88% of Industrial Firms Plan AI Security Despite Legacy Gaps

Majority of industrial firms plan to use AI for security, but legacy systems and poor data quality create significant deployment risks.
Key points
- 87.7% of industrial firms are using or plan to use AI for security, but only 7.9% have deployed it widely.
- Data quality and legacy system integration are cited as the main obstacles, affecting nearly half of respondents.
- Only 15.6% of companies have adopted specific AI governance policies to manage physical safety risks.
Industrial organizations are moving quickly to integrate artificial intelligence into their operational technology security, yet a significant portion of these systems are not technically ready to support such advanced tools. Recent research indicates that while nearly nine in ten companies are using or planning to use AI for cybersecurity, very few have successfully deployed it across multiple functions. This disconnect highlights a growing tension between rapid technological adoption and the physical limitations of existing industrial infrastructure.
The core issue is not a lack of interest, but rather a fundamental architectural mismatch. Most industrial facilities were constructed decades before AI became a standard component of security strategy, meaning their underlying control systems were never designed to handle the data demands of modern machine learning. As a result, many organizations are attempting to layer sophisticated software on top of aging hardware that struggles to provide consistent or high-quality telemetry.
Legacy systems hinder effective integration
Surveys suggest that data quality and the difficulty of integrating legacy systems are the primary obstacles for industrial firms. These two factors account for nearly half of the reported challenges in the sector. Because control systems in these environments often produce scattered and inconsistent data, AI models lack the reliable foundation they need to function accurately. This forces companies to make difficult choices between upgrading their entire physical infrastructure or accepting a higher risk of unreliable security decisions.
Experts note that connectivity also plays a critical role in this gap. Many operational technology environments are not architected to connect securely to the cloud, where the most capable AI models reside. While local models are being used for specific research tasks, they often lack the scalability and power needed for comprehensive security monitoring. This creates a situation where the most effective tools are inaccessible due to both technical and regulatory barriers that prevent cloud integration.
Governance lags behind rapid deployment
The risks of deploying AI in these unstable environments extend beyond software errors to potential physical consequences. A large majority of industry participants recognize that flawed AI decisions could lead to equipment damage, unexpected shutdowns, or safety incidents. However, fewer than one in six companies have established specific governance policies to manage these unique risks. This gap in oversight leaves organizations vulnerable to automated errors that could have real-world physical impacts.
Readiness varies across industrial sectors
The level of preparedness is not uniform across all industries. Sectors with more modern, data-friendly infrastructure are progressing faster in adopting AI security tools. In contrast, organizations operating in older, brownfield environments face significantly more hurdles. The ability to structure and provide context for data varies widely, meaning that some companies are effectively leveraging AI while others struggle to even gather the necessary information.
According to Industrial Cyber, the path forward requires addressing these foundational issues before scaling up AI usage. Without fixing the underlying data and connectivity problems, companies risk deploying systems that are inherently unstable. The focus must shift from simply adopting new technology to ensuring that the existing infrastructure can reliably support it, thereby reducing the potential for costly operational failures.






