Back to Insights Vulnerabilities

New Cybersecurity Guidelines for the Use of AI in Critical Infrastructure

From Vision Documents to Clear Rules of Play
For the First Time: A Unified Front of Leading Global Cyber Authorities
Global cybersecurity authorities – including key entities in the US (such as CISA, the FBI, and the NSA) as well as the Australian Signals Directorate – have published joint guidelines for the first time for the safe integration of Artificial Intelligence in Operational Technology (OT) systems.
OT systems are the systems that operate our “critical infrastructure” – such as water plants, energy grids, transportation, and industry. The alignment between these bodies indicates a significant shift: moving from theoretical discussions on AI to practical rules intended for these organizations.
The document acknowledges that AI has immense potential to improve efficiency and predict failures. However, it emphasizes that AI also brings new risks:
Model Drift: AI may start making decisions that diverge from those it was originally trained on over time.
Safety Bypass: The technology could accidentally or maliciously bypass existing safety mechanisms.
Uncertainty: AI introduces uncertainty into physical systems where any wrong decision could lead to actual harm.
Safety is Not the Same as Security
Why AI Should Not Make Safety Decisions in OT Systems
One of the most important contributions of the guidelines is the clear separation between information security (Security) and physical safety (Safety).
Security deals with protecting information (integrity, availability) and defending against attacks.
Safety concerns preventing harm to human life and the environment. Artificial Intelligence, especially models capable of “generating” content (like LLMs), blurs this line because it is unpredictable or non-deterministic.
The guidelines explicitly state:
Models like LLMs (Large Language Models) almost certainly should not be making safety decisions in critical operational systems.
The point is not to stop innovation, but to set a clear boundary. For example, in a water treatment plant, an AI model might interpret a small anomaly as a recommendation to change chemical dosages – a decision that could be very dangerous, even if the system wasn’t hacked. Therefore, AI is defined as an “advisor” rather than an “operator,” and active human supervision is always required.
Architecture, People, and Supply Chain
How to Integrate AI Without Opening New Doors for Attack
The guidelines offer a clear roadmap for integrating AI into operational systems:

Predictive AI: Models designed to predict (such as predicting pump failures or identifying temperature anomalies) are suitable for the core of operational systems.
Generative AI: “Creative” models (like those of ChatGPT) are more suitable for managerial layers – such as writing documentation, generating regulatory reports, and managing office processes.

To reduce attack risks, the guidelines recommend technical structures where data flows out of the operational system, but there is no permanent incoming access from the outside into the system. This prevents a situation where an AI system located in the cloud serves as an entry point into the sensitive operational network.
Beyond technology, there is a strong emphasis on people: over-reliance on AI can lead to the erosion of critical human skills. Therefore, training is required that teaches operators not only how to use AI – but also how to challenge it, verify its outputs against physical reality, and maintain manual knowledge for failure scenarios.
Practical Recommendations from IPV Security Professionals
How to start implementing the guidelines in practice:

Mapping: Check where AI is already integrated today in operational systems and information systems.
Clear Definition: AI advises – humans decide.
Maintaining Boundaries: Separate safety issues from security issues in system design.
Secure Architecture: Adopt network structures that do not allow permanent incoming access to operational systems (OT).
Demand Transparency: Ask vendors for information about the source of the models, their training methods, and a list of components (BOM).
Ongoing Training: Refresh verification and testing procedures and train operators to handle failures throughout the system’s lifecycle.

In Conclusion,
The new global guidelines do not call for stopping the integration of artificial intelligence in critical infrastructure – but rather doing it correctly and responsibly.
The central message is clear: true resilience is created when AI improves decision-making, but does not replace human responsibility. Organizations that choose a balanced approach – with boundaries, transparency, and oversight – will be able to enjoy the benefits of AI without risking the foundation upon which society as a whole relies.
For more information: New cybersecurity guidance paves the way for AI in critical infrastructure | CyberScoop

Tags: artificial intelligence, operational technology, critical infrastructure, ai safety, model drift, cisa, cybersecurity guidelines, large language models

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation