We've Seen This Movie: The OT/IT Technology Divide
We've Seen This Movie: The OT/IT Technology Divide
Manufacturing's Opportunity to Prevent Another OT/IT Technology Divide
Walk the floor of almost any manufacturer that has been in business more than a few decades and you are walking through a history of technology that predates modern Information Technology (IT) departments. The presses, furnaces, Programmable Logic Controllers (PLCs), and the supervisory systems that run them were digitized and automated long before anyone drew an org chart with a Chief Information Officer (CIO) on it. The plant ran the plant. When IT eventually arrived as a business function, it grew up somewhere else entirely, in the back office, close to finance, email, and the enterprise applications that keep the company solvent.
Two worlds formed, side by side, rarely touching. Operational Technology (OT), the systems that make the product, stayed with the engineers who had historically run them. IT, the systems that run the Business, stayed with the technologists who reported up through the CIO. Separate networks. Separate teams. Separate cultures, budgets, and vocabularies.
Nobody decided this. It simply grew organically over time.
It has been a quiet, yet occasionally combustible and expensive problem since. Ask anyone who has tried to run an Incident Response exercise that crosses the line between the enterprise network and the plant floor, or tried to get a single, honest inventory of what is actually running in both environments. The IT and OT divide is one of the most persistent sources of risk, friction, and duplicated cost in this (but not limited to) industry, precisely because no one ever sat down and chose this model. It is the accumulated residue of thirty-plus years of two groups solving their own problems in isolation.
That history matters now, because manufacturing may be making the same decision a second time. Except this time, we already know what the likely result will be.
The New Déjà Vu
Artificial Intelligence (AI) is being adopted across manufacturing at speed, and that alone is not remarkable. Every sector is adopting AI. What is remarkable, and genuinely new, is where it is being adopted.
For the first time, the same wave of technology is arriving on both sides of the divide at once. On the IT side, the pattern is familiar: copilots in the productivity suite, Large Language Models (LLMs) drafting and summarizing, AI woven into the enterprise applications finance and operations already utilize. None of that is a surprise.
The lurking surprise is on the plant floor. OT groups, the same engineers who spent three decades keeping their systems segmented from IT systems, are now adopting AI too. Small Language Models (SLMs) are moving onto edge devices sitting next to the PLCs. Vision models are inspecting parts in real time. Consider a scenario now playing out on plant floors: a maintenance team, tired of a finicky stamping press that only a soon-to-retire veteran knows how to coax back to life, loads that machine's manuals and fault history into a small model on an edge device next to the PLC. Downtime drops. It is a genuinely good idea, built and deployed entirely by OT. And no one in the enterprise Security organization knows the model exists, what data it ingests, or what it is authorized to recommend when the press starts throwing faults. This is not a pilot slide in a strategy deck. It is showing up in production, driven by the OT side, on the OT side.
The good news is also the warning: it is still early. Depending on which survey you believe, a large majority of manufacturing facilities, on the order of 87 percent in one recent United States analysis, have not meaningfully adopted AI at all. That sounds like a reason to wait, but this is incorrect. It is the reason to move.
The window that is open right now is not the adoption window. It is the governance window. Habits are not yet set. The plant floor and the back office are both early enough in their adoption that neither have hardened their own separate ways of deciding what AI is allowed to do, who is accountable when it goes wrong, and what data it is permitted to touch. In a rare moment, both sides are asking the same questions at the same time.
This is the fork in the road that manufacturing has stood at before.
The Trap: Good Guidance, Old Reflexes
Here is where the easy version of this argument would be wrong. It would be convenient to stick with the status quo and say that many "experts" advise that organizations wall OT AI off. First, I disagree. Second, that is not what many experts say.
When the Cybersecurity and Infrastructure Security Agency (CISA), alongside the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and a group of international partners, published its Principles for the Secure Integration of Artificial Intelligence in Operational Technology in December 2025, the guidance did something (surprisingly) encouraging. It called for governance that, in its own words, should "involve leadership, OT and IT subject-matter experts, cybersecurity teams, and relevant vendors." Even the federal guidance is now telling manufacturers to get IT and OT in the same room. The instinct to unify is, at last, somewhat official from a high-level government-guidance perspective. This is hopeful, as government-level guidance tends to trail the private sector adversary protection best practices by years in many cases.
So the trap is not the guidance. The trap is what happens to good guidance when it meets thirty years of muscle memory.
