OT Cybersecurity in 2026: Why Air-Gapped AI Is No Longer Optional for Industrial Environments

,
Why Air-Gapped AI Is No Longer Optional for Industrial Environments

OT Cybersecurity in 2026: Why Air-Gapped AI Is No Longer Optional for Industrial Environments

The threat landscape facing industrial control systems has shifted from opportunistic to strategic. State-aligned actors are mapping control loops. Ransomware is halting production lines. And cloud-connected AI tools are quietly expanding the attack surface that defenders are trying to shrink. Here is the case for why air-gapped, on-premises AI is becoming the defining security architecture for OT in 2026 — and what that means for plants evaluating industrial AI.

OT Cybersecurity · ICS Security · Air-Gapped AI · SCADA/HMI · IEC 62443 · NIS2 · Sasquatch Labs Industrial Series · July 2026

The Threat Reality Nobody Wants to Say Out Loud

There is a version of the 2026 industrial cybersecurity conversation that happens in vendor presentations and conference keynotes — one full of reassuring framework names, maturity models, and percentage improvements in detection speed. And then there is the version that happens in incident response rooms, where the hard question is always the same: how did they get so far in before anyone knew they were there?

The gap between those two conversations is the most important thing to understand about OT security right now. The threat environment has not simply grown larger — it has grown qualitatively different. Attackers who used to treat industrial control systems as collateral damage on the way to IT infrastructure have, in 2025 and into 2026, begun treating OT environments as the primary objective. They are studying how plants work. They are mapping control loops. They are learning the difference between an alarm that indicates a routine fault and one that precedes a process safety event. And they are doing all of this quietly, inside networks that were built for uptime and not for visibility.

This article does not argue that every industrial organization needs to completely rebuild its security architecture overnight. That is not realistic and not what the research says. What it does argue — supported by what is coming out of Dragos, TXOne Networks, Forescout, IoT Analytics, and the S4x26 conference this year — is that the question of whether to allow cloud-connected AI tools inside OT environments has shifted from a convenience-versus-performance debate to a fundamental security architecture question. And for many plants, the honest answer to that question is leading them toward air-gapped, on-premises AI rather than away from it.

The Numbers from 2026 Research

Before we get into architecture and policy, the numbers are worth sitting with — because they ground this conversation in something other than vendor fear-mongering.

96%of OT security incidents originate from IT-level compromises, per TXOne Networks and Frost & Sullivan survey of 200 C-level OT decision-makers
60%of industrial organizations experienced a cybersecurity incident in 2025, according to the same global survey
119active ransomware groups targeting industrial organizations documented in H1 2026 by Shieldworkz OT Threat Advisory
700%surge in OT attack volumes cited in 2026 industrial cybersecurity reporting, with 200,000-plus devices wiped globally

Between March 2010 and January 2026, CISA/ICS-CERT published 3,637 ICS advisories covering 12,174 vulnerabilities affecting 2,783 products from 689 vendors. That cumulative number tells a story about how much exposed surface area has accumulated across the industrial base over fifteen years of growing connectivity — and how much of it remains unpatched, unmonitored, or simply unknown to the organizations running it.

The SANS Institute’s 2025 survey found that more than 22% of organizations reported a cybersecurity incident affecting OT systems in the past year, with 40% of these incidents causing operational disruption. That figure — 40% of OT incidents resulting in production impact — is the one that tends to get executive attention in a way that abstract risk scores do not. Operational disruption means production halts, safety system activations, missed shipments, and regulatory scrutiny. It means the plant is not making product. It means someone is explaining to the board why a cyber incident became a physical operations problem.

The TXOne Networks 2026 Annual OT/ICS Cybersecurity Report also found that 88% of organizations increased OT security spending by more than 10% in the past year — which, while encouraging as a directional signal, also tells you that the threat is real enough to be moving budgets at scale across six industries and five regions.

A number that deserves attention
Only 22% of OT incidents are remediated within 48 hours, against an industry target of 75%. That 53-point gap represents not a lack of security awareness but a structural problem: many OT environments simply do not have the visibility to detect that something is happening before it becomes a production event — let alone the tooling to respond quickly once it does.

