Skip to main content
Article 10

Digital Security Magazine 19th Edition

Control, Trust and accountability at scale

Securing agentic AI in OT and critical infrastructure:
Safety, sovereignty and the kill-switch reality

In critical infrastructure, autonomy is not just a technology decision. It is a safety decision.

AI is already helping organizations detect threats, predict failures, optimize operations and support expert decision-making. But agentic AI changes the equation. These systems do not just generate answers. They can plan, retrieve information, select tools, use APIs, communicate with other agents and, in some cases, even trigger actions with limited human involvement.

That shift matters deeply in operational technology and critical infrastructure. A poor recommendation in an office workflow may lead to delays or confusion. A poor action in an industrial environment can affect production continuity, essential services, environmental conditions, or human safety.


So the question for leaders is not simply, “Can agentic AI improve resilience?”
The real question is, “Can we govern autonomous action safely, sovereignly and reliably when the consequences are physical?”

The answer starts with one principle: AI should be allowed to support decisions before it is trusted to execute them. In safety-critical environments, autonomy must be earned, constrained and continuously governed.

From trusted outputs to controlled actions

Traditional AI risk has often focused on the quality of outputs. Is the answer accurate? Is the model biased? Has it hallucinated? Those questions still matter. But agentic AI introduces a bigger challenge: What happens when an output becomes an action?

Agentic AI creates a broader attack surface than standalone language models. Risks extend beyond traditional AI concerns and include prompt injection, poisoned retrieval sources, memory poisoning, goal drift, unauthorized tool use, API abuse, compromised plugins, multi-agent manipulation and supply-chain attacks. Left unchecked, these risks can alter an agent’s objectives, influence its decisions or trigger unintended actions.

A malicious document, for example, could influence retrieved context. That context could shape the agent’s plan. The plan could trigger a tool call, file change, API request or exposure of sensitive information. What begins as manipulated input can become operational behavior.

This is why agentic AI needs a different security model. Leaders need to look at the complete chain of autonomy: what the agent is asked to do, what information it uses, which tools it selects, what permissions it has, what action it takes, and how people can intervene.

In OT and critical infrastructure, AI outputs should not automatically become operational actions. The model should provide recommendations, while decisions and execution remain under human control.

Tool calls, configuration changes, API requests and industrial interactions need validation, minimal privilege, sandboxing, monitoring and explicit policy enforcement.

Good intentions are not enough. Autonomy has to be bounded by architecture.

Safety by design starts before deployment

Safety by design begins before an agent is connected to live systems. It starts with a clear decision about what the agent may observe, recommend, prepare and execute.

Not every use case needs the same level of autonomy. In many OT environments, read-only or recommendation-based agents will be the right starting point. Human-approved actions may be suitable where the impact is limited, reversible and well understood. Fully autonomous actions should be limited to narrow, tested and auditable use cases with safe fallback procedures.

This is not a barrier to innovation. It is how innovation earns trust.

A multilayer approach is essential. Agentic AI security needs to cover infrastructure, data, model behavior, execution controls, access management, monitoring and audit. It also needs accountability. If an agent recommends or performs an action, the organization must be able to understand why it happened, which data influenced it, which tool was used, and who was responsible for the decision boundary.

For critical infrastructure leaders, agentic AI should not be seen as a single application. It is a runtime decision system. Its security depends on isolated infrastructure, trusted data pipelines, hardened models, policy-controlled execution, strong identity, reliable logging and continuous monitoring.

If the system can act, it must also be observable, explainable and containable.

Sovereignty: Beyond where data sits

Sovereignty is often discussed as a data residency issue. For agentic AI in critical infrastructure, that definition is too narrow. Sovereignty is also about control.

Who governs the model? Who manages tool access? Who updates policies? Who audits decisions? Who controls credentials? Who can disconnect an agent if something goes wrong? And can operations continue safely if a cloud service, API or third-party model becomes unavailable?

Agentic AI systems often depend on external tools, connectors, retrieval sources, identity providers and communication with other agents. Every dependency may create value. Every dependency can also create a point of risk or control.

In OT, sovereignty means the ability to understand, constrain, audit, disconnect and recover from intelligent systems without losing command of core operations. It does not mean rejecting cloud services, automation or external innovation. It means keeping autonomy within boundaries defined by the operator, regulation and safety requirements.

This is where identity becomes central. Agents need unique identities. Their permissions need to be explicit. Their access must be limited to what they need. Their lifecycle must be managed. And when an agent no longer has a valid purpose, its ability to act must be revoked.

In a safety-critical environment, every agent should be treated as an actor in the system. If it can act, it must be governed.

The real kill switch: An enforceable action

The kill switch is one of the most important concepts in agentic AI governance. But it is also one of the easiest to misunderstand.

A kill switch is not a slide in a governance deck. It is not a button that only works when everything else is working. It is not a policy statement stating that humans remain in control.