Two forces are quietly pulling manufacturing back toward the old divide. The first is hiding inside that same guidance, which also, sensibly, says AI should be folded into the OT side's existing risk management processes. Read by a group that has organically run their own Programs for over three decades, "fold it into your existing processes" can easily be heard as "build your own program." Cross-functional on paper, single-lane in practice. The second force is simpler: silos are the default, the organizational version of inertia. Absent a deliberate decision to do otherwise, IT will stand up its AI Program and OT will stand up its own, because that is how most of the previous manufacturing technology waves landed.
Picture what those two forces produce together. The IT organization stands up an AI Program: an acceptable use Policy, a model-approval process, a data-handling standard, a review board. The OT organization, folding AI into its own processes, stands up a second Program. Two Policies. Two review boards. Two definitions of acceptable Risk. Two vocabularies for the same technology, drifting further apart every quarter, maintained by two groups that already struggle to sit in the same meeting.
We have seen this movie before. It is the network divide, the inventory divide, and the Incident Response divide, all over again, this time drawn around AI. And the cost is not abstract. It is the duplicated spend of running two governance functions. It is the shadow AI risk of that edge-deployed model on the plant floor, invisible to the enterprise Security team, which is the plant-floor version of a problem every Chief Information Security Officer (CISO) already loses sleep over. It is the day an AI-influenced decision on the floor causes a safety or quality event, and the Business discovers that no single Policy, and no single accountable owner, ever spanned the two environments.
For the Business leader, that is unbudgeted duplication and an ownership gap that surfaces at the worst possible moment. For the OT engineer, it is one more enterprise mandate arriving late and landing badly. For the Security team, it is a second attack surface governed by a different rulebook. Nobody in the building actually wants the two-lane outcome. It is just where "keep them apart" quietly leads.
Answering the Wrong Question
An organization's reflex to keep OT in control of its own AI is not rooted in fantasy. This is where the argument has to be honest.
OT is genuinely different from IT, and the differences are not cultural preferences. They are physics and consequence. An IT system that goes down costs money. An OT system that misbehaves also costs money, but can also injure someone, destroy product, or take a furnace offline for a week. OT runs on availability and safety first, on equipment with twenty-year lifecycles, in environments where "just patch it" can mean shutting down the revenue line. The OT engineers who insist their world is not the back office are correct. A governance model that lets a well-meaning IT committee reach onto the plant floor and start changing how things run would be reckless, and OT is right to resist it.
But that concern is an argument about enforcement and operations. It is not an argument about Policy. The old reflex quietly fuses the two.
The real question was never "should IT and OT be unified or kept apart." The real question is "who sets the rules, and who enforces them on the ground." Once you separate those two things, the whole debate changes. You can absolutely have one enterprise-wide Policy on what AI is allowed to do, what data it may touch, who is accountable, and how Risk is measured, while leaving the OT side in full operational control of how that Policy is carried out on its own equipment. Unified Policy. Local autonomy. Those are not in tension. Treating them as if they were is the mistake.
Here is the honest version: most manufacturers do not run this way today. Many have no enterprise-wide Policy at all, and their IT and OT groups operate largely on their own, with little reference to any global standard. That is the gap. It is also the opportunity. AI is a chance to build the enterprise-wide governance muscle that may never have existed, on a domain where IT and OT are both starting at the same time.
The Model Worth Borrowing
Some large international organizations, including those in manufacturing, with operations in more than one global region have already solved this exact problem.
There is a global Chief Operating Officer (COO), a global CIO, and a global CISO. They set enterprise Policy: the standards, the Risk appetite, and the non-negotiables that apply everywhere the company operates. Then there are regional counterparts, the European COO, the Asia-Pacific CISO, and so on, who take that global Policy and enforce it inside their own region of influence, adapted to local regulation, local labor, and local operating conditions. The global office does not run the plant in Stuttgart or the line in Osaka. It sets the rules of the road. The region drives the car.
Nobody finds this controversial. It is simply how serious enterprises govern themselves across regions that are genuinely different from others. And it maps almost perfectly onto the AI problem, across three tiers.