What Changed: From Random Targets to Deliberate Industrial Campaigns

To understand why 2026 feels qualitatively different from previous years in OT security, it helps to look at how adversary behavior has shifted — not just attack volumes, but the nature of what attackers are doing once they gain access.

The Dragos 2026 OT Cybersecurity Year in Review describes a threat landscape where more adversaries are targeting OT environments, ransomware continues driving operational disruptions across critical sectors, and vulnerabilities are being exploited more rapidly, creating compounding pressure on defenders. But the more alarming detail is in the specifics of what those adversaries are doing once they are inside.

Dragos’s 2026 OT/ICS Year in Review describes a threat landscape where adversaries are spending more time learning how physical processes work and less time treating OT access as a passive foothold. A shift in 2025 involved multiple state-aligned groups moving into control-loop mapping — identifying engineering workstations, pulling configuration and alarm files, and collecting enough operational context to interfere with physical outcomes.

Read that again carefully. These actors are not just sitting in industrial networks waiting for an opportunity to deploy ransomware. They are learning how the plant works. They are figuring out which process variable, if manipulated, would cause an uncontrolled event. They are pulling alarm configurations so they understand what the operators would see — and what they would not see — if a process were quietly pushed outside safe parameters.

This is a strategic capability being built, not a crime of opportunity being exploited. KAMACITE expanded beyond Ukraine and targeted the European OT supply chain through spear phishing aimed at engineering and vendor personnel, using long-running conversations with industry-specific terms. After that campaign, KAMACITE shifted into sustained reconnaissance against internet-exposed industrial devices in the United States between March and July 2025.

ELECTRUM, the group tied to Ukraine’s 2015 and 2016 power outages, continued active destructive operations in 2025, including a wiper malware variant called PathWiper that overwrote filesystem structures and targeted all accessible storage media to cause irreversible data loss. This is not a financially motivated ransomware operation looking for a payout. This is deliberate destruction of industrial infrastructure, executed by actors who have been operating in this space for a decade and have gotten considerably better at it.

The implication for how plants think about their attack surface is direct. According to experts at IIoT World’s analysis of ICS/OT cybersecurity trends, transient device risks — USB drives and contractor laptops — cause nearly 27% of OT incidents, while AI-powered data exfiltration has emerged as a new threat vector where attackers steal industrial data to train more sophisticated attack models. The threat is not coming from one direction. It is coming from every point where the OT environment touches the outside world — and every cloud-connected tool added to the plant floor is another such point.

The Cloud AI Problem Nobody Is Talking About

This is the section that matters most for any industrial organization evaluating AI tools for plant-floor use — and it is the one that gets the least direct discussion in most vendor conversations.

The industrial AI market in 2026 is large, growing fast, and overwhelmingly oriented toward cloud-connected deployment. That is not an accident — cloud deployment is easier to scale, easier to update, and easier to sell on a subscription basis than on-premises software. For vendors, the economics strongly favor SaaS. The result is that almost every AI tool being marketed to industrial organizations in 2026 involves some form of data traversal from the plant floor to a cloud platform.

IoT Analytics’ OT Cybersecurity Insights Report 2026 identifies a critical trend: while industrial executives cite AI and IT/OT convergence as the most promising future developments, these same technologies create new and complex cyber attack surfaces. This is the central tension in the 2026 industrial AI conversation — the tools that promise the most operational value are the same tools that expand the attack surface that OT security teams are trying to reduce.

The mechanism is worth being concrete about. When an industrial organization deploys a cloud-connected AI analytics tool:

  • A new network path is opened between the OT environment and an external platform. Even if that path is encrypted and authenticated, it is a path that did not previously exist — and paths that do not exist cannot be compromised.
  • Operational data leaves the plant. Once that data is in a cloud platform, it is subject to whatever security posture that platform maintains, including its vulnerability to supply-chain attacks, credential compromises, and the vendor’s own security maturity.
  • A new software component is introduced into the OT-adjacent environment. At S4x26, OT cybersecurity experts identified hardware trojans designed for physical destruction and highlighted how MITRE EMB3D frameworks do not yet model embedded cyber-kinetic payloads designed for physical harm — which is a reminder of how rapidly attack capabilities are evolving relative to the threat models defenders are using.
  • The attack surface grows with adoption. Legacy OT devices, proprietary protocols, and safety-critical operations limit the use of intrusive controls or AI-driven enforcement, even as increased connectivity to IT and cloud environments expands the attack surface. Every cloud connection is an incremental expansion of that surface.

