Free download · PDF · 8 pages

AI in the control room: a buyer’s checklist

36 plain questions to ask before AI touches your operational technology. Based on the December 2025 joint guidance on AI in OT from Australia’s ACSC, the US CISA and seven partner agencies. Free, with no sign-up.

Cover of the free ozari.ai buyer's checklist, AI in the control room

What is inside

Four principles, 36 questions

Each question says why it matters and what evidence to ask for. Mark each one yes, partly or no, then add up your score.

Principle 1

Understand the AI

Know what the AI is, how it can fail, and whether your people can run the network without it.

“Can our people run the network with the AI switched off?”

7 questions

Principle 2

Decide if AI belongs here

Check the business case, your data, the vendor and how the AI connects to OT.

“Can the AI change setpoints or issue commands? If so, where does a person approve?”

12 questions

Principle 3

Govern and prove it

Give the AI an owner, fit it into your security framework, and test it before it goes live.

“When a model changes, who approves it, and can we roll back?”

9 questions

Principle 4

Keep people in charge

Watch the AI in service, keep a person in the decision, and plan for its failure.

“How does it fail? Can it be bypassed without disrupting operations?”

8 questions

Red flags

Stop and ask again if you hear any of these

The checklist ends with eight warning signs. They are the quickest way to spot AI that is not ready for a control room.

  • The AI can issue commands, and nobody can show you where a person approves.
  • It needs a permanent internet or vendor cloud connection to work.
  • The vendor will not say where your data goes, or whether models train on it.
  • There is no way to switch the AI off, and no tested plan for running without it.
  • Advice arrives without a confidence level or reasons.
  • Model updates arrive silently, with no approval and no way back.
  • Test results are claims, with no method, date or environment.
  • “Certified” turns out to mean self-declared.

Why we wrote it

Hold every vendor to the same standard, including us

We build AI for control rooms, so we know which of these questions are hard to answer. We wrote the checklist so that buyers can compare vendors on evidence, not on claims.

It is our plain-English reading of public guidance, with some Australian context added. It is not the guidance itself, and no agency has reviewed or endorsed it. Read the source guidance.

Start safely

Begin with a read-only shadow pilot

Ozari runs beside your current systems, sees the same data and issues no commands. You measure the value with your own data before anything changes.

Secret Link