SABSA TRAINING CONSULTING
Skip to content

Architecting the Principles of AI/OT

Malcolm Shore

Chief Architect

The emergence of Generative Artificial Intelligence (GenAI) as a new form of technology is having a substantial impact on our understanding of the digital world and how we relate to it. In both enterprise applications and at the consumer level, GenAI has started to become ubiquitous.

AI, however, is not at heart a new technology. The Book entitled Principles of Artificial Intelligence by Nils J Nilsson was published in 1980 and brings together research in the field that had started as early as the 1960s and had taken off somewhat in the 1970s. The use of AI in operational technology (OT) systems predates the rise of GenAI, as industrial robots have used certain algorithmic elements of the discipline such as vision and rudimentary planning models for many years. Algorithms of various types have been employed in the development of smart weapons with application of computer vision, machine learning, and optimal target assignment being example uses.

The integration of GenAI into OT systems is an obvious continuation of intelligence-based operational technology. However, despite the many benefits that can result from this, the fragility of current GenAI systems gives rise to significant additional risks to safety when applied to critical OT systems. In January 2025, RAND Corporation published commentary entitled The United States Needs to Stress Test Critical Infrastructure for Different AI Adoption Scenarios and pointed to the need for risk assessment.

In December 2025, the UitS Cybersecurity and Infrastructure Security Agency (CISA) and the Australian Signals Directorate (ASD) co-authored a guideline entitled Principles for the Secure Integration of Artificial Intelligence in Operational Technology, which provides practical guidance for critical infrastructure owners on managing the integration of AI in OT systems.

The guidance points to the Purdue Model of OT/IT and presents four key Principles:

  • Understand AI;
  • Assess the OT Business Case;
  • Establish Governance and Assurance;
  • Embed Safety and Security Practices.

Across these principles, there are thirteen mitigations suggested, including Mitigation 3.2: Integrating AI into Existing Security and Cybersecurity Frameworks. As a leading framework for architecting business-driven security, and one which is designed for alignment with other artefacts, SABSA is an ideal start point for integrating the Principles when considering the application of AI into OT.

The starting point in a SABSA analysis aligned with the Principles is Mitigation 2.1: Consider the OT Business Case. As with any AI initiative, understanding the role AI plays in the business value chain, whether that is an OT or IT value chain, is crucial to delivering success.

The next stage is to address the motivation, and this covers Mitigation 1.1 Understand Unique AI Risks, Mitigation 2.2: Manage AI-OT Data Security Risks, and Mitigation 3.4: Navigating Regulatory and Compliance Considerations.

SABSA provides a Governance Model, and this can be applied to address Mitigation 3.1 Governance Mechanisms for AI in OT. Part of the overall governance activity is to ensure stakeholders are informed, and this addresses Mitigation 1.3: Educate Personnel on AI.

SABSA provides an Assurance Model which can be applied to cover Mitigation 3.3: Conduct AI Testing, as well as addressing the additional assurance requirements of compliance and audit.

SABSA adopts the recognised RACI model for understanding roles and responsibilities, and has a specific approach to modelling the interactions with service providers, including the development of service definitions and SLAs. These form a rich foundation for addressing the Mitigation 2.3: Understand the Role of AI Vendors, and providing effective supply chain management.

SABSA does not include specific architectural techniques for managing systems development and implementation, and so the Mitigation 1.2: Understand the Secure AI SDLC and Mitigation 2.4: Evaluate OT-AI Integration Challenges will be addressed by whatever project management framework is being used.

The SABSA Manage and Measure phase is focused on monitoring and reporting the performance of security architecture that has been delivered. The use of metrics and measurements with thresholds in attributes covers Mitigation 4.1: Monitoring and Oversight, and the SABSA matrix with its layered security measures provides the means to satisfy Mitigation 4.2 Embed Safety and Failsafe Mechanisms in the physical layer of the architecture, including development of procedures, integration with incident response plans, and so on.

In conclusion, SABSA provides a framework in which the AI OT Principles can be integrated to enable a complete architectural approach to delivering effective AI uplift in OT systems. Adopting a SABSA approach enables an integrated compliance approach in which attributes can be mapped not only to standards such as ISO 27001 and ISO 42001 to demonstrate security and AI management compliance, but also to the Principles to show due diligence in the introduction of AI to the OT environment.