AI on Both Sides of the OT Firewall
Brussels just put AI on both sides of the plant firewall. Read from the control room, the EU's new Cyber-AI Action Plan is part threat model, part toolkit.
The banner comes up amber, not red, and that's the problem. On a night shift, the screen that matters shows a variable-speed drive on the number-two recirculation pump pulling a little more current than it did last quarter, the trend bending up where the model learned to expect it flat. An experienced hand reads that shape in a second. A bearing going dry, most likely. Write the work order, keep half an eye on it, ride out the shift.
But this year the operator has to hold a second thought beside the first. That gentle drift could be wear. It could also be the faint wake of someone already inside the network, moving slowly enough to pass for wear. The edge model that flagged the pump was trained on normal, and normal on a plant floor is gloriously dull: the same controllers speaking the same protocols to the same endpoints on the same cycle, hour after hour after hour. That dullness is the whole reason you cut a plant into zones and conduits in the first place, because once the baseline is that quiet, anything strange has nowhere to hide. And yet a failing bearing and a patient intruder can, for a few hours, leave the same small dent in the same trend.
Which is why a policy paper out of Brussels landed harder on the plant floor this summer than these things usually do. On 7 July 2026 the European Commission presented its Action Plan on Cybersecurity and Artificial Intelligence, built on top of the AI Act, the Cyber Resilience Act, and NIS2. Beneath the framing sits one operational claim every process engineer should sit with. AI is now on both sides of your firewall. The Commission is blunt about the offensive half, warning that AI "can be misused to identify vulnerabilities, automate attacks and increase the scale and speed of cyber incidents at an unprecedented speed." About the defensive half it makes a promise pointed partly at you, a secure testing platform and cyber ranges for operators in critical sectors, energy among them.
For a site already living under NIS2, none of that is abstract. Energy sits squarely in scope, and so does much of food, water, and metals processing. What the plan changes isn't the obligation you already carry. It changes the character of the adversary you're told to defend against, and the clock speed the defense has to run at to keep up.
The knowledge that used to keep them out
Think about how the standards ask you to size a threat in the first place. The ISA/IEC 62443 series rates the attacker you're defending a zone against not by the tools in their bag but by resourcefulness: casual contact at the bottom, then a deliberate attacker with simple means, then one with sophisticated means and genuine control-system-specific knowledge, and at the top a determined adversary with deep resources and high motivation. Read those tiers as a working engineer and one phrase does the load-bearing work. Control-system-specific knowledge. For years, that was the moat.
Knowing how to spoof a Modbus register, which permissives a burner management system checks and in what order, what a safe state looks like on a particular safety controller: none of that sat on the open web. It lived in the heads of a small number of people, most of them wearing your company's logo on their coveralls. An attacker either had that knowledge, spent long months acquiring it, or gave up and went looking for softer prey. The rare-knowledge barrier did a great deal of quiet defensive work that no firewall line item ever got credit for.
That's the moat machine intelligence quietly drains. Hand a capable model a stolen P&ID and a folder of scanned manuals, and the specialist reading that used to cost a trained attacker days (the slow, patient part of the job) compresses into an afternoon. The model doesn't have to be brilliant. It has to be a tireless assistant that turns a heap of scraped documents into a ranked list of the softest ways in, drafts a note to a named maintenance contractor that reads exactly like the ones they really get, and never loses interest in trying one more variation. What used to gate the sophisticated attacker was patience and scarce knowledge. One of those two just got cheap.
Consider what reconnaissance already looks like before a model touches it. A surprising share of the OT world is findable from a chair: internet-exposed HMIs, remote-access gateways left listening, vendor portals that quietly bridge into a plant network. Mapping that exposure used to be the tedious part, hours of scanning and cross-referencing before an attacker even knew what they were looking at. Point a model at the same raw output and the tedium evaporates. It fingerprints the device, matches it to known weaknesses, infers the process behind it from the tag names, and ranks your sites by how little work each would take. The same trick sharpens the human attacks. A phishing note that names the actual DCS you run, the integrator who commissioned it, and a plausible reason to click reads nothing like the clumsy mail your staff learned to delete years ago. The scanning and the lure were always possible. What's new is that turning either one into a working plan no longer needs a specialist, and the specialist was the bottleneck.
