A joint advisory from the NSA, CISA, FBI and other US agencies warns that attackers are using artificial intelligence to build exploit scripts for Siemens S7 programmable logic controllers. The agencies state this approach drastically cuts the skill level and time needed to target industrial control systems. AI enables adversaries to rapidly find exposed devices and adapt to defensive measures without deep technical expertise. Affected sectors include energy, water, chemical and manufacturing operations. The advisory classifies this as an active threat and notes that any PLC exposed to the internet faces high risk. While UK simulations by the AI Safety Institute show models failing to hack operational technology on their own, the failure occurred at the IT systems in front of the devices rather than the hardware itself.
The shift lowers the barrier for malicious actors to compromise critical infrastructure previously considered secure from unskilled threats. Defenders must now assume that automated tools can generate working exploits faster than human analysts can patch vulnerabilities. Public information about weaknesses is being weaponised instantly by AI models.
- Targeted devices include Siemens S7 programmable logic controllers.
- US agencies classify the threat as active and ongoing.
- UK tests show AI models struggle with IT layers before reaching OT hardware.




