Progressive scaling of automation as the system earns trust — from augmented analytics to closed-loop resilience.
* This model is static — awaiting federal guidance from the NIST AI Agent Standards Initiative (launched Feb 2026) and NCCoE Agent Identity & Authorization Framework. Once published, the maturity model will be updated to incorporate agent identity governance and federal control overlay requirements.
AOT cannot succeed without organizational capacity to sustain it. Every framework (ISA/IEC 62443-2-1, NIST 800-82r3) assumes organizational readiness — but most programs fail because they deploy technology without the people to operate it. Phase 0 audits whether the organization has the roles, competencies, and change management infrastructure to run AOT before any software ships. This work runs in parallel with the technical architecture assessment — you can't design what you can't staff, and you can't staff what you haven't designed.
AOT Operator (maps to existing Control Room Operator / SCADA Technician): Interprets AI-generated alerts, executes containment playbooks, monitors the AOT dashboard during incidents. Must understand both the physical process and the network topology.
Macro Custodian (maps to existing I&C Engineer / OT Security Analyst): Writes, tests, and signs off on containment macros. Must understand plant process safety, the network fabric, and the MOC process. Minimum 2 years OT engineering experience required.
Security Lead (maps to OT Security Analyst / IT Security Manager): Oversees AOT deployment, manages promotion gates, coordinates third-party audits. Acts as the bridge between corporate security and plant operations.
Executive Sponsor (maps to Plant Manager / VP Operations): Organizational commitment, resolves cross-departmental conflicts, approves MOC submissions. Must be a VP-level decision-maker, not a middle manager.
IT/OT Liaison: The single most critical missing role in OT programs. Translates corporate IT security policy to OT reality and vice versa. Without this person, AOT will be blocked by IT security policies that don't understand OT constraints, or OT engineers who don't understand security requirements.
Process Engineer Representative: Someone who understands the physical process being protected. A containment macro that isolates a network segment may also starve a reactor of cooling water — only this person knows the difference.
Items 10–12 (Regulatory, Vendor Plan, IT Dep Map) are addressed in the AOT Implementation Guide, not Phase 0. See the Phase 0 Design Rationale for methodology.
Phase 0 gates are split into hard requirements (must pass before any AOT technology deploys) and soft requirements (remediation allowed, must resolve before Phase 2). This prevents the common failure mode of deploying tools without the people to operate them — while not paralyzing organizations that are close but not perfect.
⏱️ Typical duration: 1-4 weeks for small/medium facilities with existing OT security programs. 3-12 months for large organizations requiring procurement cycles, HR approvals, or union negotiations. This phase runs in parallel with the technical architecture design.
The system observes, correlates, and explains. The human does everything else.
Translates multi-tool alerts into natural language telemetry. Suggests playbook options from the pre-approved macro library.
100% In-the-Loop. Manual copy, paste, and execution of playbooks. The human is the decision-maker and executor at every step.
The system generates tailored scripts. The human approves with a single click.
Generates localized, pre-validated containment scripts specific to the threat, zone, and operational context. Scripts are assembled from the pre-approved macro library.
In-the-Loop. Reviews proposed scripts with full context (affected assets, expected outcome, rollback path). Single-click "Approve & Execute."
The system acts at machine speed. The human watches with a kill-switch.
Instantly shoots pre-configured playbooks to the Enforcement Gate. No human approval required — the system acts within strictly defined safety boundaries.
On-the-Loop. Real-time visibility with a 5-second human veto kill-switch. The operator supervises, not executes.
The system defends itself. The human recovers and reviews.
Runs continuous parallel simulations to optimize defense postures. Full machine-speed containment within strictly defined safety boundaries. Generates forensic reports post-incident.
By-Exception. Notified only when the system encounters unknown scenarios. Primary responsibility: post-incident recovery, forensic review, and system tuning.
| Transition | Minimum Duration | Key Gate |
|---|---|---|
| Phase 0 → Phase 1 | 1 week – 12 months | 9-point assessment passed, evidence documented, commitment confirmed |
| Phase 1 → Phase 2 | 90 days | 85% concordance, 20+ macros |
| Phase 2 → Phase 3 | 180 days | 95% approval rate, zero safety incidents |
| Phase 3 → Phase 4 | 365 days | Zero false positives, <2s containment, 3rd-party audit |
No phase can be skipped. Each promotion requires all criteria met AND all four Architectural Guardrails re-validated.