Blog
Sep 3, 2026
5 min read

When AI Cyber Threats Evolve Faster Than Critical Infrastructure Can Adapt

AI-enabled cyber threats are evolving faster than critical infrastructure can safely adapt. Following OpenAI’s recent call for collective cyber defense, we examine the implications for OT security and explore how strong identity and access controls can protect legacy and hard-to-patch systems without disrupting essential operations.

How AI is Raising the Stakes for Critical Infrastructure

Today’s attackers can adopt new AI capabilities almost overnight. Critical infrastructure operators simply can’t replace decades-old operational systems at the same pace—and just as importantly, they shouldn’t try.

This tension is central to the urgency behind A Call for Collective Action on Cyber Defense, an open letter published by OpenAI and signed by Microsoft, Google, AWS, Cisco, CrowdStrike, Palo Alto Networks, and more than 100 other technology, cybersecurity, financial services, and infrastructure organizations.

The letter warns that AI-enabled cyberattacks will, in the very near future, become more widespread and sophisticated. It calls on organizations to treat cyber defense as an immediate priority and use advances in AI to address longstanding vulnerabilities before attackers gain an even greater advantage.

Critical infrastructure figures prominently in this call to action. The statement highlights risks to hospitals, water treatment plants, internet infrastructure, and other essential services, and urges greater support for the organizations that operate them.

This emphasis on critical infrastructure is absolutely warranted. But acting with urgency gets more complicated when cybersecurity decisions affect physical processes and operational systems that must continue running safely and reliably.

So how can critical infrastructure operators strengthen their cyber defenses when threats are evolving more quickly than the systems they’re protecting can adapt?

AI Threats vs. OT Security Realities

AI is making it faster and easier to carry out cyberattacks at scale. Reconnaissance, vulnerability discovery, phishing, and other tasks that once demanded significant time, expertise, and manual effort can increasingly be automated—compressing weeks or months of work into just minutes or hours.

For critical infrastructure operators, this creates a serious challenge: vulnerabilities and exposed systems are becoming easier to discover and target, while the operational constraints around addressing them remain unchanged.

PLCs, HMIs, engineering workstations, and control systems operate under very different constraints than traditional IT infrastructure. They are routinely expected to remain in service for years or even decades, and modifying them isn’t as simple as pushing an update overnight.

Even a routine patch or upgrade may require compatibility testing, vendor approval, safety validation, a hard-to-come-by maintenance window, or a planned outage. And some systems are no longer be supported at all.

Defensive AI tools can help security teams discover vulnerabilities and prioritize threats faster—but they can’t speed up maintenance windows, make legacy equipment compatible with modern software, or eliminate the operational consequences of taking a critical system offline.

Compensating Controls for Critical OT Systems

The OpenAI letter wisely acknowledges this reality. Among its recommendations is a directive with particular relevance for OT environments and critical infrastructure:

“Where a system cannot be patched without disrupting essential services, apply and verify compensating controls.”

For OT teams, this is a crucial point: remediation doesn’t always happen on the same timeline as risk discovery. There may be an extended period between identifying a risk and safely patching, upgrading, or replacing the affected system.

This is where compensating controls become essential. Strong identity and access controls, in particular, can provide an immediate and effective way to reduce exposure around vulnerable systems.

Even when a PLC, HMI, or other OT asset is difficult to change, the paths leading to it are often much easier to control. Unlike an upgrade or replacement, identity and access controls can strengthen security around these systems without requiring changes to the underlying asset. Such controls enable critical infrastructure operators to determine who—or what—gets access, when, under what conditions, and what they are allowed to do once connected.

In practical terms, this means verifying identities, enforcing least-privilege access, eliminating unnecessary standing privileges, and making access time-bound so it expires when authorized work is complete. Employees, contractors, OEM technicians, and third-party service providers should have access when they need it rather than persistent pathways into critical environments.

Effective identity and access controls also demand accountability. Organizations need visibility into who accessed what and what they did, with the ability to monitor sessions and quickly revoke privileges when work is complete or conditions change.

For legacy and hard-to-patch OT systems, this approach provides durable protection while allowing critical assets to continue operating as designed.

A Practical Path to Stronger Cyber Defense

The urgency behind OpenAI’s call for stronger cyber defense is real, especially for organizations that keep essential services and operations running. But responding to that urgency doesn’t mean forcing critical infrastructure to change at a pace it can’t safely support.

Across manufacturing plants, energy systems, water utilities, transportation networks, healthcare environments, and other critical infrastructure, security controls must reduce cyber risk without creating new operational or safety risks.

When evaluating security solutions, organizations should ask:

  • Can the solution protect legacy and unsupported systems?

  • Does it require new software, hardware, or other changes to critical assets?

  • Could deployment interrupt an essential process?

  • Can access be granted and revoked without affecting the underlying system?

Patching, upgrading, and modernization remain important parts of a broader cybersecurity strategy. But strong identity and access controls offer a way to improve security regardless of any constraints on the underlying asset. By controlling who or what can reach critical systems and what they can do once connected, organizations can significantly reduce exposure across both legacy and modern environments.

At Cyolo, we believe secure connectivity is one of the most practical levers critical infrastructure operators can pull today. Our Secure Connectivity Platform secures both human-to-machine connections and machine-to-machine communications, leaving the underlying systems unchanged.

AI-enabled cyber threats will continue to evolve faster than critical infrastructure can safely adapt. That speed gap isn’t going away, but it doesn’t have to become a security gap.

Jennifer Tullman-Botzer

Author

Jennifer Tullman-Botzer has over a decade of experience in cybersecurity marketing and is as tired as you are of hackers-in-hoodies stock images. She joined Cyolo in 2021 and currently serves as director of content marketing.

Subscribe to Our Newsletter