Controlleddecisionsupportwheretheconsequenceisphysical
Critical infrastructure is not an industry. It is a constraint profile that appears across energy, water, telecom, transport and heavy industry — and it changes what a responsible AI architecture looks like.

Thepattern
Asymmetric by design. This is the single most important diagram on the site for this audience.
OT zone
Process control. Read paths only, through a broker.
IT zone
Where the ontology, the control plane and the agents live.
Theconstraintprofile
If most of these apply to you, this page is more relevant than your industry page.
Physical consequence
An unreviewed action can hurt someone or interrupt an essential service.
IT/OT segmentation
A boundary that exists for safety and security reasons and must not be weakened.
Resilience obligations
Regulatory duties on continuity, incident reporting and supply-chain risk.
Long asset lifecycles
Equipment older than the systems documenting it, and documentation older than the staff.
Operator accountability
Named, qualified people who are answerable for operational decisions.
Scrutiny
Supervisors, auditors and the public all with a legitimate interest in how decisions were made.
Whatthearchitectureprovides
Asymmetric boundary
Read-only observation through a broker; no unattended write path across the boundary.
Private deployment
On-premises or disconnected, with local inference and no outbound dependency.
Asset intelligence
Condition, topology, work history and obligation as one traversable model.
Agent security
Per-agent identity, short-lived credentials, default-deny egress and tested kill switches.
Evidence for incidents
Decision records that double as investigation material when something goes wrong.
Degradation behaviour
Defined per workload class: what continues, what queues, what stops.
Supply-chain provenance
Provenance for images, models, dependencies and MCP servers.
Operator-first design
Approvals that assemble the case rather than asking for a rubber stamp.
Segregation of duties
Mandates that prevent one identity from proposing and approving the same action.
Stated plainly
NeuroCluster does not take autonomous action on physical processes. In these environments it prepares decisions, evidences them, and leaves the action with a qualified human inside an already-approved system.
Questions
- Why not automate the action if the analysis is good enough?
- Because the failure mode is asymmetric. A wrong analysis that a competent operator rejects costs a few minutes; a wrong action costs considerably more, and the accountability structures in these environments are built around a human decision-maker for good reason. Where automation is appropriate it already exists, under controls designed for it.
- How do you handle incident reporting obligations?
- Evidence records are designed to be usable as incident material: what was observed, what was proposed, what was decided, by whom and when. What a specific reporting obligation requires needs assessment against your own legal position.
- Can this be deployed without any internet connectivity?
- Yes. Disconnected deployment with local models and no outbound dependency is supported, and is the normal posture for the most sensitive environments.
Continue
- Security architectureThe controls a security architect will review.
- Energy & utilitiesThe pattern applied to grid operations.
- IndustrialThe pattern applied to manufacturing.
- NIS2Resilience and reporting considerations.
- Private AI cloudDisconnected and on-premises deployment.
- Trust centreDiligence material for security and procurement.
Bring us one operational problem.
You do not need a finished brief. Bring the problem — we will work out the next step together.
Or book a call with the team