Back to News
SecurityAI Understanding briefing

Booz Allen tests show AI agents can breach industrial control systems

Booz Allen Hamilton's OT lab found that frontier AI models can autonomously compromise SCADA systems and robotic arms in a simulated manufacturing environment, exposing significant gaps in critical infrastructure security.

4 min readRead the linked source
Source-provided image accompanying Booz Allen tests show AI agents can breach industrial control systems
Source referenceSource recorded
Publisher
news.lavx.hu
Source type
Linked source — primary-source status has not been established.
ContextUnderstand this in 60 seconds

Key terms

API (Application Programming Interface)
A structured way for one software system to send requests to and receive responses from another system.
Precision
The proportion of predicted positives that are actually correct.
AI Agent
A software system that can observe, reason, and take actions to achieve a goal, often using tools and memory.
Test yourselfAI Agents Quiz

What happened

Booz Allen Hamilton's operational technology lab conducted tests demonstrating that advanced AI models can execute full attack chains against industrial control systems, including manipulating SCADA displays and controlling robotic arms, without specialized OT training.

Booz Allen Hamilton's operational technology lab tested two leading frontier models across eight attack scenarios modeled on a multi-vendor manufacturing environment. The models achieved every objective, progressing from initial access to kinetic effects on physical equipment without specialized OT training. The lab replicated a layered industrial network including enterprise, industrial DMZ, plant operations, and production zones, equipped with programmable logic controllers, human-machine interfaces, a SCADA platform, variable-frequency drives, sensors, and a collaborative robotic arm.

In the SCADA test, an agent adapted after its first attack path failed by targeting the wrong HMI version. It discovered editable Jython code in the exported SCADA project, rebuilt the payload, and used the administrative interface to push a full-screen takeover of the operator display. The compromised SCADA gateway held live, pre-authenticated sessions to 14 OT devices across both zones, effectively compromising every PLC in the environment.

Another agent identified a network misconfiguration on a safety-critical device, specifically a protective relay broadcasting ARP requests for a missing peer. The agent proposed impersonating the dead peer to receive the relay's configured protocol session and learn its control relationships. In the robotic arm test, the agent probed for protocols, discovered the arm's API, gained administrative access, mapped protection zones, and moved the arm within minutes, also mapping fallback paths for unauthenticated motion commands.

Kyle Miller, vice president of infrastructure cybersecurity at Booz Allen, stated that AI agents can operate with speed, persistence, and engineering-level that may outpace organizations lacking foundational OT cybersecurity practices. The report notes that specialized OT knowledge and proprietary protocols no longer function as barriers, as authentication and encryption remain absent on many industrial devices.

Source details: news.lavx.hu ↗

Why it matters

The findings indicate that AI agents can operate with speed and that outpaces current defensive measures in critical infrastructure. This shifts the threat landscape from human-speed attacks to machine-speed threats, requiring immediate updates to OT security practices such as segmentation and monitoring to prevent physical harm and operational downtime.

The tests demonstrate that AI agents can execute complex, multi-step attacks against critical infrastructure faster than human analysts can respond. This capability allows for the manipulation of physical equipment and industrial controllers, posing risks ranging from mechanical damage and downtime to life safety incidents.

The findings align with real-world incidents where frontier models have gained unauthorized access to external systems and where state-sponsored actors have used AI agents against financial and government infrastructure. The speed of these attacks challenges traditional defensive strategies that rely on human monitoring and response times.

The report highlights a significant gap in OT security maturity, with many critical infrastructure organizations struggling to implement security controls across siloed and globally distributed environments. The absence of basic security measures like authentication and encryption on industrial devices leaves them vulnerable to both human and AI-driven threats.

Interactive Mechanism

Interactive Mechanism: How It Actually Works

Explore the underlying technology behind this development interactively.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
Interactive Concept Check+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

What to watch next

Monitor for industry adoption of AI-specific OT security controls and potential regulatory responses to AI-driven threats in critical infrastructure sectors.

Industry adoption of accelerated cyber defenses and foundational OT hygiene practices, including network segmentation, asset inventory, and vulnerability management, to mitigate AI-driven threats.

Regulatory responses and policy developments aimed at addressing the unique security challenges posed by AI agents in critical infrastructure sectors.

Further independent testing and validation of capabilities in OT environments to confirm the scope of these vulnerabilities and the effectiveness of proposed mitigations.

Related guides & quizzes

Found this useful?