AI Agents Executed All 8 Critical Infrastructure Attacks in Booz Allen Lab Tests
What happened
Booz Allen Hamilton's operational technology lab ran two frontier AI models through eight attack scenarios against a simulated manufacturing environment using multiple vendors' equipment. According to the firm's findings as reported by The Register, the models succeeded in all eight cases. Attacks included reconnaissance of industrial networks, exploiting software vulnerabilities, manipulating programmable logic controllers and supervisory control systems that manage physical equipment, and physically moving a robotic arm. Some scenarios completed in minutes. The research concludes that AI agents meaningfully lower the skill level required to attack industrial environments. Complexity and proprietary technology no longer serve as practical barriers to entry. This finding arrives amid escalating agentic threat activity. Related developments include Unit 42's documentation of a fully autonomous AI ransomware chain. There are also ongoing concerns that 88% of operational technology security leaders claim maturity while only 21% have a complete asset inventory.
Why it matters
- ·Organizations operating industrial environments, including energy, water, manufacturing, and logistics, now face a threat model in which advanced technical skill is no longer a prerequisite for a successful attack. AI agents can probe, map, and manipulate industrial control systems without a human attacker who knows those systems. This expands the pool of potential attackers and compresses the time to harm.
- ·Existing critical infrastructure risk assessments almost certainly underestimate this threat. Security controls premised on the difficulty of understanding proprietary industrial protocols are no longer reliable. Compliance programs tied to frameworks such as Five Eyes Guidance on the Careful Adoption of Agentic AI Services need to be reviewed against what an AI-assisted attacker can now achieve autonomously.
- ·Third-party AI risk programs face a new exposure: any AI agent or frontier model accessible to employees, contractors, or suppliers could, if misused or compromised, be turned toward industrial systems. Regulatory requirements for operational technology AI risk are likely to follow. The ISA's work putting agentic AI in critical infrastructure on policymakers' agendas signals that compliance teams have limited time to get ahead of formal obligations.
Governance controls affected
What to do now
- ☐Ask your security and operational technology teams whether your current critical infrastructure risk assessment assumes that industrial protocols and proprietary systems are difficult for outside attackers to understand, and if so, request a revised assessment that treats AI-assisted reconnaissance and exploitation as a realistic threat.
- ☐Review whether your AI vendor contracts and internal policies restrict the systems and networks that deployed AI agents are permitted to interact with, specifically confirming that agents cannot reach industrial control systems, manufacturing equipment networks, or building management systems.
- ☐Verify that emergency stop and shutdown procedures for AI agents operating in or near industrial environments have been tested, not just documented, and confirm there is a named owner responsible for activating those controls.
- ☐Commission or request an updated third-party AI risk assessment for any supplier or contractor that operates AI tools in environments connected to your operational technology infrastructure.
- ☐Bring findings from this research to your board or risk committee as evidence that critical infrastructure AI risk requires a dedicated line item in your risk register, separate from general cybersecurity risk.
What to watch next
Regulatory bodies with oversight of critical infrastructure sectors, including energy, water, and manufacturing, are likely to treat research of this kind as evidence that existing guidance is insufficient. Compliance teams should monitor whether the Five Eyes Guidance on the Careful Adoption of Agentic AI Services is updated to address AI-assisted attacks on industrial environments. They should also track whether sector regulators issue new requirements for AI use near operational technology. The ISA's ongoing work on agentic AI in critical infrastructure is the most direct signal of where mandatory requirements may emerge first. Organizations in regulated critical infrastructure sectors should also watch for updates to national cybersecurity strategies that reference AI-enabled offensive capabilities.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
Recent issues
- AI systems built to extend your reach are now extending attackers' reach too, and regulators in California and South Korea are making clear that containment failures belong to deployers, not just vendors.8 Oct
- AI agents this week destroyed backups at machine speed, leaked sensitive data without developer approval, and drew federal scrutiny that may extend liability to every enterprise deploying them.1 Oct
Free every Thursday. Unsubscribe anytime.
