What is Agentic AI in OT?

Agentic AI in OT is the use of autonomous AI agents, usually built on a large language model (LLM), that independently break a goal down into steps in an industrial environment and carry out actions through connected tools, such as retrieving data, raising work orders or proposing settings. Where classic AI mainly predicts and a chatbot mainly answers, an agent acts. That makes the technology attractive to operators and maintenance teams, but in OT every action ultimately touches a physical process. Stricter boundaries therefore apply than in the office environment.


🧠 What makes an AI agent different from other AI?

An AI agent combines three building blocks: a language model that reasons and plans, a set of tools (APIs, databases, scripts) the model is allowed to call, and a memory or context that holds intermediate results. The agent decides for itself which tool to use and in what order. Joint guidance from international cyber authorities describes AI agents as software that processes data, makes decisions and initiates autonomous actions using AI and ML models.

Characteristic Predictive ML Copilot / chat assistant Agentic AI
What it does Predicts or classifies Answers questions, suggests text or code Plans and executes multiple steps
OT example Predictive maintenance on vibration data Explaining an alarm in plain language Analyses a fault, raises a work order, schedules a technician
Output Number, label, probability Text for a human Tool calls that change systems
Determinism High: same input, same output Low: deliberate randomness in the model Low, plus a chain of decisions
Typical Purdue level Levels 0–3 Mostly levels 4–5 Mostly levels 4–5, using data exported from OT
Who decides A human, based on the output A human The agent, within the limits you set

The distinction from machine learning matters. A predictive model at Purdue level 2 has been doing useful work for years. Agentic AI adds the authority to act, and that authority is exactly what you need to constrain.


🏭 Where is Agentic AI used in OT?

The first applications sit mostly in supporting tasks around the process, not in the control loop itself:

  • Operator assistant: answers questions about procedures, searches manuals and summarises the process state at shift handover
  • Alarm analysis: groups alarm floods, looks for the probable root cause and supports alarm management
  • Maintenance planning: combines failure history, spare-parts stock and schedules into proposed work orders
  • Setpoint advice: suggests optimisations for energy use or yield, which the operator reviews and applies
  • Code generation: writes or reviews PLC code in Structured Text according to IEC 61131-3, which an engineer then tests on a test system
  • Reporting and compliance: gathers logs and change records for audits

What these have in common is that the agent prepares and a human decides. Fully autonomous control of a PLC by a language model is not (yet) a responsible use case in practice.


🔐 What risks does Agentic AI bring to OT?

Risk What happens Consequence in OT
Prompt injection Instructions hidden in a document, ticket or email steer the agent elsewhere The agent makes unwanted tool calls
Unsafe actions The agent changes a setting outside safe process limits Lost production, damage, danger to people
Hallucination The model invents a plausible but wrong answer The operator makes a poor decision
Data exfiltration The agent sends process data or configurations outside Attackers gain knowledge for a targeted attack
Model and supply chain risk A tampered model, plug-in or tool server Supply chain risk reaching into the OT zone
Over-reliance Operators lose the skill to run the plant without AI Slow or wrong response when the AI fails
Conflict with determinism Results are neither reproducible nor verifiable Clashes with functional safety requirements

Prompt injection tops the OWASP Top 10 for LLM Applications (2025 edition). In December 2025 OWASP published a separate Top 10 for agentic applications, with agent goal hijack as its first entry. An agent with broad permissions also creates a new path for lateral movement between IT and OT.


📜 What do the international principles for AI in OT say?

On 3 December 2025, CISA and Australia’s ASD’s ACSC published the joint guidance Principles for the Secure Integration of Artificial Intelligence in Operational Technology. Its co-authors are the NSA, the FBI, the Canadian Cyber Centre, Germany’s BSI, the Dutch NCSC, NCSC-NZ and NCSC-UK. The guidance explicitly covers ML, LLMs and AI agents, and sets out four principles:

  1. Understand AI: know the specific risks, educate staff and require a secure development lifecycle from suppliers
  2. Consider AI use in the OT domain: test the business case and manage OT data risks and the role of vendors
  3. Establish AI governance and assurance frameworks: fold AI into existing security frameworks, test continuously and account for regulation
  4. Embed safety and security practices into AI and AI-enabled OT systems: keep a human in the loop, monitor, build failsafes that revert to conventional automation or manual operation, and include AI in incident response

The guidance is unusually blunt about safety. It states that AI such as LLMs almost certainly should not be used to make safety decisions in OT, and that humans ultimately remain responsible for functional safety. CISA and its partners also recommend push-based architectures, where data is pushed out of OT without persistent inbound access, ideally through one-way transfer such as a data diode.


🛡️ How do you keep an AI agent within safe boundaries?

