonomous decision-making: as agentic systems move from advisory to action-taking, the line between “AI-assisted” and “AI-controlled” blurs, raising hard questions about accountability when something goes wrong.
- Supply chain exposure: third-party models and vendor-hosted AI services introduce dependencies that are difficult to audit, echoing the third-party risk patterns already familiar from OT vendor remote access.
- Data integrity: AI is only as trustworthy as the sensor and historian data feeding it; manipulated or corrupted inputs can poison decisions without triggering a traditional security alert.
- Operational resilience: over-reliance on AI-driven processes can erode the human skills and manual procedures needed when systems fail or go offline.
Practical Guardrails for Scaling Responsibly
None of this argues against adoption. Instead, it argues for sequencing. A few practices separate organizations that scale AI well from those that scale risk instead:
Anchor governance in existing frameworks rather than inventing new ones.
The NIST AI Risk Management Framework and NIST Cybersecurity Framework 2.0 both map well onto industrial environments when paired with control-specific guidance such as the ISA/IEC 62443 series.
For LLM- and agent-based tools, the OWASP Top 10 for LLM Applications and OWASP’s emerging guidance on agentic AI security offer a practical checklist of failure modes to test before go-live. Where agents reach plant systems through tool integrations, the OWASP MCP Top 10 covers that connection layer.
Deploy in phases, with kill switches at every stage.
Start advisory-only, prove reliability against ground truth, then expand decision authority with a tested path to revert to manual control.
Build human-in-the-loop checkpoints into anything safety- or production-critical.
Do this not as a compliance formality but as a genuine override capability operators are trained and authorized to use.
Treat AI risk assessments as continuous, not a one-time sign-off.
Monitor for drift, retrain on a defined cadence and log model decisions with the rigor applied to change control elsewhere in the plant. For audit and assurance teams, that decision log is what makes an AI-influenced operational outcome reviewable after the fact, and accountability gaps are precisely what the joint agency guidance identifies as a distinct risk category.
Make AI governance cross-functional from day one.
Cybersecurity, control engineering, operations and compliance need a shared seat at the table. A model approved by data science but never reviewed by the engineers who own the process it touches is a governance gap waiting to surface.

The Leadership Imperative
Ultimately, scaling AI responsibly is a leadership decision before it is a technical one. Boards increasingly expect and in some jurisdictions are required to demonstrate that AI governance keeps pace with AI adoption, particularly where critical infrastructure is involved.
The leaders who get this right are not the ones who slow innovation down; they build the governance structure early enough that speed doesn’t come at the expense of safety, compliance or trust.
Responsible AI scaling in industrial environments is no longer a technology initiative to delegate downward. It belongs on the same agenda as financial risk and physical safety because, increasingly, it is the same risk.