Booz Allen reports that AI agents operated industrial controls and triggered machinery movements in an isolated lab. The tests were authorized: its whitepaper, published on October 6, 2026, says agents had to wait for human approval before every exploit and any action that could produce a physical effect.

The Chantilly, Virginia lab modeled a manufacturing facility with equipment from multiple vendors, separate network zones, industrial controllers and a robotic arm. Booz Allen reports eight completed objectives across eight controlled scenarios. That count describes scenario objectives, not every individual trial or a success rate for real facilities.

In one test, the authors say models moved from the network perimeter to control-zone actions in just over 16 minutes. Local controls, firewalls and other protections slowed or prevented some approaches; agents sometimes tried other routes. The results do not show that every safeguard was ineffective.

The report does not identify precise model versions or release full trial counts and auditable raw traces. Its findings are a preliminary company evaluation, not an independently replicated measurement. The authors recommend stronger segmentation, restricted access and human approval for safety-critical interventions. The accompanying webpage appeared on October 8; the original PDF carries the earlier publication date.