The riskWhat an ungoverned agent gets wrong here.
Industrial control systems, the operational technology (OT, the systems that run physical processes) behind power grids, water plants, pipelines, and factories, are increasingly driven by AI agents. Network security tools watch the wire, but none govern the controller's behavior: an unauthorized setpoint change, tampered controller firmware, a bypassed safety system, or a breach of the boundary between the corporate network and the plant floor. The attacks are documented. The Colonial Pipeline ransomware attack shut roughly 5,500 miles of pipeline for six days in May 2021. In February 2021 an intruder reached the Oldsmar water plant's controls and raised sodium hydroxide (lye) to 111 times its normal level before an operator reversed it. Stuxnet, discovered in 2010, destroyed roughly 1,000 uranium centrifuges by altering programmable logic controller (PLC) logic while replaying normal readings to operators. Triton/TRISIS, in 2017, targeted a petrochemical plant's safety system directly. Without governance there is no enforced limit on what an agent may change and no trustworthy record of who, or what, changed it.