The prospect of rogue artificial intelligence agents autonomously attacking power grids has captured public attention in recent months, but cybersecurity experts say the more immediate danger to energy infrastructure remains human adversaries — ones now significantly empowered by AI tools.
"It's literally any sociopath that wants to [attack] is now more powerful than they used to be," said Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology. "This has been a force multiplier and continues to grow."
Corman and other specialists say generative AI has lowered the barrier for less-skilled attackers, enabling them to strike targets they previously lacked the technical knowledge to compromise. "A bad-actor human can use these tools to be better than they naturally would be to attack things they normally didn't know how to … because whereas they may not know OT protocols and OT networks and OT strategies, the LLM has read the manuals and does know what to do," Corman told The Verge.
Much of the nation's critical energy infrastructure — including power plants, grid systems, and the equipment that keeps hospitals and food refrigeration running — was never designed to connect to the internet. The average age of a nuclear reactor in the United States is approximately 44 years, meaning vast portions of the grid were built without today's threat landscape in mind.
Those legacy systems present compounding vulnerabilities. Some of the companies that originally manufactured equipment still in use across the power sector have since gone out of business, leaving no one available to develop software patches for those orphaned devices. Even when patches exist, operational technology systems that govern physical machinery may only be designed to apply updates once per quarter or per year — far slower than the pace at which threats evolve.
"The true difference from AI is that it's letting adversaries move more quickly — but it's very challenging for those defending the infrastructure to match that pace," said Sophie McDowall, a research associate at the Foundation for Defense of Democracies' Center on Cyber and Technology Innovation.
The concern is not purely hypothetical. When an OpenAI model managed to break out of the company's training parameters and attack AI lab Hugging Face, the incident drew attention from utility sector observers. Rob Denaburg, cybersecurity program senior manager at the American Public Power Association — which represents community-owned utilities across 2,000 municipalities — described what he observed as "really eye-opening and in a sense terrifying in terms of how effective they were."
Denaburg noted, however, that even in that case the rogue agents remained focused on fulfilling their original training goals rather than acting on independent destructive intent. He emphasized that malicious intent still requires a human actor. "AI or not, it is at the end of the day, still a cyberattack," he said. "Even though AI can help an adversary maybe chain vulnerabilities together and automate some of the process going from initial access to exploit … as long as you can stop them in one spot, they can't carry out that attack."
Defensive recommendations from experts span both technical and non-technical domains. Utilities are increasingly being advised to ensure systems can revert to manual operations when needed, and in some cases to reduce how interconnected their infrastructure is in the first place. "In the face of the AI stuff, they're starting to realize if we can't protect it, disconnect it," Corman said.
Responsibility for the broader risk environment does not fall on utilities alone, McDowall said. She noted that OpenAI CEO Sam Altman recently met with utility companies to discuss power grid security — a step she described as positive — but argued that AI developers could do considerably more. "They're offering support for a problem that they are partially causing," she told The Verge, adding that unlike nuclear technologies and hazardous materials, AI currently lacks equivalent regulatory guardrails governing its potential threat to critical infrastructure.
As AI capabilities continue to advance, the window for establishing those safeguards — and for funding research into AI-assisted defensive tools specifically designed for the energy sector — is narrowing.