← All articles

· Crossover Software

AI Agents in OT: Governance Controls to Put in Place Before They Act on the Plant Floor

At the Industrial AI Summit 2026, OT security experts named identity, traceability and segmentation as minimum conditions before letting an AI agent act on production data. A practical checklist for plant managers and IT/OT teams.

Industrial AIOT securityIEC 62443Smart factoryGovernance

On 1 October 2026, IIoT World published a report on a panel at the Industrial AI Summit 2026 devoted to the governance of AI agents in OT environments. The speakers were Scott Christensen (GrayMatter), Gary Tillery (Skkynet) and Ian Bramson (Black & Veatch), moderated by Matt Morris of EverLine. This is neither research nor a regulatory development, but practitioner guidance. That is precisely what makes it useful: it addresses the concrete problems faced by anyone connecting MES, IIoT and artificial intelligence tools.

A note on the source: the article is labeled as sponsored by Skkynet, although it states that it is editorially independent, and it notes that AI tools were used to help summarize its content. It is best read as food for thought, not as a standard.

The problem: one agent per vendor

In a plant with 20 or more vendors, each one could introduce its own AI agent, with its own access model, its own integrations and its own risk profile. OT systems are tightly interconnected: a change made by one agent can affect downstream systems. Without common rules, the sum of these agents becomes hard to govern.

Identity and audit trail

The first requirement the panel identified is that every agent has unique credentials, just like a human user. The audit trail should record:

  • who initiated the action;
  • what permissions the agent had;
  • what data informed the decision;
  • how the change was executed;
  • what the outcome was.

The entire data chain should be reconstructable, the way a supply chain tracks raw materials: the log must show where execution took place and who, or what, authorized it. For organizations working under quality and audit requirements, the parallel with product traceability is direct.

Technical controls

On the technical side, the panel points to role-based, least-privilege access, credentials held in a vault, network segmentation and continuous monitoring. A zero trust approach applies: no agent is considered trustworthy on any network. The goal is to limit the impact of a failure to the segment in which the agent operates. Every path by which data leaves the production area must also be managed: according to the speakers, the "air gap myth" is over.

Few principles, but clear ones

Since no single framework covers both OT security and AI, the suggestion is to combine IEC 62443 with AI-specific rules, limiting them to 5–10 core principles. Among those cited:

  • least privilege for every agent;
  • no autonomous agents at Level 0 of the Purdue model;
  • mandatory identity and access tracking for every action;
  • assessment of consequences before going live;
  • analysis of data flows before introducing AI.

The report notes that governance becomes more prescriptive in regulated sectors, especially in Europe, where additional compliance requirements apply; it does not give details, which must be verified case by case.

Three questions for Monday morning

The speakers proposed questions that managers can ask themselves right away:

  • Tillery: if connectivity were lost, what would keep working, and who decided that?
  • Christensen: we back up our data, but do we also back up the process, including configurations and ladder logic?
  • Bramson: where is the AI risk register for OT, who owns each risk, and what is the order of priority?

What to do with this

Before allowing an agent to act on production data or setpoints, check that dedicated identities, minimum permissions, segmentation and a complete audit trail are in place, along with an assessment of consequences. These controls are valuable even without AI, but with autonomous agents they become the starting condition.