A real kill switch is an enforceable capability. It must be able to pause, contain, isolate, revoke or terminate an agent’s ability to act when behavior becomes unsafe, unexpected or non-compliant.

That capability needs to reach across several layers. Credentials and tokens must be revocable. API access must be interruptible. Tool execution must be stoppable. Network paths must be segmentable. Unsafe behavior must trigger containment. And teams must know who has the authority to stop an agent and how to return the environment to a safe state.

In critical infrastructure, containment must work under pressure. It must work during partial failure. It must work when an external dependency is unavailable. It must work when an attacker is attempting to keep the agent active. A kill switch that depends on the same compromised pathway it is meant to control is not a safety mechanism. It is a false comfort.

This is why leaders need to measure more than whether a kill switch exists. They need to understand how quickly unsafe behavior can be detected, how reliably access can be revoked, how containment is validated, and how operations recover. Time to contain becomes as important as time to detect.

Governance has to move into the runtime

Agentic AI also changes where governance needs to operate. Policies, standards and approval documents remain necessary, but they are not sufficient for systems that can take action in real time. Governance has to become enforceable during execution. Access rules, approval thresholds, tool permissions, data boundaries, logging requirements and escalation paths must be embedded into the operating environment. The system should not simply know the policy; it should be technically unable to bypass it.

This calls for controlled integration layers between agents and the tools they use. Agents should not be able to connect freely to every operational interface, data source or system of record. They should pass through enforcement points that manage identity, inspect requests, apply policy, validate context, log activity, and restrict execution.

This matters in OT environments where segmentation is already a core security principle. Agentic AI should strengthen that principle, not weaken it. If an agent can bridge IT, cloud, data and operational systems, it must also be governed at every boundary it crosses.
Runtime governance reduces the likelihood that a model-level failure becomes an operational incident. It also gives leaders the evidence they need to assess performance, investigate behavior and improve controls over time.

Human accountability: Clearer, not weaker

As agentic AI becomes more capable, human accountability cannot become vague. In critical infrastructure, organizations need clarity on who defines objectives, approves high-impact actions, accepts residual risk, monitors behavior and can override the system.

The goal is not only to keep humans in the loop. It is to keep humans in command.

That requires a practical balance. If every action requires approval, the system may become too slow to create value. If too many actions are automated, accountability becomes unclear and unsafe behavior can spread faster than people can respond. The right model is risk-based.

Routine, low-impact and reversible actions may be automated within strict boundaries. Higher-impact actions require review or approval. Safety-critical or irreversible actions need escalation paths, explicit responsibility and fail-safe procedures.

Accountability also depends on evidence. Without evidence, oversight becomes retrospective guesswork.

Trust depends on bounded autonomy

Agentic AI can strengthen OT and critical infrastructure. It can support operators, accelerate incident response, improve situational awareness and help organizations make faster decisions. But its acceptance will depend less on how intelligent it appears and more on how reliably it can be governed.

The path forward is bounded autonomy. Agents need to be useful, but constrained. Fast, but observable. Adaptive, but accountable. And when something goes wrong, stoppable.

Achieving this requires defense in depth, least privilege, secure tool integration, runtime policy enforcement, strong identity, monitoring, auditability and tested containment. It also requires leadership discipline. Organizations need to decide where autonomy is appropriate, where human approval remains essential, and where the system must never be allowed to act on its own.

The future of agentic AI should not be framed as a choice between innovation and control. In safety-critical environments, control is what makes innovation sustainable. Systems that can act must also be limited. Systems that optimize must also fail safely. Systems that operate with autonomy must remain under human, organizational and sovereign command.

In critical infrastructure, trust is not created by autonomy alone. Trust is created when autonomy can be governed, constrained, explained and stopped.

As agentic AI moves toward OT and critical infrastructure, organizations are increasingly looking to combine innovation with sovereignty and enforceable control by defining where autonomy belongs, how it will be governed, and how it molds trust. Connect with me and let’s discuss how industry leaders are building secure, sovereign and accountable agentic AI for critical environments.

Share this article

X IconLinked-in Icon

Noah Wollenhaupt

Global Product Director for OT-Cyber Security

View detailsof Noah Wollenhaupt >
  • Follow Noah Wollenhaupt on LinkedIn
 

Subscribe for regular insights

Thank you for your interest. You can download the report here.
A member of our team will be in touch with you shortly

Title of this section

Agentic AI threat modeling: When AI starts acting

Cyber at machine speed: can your security program keep up?

Digital sovereignty in the age of AI: Control over decisions, not just data

Identity for AI Agents: The new nonhuman perimeter

Move from prediction to resilience: Navigating the new cyber equilibrium

Rethinking the AI supply chain security: Models, data, agents, tools, and the new skills layer

Securing AI workloads across the hybrid and multi‑cloud AI supply chain

Trustworthy AI is lost without security: Turning principles into enforceable controls