JournalDAY 34 / X

FIELD NOTE / X

OT cybersecurity is part of AI deployment.

The complete written thought and the evidence behind it. The video edition will follow its public release.

Journal September 25, 2026 · X target October 31, 2026

OT cybersecurity is part of AI deployment.

Video caption

OT cybersecurity is part of AI deployment. The model may promote data into authority. Treat retrieved text and generated output as data. #EricFieldNotes

Full written post / accessibility read

An AI assistant in the PLC workflow reads projects, notes and vendor material, then may propose or apply changes. That expands the path by which untrusted text can influence a controller artifact. OT security must account for the new access and review boundary.

Imagine a maintenance note that says to change the deployment target while describing a sensor. A human would treat it as untrusted content. If an agent treats it as a command and has write or deployment access, the note has crossed the trust boundary.

Give the assistant only the project files and staging tools needed to draft. Keep target selection, build provenance, diff review and deployment credentials under a separate owner. In a disposable project, insert a harmless conflicting note and verify the assistant cannot change the approved target.

Apply OT access controls to the AI integration, preserve a signed change packet and read back the final artifact. Do this because a useful engineering assistant should not become a silent route from an untrusted document to physical actuation.

#EricFieldNotes

Four-beat scene transcript

1. OT cybersecurity is part of AI deployment.

An AI assistant in the PLC workflow reads projects, notes and vendor material, then may propose or apply changes. That expands the path by which untrusted text can influence a controller artifact. OT security must account for the new access and review boundary.

Visual: The assistant adds a new path to engineering files and change tools.

2. A harmless note can become an instruction.

Imagine a maintenance note that says to change the deployment target while describing a sensor. A human would treat it as untrusted content. If an agent treats it as a command and has write or deployment access, the note has crossed the trust boundary.

Visual: The model may promote data into authority.

3. Scope the engineering route.

Give the assistant only the project files and staging tools needed to draft. Keep target selection, build provenance, diff review and deployment credentials under a separate owner. In a disposable project, insert a harmless conflicting note and verify the assistant cannot change the approved target.

Visual: Read-only by default; approved artifacts for change.

4. Keep the trust boundary visible.

Apply OT access controls to the AI integration, preserve a signed change packet and read back the final artifact. Do this because a useful engineering assistant should not become a silent route from an untrusted document to physical actuation.

Visual: Treat retrieved text and generated output as data.

Research and claim limits

The examples identified as illustrative or simulated are design probes, not reported incidents. Vendor specifications do not establish workload performance.

More notes from the work ↗