Control Room AI: What the Vendor Moves Mean for Deterministic Control

Major control-system vendors are rapidly integrating Artificial Intelligence (AI) into their platforms and, in a small but growing number of cases, into the control loop itself. For asset owner operators who run critical infrastructure, this is a significant opportunity. However, it arrives with a tension that goes to the heart of how control rooms are required to operate.

AI is approaching the control loop

For most of their history, industrial control systems have done exactly what they were engineered to do, no more and no less. That is changing. Over the past year, AI has moved from the edges of the control room toward its centre, and the vendors have made the first move.

Honeywell, Yokogawa, Siemens, Schneider Electric, ABB, AVEVA and GE Vernova have all announced AI capabilities across their Distributed Control System (DCS) and Supervisory Control and Data Acquisition (SCADA) ecosystems. These capabilities span engineering tools, operator-support applications, historians and asset-performance platforms and, increasingly, the control layer itself: the very platforms that run our electricity grids, transport networks, water and gas pipelines.

I have spent my career across seven of the eleven sectors regulated under Australia’s Security of Critical Infrastructure (SOCI) Act, from healthcare and defence to logistics and energy, and I can count on one hand the platform shifts of this scale. The adoption decisions taken now to implement these features will shape control room operations for the next decade and longer.

For members of the Australian Control Room Network Association (ACRNA), debating and refining how these shifts are implemented is central to our pursuit of control room best practice.

 

Not all industrial AI is the same

Reading the wave of recent vendor announcements, you’d be forgiven for thinking these are similar AI features being added to different vendor products. In fact, for control-room purposes the vendor offerings can usefully be grouped into three operational classes, sitting at different distances from the engineering control loop.

First: generative engineering assistance

This is the Large Language Model (LLM) class behind Siemens Industrial Copilot, Schneider Electric Industrial Copilot, and the copilot capability in ABB’s Genix suite, all built on Microsoft AI infrastructure. Today it is mostly applied at the engineering layer: generating candidate control code for engineering review, configuring displays, searching documentation and troubleshooting in natural language. It works upstream of live industrial controls, in the engineering and configuration environment.

OPPORTUNITY – encoded operator knowledge: preserving procedures, operating history and expert heuristics, validated by the experienced operators who hold them, which could help offset the workforce attrition many asset owners are already feeling.

Second: predictive operator support

This is the prediction class. Honeywell’s Experion® Operations Assistant, GE Vernova’s SmartSignal and Proficy CSense, and AVEVA’s industrial analytics built on the PI System all belong in this category. These are statistical models trained on the asset’s history to forecast alarms, detect anomalies and flag developing equipment issues. In vendor-reported pilots, Honeywell’s assistant surfaced predictions five to ten minutes before the associated alarm incidents were expected to occur. These systems advise the operator and sit alongside the control loop.

OPPORTUNITY – predictive operational awareness: identifying developing abnormal conditions before established alarm limits are reached, while preserving the validated alarm system as the authority layer.

Third: AI-enabled closed-loop control

Yokogawa’s Factorial Kernel Dynamic Policy Programming (FKDPP) uses reinforcement learning to control industrial processes directly. In field testing it controlled a complex distillation process autonomously for 35 consecutive days, and it has since been approved for production use at an ENEOS Materials chemical plant in Japan. Honeywell is moving in the same direction: its recently announced Experion Cognition platform is being evaluated for autonomous operational decision-making, including automated corrective actions, through a proof of concept with Borouge International (chemicals and packaging manufacturing). This class sits inside the engineering control loop itself.

OPPORTUNITY – a staged path to autonomy: automating routine, well-understood responses so human attention is reserved for situations that really need it. In the Australian energy sector, some Distribution Network Service Providers (DNSPs) already run a working example; Fault Location, Isolation and Service Restoration (FLISR) schemes locate a network fault, isolate the affected section and restore supply to surrounding customers in under a minute. Notably, FLISR is deterministic, rule-based automation rather than AI, which sets the benchmark any AI-enabled closed-loop control offering will have to meet.

