New research from Forescout’s Vedere Labs has demonstrated how artificial intelligence could begin to lower the barriers to developing sophisticated cyberattacks against industrial systems.
The research set out to answer a potentially important question for operational technology (OT) security: can AI successfully adapt a remote code execution (RCE) exploit developed for one programmable logic controller (PLC) so that it works against another?
Researchers tested this by using AI to help port an existing RCE exploit between two WAGO PLC models. The experiment was ultimately successful, demonstrating that AI can assist with highly specialised exploit development in embedded environments.
However, the results also showed that AI is not yet capable of doing this independently.
AI still needed significant human help
Throughout the experiment, researchers had to guide the AI through false leads, incorrect assumptions and technical dead ends.
Developing the final exploit took eight hours and 32 minutes and consumed $535.74 in API tokens, highlighting the cost and human involvement still required.
Once reliable code execution had been achieved, however, the process accelerated considerably. AI was able to produce multiple working network payloads within minutes.
This difference is important. While AI may still struggle with the most complex stages of exploit development, it could rapidly automate subsequent stages once the initial technical barriers have been overcome.
The experiment also demonstrated the risks of allowing AI to operate against physical technology. When researchers attempted to develop a command-and-control implant, the PLC was permanently bricked.
What happens as AI improves?
The findings raise wider questions about the future security of industrial and critical infrastructure.
PLC exploitation requires specialist knowledge of hardware, firmware, architectures and industrial protocols, creating a relatively high technical barrier for attackers. AI could gradually begin to reduce that barrier.
As models become more capable, the time, expertise and cost required to adapt an existing exploit across families of related industrial devices could fall significantly.
That could also change how organisations assess vulnerabilities. A weakness considered difficult or expensive to exploit today may become considerably more accessible as AI-assisted offensive capabilities improve.
For critical infrastructure operators, the bigger question is therefore not whether AI can autonomously develop sophisticated PLC attacks today. Forescout’s experiment shows that it cannot yet do so reliably.
Instead, organisations need to consider what happens when increasingly autonomous exploit development meets large numbers of exposed industrial devices and the technical barriers protecting them begin to disappear.
Read the full Forescout Vedere Labs research here.