Global Policy: | One enterprise AI Program sets the rules that apply everywhere, in IT and in OT alike. What classes of AI are permitted. What data may and may not be fed to a model. What level of human oversight is required based on calculated potential impact ratings. Who is accountable when an AI-influenced decision causes harm. How AI Risk is measured, in one shared vocabulary, so that the Board sees one picture instead of two. This is written once, for the whole company. |
|---|---|
Regional Enforcement: | The divisions, business units, or regions take that Policy and build the mechanisms that enforce it. Inventories, approval workflows, and monitoring, each tuned to the local environment. This is the layer that translates a global standard into something that functions in a specific place, the same way a regional CISO already handles Security Policies for organizations at this scale. |
Local Autonomy: | The plant floor executes with operational independence. The people who understand the furnace decide how the Policy is met on the furnace. OT does not surrender control of its equipment, its safety practices, or its uptime to an IT committee. It gains a seat at the table where the Policy is written, instead of a separate silo where a competing Policy is invented. |
That last point is the one to sit with, because it reframes the entire isolation argument. A unified AI Program is not IT annexing OT. Done correctly, it may be the first governance structure in the history of most manufacturers where OT has a real, permanent voice in enterprise Policy. For the many organizations where OT and IT operate almost entirely apart today, it would be the first time the two share a table at all. The engineers who spent decades being governed by rules written for the back office finally help write the rules. That is not a loss of autonomy. It is the opposite.
There is a deeper reason this structure works, and it is one I explored in more depth in a recent webinar on what InfoSec can learn from natural systems: organizations behave a great deal like living organisms, and the most resilient organisms are not centrally controlled. They are decentralized. An octopus camouflages itself with no central command at all, through skin cells that each sense and respond to their own patch of environment, producing a coherent whole out of thousands of local decisions. Nature's pattern is challenge, then competition, then cooperation: pressure pushes independent units to adapt, and the adaptations that work propagate into cooperation across the larger system. The key word is organized. The IT and OT divide is decentralization too, just the unorganized kind, local units solving their own problems with no shared Policy to make the whole coherent. A single AI Program does not centralize the plant floor. It turns unorganized decentralization into the organized kind, which is where natural systems get their resilience.
It is worth illustrating how little precedent there is for this, because it is where the opportunity actually lives. The academic and industry literature on IT and OT convergence is substantial, but when researchers map the field, they organize it into buckets like communication, control systems, and cybersecurity. A unified AI-governance dimension is simply not on the map yet. The bridge described here has not been built. Manufacturing has the chance to be the sector that builds it, rather than the sector that spends the next decade explaining why its AI governance is split down the same old line.
How To Start
None of this requires a mature AI capability to begin. In fact, the less AI you have deployed, the easier this is, because you are writing on a cleaner sheet instead of reconciling two Programs that have already diverged. A few concrete first moves, doable regardless of where you are on the adoption curve:
- One Program, Not Two:
Establish a single enterprise AI-governance body, and put both IT and OT leadership at the table from day one. Not an IT committee that later "consults" OT. One body, both worlds, shared ownership of the Policy. If you are standing up an AI governance function right now and it lives entirely inside IT, stop and widen it before the mortar sets. - Shared Accountability, Not a Takeover:
The fastest way to kill this is to let it look like IT extending control onto the plant floor. Say plainly, in the charter, that OT retains operational control and that the body exists to set common Policy, not to run anyone's equipment. The goal is shared accountability across IT and OT, which is exactly the reframe practitioners in the field are already calling for. - Policy and Enforcement, in Writing:
Put it on paper: global Policy is set centrally and applies everywhere; enforcement and operational execution belong to the regions and the plants. This one document is what prevents the model from collapsing into either extreme, an IT land grab on one side, or two silos on the other. - Start Now, While It Is Early:
This is the whole argument. The window is not open because AI is mature in manufacturing. It is open because AI is not mature yet, on either side. Governance written before habits set is a Policy. Governance retrofitted after two divergent Programs already exist is a reorganization, and reorganizations are where good intentions go to die.
While manufacturing is the clearest case, because its IT and OT divide is the oldest and deepest, this is not only a manufacturing problem. Utilities, healthcare, transportation, and any other sector where an operational environment grew up separately from the enterprise back office are standing at a version of the same fork. Manufacturing just happens to be standing closest.
The Window
Manufacturing did not choose the IT and OT divide the first time. It formed quietly, over decades, while everyone was busy solving their own problems, and the sector has been dealing with it ever since. That is what makes this moment different. This time, the divide is not sneaking up on anyone. You can watch it forming in real time, one AI pilot at a time, on both sides of a line that does not have to be redrawn.
The experts who say keep OT AI isolated are protecting something real, and they deserve to be heard. But they are answering the wrong question. The answer is not to wall the plant floor off again. It is to govern AI globally and enforce it locally, using an operating model many global enterprises already trust to decentrally run their operations across different regions.
Charter one Program. Seat both worlds at the table. Write the rules once, while the ink is still wet.
If your organization is working through where to start, the Advisory team at TrustedSec performs this kind of bridging work between Security, the Business, IT, and OT, and welcomes these conversations. If you'd like to talk to an expert, get in touch with us.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.