Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-platform-securitycritical-infrastructure-threatindustrial-control-system-vulnerabilitycybersecurity-regulation

Guidance for Secure AI Integration in Operational Technology

Updated 3mo agoFirst seen Dec 3, 20255 sources

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the Australian Signals Directorate’s Australian Cyber Security Centre and other international organizations, has released new guidance outlining principles for the secure integration of artificial intelligence (AI) into operational technology (OT) environments. The guidance addresses the unique risks posed by machine learning, large language models, and AI agents in critical infrastructure, emphasizing the need for education, risk assessment, governance, and embedding safety and security into AI-enabled OT systems. Key recommendations include continuous testing of AI models, regulatory compliance, and integrating AI into incident response plans to ensure the safety, security, and reliability of OT environments.

This initiative comes amid a broader context of increasing cyber risks to industrial control systems (ICS) and OT, as highlighted by a significant rise in internet-exposed ICS devices and a surge in vulnerability disclosures across hundreds of vendors and products. CISA’s ongoing advisories and collaborative efforts underscore the urgency for critical infrastructure operators to adopt robust security practices, including those specific to AI integration, to defend against evolving threats targeting essential services and industrial environments.

Share:
Guidance for Secure AI Integration in Operational Technology
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Dec 4, 20257mo ago

Industry reporting highlights safety and security risks from AI in OT

Subsequent coverage summarized the new joint guidance, emphasizing risks such as model drift, poor training data, limited explainability, hallucinations, operator overload, and increased dependence on cloud and third-party components in critical infrastructure OT environments.

Dec 3, 20257mo ago

CISA and international partners publish AI-in-OT security guidance

CISA, Australia, the NSA, and other partner agencies published joint guidance titled "Principles for the Secure Integration of Artificial Intelligence in Operational Technology." The document warns that using AI in OT and ICS environments can introduce new attack surfaces, safety risks, and operational failures, and recommends governance, vendor transparency, and stronger data and access controls.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

37 LINKEDOpen in app
Threat actors
1 linked
Organizations
26 linked
CISAAustralian Signals Directorate’s Australian Cyber Security CentreImmersiveNational Security AgencyMitsubishi Electric CorporationAvevaHitachi EnergyRockwell AutomationCisco SystemsGreyNoiseDelta Electronics, Inc.VolexityPalo Alto NetworksSchneider ElectricSOCRadarSiemensTrimbleCloudflareFortinetValuehdPtzopticsNiceEdimaxSmtavmultiCAM SystemsGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Guidance for Secure AI Integration in Operational Technology | Mallory