AVEVA chief technologist Arti Garg has laid out a cautious case for autonomous industrial AI safety: connect the data, let systems help workers diagnose problems, and put hard boundaries around any software that can affect equipment. Garg made the case in an MIT Technology Review Business Lab episode produced in partnership with AVEVA.
The distinction is more than a software-design footnote. Industrial AI can interact with machinery, power systems and other physical operations. An unexpected output in that setting can affect worker safety, reliability and critical infrastructure, according to the episode.
Garg said newer foundation models, physical AI and agentic systems could automate more complex industrial work than older, specialized analytics tools. That does not make their behavior predictable enough to hand them the controls without structure.
How should autonomous industrial AI be kept safe?
AVEVA's proposed starting point is data that operators can actually use. Information about a pump or mixer may sit separately in equipment telemetry, maintenance records and engineering documents. Correlating those records can help workers identify a fault and decide how to address it, Garg said. The episode also points to robots gathering information in hazardous areas, reducing the need to send workers in for inspection.
Those uses are decision support or data collection. Direct control is a different category. Garg said AI should assist rather than replace people in critical decision loops. In AVEVA's framing, guardrails should spell out which actions can be automated and where supervisors retain responsibility.
A February working-group blog from the Digital Twin Consortium offers a more concrete version of that architecture, though it is a proposal rather than a regulator-issued standard. It calls for a separation between an agent's recommendation and execution: the agent proposes an action, a separate system checks it against defined constraints, and only a validated action can run.
The consortium says such systems should preserve the operating context behind each decision, enforce hard physical and process limits, keep complete audit trails and manage policies consistently across multiple agents. It also lists emergency stops, human override, safe shutdown and graceful fallback to simpler control modes as required capabilities for safety-critical deployments.
The blog argues that a digital twin, a synchronized model of an operating system, could hold current equipment state and domain rules, validate proposed actions, record the decision context and distribute policy changes. That is an architectural claim from the consortium, not proof that a digital twin makes an autonomous system safe.
Autonomous-operation trials are already being reported in live industrial environments. ARC Advisory Group said Borouge began trials with Honeywell in 2025 for an AI-driven control room at its Ruwais facility, with a proof of concept announced in January 2026. Borouge planned further demonstrations and an assessment of wider deployment. Claims of efficiency, downtime, cost and safety benefits in that project came from the companies and have not been presented as independently audited results.
The practical path is unglamorous, which is generally a good sign around machinery: start with contextual data and worker-facing assistance, test controls around any proposed action, and retain the evidence and override paths needed when software gets something wrong.
This story draws on original reporting from MIT Technology Review.