Litmus chief warns AI integration could expose industrial controls

Why most Industrial AI initiatives stall
Litmus chief executive Vatsal Shah has warned that efforts to connect artificial intelligence systems with industrial control networks could trigger a major cyber incident within two years, as manufacturers accelerate automation without adequately securing critical infrastructure.

Shah described an internal one-dollar wager predicting a serious cybersecurity breach involving supervisory control and data acquisition systems within the next 12 to 24 months. His warning centres on network access, excessive permissions and security compromises made while demonstrating AI capabilities.

The prediction is not based on a disclosed incident or evidence that a particular industrial installation has been compromised. Rather, it identifies vulnerabilities that could emerge when organisations connect AI applications to operational technology controlling physical processes.

SCADA systems monitor and manage industrial equipment across manufacturing facilities, electricity networks, water treatment plants and other essential infrastructure. Unauthorised access can potentially disrupt production, manipulate operating conditions or interfere with equipment safety.

Shah’s concern reflects a broader cybersecurity challenge as industrial operators seek to make previously isolated operational data available to AI applications. Connecting those environments can require additional network pathways, software interfaces and authentication arrangements, creating opportunities for attackers if controls are poorly configured.

The US Cybersecurity and Infrastructure Security Agency and international partners have issued specific guidance addressing these risks. Their December 2025 recommendations warned that integrating AI into operational technology could introduce threats affecting system availability, reliability and safety.

The guidance, developed with cybersecurity authorities from Britain, Australia, Canada, Germany and other countries, urged operators to assess AI applications against the operational requirements of critical infrastructure before deployment.

It also distinguished between conventional analytical applications and AI agents capable of performing tasks with greater autonomy. Such systems require particular attention because their permissions and potential actions can extend beyond simply examining industrial data.

Further guidance issued in May 2026 warned that autonomous AI services could create vulnerabilities involving privilege escalation, unexpected behaviour and accountability gaps. Authorities recommended restricting access to sensitive systems, maintaining human oversight and continuously assessing security controls.

These recommendations closely match the weaknesses identified in Shah’s prediction. An AI application granted unnecessary administrative privileges, for example, could increase the consequences of a compromised account or manipulated instruction.

The danger also depends on whether AI tools can merely read operational information or issue commands affecting machinery. Read-only access generally presents different operational risks from arrangements permitting software to change equipment settings.

Litmus develops industrial data infrastructure designed to connect information from programmable logic controllers, SCADA platforms, production databases and other operational systems. Its technology supports the collection and contextualisation of industrial information for analytics and AI applications.

The company maintains that manufacturers need consistent access to reliable operational data before AI systems can deliver useful results. Its industrial AI offering emphasises connecting and governing information across production facilities rather than building separate integrations for individual applications.

That commercial position places Litmus within the expanding market for industrial AI infrastructure, where cybersecurity safeguards are becoming increasingly important alongside performance and interoperability.

Litmus also describes security mechanisms for its edge computing platform, including container isolation, role-based access controls, authentication, certificate management and support for environments disconnected from the internet.

Such measures can reduce exposure, although their effectiveness depends on implementation, configuration and the permissions assigned to individual applications and users.

Cybersecurity authorities have separately warned that internet-accessible industrial assets remain vulnerable to weak credentials, outdated software and misconfigured remote connections. Their recommendations include limiting unnecessary exposure, monitoring network traffic and using multifactor authentication wherever practical.

Guidance published in April 2026 also encouraged industrial operators to adopt zero-trust security principles, replacing assumptions of trusted network access with continuous verification based on identity, context and risk.

For industrial environments, that approach includes identifying connected assets, separating sensitive networks and controlling communication between operational equipment and enterprise software.

Another concern involves external contractors responsible for installing or maintaining industrial systems. A September 2026 advisory from CISA and the Federal Bureau of Investigation addressed security practices involving third-party industrial control system integrators.

The advisory encouraged infrastructure operators to establish clear security responsibilities when working with outside specialists, recognising that maintenance arrangements and supplier access can affect operational network protection.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…