The closer to control, the higher the assurance bar

A control room that runs critical infrastructure depends on control behaviour that is predictable, bounded, testable and traceable. The foundation of alarm philosophy, safety cases and the assurance that an asset will behave as designed, including how it fails. But all three AI classes are learned from data rather than specified through an inspectable ruleset, and each carries that tension differently. For AI to enter closed-loop control this bar is a significant barrier, as AI policy is far less inspectable than a conventional Proportional-Integral-Derivative (PID) loop or interlock and harder to demonstrate across every credible operating condition.

The rule is simple: the closer to control, the higher the assurance bar. Engineering copilots sit furthest from live assets, where a wrong answer costs review time; predictive assistants sit at the operator’s elbow; AI-enabled control sits inside the loop, where the output moves the asset. The loop is already being entered, led today by reinforcement learning rather than generative AI, even as boards press to introduce AI for efficiency and rapid decision-making.

The practical question for boards and executives is not whether to adopt AI, but what to require before each capability is approved. Five questions cover most of the ground:

  1. Where does the AI sit?

Engineering support, operator advice, supervisory control, closed-loop control or safety protection: the answer sets the assurance bar for everything that follows.

  1. What authority does it have?

Read-only, recommendation, operator-approved action or autonomous action.

  1. What remains independently protective?

Interlocks, protection systems, safety instrumented systems and hard operating limits must not depend on the AI being right.

  1. How is change controlled?

Model updates, retraining, prompt changes and vendor-managed services must pass through the same management-of-change disciplines as any other modification to a control system.

  1. Can the asset operate safely without it?

There must be a defined degraded mode, a rollback path and a maintained manual operating capability.

AI cyber assurance runs through every one of these questions, and it is broader than securing the model. The full inference chain matters: sensors, historians, contextual data, integration middleware, identity, cloud services, model versions, the operator interface and the final control-authority boundary. Industrial AI can introduce new cloud and vendor-access dependencies, supply-chain risks, and new failure modes when networks are isolated. Each is an assurance obligation to put to the vendor, not a footnote.

 

Lead adoption, don’t outsource judgement

If AI is already in use, identify where it sits relative to the control loop and strengthen assurance accordingly. If it is not yet in use, begin with bounded, measurable pilots outside safety-critical control.

Twenty years ago, when I was working at British Telecommunications in the UK, there’d occasionally be a JFDI (just f-ing do it). Those weren’t times for questions. Thankfully leadership language has (mostly) moved on, but the pressure is familiar. Boards are rightly asking how AI will improve asset efficiency, workforce capability and resource allocation. The danger is that pressure to show momentum collapses several very different technologies into a single instruction: deploy AI.

Given this, I believe the best approach is to lead from the front, on our terms, and work out how to do it safely.

That starts with holding a hard line on where the boundary sits between advisory and control and treating Human-Machine Interface (HMI) design, alarm philosophy and operator competency as first-order design questions from day one. It means demanding cyber assurance and explainability from vendors, applying non-deterministic AI where it suits, and keeping deterministic, engineered automation for direct control. Safety functions must remain independently engineered, validated and protected, and human oversight must be meaningful, with the time, information and authority to challenge or override AI-supported decisions.

 

A nominal approval button is not a safety case.

 

Above all, it means bringing operators along: they are the people who will have to trust, question and, when necessary, override the system.

For critical infrastructure leaders, ACRNA and its members, this is exactly the kind of challenge the association exists to work through together. The vendors have made their move. Our task is to capitalise on the opportunity, plan rollouts well, and protect the deterministic control that critical infrastructure depends on.

Keeping modern society’s services running and, above all, safe.

 

Sam Mackenzie

VP – ACRNA

Make sure to attend the 2026 ACRNA Conference featuring our first AI Workshop. Register now…