None of this means cloud-connected industrial AI tools are inherently irresponsible choices. For organizations with the security architecture to manage the added exposure — robust network segmentation, strong OT/IT boundary controls, mature incident response, and regulatory environments that permit the data traversal — the trade-off may be reasonable. But for organizations in critical infrastructure sectors, highly regulated industries, or environments where the consequences of a process disruption are measured in safety incidents rather than inconvenience, the trade-off looks very different.

The shadow AI risk in industrial settings
The enterprise security community has identified shadow AI — unsanctioned AI tools adopted by employees without security oversight — as a significant and growing risk. In industrial environments, this takes a specific form: engineers and operators adopting cloud-connected AI query tools to solve immediate workflow problems, without those tools going through the security review that any new network path into the OT environment should require. The productivity gain is real. The security review gap is also real.

Regulatory Pressure: NIS2, IEC 62443, and the EU CRA

The regulatory environment around OT security has changed more in the last eighteen months than in the previous decade, and that change is directly relevant to decisions about AI tools in industrial environments.

Three frameworks in particular are shaping how organizations think about OT security architecture in 2026.

NIS2 Directive

NIS2 imposes stricter requirements on organizations in sectors including energy, water, transport, and healthcare. Executives are personally liable for shortcomings. Incidents must be reported within 24 hours, followed by a full notification within 72 hours and a final report within one month. Risk management measures are no longer optional, and that applies to OT as well. The personal liability provision is the one that tends to concentrate executive minds: a cybersecurity failure in a NIS2-covered entity is no longer a fine that lands at the organizational level — it is potential personal sanction for board members and executives who cannot demonstrate adequate governance.

What NIS2 means in practice for AI tool selection is that every new software component introduced into or adjacent to an OT environment needs to be defensible under the directive’s risk management requirements. “The vendor said it was secure” is not a risk management framework. “We evaluated the data residency, network boundary implications, and vendor security posture before deployment, and documented our rationale” is closer to what the directive expects.

IEC 62443

IEC 62443 is the international standard for industrial automation and control system security, and its relevance to AI tools has expanded materially. As of 2026, IEC 62443 now explicitly includes Industrial IoT and cloud-based analytics that interact with field devices within its scope of cyber-physical systems that can change the physical state of equipment. This is a significant expansion — it means that a cloud-connected AI tool querying your historian and displaying results that operators act on may now fall within the IEC 62443 framework’s scope, not just the IT security team’s purview.

The standard’s zone-and-conduit model — which defines security zones with different levels of trust and governs how data and control signals are allowed to cross between them — provides a useful lens for evaluating any AI tool. A tool that operates within the plant’s existing security zones without opening new conduits to external networks is architecturally consistent with IEC 62443 principles. A tool that requires a persistent cloud connection to function is not, absent compensating controls that most plants haven’t had time to design and validate.

EU Cyber Resilience Act

The EU Cyber Resilience Act applies to manufacturers of products with digital elements, which includes many OT devices and systems. Non-compliance penalties reach up to 15,000,000 euros or 2.5% of global annual turnover. For industrial organizations selling into or operating within EU markets, the CRA adds another layer of compliance obligation that intersects directly with how AI tools are integrated into OT products and systems.