None of this makes an attacker omnipotent, and it's worth keeping the fear in proportion. AI doesn't conjure a zero-day into an air-gapped safety system. It doesn't walk a payload across a data diode that physically can't carry a return packet. The laws of your architecture still hold. A conduit that was shut yesterday is shut today, model or no model. What moves is the economics. Reconnaissance that scales across a thousand targets at once, phishing personalized at volume, exploit code drafted and debugged with help, the triage of which of your thousands of tags is the exposed one: each of those was a cost an attacker paid in time and skill, and each just got cheaper. When trying gets cheap, the number of attempts climbs. Your quiet, deterministic network is going to get knocked on far more often, by people who look more capable than their budget says they are.
The model on your side still has to keep the line running
The same compression is available to the defense, with one catch every plant engineer feels in the gut before they can put words to it. On the carpeted side of the business, a security team can meet the new tempo with the new tools: models that swallow a firehose of logs, cluster the noise, and hand a human the three events worth attention instead of three thousand. In an office, a false positive costs you a locked account and an irritated employee. Automate the containment and you claw back real hours from a job that was drowning.
Down on the process side, the worst case is a different animal, and it's the whole story. A model that's allowed to act on the control network is also a model that can trip it. Availability isn't a soft preference here; it sits in the security standard as a first-class property, level with keeping data secret, because a process that halts the wrong way can put someone in a hospital bed. An automated response that quarantines a suspect device might contain a breach in an office. On a controller mid-batch, that reflex becomes the incident. So what do you let a model do when it flags something on a live control network? For anything that can reach into the process, the honest answer is narrow: let it raise a hand, not pull the cord.
That points to where AI genuinely earns its keep inside the fence, which is in the reading, not the reacting. The edge already sees everything worth seeing. A gateway the size of a paperback, clipped to the DIN rail beside the PLC, is already trending vibration and temperature and flow, and already carries the rhythm of the conduits around it. Put a model on the same edge telemetry layer that already watches the process and you gain a second set of eyes that never blinks at four in the morning: watching for the new protocol riding an old conduit, the endpoint that has never spoken before, the engineering login at an hour the shift roster says is wrong. It flags. A person who knows the plant decides. That division of labor isn't timidity; it's the only arrangement that survives contact with a running line.
The reading problem on a plant is the inverse of the one in IT, which is what most tools get wrong. An office network throws off oceans of alerts, and the art is drowning out the false ones. A control network barely speaks above a whisper. The art is noticing the single syllable that doesn't belong. A model that helps here has to hold context an IT tool never carries: that this pump only runs during a wash cycle, that this setpoint moves on a schedule, that this badge has no business opening an engineering session at all. Get the context right and the machine turns the plant's own boredom into an alarm you can trust. Get it wrong and you've built a smoke detector that shrieks every time someone makes toast, which on a plant floor gets muted by the second week, and a muted detector is worse than no detector at all.
There's a second place the tooling helps, and it's the one the Action Plan is really pointing at. A security operations center built for IT doesn't understand a plant. Its models learned what a suspicious Windows process looks like, not what it means when a historian suddenly starts polling a controller it has no business touching. The plan's push to scale up Europe's own AI capability for cybersecurity in critical sectors reads, generously, as an admission that the defensive tools grew up on the wrong world. The signals that matter down here (the vibration signatures, the valve states, the setpoint nudges) appear in none of the datasets those models trained on. A good deal of the field's public benchmarks came from aircraft engines and lab bearing rigs, which is part of why so much off-the-shelf detection feels a size too small the moment you bolt it onto a furnace. Closing that gap is slow, unglamorous work, and no action plan closes it for you.
