- 90% of OT companies exploring AI for cybersecurity, but only 7.9% have deployed it meaningfully.
- Only 7.6% of respondents are 'very confident' in their AI protection controls.
Experts agree that while AI adoption is critical for defending against advanced threats, the current hesitation stems from legitimate concerns about reliability and security risks in high-stakes OT environments.
The AI Paradox: Critical Infrastructure's High-Stakes Bet on an Unproven Defense
SAN FRANCISCO, CA – July 22, 2026 – There's a glaring disconnect at the heart of the world’s most essential industries. A new report reveals that while nearly 90% of companies managing operational technology (OT)—the systems running everything from power grids to manufacturing plants—are exploring artificial intelligence for cybersecurity, a mere 7.9% have actually deployed it in a meaningful way. This isn't just a technology adoption gap; it's a strategic vulnerability at a moment of unprecedented risk.
The ‘State of AI in OT Cybersecurity 2026 Report,’ sponsored by security leaders Nozomi Networks and BlastWave, paints a picture of an industry caught between the urgent need to innovate and a deep-seated fear of the unknown. The numbers tell a story of widespread interest but paralyzing caution. While the intent is there, the confidence is not, creating a window of opportunity for adversaries who are already weaponizing AI with alarming speed and sophistication.
"We've reached one of the most critical inflection points in the history of cybersecurity, especially in the OT and ICS industries," said Edgard Capdeveille, CEO of Nozomi Networks, in the report's release. "Adversaries are increasingly using AI to augment their attacks, heightening the speed and sophistication of threats. As a result, defenders need to implement AI in their work to keep pace."
The Great Hesitation: Why Safety Trumps Speed
The chasm between interest and implementation isn't born from apathy. It stems from the unique, high-stakes nature of industrial environments. In the world of information technology (IT), a cybersecurity failure might lead to data loss or financial theft. In the world of OT, it can lead to physical explosions, blackouts, and threats to human life. This reality forces a level of risk aversion that is almost alien to the fast-moving tech sector.
According to the research, conducted by Takepoint Research, even among the 70% of leaders who believe AI's benefits outweigh the risks, nearly half harbor serious reservations about its reliability, data integrity, and the potential for model manipulation. These aren't abstract fears. OT environments are notoriously challenging for data-hungry AI. Decades-old legacy equipment, proprietary communication protocols, and a lack of standardized data create a messy, fragmented landscape. Training an AI model on this 'dirty' data is a recipe for disaster, potentially leading to a flood of false positives that could prompt operators to shut down critical processes unnecessarily.
This concern is reflected in the report's finding that almost two-thirds of organizations now consider attacks targeting their AI systems a top-tier or emerging operational risk. Yet, the defenses are alarmingly immature. A paltry 7.6% of respondents stated they were "very confident" in their controls to protect AI models, primarily because they were the only ones who had actually tested them. Furthermore, only 11.9% have formally reviewed which AI-driven decisions could directly impact physical processes or safety systems—a staggering oversight.
"Over the next 6 to 12 months, the organizations that progress furthest are likely to be those that expand AI use without granting it more authority than their controls, evidence, and operating models can support," noted Jonathon Gordon, Directing Analyst at Takepoint Research. This is the crux of the paradox: the very tool needed to defend against next-generation threats is itself a new, poorly understood attack surface.
The Shadow Opponent: An AI Arms Race
The hesitation on the defensive side stands in stark contrast to the rapid innovation in offensive AI. Threat actors, from state-sponsored groups to cybercriminals, are not waiting for industry to catch up. They are actively leveraging AI to automate reconnaissance, generate polymorphic malware that evades signature-based defenses, and craft hyper-realistic phishing attacks using deepfake technologies. For them, AI is a force multiplier, enabling smaller teams to launch more sophisticated attacks at a scale previously unimaginable.
One of the most insidious threats is adversarial machine learning (AML), where attackers poison the data used to train defensive AI models or craft inputs that trick a model into misclassifying a threat as benign. In an OT context, an attacker could subtly manipulate operational data over time, teaching a defensive AI that anomalous, dangerous behavior is normal. By the time the attack is launched, the AI watchdog has been effectively blinded.
This new reality demands a fundamental shift in defensive strategy. It's no longer enough to simply deploy AI; it must be deployed with the assumption that it is already a target. Tom Sego, CEO and co-founder of BlastWave, frames this as a new prerequisite for security. "Embrace AI for everything it can do in OT, but deploy it behind a perimeter that assumes the adversary has AI too," he stated. "The same AI that automates and defends OT can be turned against it."
Sego advocates for a preemptive, AI-resistant architecture. His firm's approach focuses on cloaking OT assets to make them invisible to automated reconnaissance tools and dropping any network traffic that is not cryptographically authenticated. The logic is simple: an AI-powered attack can't hit what it can't find. This underscores a growing consensus that AI is not a silver bullet but a powerful capability that must be built upon a foundation of zero-trust security principles.
Charting a Path from Pilot to Production
Despite the risks, the march toward AI adoption is inevitable. The report shows organizations are taking their first cautious steps by applying AI where it can provide the most value with the least immediate physical risk: threat detection (33.8%), network monitoring (31.5%), and augmenting human security analysts (24.5%). This "crawl, walk, run" approach allows teams to gain experience, reduce alert fatigue, and build trust in the technology within controlled contexts.
The deployment of more advanced agentic AI—which can take autonomous action—remains rare, with only 5% reporting production use. This reflects the industry's adherence to the 'human-in-the-loop' model, ensuring that a human expert validates any critical decision before it impacts physical machinery. This model is likely to remain the standard for the foreseeable future, especially as regulatory bodies like NIST, with its AI Risk Management Framework, and international counterparts push for greater transparency, accountability, and human oversight in high-risk AI applications.
Ultimately, the 'State of AI in OT Cybersecurity 2026 Report' is not an indictment of the industrial sector's slow pace, but a clear-eyed assessment of the monumental task it faces. The challenge is to thread the needle—to harness the immense power of AI for defense without introducing catastrophic new risks. For the leaders of the world's critical infrastructure, the question is no longer if they will join the AI arms race, but how they will fight it without becoming their own worst enemy.
Topics & Related
Artificial Intelligence
Agentic AI
Threat Landscape
📝 This article is still being updated
Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.
Contribute Your Expertise →