NSA Warns AI Poses New Threats to OT Security

NSA Issues AI Security Warning for Operational Technology

The U.S. National Security Agency (NSA), alongside international cybersecurity agencies, has issued new guidelines on the integration of artificial intelligence (AI) into operational technology (OT) systems. These recommendations aim to preemptively address emerging risks in critical infrastructure sectors such as energy, water treatment, healthcare, and manufacturing.

The report, titled Principles for the Secure Integration of Artificial Intelligence in Operational Technology, was developed in collaboration with Australia’s Cyber Security Centre and other global intelligence partners. While the document is tailored for OT administrators, it highlights concerns that extend into traditional IT environments as well.

Early AI Adoption Raises Concerns

AI adoption in OT networks is still in its early stages, yet the NSA and its partners are urging caution. Organizations are increasingly deploying AI to streamline operations and boost uptime, but experts warn that the rush to implement these technologies may outpace the development of robust security protocols.

“AI may not be reliable enough to independently make critical decisions in industrial environments,” the authors assert. They discourage the use of large language models (LLMs) and chatbots for safety-critical decisions, citing reliability and explainability issues. The report outlines multiple risks, including:

  • Adversarial prompt injection and data poisoning
  • AI model drift due to divergence from training data
  • Loss of human skills due to overreliance on automation
  • Compliance challenges amid rapidly evolving AI technologies
  • Cognitive overload from excessive AI-generated alerts

These vulnerabilities, if left unaddressed, could lead to significant safety hazards in OT environments where the tolerance for errors is minimal.

Challenges Unique to OT Systems

One of the critical distinctions between OT and IT environments lies in their respective risk profiles. OT networks are typically safety-critical, meaning any security lapse could have serious physical consequences. This makes the integration of untested AI technologies particularly dangerous.

Sam Maesschalck, an OT engineer at cybersecurity training company Immersive Labs, emphasized the importance of addressing foundational issues before adding AI into the mix. “We’ve already seen what happens when operational demands outpace secure design,” he said, referencing the ongoing struggles with IT/OT convergence.

According to Maesschalck, many OT systems lack the infrastructure to support AI. These include outdated devices that cannot generate the necessary data volumes and incomplete asset inventories that increase the likelihood of unpredictable interactions.

Recommendations for Safer AI Integration

To mitigate these risks, the guidelines recommend adopting secure design principles from the Cybersecurity and Infrastructure Security Agency (CISA). Organizations are also encouraged to evaluate whether developing AI-OT projects in-house could offer better control and transparency over implementation processes.

These recommendations serve a dual purpose: they provide clarity for system operators and offer a framework for resisting unsafe or rushed AI deployments. “Having government-backed principles to reference gives owners and engineers something concrete to point to,” Maesschalck noted.

Education and awareness are also emphasized as key components of any AI deployment strategy. The report underscores the need for continuous training to ensure that human operators remain capable and confident, even as AI becomes more integrated into daily operations.

Budget and Policy Gaps Remain

Despite these comprehensive guidelines, some concerns remain unaddressed. Chief among them is the persistent underfunding of OT security initiatives. While the new report builds on last year’s NSA and ACSC recommendations for securing critical infrastructure, it stops short of tackling the financial and policy limitations that hinder real-world implementation.

As AI continues to evolve and permeate new sectors, the NSA and its partners are making a concerted effort to stay ahead of the curve. Their latest guidelines serve as both a warning and a roadmap for organizations looking to integrate AI responsibly into their OT environments.


This article is inspired by content from Original Source. It has been rephrased for originality. Images are credited to the original source.

Subscribe to our Newsletter