The uncomfortable question that such a gap raises is accountability, mainly who's responsible when an AI system influences a call on the plant floor, and what guardrails exist when something goes wrong in an environment where a bad decision isn't just a data breach; it's a safety event. Critical infrastructure operators tend to have more mature oversight structures, but manufacturers and less-developed industrial sectors are largely still borrowing IT governance frameworks never designed with OT realities in mind, leaving a growing slice of the industry operationally ahead of itself.