Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems

Security experts warn that human attackers remain the principal cybersecurity threat to energy systems, even as generative AI tools lower the skill barrier for malicious activity. Aging, internet-connected operational technology and limited resources at many utilities make power infrastructure especially vulnerable to cyber intrusion, and AI can act as a force multiplier for human adversaries.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished 22 minutes agoUpdated 22 minutes ago0 views
Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems

Why It Matters

The resilience of electricity and other critical energy systems underpins public safety and economic activity; growing AI capabilities can accelerate and scale attacks, increasing the urgency for utilities and policymakers to shore up defenses. The gap between adversary capabilities and defenders’ ability to patch and respond could lead to more frequent or severe disruptions if not addressed.

Key Facts

  • Expert quoted: Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology (IST) said utilities were "always prey" to attackers.
  • Concern about AI: Experts say generative AI amplifies attackers' effectiveness by automating tasks and encoding domain knowledge.
  • Aging infrastructure: The average age of a U.S. nuclear reactor is about 44 years, and many critical systems were not designed with internet-era cybersecurity in mind.
  • Operational constraints: Operational technology (OT) systems may be designed to receive updates only quarterly or annually, slowing patch deployment.
  • Utility representation: Rob Denaburg is cybersecurity program senior manager at the American Public Power Association, which represents community-owned utilities across 2,000 municipalities.

Cybersecurity experts interviewed by The Verge emphasize that while AI-driven attacks draw media attention, human actors continue to pose the greatest and most immediate danger to energy infrastructure. Joshua Corman of the Institute for Security and Technology described utilities as longstanding targets for attackers, noting that the threat is growing as adversaries gain access to more powerful tools. Generative AI, the experts say, acts as a force multiplier that can speed up reconnaissance, automate exploitation steps, and enable less-skilled actors to execute sophisticated attacks. A central vulnerability is the legacy nature of many systems that control electricity generation and distribution. Much critical infrastructure was designed long before networked, internet-connected environments became ubiquitous; replacing or retrofitting decades-old equipment is costly and slow. Some manufacturers of older devices no longer exist, leaving equipment without available software patches. Even when fixes exist, operational technology often has limited maintenance windows, with updates applied only quarterly or yearly, which constrains timely remediation. Analysts stress that intent remains a key factor: AI can accelerate and expand an attacker’s capabilities, but a human-directed campaign is still required to target energy systems specifically. Rob Denaburg of the American Public Power Association pointed out that prior incidents involving AI agents breaking out of controlled environments showed impressive technical capabilities, yet those agents were pursuing pre-set objectives. If a malicious actor deliberately trained models to attack power infrastructure, the consequences for utilities would be more severe because the human adversary is driving the intent. Defensive options are pragmatic and largely independent of whether an attack leverages AI. Utilities can adopt best practices such as designing fallback manual controls, reducing unnecessary interconnectivity, and strengthening detection and segmentation to stop adversaries at a single point of failure. Experts also call on AI developers and governments to take responsibility: meetings between AI company leaders and utilities are a useful step, but analysts say more systemic controls and support are needed to mitigate risks that advanced models help create.

Keep Reading