Even Anthropic is worried about your substation.
The AI company published its Advanced AI Framework in June 2026 - a policy document ostensibly aimed at governing frontier AI development. Tucked inside Part 2, in a section on cyber resilience in the face of AI threats, is a set of recommendations that reads less like an AI policy brief and more like an OT (operational technology) security practitioner’s wish list. Three such recommendations stood out to our product teams:
1. Establish binding patch-deployment frequency for critical infrastructure operators
2. Fund operators to inventory and isolate systems that can no longer receive security updates
3. Build a strategic reserve of long-lead-time OT hardware (protective relays, RTUs, PLCs) for operators whose equipment could be rendered inoperable by a destructive attack
The recommendation to "isolate systems that can no longer receive security updates" is the most serious because:
1. It impacts most of the legacy OT equipment installed base
2. It’s calling for a return to what amounts to "air-gapping" OT networks.
But there is a way to isolate systems securely, while maintaining connectivity: with data diodes. Anthropic even names data diodes explicitly earlier in the same section, under prevention measures for under-resourced operators: “reducing internet exposure of operational technology (via data diodes).”
The Problem with “Just Isolate It”
End-of-life OT equipment is everywhere. You’ll find programmable logic controllers running firmware from 2009, SCADA systems that predate the iPhone and even historian servers on Windows Server 2008. These systems often cannot be patched as the vendor is gone, the support contract lapsed, or the update would require a production shutdown measured in days or weeks, not minutes.
The standard advice, sound in principle, is to isolate the system. Remove it from the network, break the attack path, and contain the blast radius. But in practice, “just isolate it” creates its own problems:
- Isolation without visibility is blindness to attacks. If your EOL historian goes dark because a threat actor has compromised it or is staging lateral movement, you won’t know until it’s too late. Operators who air-gap a system without ensuring they can still see the systems have traded one risk for another.
- Isolation without data flow breaks operations. Most OT systems that can’t be patched are still doing useful and sometimes critical work. They’re generating sensor readings, logging process data, feeding dashboards that operators rely on for analytics, status checks, compliance, and running the plant effectively. A hard network disconnection isolates the threat surface but also cuts off the operational data that keeps the lights on.
- Isolation without compliance evidence is an unverified claim. Auditors and regulators will ask for proof that a system is genuinely isolated, not just believed to be isolated. A firewall rule is software control. Software controls fail.
What Data Diodes Actually Do Here
A hardware-enforced unidirectional gateway (a data diode) is the security control that makes isolation operationally viable.
The physics is the point. Data diodes transmit in one direction only, enforced in hardware with optical isolation. There is no software configuration to misconfigure, no rule to bypass, no bidirectional channel to exploit. An attacker who compromises an external OT or IT network cannot pivot in through the data diode to a secured network.
OPSWAT delivers this protection through the MetaDefender Optical Diode™ which enforces one-way data transfer in purpose-built hardware designed for OT environments. The Optical Diode enforces unidirectional flow at the physical layer through fiber optic transmission: there is no return path because light does not flow backward through the medium. In environments where the consequence of a breach is measured in public safety terms, you need certainty, not probability.
Applied to Anthropic’s recommendation #2, this changes the calculus:
Isolation becomes “protect and observe” instead of “protect and ignore.”
You can run a data diode out of the EOL system, feeding logs, sensor telemetry, and event data to a SIEM (security information and event management) or OT monitoring platform. The system is effectively isolated; nothing reaches back in. However, your SOC (security operations center) can still watch it. Anomalies are visible and incidents are detectable.
Operational continuity is preserved.
The historian still logs; the the RTU (remote terminal unit) still reports. The data that downstream systems depend on still flows outbound, safely, through hardware that can’t be subverted. Operators don’t face the false choice between security and uptime.
Compliance evidence is hardware-rooted.
The isolation is provable. You’re not asserting that a firewall policy protects the system; you’re demonstrating that the physical architecture of the network makes inbound traffic to that system impossible. That’s a very different conversation with an auditor.
The Inventory Problem Comes First
Anthropic’s recommendation specifically pairs “inventory” with “isolate”; you can’t protect what you don’t know exists.
A systematic EOL asset inventory is step zero. It surfaces the systems that need protection, establishes their network exposure, and creates the baseline against which isolation controls are measured. OPSWAT’s approach to critical infrastructure protection starts there: understand what’s on the network before deciding how to protect it.
Once the inventory exists, data diodes can be applied with surgical precision, protecting the highest-risk EOL systems first, while preserving the data flows that operations depend on.
A Policy Signal Worth Taking Seriously
Anthropic is not an OT security company. That’s what makes this framework interesting. When an AI developer building LMMs is writing cyber resilience recommendations that name data diodes and RTUs, it reflects a broader consensus that’s been building: the security of operational technology infrastructure is a systemic risk, not a niche concern.
The recommendation to “fund operators to inventory and isolate systems that can no longer receive security updates” is going to show up in procurement conversations, regulatory requirements, and board-level risk discussions. The operators who have already solved this problem, who have inventoried their EOL assets and protected them with hardware-enforced isolation, will be ready for that conversation.
The ones who haven’t will be left to explain why they've allowed their systems to remain at risk.
Talk to an OPSWAT expert about deploying hardware-enforced data diodes across your unpatchable OT assets.