Somewhere to fail that isn't the furnace
Here's the piece of the plan a controls team can actually put its hands on. Alongside the regulation, the Commission is standing up, with ENISA and its Joint Research Centre, a secure testing platform and cyber ranges built for exactly the sectors that can't afford to learn on the live asset. That phrase deserves its weight. You can't red-team a running clarifier. You can't fuzz the controller on a reheat furnace to watch how it fails, because the way it fails is molten. A cyber range is a rehearsal room, a faithful-enough twin of the control system (faithful enough to break in the same places) where you can throw this new class of AI-assisted attack at your own architecture and see what gives, without a single tonne of product on the line.
For a discipline that has always had to test in production or not at all, that's a real gift, and it's the first door I'd send a controls team through when the platform opens to industry. Rehearsal is where an incident-response plan stops being a binder on a shelf and becomes a reflex in a control room. It's also where you find out, cheaply and in private, that the plan quietly assumed things the plant will never hand you. The account you were sure you could disable turns out to run a critical historian feed. The network tap you counted on isn't where the drawing says it is. Better to learn that on a twin than at two in the morning with a regulator's clock already ticking.
The rehearsal also drags the non-technical failures into daylight, and those sink more responses than any missing patch. Who actually places the call to the national authority, and do they know the plant well enough to describe what happened? The OT team often doesn't even hear about an IT compromise in time; the news reaches the control room from a headline. And the vendor who holds the keys to the controller you now need to examine may be unreachable on a Sunday. A range run turns those unknowns into a checklist with a name against each line. That's the unglamorous part, and it's exactly what a live incident punishes you for skipping.
And that clock is unforgiving about time, because the plan doesn't touch the underlying obligation. Under NIS2, a significant incident starts a countdown: an early warning to your national authority inside 24 hours, a fuller notification inside 72. Set that against how an OT investigation really unfolds. In IT you isolate the host, take an image, stand up a clean one, and move on. Down here you often can't take the image at all, because the evidence is a controller mid-campaign that can't be stopped without stopping the process, and the next maintenance window is weeks out. So you're asked to characterize, inside a day, an intrusion into a machine you aren't allowed to touch. AI-assisted forensics that can reason across the historian, the packet capture, and the controller's own thin logs isn't a luxury in that spot. It might be the only way the 24-hour clock and a live process ever meet in the same room.
And so the banner stays amber. The pump still pulls a little more than it did last quarter, the trend still bending up where the model wants it flat. Somewhere in the plan, a testing range is being wired together. Somewhere past the firewall, a tool now reads your manuals faster than the people who wrote them ever could. The operator on nights makes the same call they've always made, on the same thin evidence. A bearing going dry, or a hand on the network? This is the first year you can't answer that from the shape of the trend alone, and have to go and look.
Notes
Two caveats worth stating plainly. The Action Plan is a direction of travel, not a delivered capability: the ENISA and JRC testing platform and cyber ranges are still being built, and what they give industry stays unclear until a controls team can actually log into one. And this is not a universal prescription. Where the reasoning holds is a plant already inside NIS2 with real OT to defend; a small site running a flat network with no historian has a different first problem, and it isn't AI. The threat sizing here is deliberately qualitative. The two hard specifics I leaned on, the Commission's plan and the NIS2 reporting deadlines, are linked above; the rest is engineering judgment, which has limits of its own and gets sharper the day you rehearse it against something that pushes back.
References
Reuse & license
This article is published by Zoniax OÜ under a Creative Commons Attribution 4.0 International (CC BY 4.0) license. You are free to share and adapt it for any purpose, including commercially, as long as you give appropriate credit to Zoniax and link back to the original article.
Disclaimer
These Field Notes are general technical information, published as-is for industry peers. They are not professional, engineering, safety, legal, or financial advice, and nothing here is a recommendation to buy, sell, or act. Figures are cited from public sources believed reliable but are not independently guaranteed - verify them against the primary sources and your own plant conditions before acting. Zoniax OÜ and the author accept no liability for decisions made from this content. Naming a standard, product, or vendor is not an endorsement.
Cite this article
Nõmm, A. (2026). AI on Both Sides of the OT Firewall. Zoniax. https://zoniax.com/blog/posts/ai-cyber-threats-industrial-operators
Permalink: https://zoniax.com/blog/posts/ai-cyber-threats-industrial-operators