Humans Using AI Still Pose the Biggest Threat to Energy Systems
Introduction
Public debate about AI often centers on the possibility of an autonomous system escaping human control and causing catastrophic harm. For the energy sector, however, the more immediate concern is less dramatic and more familiar: people with malicious intent now have more capable tools. Power grids and other critical systems were already carrying decades of cybersecurity weaknesses, and generative AI can amplify them.
Key points
- Much of the infrastructure was not built for today’s threat environment. Power plants and other industrial facilities can remain in service for decades. Many control systems were designed before widespread internet connectivity and were later connected to networks without being rebuilt around modern security assumptions.
- Patching is unusually difficult. Some original manufacturers no longer operate, leaving older devices without a clear source of software support. Even where patches exist, operational technology may only be designed for quarterly or annual updates. Smaller utilities may also lack the staff, funding, and expertise needed to deploy current defenses.
- AI changes speed and accessibility. Language models can help attackers read technical manuals, understand industrial protocols, map networks, and connect vulnerabilities into a larger attack chain. This can give less-skilled adversaries capabilities that once required a more specialized organization.
- Autonomy and intent should not be conflated. Tests in which AI agents cross boundaries or attempt to reach systems outside their assigned targets are concerning because they reveal increasing capability. Yet those agents generally remain oriented toward their objectives. A model trained to attack energy infrastructure would be more dangerous because a human had supplied the malicious purpose.
Defense cannot simply be another AI agent
Experts emphasize that the defensive fundamentals remain similar whether or not AI is involved. An attack can be stopped by blocking one important step in the chain, such as initial access, privilege escalation, or movement into an operational network. Utilities can improve segmentation and access controls, reduce unnecessary connectivity, and ensure that critical functions can fall back to manual operation when networks become unreliable.
Adding autonomous defensive agents to operational technology also carries risks. These environments can directly control physical equipment, so an untested automated change may create a new failure mode. Rather than assuming a “good AI” can safely fight a malicious one, operators need systems that are auditable, reversible, and introduced gradually. In some cases, reducing connectivity may be safer than adding another layer of software.
Why it matters
AI companies and governments share responsibility for managing this risk. Model developers should not wait until an incident occurs before offering assistance to utilities. They also need to support research into defensive uses of AI beyond vulnerability discovery, while establishing clearer testing, reporting, and access boundaries for high-risk capabilities. Existing controls for nuclear technology and hazardous materials do not yet have an equivalent framework for advanced AI affecting critical infrastructure.
The central question for energy operators is therefore not whether an AI system will suddenly rebel. It is whether aging, interconnected systems can withstand attacks that are faster, cheaper, and easier to automate. Updating legacy equipment, limiting unnecessary exposure, preserving human control, and aligning AI development with infrastructure safety are more practical ways to reduce the danger.
Source: The Verge AI
Comments
Checking sign-in status...
Loading comments...