FIELD NOTE / INSTAGRAM
An AI assistant extends the OT trust boundary.
The complete written thought and the evidence behind it. The video edition will follow its public release.
The written argument is here.
This approved Instagram edition is on the journal now. Its video player and original platform link will appear after each public release is verified.
An AI assistant extends the OT trust boundary.
Video caption
An AI assistant extends the OT trust boundary.
A note influences a tool with more authority.
Source, model, project, build, deployment.
Assistants draft; approved artifacts cross the OT boundary.
#EricFieldNotes
Full written post / accessibility read
Once an AI tool reads controller projects, maintenance notes or cloud references, the team has added an integration across trust zones. NIST OT guidance emphasizes performance, reliability and safety; ISA/IEC 62443 gives an industrial cybersecurity lifecycle. The integration must be designed, not assumed safe.
In a fictional workflow, an operator note includes a sentence telling the assistant to skip review. The note is legitimate data for context, but not a policy authority. If the assistant can write a PLC project directly, a text boundary has become a change boundary.
Map where data enters, which identity reads it, whether the assistant can write, who approves the exact diff and target, and which credential can deploy. On an isolated copy, inject a harmless conflicting instruction and inspect whether the approved artifact changes.
Keep drafting in a scoped environment and move only reviewed, versioned artifacts through the authorized change process. Do this because protecting the route from untrusted text is as important as protecting the network port.
#EricFieldNotes
Four-beat scene transcript
1. An AI assistant extends the OT trust boundary.
Once an AI tool reads controller projects, maintenance notes or cloud references, the team has added an integration across trust zones. NIST OT guidance emphasizes performance, reliability and safety; ISA/IEC 62443 gives an industrial cybersecurity lifecycle. The integration must be designed, not assumed safe.
Visual: A new reader and writer enters the engineering path.
2. The riskiest arrow is often invisible.
In a fictional workflow, an operator note includes a sentence telling the assistant to skip review. The note is legitimate data for context, but not a policy authority. If the assistant can write a PLC project directly, a text boundary has become a change boundary.
Visual: A note influences a tool with more authority.
3. Draw each permission crossing.
Map where data enters, which identity reads it, whether the assistant can write, who approves the exact diff and target, and which credential can deploy. On an isolated copy, inject a harmless conflicting instruction and inspect whether the approved artifact changes.
Visual: Source, model, project, build, deployment.
4. Make change authority explicit.
Keep drafting in a scoped environment and move only reviewed, versioned artifacts through the authorized change process. Do this because protecting the route from untrusted text is as important as protecting the network port.
Visual: Assistants draft; approved artifacts cross the OT boundary.
Research and claim limits
- NIST SP 800-82 Rev. 3 final (S137)
- ISA/IEC 62443 overview (S142)
The examples identified as illustrative or simulated are design probes, not reported incidents. Vendor specifications do not establish workload performance.