Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/book/ This episode: https://protectitallpod.com/ep123/ The OT Security Starter Kit: https://protectitallpod.com/starter-kit/ AI is a consensus engine, and consensus on the internet is frequently wrong. So what does that mean for the people defending power plants, water systems, and factories with it? In this episode of Protect It All, host Aaron Crow welcomes back Jori VanAntwerp, CEO and founder of EmberOT, for a completely unscripted conversation on AI in OT. Two practitioners who use AI aggressively every day make the case for restraint in exactly the places that matter. Jori explains why human in the loop is non-negotiable: AI shapes a junior's output to look senior without the understanding underneath, so you have to be able to interrogate it. Aaron walks through his own sandbox discipline, where AI gets a folder and not the keys, and nothing goes in that he would not publish on the internet. The conversation then turns to the OT reality behind AI-found vulnerabilities, why an attacker who can reach your HMI or PLC does not need your unpatched CVE, teaching AI your voice with markdown primers, the build-versus-buy MVP trap, the submarine principle for modular defense, and why an operator flipping to manual is still the save of last resort. Underneath all of it is the workforce math nobody is doing on air: if one person plus AI does the work of five, nobody is training juniors, and no juniors today means no seniors in ten years. OT's aging-out workforce is the preview. In this episode, you'll learn: Why AI is a consensus engine, and why that framing predicts where it fails Why human in the loop is not optional for anything that matters How to sandbox AI in real workflows: a folder, not the keys How to rank AI-found vulnerabilities against what an attacker in your OT network can actually do How primers teach AI your voice, brand, and rules The build versus buy trap: if a power company builds its own software, it is now a software company The submarine principle: compartments, modular tooling, and swapping tools without ripping out the estate Why analog fallbacks and operators keep saving critical infrastructure The junior pipeline problem: no juniors today means no seniors in ten years Why the entry-level job for OT cybersecurity is IT Tune in for the most honest AI conversation the show has had, from the people who actually run it in OT. About the guest: Jori VanAntwerp is a two-time cybersecurity founder and CEO who has spent over two decades helping industrial and IT/OT organizations reduce risk, strengthen compliance, and mature the way they defend critical infrastructure. He has held executive and leadership roles at McAfee, FireEye, CrowdStrike, Dragos, and Gravwell before stepping into the founder seat, first at SynSaber and now as the Founder and CEO at EmberOT. The result is a vantage point that runs from the boardroom to the packet capture, from silicon to the cloud. At EmberOT, he is focused on bringing visibility, security, and risk quantification to the critical infrastructure the rest of the world takes for granted. From EmberOT: Want to see what is really happening in your OT environment? EmberOT provides flow-first, passive OT visibility and threat detection without requiring proprietary hardware. Learn more about EmberOT...