The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the Australian Signals Directorate’s Australian Cyber Security Centre and other international organizations, has released new guidance outlining principles for the secure integration of artificial intelligence (AI) into operational technology (OT) environments. The guidance addresses the unique risks posed by machine learning, large language models, and AI agents in critical infrastructure, emphasizing the need for education, risk assessment, governance, and embedding safety and security into AI-enabled OT systems. Key recommendations include continuous testing of AI models, regulatory compliance, and integrating AI into incident response plans to ensure the safety, security, and reliability of OT environments.
This initiative comes amid a broader context of increasing cyber risks to industrial control systems (ICS) and OT, as highlighted by a significant rise in internet-exposed ICS devices and a surge in vulnerability disclosures across hundreds of vendors and products. CISA’s ongoing advisories and collaborative efforts underscore the urgency for critical infrastructure operators to adopt robust security practices, including those specific to AI integration, to defend against evolving threats targeting essential services and industrial environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Subsequent coverage summarized the new joint guidance, emphasizing risks such as model drift, poor training data, limited explainability, hallucinations, operator overload, and increased dependence on cloud and third-party components in critical infrastructure OT environments.
CISA, Australia, the NSA, and other partner agencies published joint guidance titled "Principles for the Secure Integration of Artificial Intelligence in Operational Technology." The document warns that using AI in OT and ICS environments can introduce new attack surfaces, safety risks, and operational failures, and recommends governance, vendor transparency, and stronger data and access controls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcecsoonline.com
Open sourcebankinfosecurity.com
Open sourcecisa.gov
Open sourcesocradar.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.