AI Agents Demonstrate Lethal Potential Against Critical Infrastructure
A Booz Allen Hamilton report reveals autonomous AI agents can rapidly exploit operational technology systems, posing a significant threat to critical infrastructure with defenses lagging.

Autonomous AI systems are now capable of executing sophisticated cyberattacks against critical operational technology (OT) and industrial equipment, potentially leading to widespread disruptions of essential services like power and water. A recent report from Booz Allen Hamilton details tests where AI agents successfully navigated complex OT environments, identified vulnerabilities, and initiated physical actions within minutes, highlighting a critical gap in current cybersecurity defenses.
The consulting firm's OT lab conducted eight simulated attack scenarios to assess the capabilities of advanced AI models. Across all tests, the AI agents demonstrated the ability to translate digital access into tangible physical impacts. In one alarming instance, an AI agent identified and manipulated a robotic arm in mere minutes. Another test saw an AI model progress from an initial perimeter breach to executing actions within an industrial control network in just over 16 minutes, underscoring the speed at which such attacks could unfold.
"Our testing showed that AI agents can operate with a speed, persistence, and engineering-level precision that may outpace organizations that have not implemented foundational OT cybersecurity practices," stated Kyle Miller, VP of infrastructure cybersecurity at Booz Allen. He further noted that while a specific timeline for a "nightmare scenario" is uncertain, the increasing use of AI in real-world attacks, coupled with growing model capabilities, significantly elevates the risk to critical infrastructure.
Booz Allen Hamilton's testing involved two leading frontier AI models, configured to mimic real-world OT systems across various industries. The test environment was designed to replicate the complexity of multi-vendor OT setups, including programmable logic controllers (PLCs), human-machine interfaces (HMIs), SCADA platforms, and physical equipment like robotic arms and variable-frequency drives. This setup aimed to accurately reflect the technical debt and imperfect segmentation common in long-lived OT environments.
Crucially, the AI models were not provided with source code, engineering documents, or advanced OT/IT guidance. This approach allowed testers to evaluate the AI's ability to research, plan, and execute attacks autonomously. While human oversight was maintained with guardrails requiring approval before exploiting vulnerabilities or causing physical impact, the tests demonstrated the AI's inherent capacity for independent offensive operations.
The AI agents successfully mapped environments, identified critical assets, discovered vulnerabilities, and exploited them to gain access and manipulate production systems. They demonstrated the ability to interact with multiple controller brands, alter process values, and initiate kinetic changes, such as modifying motor speed and stopping/starting equipment. The report emphasizes that specialized OT knowledge is no longer a prerequisite for attackers, as AI agents can rapidly learn and exploit these complex systems.
One notable SCADA test involved an AI agent adapting its strategy after an initial failure. The agent identified an incorrect HMI client version, then pivoted to find editable Jython code, rebuild a payload, and successfully execute a full-screen takeover of the HMI. Furthermore, the AI discovered that a compromised SCADA gateway provided access to 14 other OT devices, illustrating the cascading impact of a single breach.
The findings underscore an urgent need for enhanced cybersecurity measures across OT and critical infrastructure. Booz Allen Hamilton advocates for increased industry testing, development of advanced defenses, and broader deployment of cybersecurity practices specifically tailored for OT environments. The report serves as a stark warning that the convergence of AI and OT presents a formidable and rapidly evolving threat landscape that demands immediate attention and proactive defense strategies.