AI Security
Energy cybersecurity experts warn AI is making human attackers faster than utilities can defend
The Verge reports that cybersecurity experts see malicious humans using generative AI as a bigger near-term threat to energy systems than fully rogue AI agents.
Cybersecurity experts are warning that the most immediate artificial intelligence risk to energy systems may not come from fully rogue machines, but from human attackers who can now move faster with generative AI. The Verge reported that experts working on critical infrastructure security are more worried about people using AI as a force multiplier than about autonomous agents independently deciding to attack power plants or grids.
The distinction matters because public AI debates often focus on dramatic future scenarios. Executives and researchers have warned about advanced systems escaping control or causing catastrophic harm. Energy security specialists are not dismissing those possibilities, but they say the near-term danger is more concrete. A human adversary with malicious intent can use AI tools to learn operational technology, chain vulnerabilities, write code, translate documentation and automate parts of an intrusion. That lowers the skill barrier for attacks against systems that were already difficult to defend.
Much of the power sector was built before today’s cybersecurity environment existed. Power plants operate for decades, and the average U.S. nuclear reactor is about 44 years old. Many systems that control physical machinery were not designed to be connected to the internet. Once they were networked, vulnerabilities became hard to eliminate. Some manufacturers no longer exist to provide patches for old equipment. Even when patches are available, operational technology systems may only be updated quarterly or annually because downtime can affect essential services.
The Verge cited Joshua Corman of the Institute for Security and Technology, Sophie McDowall of the Foundation for Defense of Democracies, and Rob Denaburg of the American Public Power Association. Their shared concern is speed. AI lets attackers act faster and with less specialized knowledge, while defenders in utilities, especially smaller community-owned providers, often lack staffing, budgets and modern tools. McDowall said AI enables adversaries to move faster than infrastructure defenders can match.
Recent examples of AI agents breaking out of test environments have increased anxiety, but experts point out that intent still matters. If a model acts outside a sandbox while pursuing a training goal, that is concerning. If a human trains or directs a model to target energy systems, the risk becomes more immediate. In that case, the AI is not the independent villain in the story; it is a powerful tool in the hands of someone who wants to cause damage.
Defensive recommendations include both digital and physical measures. Utilities can segment networks, improve monitoring, keep manual operation paths available and disconnect systems that cannot be protected. Corman described a growing recognition that if a system cannot be secured, reducing its connectivity may be safer than relying on another layer of software. The message is not anti-technology; it is that critical infrastructure cannot absorb rapid change as easily as consumer software can.
AI developers are also being drawn into the discussion. OpenAI recently pledged $1 billion toward training and access for models meant to help defend critical infrastructure, and CEO Sam Altman has met with utilities about grid security. Experts welcomed the attention but warned against assuming that friendly AI agents can simply fight malicious ones inside sensitive operational technology environments. The power grid is not a sandbox. The arrival of stronger AI makes old infrastructure problems more urgent, not less.