Framework Key requirement for OT AI tools Enforcement status (2026)
NIS2 Directive Risk management measures mandatory; personal executive liability; 24-hour incident reporting Active — enforcement underway across EU member states; late-2026 full enforcement window
IEC 62443 Now explicitly includes IIoT and cloud analytics interacting with field devices; zone-and-conduit model applies Voluntary but increasingly referenced in procurement and insurance requirements
EU Cyber Resilience Act Products with digital elements must meet security requirements; penalties up to EUR 15M or 2.5% global turnover Transitional period ongoing; compliance expected by 2027 for most product categories
NIST 800-82 US guide to ICS security; widely referenced in North American industrial procurement Voluntary federal guidance; increasingly embedded in TSA, NERC CIP, and sector-specific directives

The Frameworks Shaping OT Security Architecture in 2026

Understanding the regulatory landscape is one thing. Understanding how security teams are actually translating it into architecture decisions is another. Four conceptual frameworks are doing the most work in 2026 OT security conversations.

The Purdue Model — Still the Baseline, Now Under Pressure

The Purdue Model remains the foundational method for separating IT and OT networks into hierarchical levels that prevent lateral threat movement between enterprise and industrial zones. It defines which systems are allowed to communicate with which other systems, and at what level of trust. The challenge in 2026 is that cloud-connected AI tools often require connections that cut across Purdue Model layers — creating conduits from Level 3 or 4 (business/operations systems) directly to cloud platforms, bypassing the security controls at each layer boundary. An air-gapped AI layer that operates within the existing Purdue Model structure is architecturally cleaner and easier to defend.

Zero Trust Microsegmentation

The rise of zero trust microsegmentation is one of the five dominant OT security trends identified in the IoT Analytics OT Cybersecurity Insights Report 2026. Zero trust in an OT context means no device, user, or software component is implicitly trusted just because it is on the plant network — every connection is verified, every data flow is governed. Applying this principle to AI tools means asking: does this tool need to see everything, or can we scope its access to specific data sources and users? Air-gapped AI tools that operate within the plant’s own network are easier to microsegment and govern than cloud-connected tools that require external connectivity as a prerequisite to function.

Prevention-First Over Detection-Only

The TXOne Networks 2026 report concludes with a framework for shifting from detection-focused strategies to prevention-first architectures. The detection-only model has a fundamental flaw in OT environments: by the time you detect a sophisticated actor who has been inside your control-loop environment conducting reconnaissance for weeks, they have already achieved their pre-positioning objectives. Prevention — including architectural choices that reduce the available attack surface — is more valuable than faster detection of breaches that should not have been possible in the first place. Air-gapping an AI tool does not eliminate risk, but it eliminates one category of attack vector that cloud-connected tools introduce.

Hybrid Security Architecture

The shift to hybrid central-decentral security architecture is the first of five IT/OT convergence trends identified in the 2026 OT Cybersecurity Insights Report, reflecting a recognition that neither fully centralized nor fully local security architectures are adequate on their own. For AI tools specifically, this manifests as a preference for tools that process data locally — at the edge, inside the plant network — while potentially sending anonymized metadata or alerts to centralized monitoring systems, rather than tools that require full operational data to flow to a cloud platform before any value is delivered.

What Air-Gapped AI Actually Means — And Why It Matters Now

The phrase “air-gapped AI” gets used loosely, so it is worth being precise about what it actually means in an industrial context and why the architectural distinction matters beyond marketing language.

An air-gapped AI system is one where the AI processing — the inference, the natural-language interpretation, the data retrieval — happens entirely within the plant’s own network boundary. No data is sent to a cloud platform. No external API is called during a query. No query results are logged on a server outside the plant. The system operates as a self-contained layer sitting on top of existing infrastructure, using only what is inside the network perimeter to do its work.

This is different from an “on-premises deployment option” that still requires periodic cloud connectivity for licensing validation, model updates, or telemetry. It is different from a “hybrid deployment” where the inference happens at the edge but the model weights or configuration are cloud-managed. True air-gapping means the system can function — including all AI capabilities — without any external network path. Everything needed to answer a question is inside the boundary.

