AI Adoption in OT Security Surpasses Governance Controls

Key Takeaways

  • 87.7% of industrial organizations are exploring or using AI for operational technology cybersecurity, but only 7.9% have fully integrated it across functions.
  • AI is primarily utilized for threat detection (33.8%) and network monitoring (31.5%), with concerns about reliability and the need for human oversight being prevalent.
  • Only 15.6% have formal policies for AI use in operational environments, highlighting a gap in governance and oversight.

AI Adoption in Industrial Cybersecurity

A recent survey, “The State of AI in OT Cybersecurity 2026,” reveals that while a significant portion of industrial organizations is adopting artificial intelligence for cybersecurity measures, there are limitations regarding formal controls in operational technology (OT) environments. The study found that 87.7% of respondents are currently using, evaluating, piloting, or planning to adopt AI technologies for OT cybersecurity, but only 7.9% have integrated it across various security functions.

Deployment of AI for OT cybersecurity functions has seen varied results. Approximately 30.8% have implemented AI for at least one cybersecurity function, while 37.1% are in the evaluation or pilot stages. An additional 19.9% plan to implement AI within the next year, but 12.3% currently have no plans at all. The most common applications include threat detection and alerting (33.8%), network monitoring and anomaly detection (31.5%), and support for security operations (24.5%).

Despite the promising applications, only 15.6% of respondents reported having an enforced AI policy that specifically addresses the needs of industrial environments. This lack of formal governance raises questions about the effective and safe use of AI. Many organizations rely on informal oversight practices, with only 23% having a documented protocol for human intervention in AI-driven decisions.

Challenges in Implementation and Oversight

The survey highlighted significant barriers to effective AI deployment. Data quality, availability, and labeling were identified as the top challenges (45.4%), followed closely by integration issues with legacy systems (42.4%), and concerns about reliability in safety-critical environments (38.7%). Over 87.7% of respondents acknowledged the risk of potential AI-related cyberattacks leading to operational downtimes or safety incidents.

Most respondents acknowledged the positive impacts of AI, with 69.9% believing that its benefits outweigh the associated risks. However, only 20.9% felt the benefits were clearly greater than the risks, indicating prevalent concerns about reliability and data integrity.

Human oversight remains a critical component in AI decision-making, with 78.7% of respondents reporting some level of human monitoring. However, the nature of this oversight is mostly informal. Among those who could answer, more than half lack a formal oversight process.

The Growing Need for Governance

The study found that specific governance policies for AI remain largely underdeveloped in OT contexts. Just 15.6% of respondents have an enforced policy on AI use. However, nearly 50.3% either have such a policy in place or are developing one. Among those who currently deploy AI, 81.7% either have a formal policy or are in the process of creating one.

Formal governance is crucial, particularly as attackers increasingly utilize AI to optimize their operations. Consequently, organizations must engage with technical safeguards for their AI systems, as only 35.1% claimed they have mechanisms in place to prevent manipulation or compromise of AI tools.

With the anticipated increase in AI regulations and frameworks, over half of the respondents are monitoring developments in this area, though only 17.9% have initiated formal programs to comply.

As the landscape evolves, organizations must balance expanding their AI capabilities with ensuring that appropriate governance and operational controls are maintained to safeguard against potential risks. In the next six to twelve months, organizations that progress effectively will be those that enhance AI utilization while ensuring its authority remains consistent with their control measures and operational standards.

The content above is a summary. For more details, see the source article.

Leave a Comment

Your email address will not be published. Required fields are marked *

ADVERTISEMENT

Become a member

RELATED NEWS

Become a member

Scroll to Top