AI agent security / Mining

Secure the agents working with mining data.

Mining teams are using AI agents for research, internal knowledge and connected business workflows. As agents gain access to project data and tools, permissions become part of operational readiness. Oktsec helps you test what they can read, share and change.

BHP reports using specialized AI agents in copper-leaching research.See the industry evidence
Why now / published industry evidence

Mining companies are already working with agents.

The evidence spans scientific research, internal knowledge and a reported implementation in Chile. These are different levels of adoption, with different access requirements.

BHP + Microsoft

Global research · Work reported · June 2026

More than half a million molecules screened.

BHP used Microsoft Discovery, which combines specialized AI agents and high-performance computing, to investigate copper-leaching candidates. Selected molecules proceeded to laboratory testing in Australia.

Read BHP’s research account

SONDA

Chile · Supplier-reported implementation

Agents connected to existing mining systems.

SONDA publishes a mining case implemented in Chile, describing agents that support tasks and access existing systems. The brief does not identify the customer or provide a technical architecture.

Read the implementation brief (PDF)

Ma’aden

Saudi Arabia · Customer story · January 2025

Company-policy agents available inside Teams.

Ma’aden built Copilot Studio agents for governance documents and delegation-of-authority policies. Employees use them to search company documents; the story does not establish autonomous approval authority.

Read the customer story
What this means for security

Research data and business authority need explicit boundaries.

An agent can bring external papers, project files and internal systems into the same task. The security review needs to establish which sources it may trust, which tools it can run and where results may go. A useful research or planning assistant should not inherit unrelated project access or approval rights.

Public accounts reviewed September 9, 2026. These organizations are not presented as Oktsec customers. Security implications are Oktsec’s analysis, not reported incidents at these companies.

Where to begin

Keep research, project access and purchasing authority separate.

For copper and lithium teams in Chile and Argentina, agents may connect technical literature, project files and supplier systems. Access should follow the assignment: which project, which dataset, which tools and which recipient.

01

Research & technical analysis

Combine approved project data with technical literature. Review the analysis tools and the destinations used to share results.

At stake: proprietary research and project information
02

Project & contractor access

Prepare a report for one project without opening the rest of the exploration archive to the agent or an external consultant.

At stake: information separated by project and partner
03

Maintenance & supplier decisions

Prepare work plans or compare offers. Keep equipment release, vendor changes and purchasing approval under existing authority.

At stake: records and decisions used by operational teams
AI adoption with security built in

Accelerate mining work. Build security into the workflow.

AI can help teams connect research, compare technical information and prepare decisions faster. Putting it to work requires clear access to project data, defined authority and a way to review what it did.

Plan a secure rollout

Make research easier to use.

Let agents bring together approved technical sources and project information. Keep proprietary datasets within the scope of the assignment.

Help specialists work together.

Prepare analyses and share findings with the right people. Define who can receive project information before an agent sends it.

Keep decisions accountable.

Use AI to support the work of engineers, researchers and buyers. Preserve their approval authority and review the available action records.

Example: a research assistant with access to project data

The taskCompare copper-leaching research using Project A’s approved dataset.

Within the assignment

Retrieve the approved documents for Project A.

Use project-scoped credentials and constrain the tool’s project parameter.

The summary stays within the assigned dataset.The source system must enforce project access; an instruction in a document cannot grant it.
Outside the assignment

Send the exploration archive to an unapproved domain.

Allow only the destinations required by this workflow.

The routed request to the unapproved domain is denied.Test direct SDK and shell routes too. Destination filtering does not establish that every encrypted payload was inspected.

Illustrative configuration to validate in an assessment. Project permissions belong in the source system; Oktsec enforcement applies to supported, routed actions.

From assessment to deployment

Test the workflow. Put the controls in place.

Assessment

Test project isolation and export paths.

Exercise cross-project retrieval, instructions embedded in technical sources and unintended transfers through the connected tools.

Explore Assessment
Control + Cloud

Apply limits where the agent acts.

Use supported Node integrations to constrain tools, parameters and destinations. Keep project authorization in the source system and review available evidence in Cloud.

Explore Control + Cloud
Signal / powered by Aguara

Inspect the research toolchain.

Review the agent’s MCP servers, skills and software dependencies. Continuous monitoring of external ecosystem changes is in development.

Explore Signal
Application and agent security.

Coverage follows the configured integration. Industrial control and safety systems remain under their dedicated protections. Review backend permissions, bypass paths and site connectivity before deployment.

Check deployment coverage
Your first engagement

Start with an agent that uses project data.

Bring the project owner, the data team and security. Identify the sources, analysis tools and recipients before testing.

What we review together

  • One research, project-document or supplier agent
  • Representative project data approved for testing
  • The source permissions, analysis tools and export destinations

Define what success looks like

The agent retrieves the approved project data and completes its assigned task. Cross-project access and transfers to unapproved destinations are tested, including routes outside the configured integration.

What your team receives

Reproducible findings, prioritized access and integration changes, and a record of what was tested. Use the findings to define a Control evaluation and agree any retesting.

Plan an assessment

Before you connect an agent.

What should we establish before expanding agent access?

Identify the task, its owner, the connected systems and the permitted actions. Test that the intended workflow works, that out-of-scope actions are rejected on the configured path, and that alternate access routes and evidence gaps are documented.

Where does Oktsec fit in mining cybersecurity?

Oktsec focuses on AI agents and their connected software: project information, tools, dependencies and recorded actions. It complements existing IAM, network and OT security. It does not monitor haul-truck control networks or certify the safety of process decisions.

Can you work with copper and lithium project teams?

The proposed starting point is a scoped review of an AI-assisted information or business workflow. Define the project, data owner and connected systems first. Site access, delivery location and operational constraints are agreed for each engagement.

Does Node support remote or disconnected sites?

Deployment and connectivity requirements must be evaluated for the specific site. Agree and test behavior when policy synchronization or evidence delivery is unavailable. This page does not promise an air-gapped or safety-critical deployment.