Why does this matter specifically in 2026? Because the attack surface expansion risk from cloud-connected tools has become concrete rather than theoretical. A May 2025 incident involved exploitation of Ivanti Endpoint Manager Mobile at a US utility. Attackers extracted data from the backend MySQL database, including LDAP user details and Office 365 tokens, then replayed those credentials internally for lateral movement. This is exactly the pattern that concerns OT security architects when any cloud-connected tool is introduced into an OT-adjacent environment: a compromise at the cloud platform layer, or of the credentials used to connect to it, becomes a potential path for lateral movement into the plant network.

An air-gapped AI tool removes that path by design. There is no cloud platform to compromise. There are no cloud credentials to steal. The attack surface available to a threat actor attempting to pivot from the AI tool into the OT network is limited to whatever is inside the plant’s own security boundary — where the organization already has visibility and controls.

Air-gapped is not the same as “insecure by isolation”
A common pushback on air-gapping is that isolated systems become security liabilities over time — they don’t get patched, they accumulate technical debt, and they create a false sense of security. That concern is legitimate for passive systems. It is less applicable to a modern agentic AI layer that is designed for air-gapped operation from the ground up, with defined update pathways that don’t require cloud connectivity, and which adds intelligence on top of existing systems rather than replacing them.

How Valak Fits Into the 2026 OT Security Architecture

Everything in this article has been building toward a practical question: given this security landscape, what does “responsible AI adoption in OT” actually look like?

Valak, built by Sasquatch Labs, was designed specifically to answer that question. It is an agentic AI layer for HMI and SCADA systems — one that sits on top of OPC UA, AVEVA PI, GE Proficy, and other industrial historians — and it was architected from the ground up around two principles that the 2026 OT security environment demands: air-gapped deployment and lossless data fidelity.

On the security architecture questions raised in this article, Valak’s position is clear:

  • No new cloud connections required. Valak deploys and operates entirely inside the plant’s existing network boundary. There is no remote agent sending data to a cloud platform, no external inference API, no persistent outbound connection that could be exploited as a pivot point.
  • Consistent with IEC 62443 zone-and-conduit principles. Because Valak operates within the plant’s own security zones without opening new conduits to external networks, it does not introduce the kind of cross-zone data flows that IEC 62443 compliance requires organizations to document and control as new attack surface.
  • Compatible with NIS2 risk management requirements. An AI tool that stays inside the network boundary is significantly easier to defend in a NIS2 audit than one that requires justifying a persistent cloud connection to a third-party platform.
  • Lossless signal integrity. In an environment where threat actors are studying control loops and alarm configurations, the last thing an organization needs is an AI layer that silently averages, smooths, or filters the operational signal before presenting it to the operator. Valak’s lossless architecture means the data an operator sees through the AI query interface reflects the actual historian record — which is also the foundation of accurate anomaly detection and incident response.
  • Voice and natural-language access without adding cloud exposure. The operational efficiency argument for conversational AI on the plant floor is real — faster question-answering, broader operator access to data, reduced dependence on specialist knowledge. Valak delivers those benefits without the security trade-off that cloud-connected AI tools require.

A Practical Checklist for Evaluating Industrial AI in 2026

If your organization is currently evaluating AI tools for plant-floor use — or if you are a security or OT architect being asked to sign off on a tool someone else has already selected — these are the questions that matter most from a security architecture standpoint in 2026.

  • Does the tool require any outbound network connection to function? If yes: what is the destination, what data crosses that connection, and what is the vendor’s security posture for that destination platform? If the connection is required for core functionality (not just updates or telemetry), you are adding a cloud-dependent component to your OT-adjacent environment.
  • What data leaves the plant network and in what form? Raw operational data, tag values, and historian records leaving the plant boundary are a fundamentally different exposure than anonymized usage telemetry. Confirm precisely what the tool sends out and under what circumstances.
  • Has the tool been evaluated against your IEC 62443 zone-and-conduit model? If your organization has implemented network segmentation based on IEC 62443, a new AI tool that requires cross-zone connectivity needs to go through the same security review as any other new conduit — not be provisioned as a convenience exception.
  • What happens to your data if the vendor is acquired, goes offline, or has a security incident? Cloud-hosted platforms introduce counterparty risk that on-premises tools do not. Your operational data should not become a liability in someone else’s security incident.
  • How does the tool handle data fidelity? Does it present raw data or a summarized, pre-processed version? For operational queries that may inform safety decisions, understanding what the tool did to the data before presenting it is not optional.
  • Is air-gapped operation supported as a first-class deployment option, or as an afterthought? A tool designed for cloud-first deployment that also has an “air-gapped mode” often has that mode as a limited subset of its capabilities. A tool designed for air-gapped operation from the start treats it as the full product, not a constraint to route around.
  • Can you demonstrate NIS2 compliance for this tool’s deployment? If your organization is NIS2-covered, you need to be able to document your risk management rationale for every software component in your OT environment. “The vendor’s marketing materials said it was secure” is not that documentation.

