Security News

AI Agents Reached Industrial Controls in Minutes During Booz Allen Lab Tests

The Register · 11 Oct 2026
Key Takeaway If your business runs industrial or other operational equipment, put foundational OT security basics in place now, because AI-driven attacks may leave very little time to respond.

Autonomous AI systems are capable of attacking the operational technology (OT) that runs water, power and other essential services, according to a report from consulting firm Booz Allen Hamilton. Its OT lab tested eight scenarios to see what advanced models could do inside an autonomous, AI-enabled attack chain. The models achieved the objectives in all eight, turning digital access into physical actions. In one case they found and moved a robotic arm within minutes.

In another test, the models went from compromising the network perimeter to acting inside an industrial control network in just over 16 minutes. The firm warns that defenders may have only minutes to detect and block such an attack. The test environment was modelled on a general manufacturing facility, with separate enterprise, industrial DMZ, plant operations and production zones. Firewalls and switches defined the intended pathways between them. Booz Allen did not name the two models, describing them only as the latest frontier models from leading AI providers.

Kyle Miller, Booz Allen's VP of infrastructure cybersecurity, said AI agents can work with a speed, persistence and precision that may outpace organisations without foundational OT security practices. He noted there is no defined timeline for a worst-case scenario, but that AI use in real-world attacks is growing. Booz Allen wants more industry testing, development and deployment of cyber defences across OT and critical infrastructure networks.

Summarised by CISO AI from The Register, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.