RSS Amplifier

Edward's Substack · Jun 3, 2026

The New Operator Needs a New Trust Boundary

0
Sign in to vote or save

Edward J. Liebig · Edward's Substack

Mohamed Saad’s recent OT CISO Newsletter article on agentic AI in operational technology struck me because it put clean language around something that has concerned me for a long time.

He described agentic AI as “the new operator.”

That is the right framing.

For those of us who have worked around industrial environments, the word operator carries weight. Operators are not just users of a system. They are part of the operating model. They interpret conditions, follow procedures, respond to abnormalities, escalate when needed, and take actions that can affect production, safety, environmental performance, and business continuity.

Once AI begins to influence operational decisions, it is no longer just a tool in the background. It becomes part of the decision fabric.

That is where my concern begins.

For much of my career, I have been trying to capture and analyze what I often call the “rest of the story” in OT.

The network matters. Asset discovery matters. Packet visibility matters. Threat detection matters.

But none of those, by themselves, tells the full operational story.

In OT, the real questions usually sit one layer deeper.

  • What is happening in the physical process?

  • What consequence could this condition influence?

  • What control or safeguard is supposed to keep the process inside its intended margin?

  • What assumptions are we making from the available data?

  • Can those assumptions be validated?

  • What action would actually reduce risk without creating new operational exposure?

That last question has always been the difficult one.

It is one thing to observe. It is another thing to understand. It is another thing altogether to act.

And in OT, action carries a very high trust burden.

I saw that firsthand when cybersecurity teams began introducing passive packet sniffers into OT environments.

Even when those tools were designed only to observe, seasoned engineers often pushed back. Some people outside the plant environment interpreted that resistance as cultural friction or fear of change.

But the questions from engineering were valid.

  • What is connected to the system?

  • What can it affect?

  • Who understands the process context?

  • What conclusions are being drawn from this data?

  • Could this create operational risk?

  • What happens if someone misinterprets what they see?

All of that concern was raised around simple passive visibility.

Now compare that to agentic AI that can recommend, prioritize, escalate, suppress, isolate, tune, or eventually take action. The trust threshold is much higher.

So, in my mind, no seasoned engineer would ever be expected to trust unbounded and unassured AI influence in a physical process environment.

That is not resistance to innovation. That is engineering discipline.

AI changed the way I thought about how to address the overall security problem.

For the first time, I could see a credible path to synthesizing the broader OT picture at the speed and scale required to make operational sense of it.

  • Cyber signals.

  • Configuration context.

  • Control logic.

  • Physical observations.

  • Operator actions.

  • Maintenance activity.

  • Process drift.

  • Environmental conditions.

  • Procedure execution.

  • Decision history.

All of that context is relevant. The opportunity was not simply to collect it. The opportunity was to correlate it into something useful enough to support better operational decisions.

That was the glimpse AI provided.

But the trust issue was always going to be the showstopper.

In sensitive environments, it is not enough for AI to be impressive. It has to be bounded. It has to be governed. It has to be observable. It has to preserve evidence. It has to respect authority. It has to keep sensitive knowledge inside a trusted boundary. It has to show its influence surface.

For OT, the analysis also has to begin from consequence. The relevant question is not only whether the AI is accurate. The more important question is what consequence its output could influence, what control fabric it touches, and whether the assumptions behind that influence remain valid.

That requires more than a model.

It requires trusted infrastructure.

My perspective shifted when I met Francis Cianfrocca and saw the Genomic AI foundation running InsightCyber.

That was the first time I felt we were closer than ever to the kind of synthesis I had been chasing. Not just another dashboard. Not just another stream of security events. Something closer to a living analytical foundation that could correlate signals, learn context, and support decision-making across complex environments.

But, the real evolution came when Francis, his crew, and I put our heads together.

This was a team revelation.

Each of us saw part of the problem from a different angle. Together, we kept coming back to the same missing piece.

The analytics were only part of the answer.

The trust boundary around the analytics was the real enabler.

That thinking became the foundation for NexGenomics.

