Why your next AI insight might come from outside your industry

If you’re running an AIoT initiative, the following questions probably sound familiar. Your devices are connected. Data is flowing. So why is it still hard to know whether an AI-driven decision made on that data can actually be trusted? Why does every new use case seem to surface a data-governance problem you thought you’d already solved? And why does the security review always take longer than the pilot itself?

Those questions aren’t unique to any one industry - they’re the questions we hear from customers building connected products and AI-driven operations across manufacturing, energy, fleet, and infrastructure. Which is exactly why it was worth spending an hour last week somewhere well outside our usual orbit: an IET Aerospace Technical Network webinar built around a deceptively simple question — AI and drones, are we safe? — timed just ahead of Farnborough International Airshow, the world’s second-largest aerospace and defence event, expecting more than 100,000 visitors this year.

Aerospace and defence sit at the sharp end of AI adoption — higher stakes, harder regulation, less tolerance for error. That makes them a useful place to go looking for answers before the rest of us have to learn them the hard way. Three speakers, three sectors, and the same underlying lesson showed up in each: the technology is rarely the hard part. What surrounds it is.

Lesson 1: The blocker usually isn’t where you think it is

Henry Tse (Meriva Impact, and an adjunct professor at Southampton) opened with a framework for why commercial drone adoption is stalled. Progress splits into three tracks: the technology (largely ready — platforms are AI-capable, concepts have been proven), policy and regulation (moving — the UK’s BVLOS roadmap is published, Remote ID is now mandatory), and the market and public (lagging — use cases are demonstrated, but public trust and insurance frameworks haven’t caught up). The gap sits exactly where those three intersect, and nobody owns all three at once.

The takeaway for any AIoT deployment: if your initiative feels stuck, audit where the actual blocker sits before assuming it’s the platform. Most of the time, it isn’t.

Lesson 2: AI is only as trustworthy as the consistency behind your data

The sharpest parallel came from Group Captain Alistair Scott (Air Cap Futures), discussing AI-assisted command and control for military operations. His point wasn’t really about drones — it was about data: AI is only safe to lean on operationally if the underlying data means the same thing across every system that touches it, and if its decisions remain explainable to the human who owns the outcome.

That’s the exact problem our Digital Twin Manager exists to solve — creating meaningful, consistent relationships between devices, systems, and business processes so that equipment data carries context wherever it goes, rather than needing to be re-interpreted every time it crosses a system boundary. Hearing the same requirement, in the same words, from someone building AI-assisted decision loops for crewed and uncrewed military platforms was a good reminder that this isn’t a nice-to-have. It’s the precondition for using AI safely once the stakes are real.

Lesson 3: Security-by-design isn’t optional once AI writes your code for you

Ken Munro (Pen Test Partners) brought the sharpest edge to the session. He walked through where AI application security tends to break down in practice — the OWASP Top 10 categories for LLM applications aren’t hypothetical; his team sees them routinely in client work. His most pointed warning was about “vibe coding”: AI-generated code shipped with minimal review. He cited research showing AI-generated code scores poorly on security benchmarks on average, with infrastructure and DevOps code failing most often, and drew a direct line back to the early smart-home land grab — ship fast, fix never, worry about security later, if at all.

The takeaway: the same “move fast and skip the boring bit” instinct that produced a decade of insecure IoT devices is now showing up in AI-generated code for embedded and edge systems. Security and compliance can’t be a step you add later — it has to be built into the platform from the start, including the regulatory groundwork (in Europe, that increasingly means the Cyber Resilience Act and NIS2) that most teams don’t think about until an auditor asks.

He also told a story with nothing to do with aviation: a power outage in San Francisco that knocked out traffic lights and stalled around 1,600 autonomous robotaxis mid-journey, after the fleet had logged more than 170 million autonomous miles without major incident. The vehicles weren’t equipped to reason about standing water depth or a failure mode nobody had trained them on — and remote support was overwhelmed trying to intervene on that many vehicles at once. A long, clean track record isn’t proof against the one edge case your training data never saw.

What this means if you’re the one building it

Strip away the aviation specifics and every one of these lessons maps directly onto the AIoT deployments we work on every day:

  • Diagnose before you build. The technology is rarely the blocker — figure out whether your real gap is regulatory, organisational, or a question of public/internal trust before you assume you need more platform.

  • Contextualise data before you act on it. Raw device data isn’t AI-ready data. It needs a consistent model — device to system to business process — before any AI decision built on top of it can be trusted or explained.

  • Design security in, not on. Compliance and security posture have to be part of the platform from day one — bulk device management, credential hygiene, and update discipline aren’t optional extras once you’re moving at AI speed.

  • Plan for the edge case, not just the average day. However clean your track record, your human-in-the-loop capacity needs to scale with your fleet, not exist as a box you ticked once.

This is, in a fairly direct sense, what we built the Cumulocity AIoT platform to do: bridge operational technology and IT, turn raw device data into AI-ready insight through a Digital Twin Manager that gives it consistent meaning, and embed security and compliance across the full device lifecycle — validated to scale from a single pilot to well over 100 million devices without a redesign.

Are we safe?

Depends what you mean by “we.” The technology, on the whole, is ready enough. The policy is moving. It’s the space in between — trust, ownership, and disciplined data governance — where the real work still needs to happen, whether that’s in a battlespace, in commercial airspace, or in an industrial AIoT deployment. If you’re building AI into safety- or mission-critical systems in any industry, it’s worth finding the version of this conversation happening in a field that isn’t yours. You’ll probably recognise more of it than you expect.

Thanks to Henry Tse, Ken Munro, and Group Captain Alistair Scott for a genuinely thought-provoking session, and to the IET Aerospace Technical Network for hosting.

1 Like