The Networks Are Converging. The Priorities Are Not.
IT and OT networks are converging at the infrastructure layer. The governance frameworks, compliance obligations, and accountability structures that govern them are not. In critical infrastructure, that tension is intentional — and the arrival of cloud and AI is forcing the question of where digital decisions become operational consequences.
Disclaimer: The views expressed in this article are the author's own and are based on publicly available information. This content is intended for informational purposes and does not constitute legal, regulatory, or compliance advice.
Dominique West published thought leadership on IT/OT convergence that named me as an influence, and I have been thinking about it since.
Her core observation is sound. When ownership of risk is assumed instead of assigned, it disappears.
I want to add the structural reality behind that challenge.
The goal is not to merge IT and OT into a single function and declare the ownership problem solved.
In critical infrastructure, these domains are kept distinct by design.
The work is not erasing the line between them. It is knowing exactly where that line sits and who stands on each side of it.
Different mandates, different reporting lines
In many sectors, IT and OT functions can be brought under a common accountable leader with relatively little disruption. In power utilities, that is rarely how the operating model has evolved.
IT usually reports to the CIO or CTO.
OT frequently reports to the COO or CCO, and in a growing number of cases to the CISO.
Those are not arbitrary lines. They reflect two different mandates. One protects information. The other keeps the physical system stable and keeps people alive.
The separation runs deeper than reporting structure. Strict network segmentation has historically required IT and OT to operate as distinct environments, with different operational priorities, security models, and compliance obligations.
IT compliance tends to organize around SOX IT General Controls, payment security requirements such as PCI DSS for customer payment environments, federal and state level privacy obligations, and enterprise third-party risk management.
OT answers to NERC CIP, ISA/IEC 62443 for industrial control systems, and in the nuclear fleet to NEI 08-09 under the NRC cybersecurity rule.
Different frameworks. Different auditors. Different accountable leaders. Different muscle memory.
The CIA triad does not weigh the same in both environments
These differences are not accidental. Put in CIA triad terms, both environments value confidentiality, integrity, and availability, but the weighting is different.
In many IT environments, confidentiality and integrity often drive risk decisions. In OT environments, availability and integrity are frequently inseparable from safety and public impact.
When availability is tied directly to public safety, it cannot be traded away the way it can in a data platform. That is not a maturity gap. That is physics.
The friction shows up when newer technologies such as cloud, AI, and computationally intensive workloads begin crossing these historically separated domains.
So when people say convergence, I pause on the word. The networks are converging. The priorities are not.
And in critical infrastructure, that tension is intentional because the consequences of failure are different. Keeping the disciplines distinct is a deliberate design choice, not an oversight.
The accountability map matters more than the org chart
This is why the accountability map matters more than the org chart. Name, in writing, who owns each failure scenario across two operating domains that will and should remain distinct.
Convergence at the network layer without a matching accountability map is how you build a control interface that everyone can reach and no one owns.
Which raises the bigger question underneath all of this. The governance challenge is not where IT ends and OT begins.
Where is the boundary where digital decisions become operational consequences?
Nothing tests that boundary harder than cloud and AI. Both are reshaping assumptions that have long underpinned OT governance.
Ampyx CEO Patrick Miller has an excellent breakdown in his latest post Cloud Comes to NERC CIP: The 100-Series and Project 2023-09.
Meanwhile, I have been tracking the AI side of that evolution in my writing on FERC's move on computational load integration. Changes in computational demand, such as scaling AI workloads from inference to training, are becoming factors that grid planners and regulators must account for.
AI governance and grid reliability are converging on the same reality: digital decisions can create physical consequences.
CIP-004 and the AI governance layer
Dominique makes the case that the human layer is where governance quietly fails. She is spot on.
CIP-004 is the standard that has carried that weight for years. It covers personnel risk, access management, and the training that decides whether the person closest to the machine understands what they are looking at.
Autonomy does not retire that standard. It stretches it.
So here is the AI governance layer I would add alongside CIP-004, framed as questions worth asking before an incident asks them for you:
Does your training program teach operators what an autonomous system is permitted to do on its own, and how to recognize when it has acted outside those bounds? Awareness written for phishing and badge discipline does not prepare anyone to supervise a system that moves faster than they do.
When an autonomous system takes an action, under whose authority does it act? CIP-004 was designed around the human role in protecting cyber systems. An AI system acting on an operator's behalf is a non-human actor operating inside a historically human-centered accountability model, and most programs have not decided whether that is even in scope.
Who is the named, trained human accountable for each autonomous decision, and are they close enough to the physical process to intervene in time? If that person does not exist on paper before the event, they will not exist during it.
Building accountability across the boundary
The future of AI governance in critical infrastructure will not be defined by choosing between IT governance and OT governance. It will be defined by building accountability across the boundary where the two meet.
I have learned a great deal from Dominique's work on AI governance, and this series is some of the clearest thinking on the subject I have read.
I am building on her piece because that is what strong work invites, more of it.
Read the full CISO Blueprint series, then take these questions into your own environment.
The organizations that answer these questions before autonomy scales will be in a far better position than those answering them after an incident.
Originally published on LinkedIn Pulse, July 23, 2026.