Gartner, Inc., has issued a prediction that, by 2028, misconfigured AI in cyber physical systems (CPS) will shut down national critical infrastructure in a G20 country.
Gartner defines CPS as engineered systems that orchestrate sensing, computation, control, networking, and analytics to interact with the physical world (including humans). CPS is an umbrella term encompassing operational technology (OT), industrial control systems (ICS), industrial automation and control systems (IACS), industrial Internet of Things (IIoT), robots, drones, and Industrie 4.0.
Misconfigured AI can autonomously shut down vital services, misinterpret sensor data, or trigger unsafe actions, warns Gartner. This could result in physical damage or large-scale service disruption, posing direct threats to public safety and economic stability by compromising control of key systems such as power grids or manufacturing plants.
For example, modern power networks rely on AI for real-time balancing of generation and consumption. A misconfigured predictive model could misinterpret demand as instability, triggering unnecessary grid isolation or load shedding across entire regions or even countries.
To mitigate risks, Gartner recommends that chief information security officers (CISOs) should:
- Implement safe override modes: for all critical infrastructure CPS, include a secure ‘kill-switch’ or other override mechanisms accessible only to authorised operators, so that humans retain ultimate control, even during full autonomy.
- Digital twins: develop a full-scale digital twin of the systems supporting critical infrastructure for realistic testing of updates and configuration changes before deployment.
Real-time monitoring: mandate real-time monitoring with rollback mechanisms for changes made to AI in CPS, while also ensuring the creation of national AI incident response teams.
“The next great infrastructure failure may not be caused by hackers or natural disasters but rather by a well-intentioned engineer, a flawed update script, or a misplaced decimal. A secure ‘kill-switch’ or override mode accessible only to authorized operators is essential for safeguarding national infrastructure from unintended shutdowns caused by an AI misconfiguration.”
Wam Voster, VP Analyst at Gartner
Gartner clients can learn more in Predicts 2026: Emergent Critical Risks of AI in CPS Security.






