
AI is designed to solve problems, but that problem solving doesn’t always happen in the way we humans might expect. For manufacturers and industrial companies exploring how to use AI to improve software development, productivity and operations, this can become a serious IT security issue.
That unpredictability stems from the way AI approaches a task. When given a goal, AI models don’t necessarily approach it using the process a human would. If it identifies a faster or easier path to the desired result, it may instead pursue a route that its developers never intended for it to access.
Over the last few months, we’ve seen a rash of advanced AI models autonomously breaking out of isolated testing environments and using cyberattack capabilities to solve the problems posed to them by their developers.
One OpenAI model recently escaped its sandbox to compromise Hugging Face production servers to solve a hacking problem it has been assigned, while another agent was able to infiltrate the Australian Healthcare System’s Medicare portal. A Google Gemini model breached three corporate networks by guessing passwords and scraping repositories, and models from both Anthropic and Meta were able to override environment controls and resist shutdown commands during third-party testing.
AI security is not a singular problem that can be solved by a blanket solution, but by a series of potential failure points that need to be addressed along the way. So how should manufacturers prepare for the future of AI advancement? Here are three key considerations.
1. Start with the Basics
The Open Worldwide Application Security Project (OSWAP) is a good place for manufacturers to get a grip on the basics of cybersecurity best practices. The nonprofit organization, which is dedicated to improving software security through open-source projects, global communities and education, has developed a framework for companies looking to establish a baseline for managing their tech environments in the age of AI, and according to OSWAP, the fundamentals still matter most.
As a first step, companies should review which of their systems are connected to the internet, and consider which actually need to be online to work most efficiently. If a system does not require internet access to function properly, it shouldn’t be online. Remember: for AI hackers, every open connection is a potential entry point.
The next step is to look at system permissions. Every system, application and user should have access to the specific things they need to do their jobs. If a user requires access to multiple systems, it is imperative to ban the reuse of passwords and usernames across systems. In the Hugging Face incident, for example, shared credentials across different environments were one of the issues that allowed the attack to happen.
Think of these controls as individual links in an “attack kill chain.” To reach a critical system, an AI-enabled attack must find an internet-facing system, gain access, obtain the necessary permissions and move through the network in a series of complex and connected steps.
Manufacturers do not have to stop the attack at the first step. Breaking any link in that chain can prevent a hacker, whether AI or not, from reaching its ultimate target.
Patching is another important part of the process. As new vulnerabilities are discovered, immediately addressing and patching these issues can prevent AI hackers from exploiting them down the line.
2. Know What Your AI Systems Are Doing
While much of the usefulness of AI comes from a model or agent’s ability to autonomously act, manufacturers incorporating AI into their workflows must pay close attention to what those models are actively doing inside their systems.
With traditional software, it’s easy understand how a software is behaving and what actions it’s taking. But with AI, it can be difficult to have that same level of visibility into how or why any given action is made, or what they can do inside a company’s technology environment.
That makes observability, or the ability to monitor what an AI system is doing inside an environment, increasingly important. Manufacturers should have tools and controls in place that allow their technology teams to monitor system activity, even to the point of reviewing chain of thought reasoning in agentic workflows, then establish what normal behavior looks like and flag unexpected actions for review.
Before giving an AI system additional access, companies need to understand not only what that access is intended to enable, but what else the system could potentially reach or do with it.
AI itself can play a role in providing that visibility. Security tools can monitor activity over time and identify behavior that falls outside established patterns. If an employee or system suddenly begins accessing applications, files or network resources they don’t normally use, AI-powered security tools can flag that activity before it progresses further.
3. Calculate the Risk
While larger companies generally have security practices and budgets built into their operations, smaller businesses may not have much digital infrastructure needed to incorporate AI tools and defense systems into their workflows.
That gap is especially common for middle-market manufacturers. It’s common for a company to have digitized significant parts of its operation while still relying on aging ERP systems, legacy infrastructure or technology that was implemented long before AI-enabled threats entered the equation.
While it can be a challenge to ask your CFO for a significant increase in the technology budget to defend against a risk that may or may not materialize, the crucial question to bring up in these conversations is this: What would happen if our operations couldn’t run for a month?
The consequences of a hack can extend far beyond lost production, impacting customer relationships, delaying orders, damaging a company’s reputation or even disrupting a pending transaction.
Importantly, the goal is not to eliminate every possible risk, but to ensure your company is not an easy target. Even baseline controls can eliminate the vulnerabilities that automated tools and human hackers alike are most likely to exploit. When budgets are tight, companies should focus resources on the risks that could cause the greatest operational damage.
Security practices surrounding AI usage and integration need to mature alongside a company’s technology. Manufacturers that understand where their systems are exposed, limit unnecessary access, monitor how AI is behaving and continually reassess their risk of an attack can better take advantage of what AI can offer without creating vulnerabilities that threaten the rest of the business.






















