Surprisingly Useful AI Article Enhancements
Dragos has introduced EmberAI, an operational technology (OT)-native AI assistant designed specifically for critical infrastructure environments including power grids, manufacturing facilities, water utilities, pipelines and data centres.
Unlike general-purpose AI tools, EmberAI is built on the Dragos Intelligence Fabric, drawing on more than a decade of OT threat intelligence, incident response experience, vulnerability research and real-world operational data.
The platform is designed to help security teams quickly understand assets, vulnerabilities and threats, prioritise risks based on operational impact and accelerate incident response.
Addressing A Growing Skills Gap
The launch comes as cyber threats targeting critical infrastructure continue to rise and organisations face ongoing shortages of OT cybersecurity expertise.
Existing tools tend to prioritise visibility over understanding, while general-purpose AI lacks the operational context to distinguish a critical exposure from background noise or to prioritise threats by their actual impact on operations. In OT environments, any delayed or incorrect decision can have direct consequences for operational safety, resilience and control.
Organisations responsible for securing extended operational technology (xOT) environments need AI that is built on relevant intelligence and grounded in operational reality. EmberAI is designed to help analysts across the full range of experience – from IT practitioners and plant engineers operating in OT environments to seasoned OT professionals – see, understand and act with greater confidence.
Robert M. Lee, CEO and Co-Founder at Dragos, explained the thinking behind the product.
“We built EmberAI to harness Dragos’s decade-plus of experience in threat intelligence, incident response, adversary tracking and frontline operations for OT environments,” Lee remarked. “It is hard to reproduce this depth of OT-specific expertise and build AI that understands and can action OT-specific findings.”
What Powers EmberAI
The Dragos Intelligence Fabric is built on more than five petabytes of daily OT telemetry, more than 10 years of adversary tracking across named OT threat groups, proprietary OT vulnerability research as a CVE Numbering Authority, asset and protocol research spanning more than 600 OT protocols and frontline incident response experience from critical infrastructure environments.
The Intelligence Fabric continuously learns as new intelligence surfaces, field insights accumulate and threat groups adopt new behaviours.
This foundation enables EmberAI to operate on a principle that distinguishes it from generic AI: OT-specific intelligence applied in context.
EmberAI is central to Dragos’s xOT security strategy, securing the full extended operational technology environment that influences critical operational processes. As Dragos’s xOT integrations expand the Intelligence Fabric with new data sources, EmberAI’s intelligence and capabilities are expected to grow with it.
Gartner guidance on AI for cyber-physical system (CPS) security supports this approach, recommending organisations favour solutions that use a tuned, CPS-specific intelligence engine rather than risking intellectual property and data sovereignty by feeding sensitive operational telemetry into opaque, cloud-based global models.
How It Works
EmberAI offers several core capabilities aimed at improving how OT security teams operate.
The Intelligence-Driven Query Engine allows analysts to ask questions in plain language and receive OT-contextual answers grounded in the Dragos Intelligence Fabric. This eliminates the need to manually pivot across disconnected tools or correlate data from multiple sources.
Related: Best Business Laptops for work & school
Related: Best Gaming Laptops
Related: Best Portable Laptop
Contextual Correlation Across the Environment connects assets, vulnerabilities, threat intelligence and network activity into a unified, real-time understanding. Decisions are based on full operational context rather than isolated or irrelevant technical signals.
Through Adversary-Informed Guidance, detections and alerts are mapped to known OT threat groups, observed attack patterns and real behaviours drawn from the Intelligence Fabric. Analysts can understand not just what is happening but what it means for their environment and how to prioritise their response.
Workflow Acceleration and Automation Support covers tasks from alert triage to incident summaries and reporting, reducing what Dragos describes as hours of error-prone manual work. The aim is for analysts to spend less time gathering data and more time making informed decisions.
Dragos analysts are also building and validating a library of guided, repeatable workflows that encode the expertise they apply during proactive services, investigations and incident response. This library is expected to be available soon.
The platform also features Continuous Learning Through the Intelligence Fabric, meaning that as new intelligence and field insights surface, the Intelligence Fabric evolves and EmberAI becomes more capable over time.
Human-In-The-Loop Design
Dragos has built EmberAI around several design principles that reflect the high-stakes nature of OT environments.
The analyst remains in control at every step. Every recommendation that EmberAI surfaces is transparent and auditable, enabling defensible workflows. Customer data never leaves the customer’s environment, with EmberAI operating inside the Dragos Platform deployment the organisation already controls.
These design choices reflect what Dragos describes as a foundational “human in the loop” principle for OT: the person responsible for protecting an environment must own the final decision.
EmberAI is available inside the Dragos Platform. More information can be found at dragos.com/emberai.
Last Updated on June 24, 2026 by Nick Ross



