menu_open Columnists
We use cookies to provide some features and experiences in QOSHE

More information  .  Close

An AI Cyber Defender Can Stop The Attack And Still Lose The Mission – OpEd

12 0
21.09.2026

The author says the next AI-cyber failure may start after the find: an agent isolates a hospital backup, water plant, radio, or controller, the dashboard goes green, and the physical service dies. OT is not IT; NIST treats safety and uptime as peers of security. WEF: industrial AI is outrunning visibility.

Design rule in the piece: mission-preserving containment—cut the attacker and keep the function. Split watch, reversible digital steps, and acts that can stop a pump. Pre-agreed local emergency moves; the detector must not be the only definer of a safe physical state. NSA/CISA and partners: humans on critical calls, fail-safes, tight privileges.

Count defender-caused outages separately so metrics do not reward the fastest cut. Buy tests for bad comms, conflicting sensors, and missing bosses—not only detection scores. NIST is revising SP 800-82 (2026). A green panel is not a win if the lights or radios are out.

As AI agents gain authority to isolate devices, change configurations and patch networks, success cannot be measured only by whether the intrusion stopped. The defense must preserve the physical service the network exists to protect.

The next serious AI-cyber failure may not begin when an attacker gets in. It may begin after the attacker is found.

Imagine a defensive AI agent detects suspicious activity on a computer connected to a hospital’s backup power, a water-treatment process, a military communications link or an industrial control system. The agent does what its security objective rewards: it isolates the machine, revokes access or pushes a configuration change. The malicious path closes. The dashboard turns green.

Then the physical service stops.

This is a hypothetical scenario, but the underlying engineering problem is not. Security teams have always had to balance containment against availability. Agentic AI raises the stakes because a defensive system can investigate, decide and act across many assets at machine speed, potentially faster than a human operator can reconstruct the dependencies behind them.

That distinction deserves more attention as critical-infrastructure operators adopt AI. A recent World Economic Forum article argued that AI adoption in industrial environments is moving faster than security visibility in many of those environments. The important question is not simply whether AI can defend........

© Eurasia Review