Gartner analyst Wam Voster warned that agentic AI in operational technology (OT) environments could create new cyber-physical and safety risks as autonomous systems begin making production decisions in industrial settings. He said factories may increasingly rely on AI agents to adjust variables such as temperature, timing, and equipment settings based on external and process data, raising the possibility that configuration errors or unsafe automated decisions could move beyond downtime and production loss into physical harm.
Voster highlighted that a misconfigured AI agent could make dangerously incorrect adjustments—for example, changing a process by 200 degrees instead of 2 degrees—with potential consequences including equipment destruction, explosions, or injury and death. He also emphasized that human error remains a major cause of cyber-physical incidents and discussed the limits of applying full zero trust concepts in industrial environments. A separate ZDNET workplace advice article about employee anxiety over AI agents is not about OT security or this specific risk discussion and should be excluded.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Gartner vice president analyst Wam Voster warned that agentic AI in industrial and operational technology environments could autonomously change process variables such as temperature, timing, and equipment settings, creating serious safety and security risks if misconfigured. He highlighted governance, asset visibility, human error, and the practical limits of zero trust in industrial settings as key concerns.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.