For decades, one of the basic security principles of critical infrastructure has been simple: if a system does not need to be connected, don't connect it.

Power plants, water treatment facilities, manufacturing environments and other industrial systems may therefore operate networks that are heavily segmented, isolated from corporate IT, or completely disconnected from the Internet.

That isolation is valuable.

But industrial systems are becoming more automated and more data driven. They are also generating more information than ever before, and much of that information is difficult for people to analyze manually.

That is where AI and machine learning enter the picture.

More Data Than Operators Can Reason About

Modern industrial environments can produce enormous quantities of operational data.

Temperature. Pressure. Flow. Vibration. Electrical load. Valve position. Motor current. Chemical measurements. PLC states. Alarm histories.

Individually, many of these signals are relatively simple.

The challenge is understanding what they mean together.

A change in vibration may be harmless under one operating condition and an early indication of mechanical degradation under another. A pressure fluctuation may be normal during one process and abnormal during another.

Machine learning models can help identify these relationships.

They can be used for anomaly detection, predictive maintenance, process optimization and condition monitoring. This allows operators to identify patterns that would be difficult to detect by looking at individual measurements.

This is already an active area of industrial and scientific research. Recent work, for example, has demonstrated machine learning approaches for equipment health monitoring in nuclear power plants and for predicting failure characteristics of nuclear coolant pumps.

Water treatment provides another example. Recent research has demonstrated machine learning and reinforcement learning approaches for optimizing chemical dosing, including a 2026 study that evaluated real time control at a full scale wastewater treatment plant.

The important point is not that every plant is already being run by AI.

It isn't.

The important point is that AI is moving from a purely analytical tool toward systems that can increasingly influence operational decisions.

And that changes the security discussion.

Why Run AI Inside the Air Gap?

If the data never leaves the facility, why not simply send it to a cloud AI service?

In many industrial environments, that may not be acceptable.

There can be security, regulatory, operational, sovereignty and availability requirements that make external connectivity undesirable or prohibited. There may also be practical considerations such as latency, bandwidth, reliability and the need for the system to continue operating when external services are unavailable.

As a result, organizations may choose to run models locally.

That can mean a dedicated server, an industrial edge computer, a local analytics platform, or another system operating entirely within the protected environment.

The AI system itself may therefore have no Internet connection at all.

At first glance, that sounds like a security advantage.

It is.

But now the AI system itself becomes part of the trusted environment.

And that changes the security problem.

The Air Gap Protects the Network. It Does Not Automatically Protect the AI.

An air gap is a network architecture.

It is not a guarantee that every file, model, device, administrator or data source inside that architecture is trustworthy.

Consider what has to happen before an AI model can run inside an isolated environment.

Someone has to obtain the model.

Someone has to transfer it into the environment.

Someone has to install it.

Data has to be collected and prepared for training or inference.

Models may need to be updated.

Libraries and operating system components may need to be patched.

And, in some architectures, models may eventually be allowed to influence operational systems.

Every one of those activities creates a potential trust boundary.

This is not merely theoretical.

In 2017, researchers demonstrated the BadNets attack, showing that a machine learning model can contain a hidden backdoor while appearing to perform normally on ordinary test data. The research specifically identified the machine learning model supply chain as a security concern.

The significance for an air gapped environment is straightforward:

Disconnecting the environment from the Internet does not make an imported model trustworthy.

If a malicious or compromised model is deliberately transferred into the environment, the air gap has not failed. The problem is that the air gap was never designed to determine whether the object being transferred was trustworthy.

The network may be isolated.

The object crossing that boundary may not be.

The Same Problem Exists With Data

Models are only part of the equation.

AI systems also depend on data.

If training data is manipulated, incomplete, corrupted or deliberately poisoned, the resulting model can behave differently from what its operators expect.

This is one reason organizations such as DARPA have invested heavily in research into adversarial machine learning, including data poisoning, adversarial examples, model extraction and related attacks.

Again, this does not mean that a particular critical infrastructure facility has already been compromised by AI data poisoning.

It means that the attack class is credible enough to have become an active area of security research.

That distinction matters.

There is a big difference between:

“Researchers have demonstrated that this attack is possible.”

and:

“A power plant was compromised using this attack.”

A serious security assessment should never blur those two statements.

When AI Moves From Observation to Action

The security implications become considerably more significant when an AI system moves beyond monitoring.

There is a fundamental difference between:

AI says:

“Something appears unusual.”

and:

AI decides:

“Change this operating parameter.”

The first is an analytical function.

The second is part of an operational control process.

Machine learning is increasingly being investigated for control and optimization applications. In water treatment, for example, researchers have demonstrated approaches in which machine learning is combined with reinforcement learning to optimize chemical dosing.

Similar research exists across energy and industrial applications, including turbine condition monitoring and cavitation detection.

But it is important not to confuse research demonstrations with widespread autonomous control of critical infrastructure.

In many real systems, AI is more likely to begin as:

  • Anomaly detection
  • Predictive maintenance
  • Decision support
  • Process optimization
  • Operator recommendations

Only later, and under considerably stronger safety constraints, might some functions become partially or fully automated.

That progression matters from a cybersecurity perspective.

The more authority an AI system receives, the greater the consequences if its inputs, model, configuration or behavior are compromised.

Air Gaps Have Never Been Absolute Security Boundaries

We already have a well known example of this problem that has nothing to do with AI.

Stuxnet.

The systems targeted by Stuxnet were not simply exposed Internet servers waiting for an attacker to connect to them. The malware used several propagation mechanisms, including infected USB devices and infected project or database files. CISA documents these propagation methods in its Stuxnet advisory.

Stuxnet therefore demonstrated an important principle:

A network can be isolated from the Internet and still receive malicious code.

AI introduces another layer to that problem.

The issue is no longer only whether malware can get into the network.

It is whether an untrusted model, dataset, software component or AI generated decision can enter an environment that was designed to trust what is already inside it.

That is a very different security problem.

The New Security Boundary

An air gap alone is no longer enough.

An AI enabled air gapped environment may have to establish trust in much more than network connectivity.

It may need to establish trust in:

  • The AI model
  • The model's source
  • Model updates
  • Training and inference data
  • Software dependencies
  • AI infrastructure
  • Model configuration
  • Users and administrators
  • Input data
  • Outputs and decisions
  • Interfaces between AI and OT systems

There is also another operational problem:

How do you know that the model is still behaving as expected?

AI systems can change behavior without a conventional software vulnerability being present.

Changes in the underlying data can produce data drift. Changes in model behavior can require monitoring and validation. Siemens, for example, provides tooling for detecting data and model drift in industrial AI deployments, illustrating that model behavior and reliability have become operational concerns in their own right.

This means that introducing AI into an air gapped OT environment potentially changes the security boundary itself.

Previously, the primary concern might have been protecting the network and the systems connected to it.

Now there is another layer:

Can we trust what the AI is doing inside that network?

The Question We Should Be Asking

The question is not:

“Is AI safe inside an air gapped network?”

Nor is it:

“Does an air gap make AI safe?”

Neither question captures the real problem.

The more useful question is:

“What additional security controls are required when an AI system is introduced into an environment that was previously designed around a much simpler trust model?”

That question leads directly to the next part of the discussion.

Securing an air gapped AI system is not simply a matter of protecting the network.

It means securing the entire AI lifecycle:

model acquisition → transfer → installation → data → inference → monitoring → updates → validation → operational integration.

And that is where the real security challenge begins.