Critical infrastructure is racing to adopt AI. Why visibility must come first

State-backed cyber adversaries are already mapping physical control loops to target critical infrastructure. Image: Unsplash/Ximin Lin
- AI adoption in the industrial sector is moving faster than security monitoring in operational environments.
- State-backed cyber adversaries are already mapping physical control loops to target critical infrastructure.
- Organizations must establish strict AI governance and operational visibility before blind spots expand.
Across industrial and critical infrastructure, we’re racing towards an AI-powered future with tremendous promise for efficiency, optimization and competitive advantage. But we’re not addressing the risks that AI poses to the industrial systems that make modern life possible.
Cybersecurity for enterprise IT and AI models themselves are getting attention, but the focus on how AI affects the safety, security, and resilience of operational environments lags far behind. You cannot have an AI revolution without energy and infrastructure; you cannot keep your energy and infrastructure for long without operational technology (OT) cybersecurity.
Findings from Dragos’s 2026 OT/ICS Cybersecurity Report confirm a stark reality: adversaries are already operating inside industrial environments that aren’t monitoring for them. AI adoption will make that visibility problem significantly harder to solve.
Why change is accelerating as OT evolves
Over the past 40 years, OT environments have evolved from mechanical controls to digital systems; over the past 30 years, from isolated networks to IP-connected infrastructure; and over the past 20 years, into complex automation environments made up of OT, IT and Internet of Things (IoT) devices.
The past decade has seen this accelerate dramatically. Digital transformation has brought enormous efficiency benefits but also created new attack surfaces and dependencies we have still not appropriately secured.
Now we’re entering the next phase: AI integration into OT. Unfortunately, adoption is moving faster than our ability to manage the risks.
AI is moving into the control loop
Manufacturing plants, electric grids, data centres and other organizations with physical processes are moving AI from supporting roles into the control loop, harnessing the fundamental capability of these systems to impact the physical world. Early adopters are deploying AI applications, controllers and software into operations. Some are exploring agentic AI in battery farms, solar farms, wind farms, the mining industry and other critical infrastructure.
Boards, executives and investors are pushing adoption. The result is pressure on testing and validation timelines, reduced scrutiny of new vendors, and more complexity than these environments have ever managed before.
The threat landscape isn’t waiting
Our 2026 OT/ICS Cybersecurity Report found that adversaries targeting OT environments have crossed a significant threshold. Multiple threat groups linked to state-backed and criminal organizations around the world moved into actively mapping control loops: identifying engineering workstations, exfiltrating configuration files and alarm data, and learning how physical processes operate well enough to disrupt them. Two such threat groups included ELECTRUM and KAMACITE.
KAMACITE spent months systematically mapping control loops across US infrastructure. ELECTRUM, the group responsible for the 2015 and 2016 Ukrainian power grid attacks, has spent a decade refining its capability against Ukrainian targets. That experience, once gained, does not stay confined to a single region. In December 2025, ELECTRUM struck Poland, conducting the word’s first major coordinated cyberattack against distributed energy resources, including the renewable energy management systems that represent exactly the infrastructure AI is being deployed to optimize.
When something goes wrong in an OT environment, whether it’s a cyberattack, malfunction or operational error, organizations need the ability to conduct root cause analysis. Too many cannot. They either rely on IT monitoring that doesn’t cover OT, or have invested so little in OT visibility that when an incident occurs, they can’t determine what happened, when or why.
AI adoption makes this problem worse by adding layers of autonomous decision-making to environments that already lack visibility.
Two failure scenarios that demand attention now
As organizations integrate autonomous decision-making into critical infrastructure, two emerging risk scenarios highlight why visibility and resilience must precede rapid deployment.
Risk scenario one: AI technologies and data disappear with a market reset.
There will likely be an AI correction at some point. What happens to your operations if an AI application or associated data becomes unavailable overnight? Organizations need to ask now: what warranties and continuity commitments are you getting from AI vendors? Can you operate manually or with legacy systems if AI becomes unavailable? The pace of adoption means organizations could find themselves dependent on systems that suddenly disappear.
Risk scenario two: AI blind spots prevent root cause analysis.
As AI makes operational environments more complex, understanding what’s happening in your systems becomes exponentially more difficult. Whether it’s a cyberattack, malfunction or operational error, organizations need data collected in operational environments to support root cause analysis after an incident. We already see this gap in today’s environments. AI adoption will make that problem dramatically worse for organizations without adequate monitoring.
What organizations must do now
First, organizations must establish governance for AI adoption that applies the same testing, validation and continuous assessment rigour they have historically applied to control systems. Leaders must understand the risk of letting competitive pressure override the engineering discipline that has kept operations safe.
Second, organizations must deploy OT-native visibility and monitoring now, before AI adoption further accelerates complexity. The data in our report showed that industrial organizations with comprehensive OT visibility detected and contained ransomware incidents in an average of five days, compared to the industry-wide average of 42 days. Defenders cannot adequately mitigate threats they cannot see, nor can security teams investigate incidents that were never recorded. Visibility gaps only grow bigger as AI increases complexity.
Third, plan for failure by understanding threat scenarios already occurring. Document your AI dependencies. Understand what happens if a system or vendor fails. Maintain the capability to operate without AI when necessary.
Defense is doable
We know how to secure complex industrial systems. The talent and technology exist. Countries can align around protecting civilians, families and shared infrastructure.
What’s required is awareness that this is a problem, dialogue to address it across organizations and sectors, and execution to implement the right safeguards.
The pressure to innovate with AI is real and will only intensify. But the organizations that succeed in the long term will be those that prepare beforehand.
Don't miss any update on this topic
Create a free account and access your personalized content collection with our latest publications and analyses.
License and Republishing
World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.
The views expressed in this article are those of the author alone and not the World Economic Forum.
Stay up to date:
Cybersecurity
Forum Stories newsletter
Bringing you weekly curated insights and analysis on the global issues that matter.





