OT security architecture diagram: cameras and an edge appliance inside an air-gapped dashed boundary with only minimal outbound events and no inbound connections, cloud optional

The OT Security Question: Adding Safety AI Without Exposing Your Operations

There is a version of the safety-AI conversation that goes well right up until it reaches the security team, and then stops. The safety case is strong, operations are on board, and then someone asks a plain question. What exactly are we connecting to our network, and what leaves the site? If the vendor's answer involves streaming live operational video to their cloud, the review ends there, and it should.

This guide is for the operations and security leaders who own that review. It explains what OT security teams legitimately worry about when safety AI meets operational technology, and the design that lets you say yes without weakening the environment.

Why this is an OT problem, not an IT one

In an oil and gas facility, the cameras and the systems around them sit close to operational technology, or OT: the control systems, sensors and networks that run the physical process. OT security is a different discipline from ordinary corporate IT security, and it has a different order of priorities.

In IT, confidentiality usually comes first. In OT, the availability and integrity of the physical process come first, because a compromise there does not leak a spreadsheet. It can stop or endanger a live operation. That reordering is why OT security teams are cautious, and why they are right to be. Anything that touches the operational environment is a possible path to the one thing that must never be disturbed. A safety system that watches the operation is, by its nature, close to that environment, so the security review is not red tape. It is the correct response to a real risk.

What the security team worries about

Four questions sit under most OT reviews of a safety-AI system.

The first is what you are connecting, and which way data flows. Every new component on or near the OT network is new attack surface. The reviewer wants to know what the system talks to, and whether connections reach inbound into the environment, which is risky, or stay strictly outbound and limited.

The second is what leaves the site, and where it goes. Operational video is sensitive. It can reveal process details, staffing, layout and weak points. A system that ships raw footage off-site, especially to a third-party cloud, creates both a confidentiality exposure and a dependency on someone else's security.

The third is what happens when connectivity drops. If the safety function depends on a live link to the cloud, then a network problem becomes a safety problem. OT environments value systems that keep working when they are isolated.

The fourth is whether it can run in the most restrictive setting. The most security-critical sites are air-gapped, deliberately cut off from external networks. A system that cannot run without cloud connectivity cannot be deployed there at all.

Checklist mapping the four OT security questions to their architecture answers: on-site inference, raw video stays local, air-gap capable, outbound-only minimal data
Checklist mapping the four OT security questions to their architecture answers: on-site inference, raw video stays local, air-gap capable, outbound-only minimal data

The design that passes review

A safety-AI system built for OT environments answers those worries through its architecture, not through promises. A few properties define the pattern.

Inference runs on-site, on an edge appliance. The video is taken in and analysed locally, so the intelligence lives where the cameras are rather than in a distant cloud. Detection does not depend on an external link, and the sensitive video does not need to travel anywhere to be useful.

Raw video never leaves the network by default. This is the single most important property. Footage stays on the operator's own infrastructure. What syncs outward, if anything, is limited to structured events, metadata and specifically consented evidence clips, and only where the operator allows it. The reviewer's hardest question, whether operational video goes to the vendor's cloud, gets a clear answer: no, not by default, and not without your explicit say-so.

It can run fully air-gapped. For the most restrictive sites, the system works with no external connectivity at all, with inference, review and record keeping all happening locally. The cloud becomes an optional convenience for dashboards and fleet management at less restrictive sites, never a requirement for the safety function.

Data flow is outbound and minimal. No inbound connections into the OT environment, and only limited, outbound, operator-approved sync of events. Least privilege, applied to the network path.

It also makes for better safety

The architecture that satisfies OT security happens to be the architecture that works in the field. Edge inference that survives a dropped link is both more secure and more reliable at a remote site. Keeping raw video local cuts both your attack surface and your bandwidth cost. The security-driven design and the reliability-driven design point at the same answer, which is usually a sign the answer is right rather than a compromise.

There is a workforce-trust dimension too. A system that keeps operational and personal video on-site, and treats worker identity as something people consent to rather than something they are subjected to, is easier to defend to the security team, to the workforce and to their representatives. Security and trust point the same way.

Questions to put to any vendor

Before a safety-AI system goes anywhere near your OT environment, ask a few direct questions. Where does inference run, on-site or in your cloud? Does raw operational video ever leave our network, and under what conditions? Can the system run fully air-gapped, with no external connectivity? Are there any inbound connections into our environment, where the answer you want is none? And exactly what data syncs outward, and can we control and inspect it? The answers separate systems designed for industrial reality from systems designed for connected corporate settings and hopefully adapted afterward.

Where deployments live or die

The OT security review is where safety-AI deployments live or die, and rightly so, because nothing should touch the operational environment without earning it. The good news is that the design which passes a serious review is not a stripped-down compromise. It is the stronger design. On-site inference, raw video that stays on the network by default, full air-gap capability and minimal outbound data give you a system that is both safer to connect and more reliable to run. When security and operations are both asking the hard questions, the right system is the one whose answers make the questions go away.


MilkenLabs runs inference on-site, keeps raw video on the operator's network by default, and supports fully air-gapped deployment, built for cautious OT security reviews from the start. Explore capabilities or request a demo.