Ranked on the Inc. 5000 list of America's fastest-growing companies
Cluster Post 4 min read

Securing OT and IT Convergence: AI Governance for the Connected Factory

Modern automated production line with networked control cabinets on a clean factory floor

Last Updated: August 5, 2026

What is OT and IT convergence?

OT and IT convergence connects plant control networks to enterprise systems and cloud analytics, so historian data reaches business applications and model output flows back toward scheduling and supervisory control.

Convergence is what makes manufacturing AI possible. It is also what dissolved the separation the Purdue model in ISA-95 assumed. Once a cloud model reads Level 2 data and writes a recommendation into a Level 4 scheduler, the boundary exists only as policy.

What new risk does plant-floor AI introduce?

Three risks stack: a new network path between business and control zones, a new data egress channel carrying process detail, and a new class of decision whose logic no controls engineer wrote.

Manufacturing has ranked as the most-attacked industry in IBM X-Force Threat Intelligence Index reporting for several consecutive years, and exploitation of internet-facing applications remains a leading initial access route. Attackers go after the connectivity the pilot justified. Process data is also competitively sensitive: recipes, yields, and throughput leave the plant the moment you pipe historian tags to a cloud model.

Which frameworks govern connected factory security?

NIST SP 800-82 Revision 3 sets the US reference for OT security and aligns it to the NIST Cybersecurity Framework 2.0, including the Govern function. ISA/IEC 62443 supplies the security program structure and zone-and-conduit design.

The two are complementary rather than competing. NIST SP 800-82r3 gives risk management and control selection; ISA/IEC 62443 gives system design and supplier requirements. In the EU, NIS2 adds obligations for manufacturers designated as essential or important entities. Asset discovery platforms including Claroty, Dragos, Nozomi Networks, Armis, and Tenable OT Security use passive traffic analysis, because active scanning can disrupt fragile industrial protocols.

How do you govern an AI model that touches control systems?

Classify by what the model can do. Prediction accuracy is a separate question. A model that writes a setpoint needs functional safety review. A model that emails a recommendation needs far less.

Set the boundary in writing before the pilot. Define read-only versus write-capable scope, the human approval step for any write path, the rollback procedure, and who holds the process veto. NIST AI RMF and ISO/IEC 42001 give the management-system language, and the EU Machinery Regulation (EU) 2023/1230 pulls AI-based safety components into stricter conformity assessment from 20 January 2027. Keep the model in the same change control as any other system that can affect the process.

What to do next

Before the next plant-floor AI pilot, write down two things: every network path the pilot creates between control and enterprise zones, and whether the model can write anything back. If the answer to the second is yes, route it through functional safety review now rather than at go-live.

Read next: AI for Manufacturing Operations: Quality, Uptime, and Safety

Let's Build Together

Let's build your next success story together.