NexGenomics is a bounded trusted AI fabric that allows sensitive organizations to use AI without surrendering control of their data, knowledge, models, applications, agents, prompts, or decision pathways.

The purpose is not to ask people to trust AI more.

The purpose is to give them more evidence, more control, more containment, and more visibility into how AI is being used and what it can influence.

This trusted infrastructure is already being applied through our Helix Model for healthcare and medical research.

Healthcare and research environments carry their own deep trust burden. Sensitive data, institutional knowledge, research context, and decision lineage cannot be treated casually. Organizations need AI capability, but they also need confidence that proprietary and sensitive intelligence stays inside the intended trust boundary.

That same foundation now gives us confidence to extend into the Axiom Model for Operational Assurance and Resiliency in OT.

For Axiom, the goal is not to turn AI loose inside the plant.

The goal is to help operators, engineers, cyber teams, and executives understand whether critical operational conditions are still inside intended margins, whether the controls protecting those margins are still aligned, and whether emerging drift deserves attention before it becomes consequence.

This is where the “new operator” framing becomes especially useful.

If AI can influence operational decisions, engineers need visibility into the AI influence surface.

  • They need to know what it can touch.

  • They need to know what authority it has.

  • They need to know what data it used.

  • They need to know what assumptions shaped its output.

  • They need to know whether its recommendations are tied to operational consequence.

  • They need to know whether rollback, override, and evidence-grade traceability are present.

Most of all, they need assurance that AI is strengthening engineering judgment, not bypassing it.

The most useful path forward is not to start with AI capability and then search for places to apply it.

In high-consequence environments, the starting point should be the outcome that must be protected.

  • What must not happen?

  • What operational margin protects against that consequence?

  • What control fabric supports that margin?

  • What cyber, physical, procedural, human, or organizational pathway could erode it?

  • What signals would show that erosion early enough to matter?

  • Where can AI help humans see, synthesize, and act more effectively?

That is the discipline I have been applying in one form or another for years. Long before the newer terminology caught up, my teams at CSC and Unisys were using consequence-first, engineering-led methods to understand how cyber conditions could affect physical outcomes. The newer language now helps describe the approach more clearly, but the underlying field lesson has remained consistent.

  1. In OT, risk becomes meaningful when it is tied to consequence.

  2. AI becomes useful when it improves human decision quality.

  3. AI becomes trustworthy when its influence is bounded, visible, governed, and continuously validated.

Mohamed’s article is timely because the industry is moving quickly toward AI agents that can do more than answer questions.

They can plan. They can select tools. They can execute tasks. They can interact with systems. They can influence decisions.

In enterprise IT, that already creates governance challenges.

In OT, it raises a different level of concern.

Physical systems do not care whether the action came from a person, a script, a vendor platform, or an AI agent. If the action changes the wrong condition at the wrong time, the consequence is real.

The architecture around agentic AI therefore matters as much as the capability of the agent itself.

  • We need bounded authority.

  • We need containment.

  • We need data boundary control.

  • We need evidence lineage.

  • We need operational explainability.

  • We need local override.

  • We need visibility into the AI influence surface.

We need assurance that AI remains inside the trust boundary appropriate to the consequence it may influence.

I remain optimistic and excited about AI in OT, but only under the right conditions.

AI can help us finally make sense of the broader operational picture.

  • It can help us connect cyber signals to physical meaning.

  • It can help us reduce noise.

  • It can help us identify drift.

  • It can help us preserve institutional knowledge.

It can help us give engineers and executives a clearer view of operational assurance and resiliency.

But it cannot be allowed to inherit trust just because it is useful.

Trust has to be engineered.

That is the work now.

It is also why NexGenomics is emerging at the right time.

Not as a claim that AI should run the plant.

Rather as a trusted fabric to help organizations use AI in sensitive environments with clearer boundaries, stronger evidence, better containment, and more assurance over the decisions AI may influence.

The new operator needs a new trust boundary.

That’s what we’ve created, and that’s the part none of us can afford to skip.

No posts

Read the original on edwardjliebig.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.