OT Security Brief
AI Agent Governance for Natural Gas Pipeline Operations
AI agent governance for natural gas pipeline operations requires assigning each AI agent a distinct, non-human identity, scoping its permissions to specific SCADA tags or commands, enforcing policy at runtime before any tool call executes, and logging every agent action in a tamper-evident record suitable for TSA and PHMSA reporting. No current TSA Security Directive or PHMSA regulation names AI agents explicitly, so operators must extend existing cybersecurity and safety frameworks to cover them.
Architectural Controls for Governing AI Agents at the IT/OT Boundary
Five interlocking controls define how AI agents should be identified, constrained, enforced, and audited as they operate near pipeline control systems.
- 1
Agent Identity and Credentialing
Each AI agent is issued a distinct, non-human identity separate from human operator accounts, enabling individual attribution of actions in logs.
- 2
Scoped, Task-Specific Permissions
Permissions are defined at the tag or command level rather than broad SCADA read/write access, consistent with least-privilege design.
- 3
Runtime Policy Enforcement
Enforcement points sit at or inside the IT/OT boundary and evaluate agent tool calls before execution, with stricter handling for any write or control-affecting action.
- 4
Tamper-Evident Audit Logging
Agent identity, actions taken, and data accessed are recorded in immutable logs sufficient to support regulatory incident reporting and safety investigations.
- 5
Network and Compute Segmentation
AI agent inference workloads remain isolated from safety-instrumented systems and core control networks, preserving existing segmentation boundaries.
Governance Requirements at the IT/OT Boundary
Four capabilities summarize what an agent governance architecture needs to provide before it is trusted near live SCADA systems.
Agent Identity
Distinct, revocable identity per agent, separate from human operator accounts.
Least-Privilege Access
Permissions scoped to specific tags, points, or commands, not system-wide access.
Runtime Policy Enforcement
Policy evaluation before tool calls reach SCADA systems, not after the fact.
Audit Logging
Immutable records of agent identity, action, and authorization for incident review.
Evaluation Criteria Before Deploying AI Agents in Pipeline Operations
Security and compliance teams should be able to answer each of the following before connecting an AI agent to live OT infrastructure.
- Can the platform issue and manage distinct, revocable identities and credentials for each AI agent operating in or near OT environments?
- Does the solution support tag-level or command-level permission scoping for SCADA/ICS interactions rather than broad system access?
- Can runtime policy enforcement block or require human approval for agent actions that would modify control system state, as distinct from read-only queries?
- Does the platform produce immutable, exportable audit logs suitable for TSA and PHMSA reporting and incident investigation requirements?
- What testing or validation process supports verifying agent behavior in non-production OT environments before connecting agents to live SCADA systems?
What AI Agent Governance Means in Pipeline Environments
Natural gas pipeline operators are introducing AI agents for predictive maintenance, leak detection, SCADA anomaly response, and compliance reporting. These agents consume data from OT historians and SCADA feeds, often in a read-only or advisory capacity, and generate outputs that inform or automate downstream decisions. Governance, in this context, is not a single control but a set of interlocking requirements: each agent needs a verifiable identity distinct from human operator accounts, permissions limited to the specific data or commands required for its task, a mechanism to evaluate and, where necessary, block its actions at the moment they occur, and a durable record of what the agent did and under what authorization. Without these elements, an organization cannot answer basic operational questions after an incident, such as which agent accessed which system, what action it attempted, and whether that action was authorized.
Why Pipeline SCADA Environments Change the Governance Calculus
Pipeline SCADA and ICS environments are built to prioritize availability and physical safety over confidentiality, which is the inverse of typical IT security assumptions. Governance controls introduced for AI agents must respect this priority: they cannot add latency to control loops, and they cannot permit unverified write actions to reach field devices. Existing IT/OT architectures commonly rely on demilitarized zones and one-way data flows, such as data diodes, to separate corporate networks from control networks. AI agent deployments are expected to operate within these established segmentation boundaries rather than bridge them. This also changes how permissions should be defined. Rather than granting an agent broad API or system-level access, tool calls into OT systems need to map to specific permitted tags, points, or commands, consistent with the narrower, task-bound nature of pipeline control interactions.
Regulatory Context: TSA, PHMSA, and the AI Agent Gap
TSA Security Directive Pipeline-2021-02, issued in 2021, requires critical pipeline owners and operators to report cybersecurity incidents to CISA and designate a Cybersecurity Coordinator. Subsequent revisions have moved toward performance-based requirements, including network segmentation between IT and OT systems. TSA and CISA also publish Pipeline Security Guidelines recommending security measures for control systems including SCADA, which are voluntary for operators not subject to a Security Directive. PHMSA regulates pipeline design, construction, and safe operation under 49 CFR Parts 192 and 195, but does not itself issue cybersecurity or AI-specific technical requirements.
| Framework | Scope relevant to AI agents |
|---|---|
| NIST AI Risk Management Framework | General AI risk identification and management practices, not pipeline-specific |
| NIST SP 800-82 Rev. 3 | OT security guidance applicable to control systems AI agents may interact with |
| NIST SP 800-207 | Zero Trust Architecture principles for identity and access boundaries |
| CISA Cross-Sector Cybersecurity Performance Goals | Baseline security practices referenced in pipeline guidance |
| API Standard 1164 | SCADA security practices for pipeline control systems |
None of these references AI agents by name. Operators must interpret and extend existing cybersecurity coordinator, incident reporting, and segmentation requirements, and align AI agent deployment documentation with existing TSA-required Cybersecurity Implementation Plans and Incident Response Plans, to bring agent-based systems under the same regulatory umbrella as other pipeline control assets.
Frequently Asked Questions
Do AI agents need credentials separate from human SCADA operators?
Yes. Distinct non-human identities for each agent, separate from human operator accounts, support individual attribution of actions in audit logs and allow permissions to be scoped and revoked independently of human access.
Can AI agents issue direct control commands to pipeline SCADA systems today?
Current deployments generally use AI agents in a read-only or advisory capacity against OT historians and data feeds. Any action that would modify control system state should pass through runtime policy enforcement and typically a human-in-the-loop checkpoint.
Does TSA or PHMSA directly regulate AI agents in pipeline operations?
Neither does so explicitly. TSA governs pipeline cybersecurity reporting and coordination, and PHMSA governs pipeline safety under 49 CFR Parts 192 and 195. Operators must map AI agent governance to both regimes rather than assume a single authority addresses agent-specific behavior.
Bring Runtime Governance to Your AI Agent Deployments
Before connecting AI agents to pipeline SCADA or OT systems, confirm identity, permission scoping, runtime enforcement, and audit logging are in place.
Request a Demo