AI Governance Institute
← News
Research2026-09-23

88% of OT Security Leaders Claim Maturity; Only 21% Have a Complete Asset Inventory

What happened

Honeywell published its 2026 OT Cybersecurity Benchmark Report, drawing on survey data from 603 industrial security leaders across critical infrastructure sectors globally. The headline finding is a structural credibility gap: 88% of respondents rated their OT security programs as mature, but only 21% maintain a complete asset inventory. On AI specifically, the report finds that just 23% of organizations currently deploy autonomous or agentic AI for threat detection, with the remainder relying on human-directed AI assistance. Honeywell explicitly flags the governance prerequisites that are absent in most programs: defined decision rights for AI-driven actions, tested human oversight thresholds, and consequence testing for autonomous responses in operational environments. The report positions these as necessary conditions before any expansion of AI autonomy in OT settings, not aspirational additions.

Why it matters

  • ·A complete asset inventory is the foundational prerequisite for AI system risk classification. Without it, organizations cannot know which assets an autonomous agent can affect, making pre-deployment consequence testing impossible and human oversight design meaningless.
  • ·The Five Eyes Guidance on the Careful Adoption of Agentic AI Services specifically requires organizations in critical infrastructure to define and test human oversight controls before deploying autonomous AI. The 21% inventory figure suggests most OT operators are not positioned to meet that standard today.
  • ·Self-assessment inflation is a material audit risk. Regulators and auditors increasingly cross-reference claimed maturity against documented controls. A program that rates itself mature but cannot produce an asset inventory or tested kill-switch documentation faces direct credibility exposure in any regulatory examination.

Governance controls affected

What to do now

  • Audit your OT asset inventory completeness before approving any agentic AI deployment for threat detection or response in operational environments.
  • Document and test the human approval thresholds that govern AI-driven actions in OT settings, specifying which actions require human sign-off and which may proceed autonomously.
  • Run a consequence testing exercise for any autonomous AI response capability, mapping the blast radius of an incorrect or manipulated AI-driven action against your current asset inventory.
  • Review your AI system risk classification records for OT environments and flag any system classified as lower-risk that operates without a verified, complete asset inventory as a dependency.
  • Require OT security vendors to provide evidence of their own asset inventory completeness and governance controls rather than accepting self-reported maturity ratings during due diligence.

What to watch next

CISA and sector-specific regulators are intensifying focus on agentic AI in critical infrastructure, a trend likely to produce more prescriptive guidance on pre-deployment readiness requirements in OT environments. The Five Eyes Guidance on the Careful Adoption of Agentic AI Services is already in effect, and enforcement attention on industrial operators is building. Compliance teams should also watch for whether the self-assessment inflation pattern Honeywell documents becomes an explicit auditor focus in upcoming OT and ICS regulatory examinations.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.