Various national cyber security agencies have jointly published a new guide for the secure integration of artificial intelligence in operational technology (OT).
‘Principles for the Secure Integration of Artificial Intelligence in Operational Technology’ aims to help organizations mitigate risks and achieve a balanced integration of AI in OT systems.
The agencies involved in the development of the guide were:
- U.S. Cybersecurity and Infrastructure Security Agency
- Australian Signals Directorate’s Australian Cyber Security Centre
- U.S. National Security Agency’s Artificial Intelligence Security Center
- U.S. Federal Bureau of Investigation
- Canadian Centre for Cyber Security
- German Federal Office for Information Security
- Netherlands National Cyber Security Centre
- New Zealand National Cyber Security Centre
- United Kingdom National Cyber Security Centre
The guide is structured around four key principles that will help critical infrastructure owners and operators safely and effectively integrate AI into OT systems. These are:
- Understand AI: educate personnel on AI risks, impacts, and secure development lifecycles.
- Assess AI use in OT: evaluate business cases, manage OT data security risks, and address immediate and long-term integration challenges.
- Establish AI governance: implement governance frameworks, test AI models continuously, and ensure regulatory compliance.
- Embed safety and security: maintain oversight, ensure transparency, and integrate AI into incident response plans.






