Cybersecurity
AI changed vulnerability discovery: but there is an OT gap you cannot ignore
New AI models discover vulnerabilities autonomously and at industrial scale. But the tools stay tuned for IT: the OT world risks falling behind just as attackers accelerate.

Automated vulnerability discovery has just taken a generational leap. The latest AI models no longer merely suggest where to look: they find unknown flaws on their own, reproduce exploits, and do it at a scale that until yesterday required entire teams of researchers. That is good news for defenders. But there is a gap the industrial sector cannot afford to ignore.
What actually changed
Recent announcements are clear. The new systems reach success rates around 83% on vulnerability-reproduction benchmarks, discover zero-days autonomously on widely used operating systems and browsers, and in one case identified a bug that had stayed hidden in OpenBSD for 27 years.
The point is not the individual number, but the paradigm shift: vulnerability discovery is becoming industrialized. When a capability like this scales, it scales for everyone.
The gap: these tools speak IT, not OT
The initiatives deploying these models today focus on operating systems, browsers, cloud platforms, and open source software. All areas where patching is an established practice and remediation can be fast.
The OT/ICS world runs by different rules:
| Dimension | IT | OT/ICS |
|---|---|---|
| Patching | standard updates | requires planned downtime, often impractical |
| Consequences | digital only | physical-world impact |
| Hardware | x86 with standard OS | PLCs with proprietary and legacy protocols |
| Protocols | modern standards | Modbus, DNP3, EtherNet/IP, IEC 61850 |
| Access | software only | often requires physical interaction with the hardware |
Assessing an OT vulnerability does not just mean understanding the software: it means understanding how the hardware interacts with the physical world. That is domain expertise the tools designed for IT do not have.
The dual-use risk
Any technology that industrializes vulnerability discovery benefits both defenders and attackers. Whoever is already equipped to act on the results gains an asymmetric advantage.
For critical infrastructure the imbalance is concrete: if attackers acquire AI-enhanced discovery capabilities while OT defenders lack tools tuned to their own environment, the risk grows exactly where the consequences are most severe.
Why remediation in OT is a different craft
A vulnerability found in a SCADA system or a safety instrumented system is not closed with an update. You have to reason about:
- the blast radius of a potential exploit
- which compensating controls already exist in the field
- how to intervene without stopping production or compromising functional safety
These considerations are absent from standard IT workflows, but decisive in an industrial environment.
What is needed now
OT and critical infrastructure security cannot be an afterthought to where this technology is heading.
The direction is clear: bring OT expertise into the design of these tools, not bolt it on afterwards. Industrial defenders need capabilities calibrated to the specific, unforgiving environments they operate in, where unexpected behavior is not acceptable and where the physical world is always downstream of the digital one.
The MON5 point of view
This is exactly the ground we work on. Visibility into OT assets, the correlation of vulnerabilities with the real plant context, and anomaly monitoring without stopping production are the prerequisites for turning the power of AI into concrete defense, including for those who run industrial networks.
AI has changed vulnerability discovery forever. What remains to be decided is whether the industry will leave OT a step behind or put it at the center.
Analysis and commentary by MON5 based on public-domain research and data from the OT/ICS sector.
Related articles

Cybersecurity
CODESYS Under Attack: Three Chained Flaws to Plant a Backdoor in a PLC
Three chained CVEs in the CODESYS Control runtime let a Service user replace the PLC application with a backdoored version and run code as root.
Cybersecurity
Firmware Tampering in Field Devices: How It Happens and How to Detect It
The firmware in OT field devices is a prime target for persistent, hard-to-detect attacks. How tampering happens, why it is so insidious and what countermeasures exist.

Cybersecurity
Vulnerabilities in Industrial Protocols: Modbus, DNP3, OPC UA, and the Hidden Risks
Modbus, DNP3, OPC UA, and PROFINET underpin industrial communications. Designed for reliability in closed networks, they carry intrinsic vulnerabilities that become critical in increasingly connected environments.
Do you have visibility into your OT network?
MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.