The Bottom Line

The 2026 OT security environment has arrived at a place that the threat intelligence community has been pointing toward for several years: industrial control systems are now primary targets, not collateral. State-aligned actors are conducting sustained reconnaissance inside plant networks. Ransomware groups are industrializing their OT attack capabilities. And the regulatory frameworks — NIS2, IEC 62443, the EU CRA — have moved from voluntary guidelines to mandatory requirements with real consequences for organizations that cannot demonstrate adequate governance.

Into this environment, the industrial AI market is introducing a wave of cloud-connected tools that promise to unlock the value in plant-floor data. Most of them require operational data to leave the plant network in order to function. Most of them open new network paths between OT-adjacent environments and cloud platforms that represent new attack surface. Most of them were designed for the efficiency-first world that existed before sophisticated industrial threat actors started treating control-loop mapping as a strategic capability.

Air-gapped AI is not a retreat from industrial innovation. It is an architectural response to a security environment that has changed. It says: you can have the conversational, natural-language, voice-accessible intelligence layer on top of your HMI and SCADA data — and you can have it without adding to the attack surface your security team is already struggling to defend. That is not a trade-off. That is good design for the world as it actually is in 2026.

The plants that get this right over the next two years will not be the ones that moved fastest to adopt cloud-connected AI. They will be the ones that moved deliberately — choosing tools that were designed for their actual operating environment, and that can be defended to a regulator, an insurer, and an incident response team, not just to a vendor’s sales slide.

Frequently Asked Questions: OT Cybersecurity and Air-Gapped AI in 2026

1. What does “air-gapped” mean in an industrial or OT context?

In an industrial or OT context, air-gapping means physically or logically isolating a system from external networks, including the internet and third-party cloud platforms, so that no data can leave or enter the system through a network connection. A truly air-gapped AI system processes all queries and retrieves all data entirely within the plant’s own network boundary — no outbound connections are required for any part of its operation, including inference, data retrieval, or result delivery.

2. Why is OT cybersecurity getting worse in 2026, not better?

Several factors are converging simultaneously. More adversaries are targeting industrial environments specifically, not just using them as IT entry points. State-aligned threat groups have moved from passive access-holding to active control-loop mapping — studying how plants work in order to interfere with physical processes. At the same time, the IT/OT convergence that brings operational benefits (remote monitoring, cloud analytics, IIoT sensors) also expands the attack surface available to those adversaries. The result is a threat environment that is growing in sophistication faster than most organizational security programs are growing in capability.

3. Do cloud-connected industrial AI tools make OT environments less secure?

Not inherently, but they do expand the attack surface and introduce new categories of risk that need to be managed. Every cloud connection is a new network path that did not previously exist. If that path is exploited — through vendor credential compromise, supply chain attack, or a vulnerability in the cloud platform itself — it can become a pivot point for lateral movement into the OT environment. For organizations with mature security architectures, robust boundary controls, and regulatory environments that permit the data flow, the trade-off may be manageable. For organizations in critical infrastructure sectors, regulated industries, or environments without strong OT/IT boundary controls, the risk addition is harder to justify.

