The Convergence Imperative: Why AI Collapses Security Silos
Hillstrong Group Security ·

AI is not an OT feature, it is a governance test that merges security, privacy, and accountability.
Not another feature
Most of the AI messaging aimed at industry is framed as incremental progress. Vendors pitch smarter anomaly detection, predictive maintenance, or faster inspection. The sales language makes it sound like a routine software upgrade.
That framing is misleading. AI is not just another feature. It moves data in ways plants have never had to govern, and it erases the boundaries executives rely on to divide responsibility. Information that used to stay within OT networks is now shared with IT systems, pushed into cloud pipelines, and ingested by models that may retain it. Logs once used for troubleshooting can be summarized by large language models (LLMs) that inadvertently surface personal details. Engineering data uploaded for support may end up outside your control.
AI collapses the walls between OT security, IT security, privacy, and corporate governance. The question for boards is whether the organization is ready for that collapse.
How boundaries erode
For decades, manufacturing risk was managed through specialization. OT security focused on safety and uptime. IT security defended infrastructure and corporate information. HR and legal handled privacy. These groups rarely collided.
AI changes that equation. Even modest pilots create flows that jump lanes:
- Predictive systems collect operational data and store it in external environments.
- OT alerts arrive in IT-managed security operations centers, where staff lack industrial context.
- Maintenance notes, often containing names or supervisor comments, are ingested by LLMs.
It doesn’t take widespread deployment to create exposure. The simple act of experimenting with AI forces executives to govern across functions.
What convergence looks like in a plant
Operational data as performance data
Smart torque tools, barcode stations, and badge-gated checkpoints already log who did each step, how long it took, and in what sequence. When AI models use this data to optimize cycle time, the result isn’t just efficiency, it becomes a profile of individual or team performance. That is privacy-sensitive information whether executives label it that way or not.
Maintenance notes as personal records
Enterprise Asset Management (EAM) systems and root cause analysis (RCA) databases contain years of incident reports, work orders, and comments. Training an LLM on this corpus can be useful for spotting trends. It can also resurface employee names, shift identifiers, and even blame language. What started as a maintenance project quickly becomes a labor and privacy issue.
Configuration data as intellectual property
Under pressure to restore uptime, engineers may upload Programmable Logic Controller (PLC) backups, recipes, or network diagrams into an AI-powered support assistant. Those files encode tolerances, sequencing, and architecture, the design DNA of the operation. If the vendor retains them for “model improvement,” a company’s crown jewels have effectively been transferred.
Each of these examples is operationally realistic. Each one shows how quickly AI pilots can cross into privacy, security, or intellectual property territory.
Misjudgments I hear from leadership
In executive discussions, four themes repeat:
- “This belongs to OT.” It doesn’t. AI crosses IT and privacy boundaries on day one.
- “It’s only a pilot.” Pilots normalize behaviors, where data is sent, what is retained—that are hard to undo later.
- “Privacy doesn’t apply here.” It does once telemetry or text corpora can be linked to individuals.
- “The vendor will cover us.” Vendors design contracts to disclaim liability. Boards inherit the risk.
These are not trivial misunderstandings. They represent a blind spot that will eventually expose the organization if governance is not reset.
How this plays out in real scenarios
Imagine three common situations:
- A cycle-time optimization tool uses smart tool telemetry. Months later, workers ask why the company is ranking them without disclosure or consent.
- A predictive maintenance pilot trains on years of shift notes. The AI model produces summaries that include supervisor critiques of specific employees. Legal and HR are drawn in after the fact.
- A troubleshooting request involves uploading PLC backups to a vendor. The files are retained, and later the company realizes proprietary tolerances have left its control.
None of these scenarios are exotic. They are natural consequences of how AI consumes the data plants already produce.
The governance gap
What makes AI different is not the features, it’s the accountability vacuum. Vendors market efficiency but decline liability. IT and OT functions push responsibility back and forth. Privacy is often consulted too late.
Without governance in place, early projects set their own rules by convenience. Data leaves plants without review. Logs are retained without oversight. Sensitive files are uploaded under pressure. By the time boards intervene, practices are entrenched.
This is the real risk: AI doesn’t just collapse silos of data. It exposes silos of accountability.
What boards can do now
The right time to act is before adoption accelerates. Boards should:
- Create a governance policy. Define what operational, personal, and configuration data can be used in AI projects and what protections are mandatory.
- Run impact reviews. Assess not only what data is collected but also what inferences are generated.
- Set strict vendor terms. Require contracts that prohibit retention or reuse of data unless explicitly authorized.
- Name a responsible executive. Decide whether AI governance belongs to the CIO, CISO, or COO. Vagueness guarantees gaps.
What this means for directors
AI will not remain confined to pilots for long. The pressure to show efficiency gains will push adoption forward. Once it does, the old divisions between OT, IT, privacy, and governance won’t hold.
The boards that prepare now will adopt AI on their own terms, with clear policies, contracts, and accountability. The boards that delay will discover that AI adoption has already rewritten the rules without them.
The test is straightforward: do you treat AI as another plant feature, or do you see it as the governance stress test it really is?