The experiment
Forescout Research - Vedere Labs reported Sept. 1 that it used Claude Code and reverse-engineering tools to adapt a known remote-code-execution exploit from a WAGO 750-852 controller to a related 750-831 target. The test used a physical programmable logic controller and substantial researcher guidance; it was controlled research, not a reported customer compromise.[1,2,3]
Forescout says the final stage took eight hours and 32 minutes and consumed $535.74 in model API tokens for one exploit and one target. A later extension bricked the test PLC, turning an agent error into hardware damage. PLCs can coordinate industrial processes, so a failed experiment has a safety consequence even when no production asset is affected.[1,2]
The decision delta
That makes AI-assisted OT work part of the safety case, but not autonomous exploitation. SecurityWeek and Cybersecurity Dive describe extensive human oversight and target-specific dead ends. The test shows assistance around a known vulnerability, not a repeatable attack across controller families, a production compromise, or robot takeover.[1,2,3]
Operators should gate agent access to firmware and test hardware, preserve known-good recovery images, and require human approval before any action that can write to a physical target. The next catalyst is a repeatable result with less human steering or a confirmed field incident; until then, rollback and change control remain the measurable controls.[1,2,3]