4. What is NIS2, and does it affect how industrial organizations choose AI tools?

NIS2 is the EU’s Network and Information Security Directive, which imposes mandatory cybersecurity risk management requirements on organizations in critical sectors including energy, water, manufacturing, transport, and healthcare. It includes personal executive liability for governance failures, 24-hour incident reporting requirements, and mandatory security measures that apply to OT environments. It is directly relevant to AI tool selection because any new software component introduced into or adjacent to OT infrastructure needs to be defensible under NIS2’s risk management framework — including the data residency implications of cloud-connected tools.

5. What is IEC 62443 and how does it apply to AI tools in 2026?

IEC 62443 is the international standard for industrial automation and control system cybersecurity. It defines security levels, zones, and conduits — the architectural model for how OT systems are segmented and how data and control signals are governed between zones. As of 2026, its scope has been explicitly expanded to include Industrial IoT and cloud-based analytics that interact with field devices. This means AI tools that query historians or SCADA systems and present results that operators act on may now fall within IEC 62443’s scope, requiring evaluation against its zone-and-conduit model rather than being treated as purely IT software.

6. How do threat actors typically gain access to OT environments?

The most common initial access vectors include IT-level compromises that then move laterally toward OT systems — phishing, exploitation of internet-facing systems, and supply-chain attacks on vendor or contractor accounts are the dominant entry points. Once inside, sophisticated actors conduct reconnaissance to understand network topology, identify engineering workstations, and pull configuration and alarm files before taking any disruptive action. Transient devices — USB drives and contractor laptops — account for nearly 27% of OT incidents in recent research. The 96% figure from TXOne Networks’ survey, finding that nearly all OT security incidents originate from IT-level compromises, underscores why the OT/IT boundary is the most critical security control in most industrial environments.

7. Can AI tools themselves be a target for OT attackers?

Yes, and this is an underappreciated risk in 2026. AI tools that are connected to plant-floor data sources and presented to operators as authoritative are potentially high-value targets precisely because of their trusted position. An attacker who could manipulate the output of an AI query tool — causing it to present false process data, miss anomalies, or direct operator attention away from a real event — would have achieved a form of information manipulation that is extremely difficult to detect. This is one more reason why data fidelity (lossless access to the raw historian record) and air-gapped architecture (no external tampering path) are security properties, not just convenience features.

8. What is the Purdue Model and is it still relevant in 2026?

The Purdue Model is a hierarchical framework for industrial network architecture that defines levels of the OT/IT stack — from Level 0 (field devices) through Level 4 (enterprise IT) — and governs how systems at different levels are allowed to communicate. It remains the foundational reference model for OT network segmentation in 2026, though it is under increasing pressure from cloud-connected tools and IIoT deployments that require cross-level data flows. AI tools that operate within a single Purdue level or between adjacent levels using existing conduits are architecturally cleaner than tools that require new cross-level connections to cloud platforms.

9. How does Valak address OT cybersecurity concerns?

Valak is designed for air-gapped, on-premises deployment, which means it operates entirely within the plant’s own network boundary without requiring any cloud connection for its core functionality. It connects natively to OPC UA, AVEVA PI, and GE Proficy systems using the protocols those systems already speak, without introducing new network paths to external platforms. Its lossless data fidelity approach means the AI layer presents data as it exists in the historian, without intermediate filtering or summarization. These architectural choices are directly responsive to the OT security concerns documented in 2026 threat research — reduced attack surface, no cloud-dependent exposure, and a trusted interface to authoritative data.

10. Is air-gapped AI more expensive or harder to deploy than cloud-connected AI?

Air-gapped deployment does require that the full AI capability runs inside the plant’s own infrastructure, which has implications for compute requirements that a cloud-hosted tool would handle externally. However, for organizations already operating on-premises historians and SCADA systems — which is the majority of the industrial base — the infrastructure to support a well-designed air-gapped AI layer is typically already present or can be provisioned without a major new infrastructure investment. The cost comparison that matters most is total cost including security risk mitigation, regulatory compliance posture, and the operational overhead of managing a new cloud vendor relationship — not just the license price comparison.

See Air-Gapped Industrial AI on Your Own Plant Data

No cloud connection required. No data leaves the building. Natural language and voice query over OPC UA, AVEVA PI, and GE Proficy — running entirely inside your own network.

Visit Valak.ai