The latest AI warning is different from the usual debate about whether artificial intelligence will eventually become dangerous. Some of the risks are already becoming operational.
In September 2026, Anthropic CEO Dario Amodei argued that frontier AI capability is advancing so quickly that safety work may no longer be keeping pace. His two central concerns are particularly relevant to industry: AI is increasingly helping to build the next generation of AI, and autonomous groups of agents have demonstrated behaviour that can move beyond their intended task.
At almost the same time, Anthropic’s latest threat-intelligence report documented real cases in which AI was used not merely as a chatbot, but as an orchestrator of cyber operations. Multi-agent systems carried out reconnaissance, exploitation and data theft, sometimes operating for hours or days with minimal human intervention.
The change is autonomy
Cyberattacks are not new. What changes with AI agents is the economics of an attack. One capable operator can increasingly automate work that previously required a team: understanding an unfamiliar environment, finding weaknesses, adapting tools, running parallel attacks and maintaining campaign memory.
Anthropic reports that some breaches were completed in two to three hours and that individual operators could handle dozens of victims in parallel. It also warns that “security through obscurity” is becoming increasingly ineffective because AI can rapidly interpret unfamiliar systems and configurations.
For industrial companies, this matters. Plants increasingly connect PLCs, SCADA, historians, MES, ERP, cloud platforms, remote-maintenance systems and IIoT gateways. Every new connection creates value, but also expands the attack surface.
AI should not be given unrestricted authority
I do not think the answer is to stop using AI. It is already too useful in engineering, maintenance, optimisation and business operations. But I would keep one rule very clear: AI can reason broadly; its authority to act should stay deliberately limited.
In an industrial environment this means separating AI reasoning from deterministic control. Safety interlocks, PLC logic and critical sequencing should remain local and independently enforceable. AI agents should operate through authenticated interfaces with least-privilege permissions, complete audit trails and explicit approval gates for high-consequence actions.
Network segmentation also becomes more important, not less. An AI agent connected to ERP does not automatically need access to the control network. An analytics agent reading historian data does not need permission to write PLC parameters. Remote engineering access should be isolated, monitored and revocable.
The next cybersecurity problem may be machine speed
Traditional security assumes that defenders have some time to investigate unusual behaviour. Autonomous AI compresses that window. Reconnaissance, adaptation and exploitation can increasingly happen at machine speed and in parallel.
That means industrial cybersecurity must also become more automated: continuous asset discovery, behavioural monitoring, identity controls, anomaly detection, immutable logs and rapid isolation of compromised services.
The important distinction is that defensive automation should not create another uncontrolled autonomous system. Critical decisions still need defined authority, deterministic safeguards and a clear path for human intervention.
AI remains worth pursuing
The same technology creating these risks can improve predictive maintenance, engineering productivity, energy optimisation, production planning, quality analysis and cyber defence. The issue is therefore not AI or no AI.
The issue is whether we can put the technical boundaries in place quickly enough as the agents become more capable. In an industrial system, I would rather have a very capable AI inside a well-defined cage than a less capable one with broad access to everything.
The architecture matters as much as the model. AI should sit inside the operating system, not become the operating system.
CANS is incorporating this principle into CansNEXUS and its industrial digitalisation work: AI-assisted reasoning and automation with explicit system boundaries, local control, traceability and human authority where consequences matter.
Recent Comments