An AI System Reaches a PLC Inside Labshock, Under Constraint
Raffaele Forte publishes a controlled OT exercise in which Xfenser AI reads an industrial scenario, interacts with a PLC and produces a measurable outcome without leaving its defined limits.

January 17, 2026 — Raffaele Forte has published a controlled OT and ICS exercise carried out in a Labshock environment, in which the Xfenser AI system interpreted an industrial scenario, interacted with a PLC and reached a measurable outcome inside defined constraints.
The framing Forte gives it is the useful part. AI in security is usually discussed against ordinary IT workflows; the real test, he argues, starts when the environment changes — when the thing on the other end of the action is a controller with a physical process behind it rather than a host.
That is a question best asked somewhere consequences are educational rather than industrial, which is what makes a virtual plant the right venue for it. An AI system permitted to write to a PLC is either operating under constraints that hold, or it is not, and the only honest way to find out is to let it try where the answer is safe.
The exercise is documented in full in the linked article.
Labshock is a platform for learning and testing OT cybersecurity through hands-on labs and realistic industrial environments. Part of it is open source at github.com/zakharb/labshock.
Media enquiries: info@labshocksecurity.com