  • Never write to the SIS: the safety system stays independent, deterministic and out of reach of any agent
  • Read-only by default: an agent gets read access to historian or MES data; write access is the exception
  • Bounded actions: each tool has a fixed list of permitted operations and hard upper and lower limits
  • Human in the loop: changes to setpoints or logic go through approval and change management
  • Least privilege and its own identity: the agent runs under its own account, so logs show what the AI did and what a person did
  • Complete logging: record prompts, tool calls and results for forensic analysis

Tool protocols such as the Model Context Protocol (MCP), which Anthropic introduced in November 2024 and transferred to the Linux Foundation’s Agentic AI Foundation in December 2025, make connecting tools easy. That is precisely why you should treat every MCP server as a new access path: allow only approved servers, each with its own authentication and as few functions as possible.


⚖️ How does Agentic AI relate to the AI Act and the Machinery Regulation?

The AI Act classifies AI systems as high-risk when they are a safety component in the management and operation of critical digital infrastructure, road traffic or the supply of water, gas, heating or electricity (Annex III, point 2). Following the Digital Omnibus, which entered into force in July 2026, those obligations apply only from 2 December 2027. The definition of a safety component was also narrowed: AI used only for user assistance, optimisation or convenience falls outside it, unless its failure would endanger health or safety.

For machinery, the Machinery Regulation (EU) 2023/1230 is decisive and applies from 20 January 2027. Under its Annex III, machinery with fully or partially self-evolving behaviour or logic must not perform actions beyond their defined task and movement space. The Omnibus moved the Machinery Regulation to Section B of Annex I of the AI Act, so AI-specific requirements for machinery will be added to the Machinery Regulation itself through delegated acts.


🛠️ How do you set up governance for Agentic AI in OT?

  1. Take inventory: map every AI component and agent, including AI inside vendor products and shadow AI
  2. Classify the use case: advisory, preparatory or acting; read-only or writing; outside or inside process control
  3. Assess the risk: add prompt injection, hallucination and new failure states to your HAZOP and security risk assessment
  4. Design the boundaries: tools, permissions, limits, approval steps and hard separation from the SIS
  5. Test outside production: on a test system or digital twin, including red teaming with malicious prompts
  6. Monitor and evaluate: log every action, track error rates and review model updates from vendors
  7. Rehearse the fallback: operators must be able to run the process without AI; include AI failure in incident response

❓ Frequently asked questions

Can an AI agent control a PLC directly?

Technically an AI agent can control a PLC, but the international guidance on AI in OT strongly advises against letting language models make safety decisions. Responsible use of Agentic AI in OT means the agent proposes and a human approves. A direct write connection to a safety system should never be part of the design.

What is the difference between a copilot and an AI agent?

A copilot gives answers or suggestions that a human then acts on. An AI agent carries out steps itself through tools, such as retrieving data or raising a work order. In OT, an AI agent therefore needs stricter permissions, logging and approval steps than a copilot.

Did the Dutch NCSC sign the guidance on AI in OT?

Yes, the Dutch NCSC is a co-author of Principles for the Secure Integration of Artificial Intelligence in Operational Technology, published on 3 December 2025. The guidance was written by CISA and ASD’s ACSC together with the NSA, the FBI, the BSI and the cyber authorities of Canada, New Zealand and the United Kingdom. It is not legally binding, but it is a key reference for Agentic AI in OT.

Is Agentic AI in OT high-risk under the AI Act?

Agentic AI in OT is high-risk under the AI Act when the system is a safety component in critical infrastructure, such as the supply of water, gas, heating or electricity. An agent that only summarises, advises or optimises without a safety function usually falls outside that category after the 2026 amendments. The obligations for these high-risk systems apply from 2 December 2027.

What is prompt injection in an industrial environment?

Prompt injection is an attack in which hidden instructions in text that an AI agent reads, such as a fault report, a manual or an email, make the agent deviate from its task. In an industrial environment this can lead to unwanted actions or leaked process data. You should therefore treat all external text as untrusted input.

Why does AI not belong in a safety instrumented system (SIS)?

A safety instrumented system must be deterministic and verifiable, and must demonstrably comply with IEC 61508 and IEC 61511, including the required SIL. A language model does not always give the same result for the same input and can hallucinate, so it cannot meet those requirements. Agentic AI should therefore always remain outside the safety system.


📌 In summary

Agentic AI in OT can take a great deal of work off operators and maintenance teams, provided the agent is read-only by default, acts within hard limits and never touches the safety system. The joint principles published in December 2025 by CISA, ASD’s ACSC, the Dutch NCSC and partners are the starting point; the AI Act and the Machinery Regulation determine when additional legal requirements apply.