JournalDAY 34 / LINKEDIN

FIELD NOTE / LINKEDIN

Use an OT threat model for AI integration.

The complete written thought and the evidence behind it. The video edition will follow its public release.

Journal September 25, 2026 · LinkedIn target October 31, 2026

Use an OT threat model for AI integration.

Video caption

Use an OT threat model for AI integration.

A protected route can still build wrong behavior.

Document → agent → file → build → staging → plant.

My rule: Separate assistance from change authority.

#EricFieldNotes

Full written post / accessibility read

Industrial AI is not just another office SaaS integration. It may read controller projects, operational notes and vendor docs, then influence a change artifact. The trust model must cover those data flows, model-provider boundary, service identities and path to physical deployment.

ISA/IEC 62443 addresses industrial cybersecurity; applicable machinery or process-safety standards govern required safety functions. A well-secured AI drafting workflow can still propose control logic that fails a physical fault. Both reviews need owners and evidence.

For each edge, name the trust level, identity, allowed operation, review artifact and independent readback. Test a harmless prompt-injected note in staging and verify it cannot alter the approved target. Keep deployment credentials outside the drafting identity and record a rollback package.

Let AI help analyze and draft, but require a versioned diff, qualified review and site-approved deployment process. Do this because the safest integration keeps the assistant's useful context without granting an untrusted sentence a path to plant actuation.

#EricFieldNotes

Four-beat scene transcript

1. Use an OT threat model for AI integration.

Industrial AI is not just another office SaaS integration. It may read controller projects, operational notes and vendor docs, then influence a change artifact. The trust model must cover those data flows, model-provider boundary, service identities and path to physical deployment.

Visual: A chat tool changes the engineering attack surface.

2. Security and safety answer different questions.

ISA/IEC 62443 addresses industrial cybersecurity; applicable machinery or process-safety standards govern required safety functions. A well-secured AI drafting workflow can still propose control logic that fails a physical fault. Both reviews need owners and evidence.

Visual: A protected route can still build wrong behavior.

3. Threat-model the change chain.

For each edge, name the trust level, identity, allowed operation, review artifact and independent readback. Test a harmless prompt-injected note in staging and verify it cannot alter the approved target. Keep deployment credentials outside the drafting identity and record a rollback package.

Visual: Document → agent → file → build → staging → plant.

4. Move only approved artifacts into OT.

Let AI help analyze and draft, but require a versioned diff, qualified review and site-approved deployment process. Do this because the safest integration keeps the assistant's useful context without granting an untrusted sentence a path to plant actuation.

Visual: Separate assistance from change authority.

Research and claim limits

The examples identified as illustrative or simulated are design probes, not reported incidents. Vendor specifications do not establish workload performance.

More notes from the work ↗