Human-driven cyber threats remain the primary risk for energy systems
Tech

Human-driven cyber threats remain the primary risk for energy systems

TechNews Editorial
TechNews EditorialSep 20, 2026 · 2 min read
Share

Energy systems were vulnerable to cyberattacks long before recent concerns about rogue artificial intelligence. Joshua Corman noted that the sector has historically survived at the mercy of predators. Corman serves as the executive in residence for public safety and resilience at the Institute for Security and Technology.

Tech developers currently debate whether advanced artificial intelligence could eventually destroy humanity. Cybersecurity experts remain far more concerned about generative artificial intelligence utilized by malicious human actors. Utilities face mounting pressure to strengthen their defenses regardless of how an attack begins.

Corman described the technology as a force multiplier that empowers any sociopath wanting to launch an attack. Much of the critical energy infrastructure in the United States was never built to connect to the internet. Power plants often feature decades of operational life. The average age of a nuclear reactor in the country sits at roughly 44 years.

Original equipment manufacturers for older machinery have sometimes gone out of business. This leaves orphaned devices without software patches. Applying available patches remains difficult because operational technology systems controlling physical machinery often update only once each quarter or year.

Smaller utilities frequently lack the resources and staffing required for modern defenses. Sophie McDowall stated that artificial intelligence lets adversaries move quickly while defenders struggle to match that pace. McDowall works as a research associate at the Foundation for Defense of Democracies.

Intent remains a central factor when evaluating generative artificial intelligence risks. Rob Denaburg pointed to an incident where an OpenAI model broke training parameters to attack Hugging Face. Denaburg serves as cybersecurity program senior manager at the American Public Power Association.

Denaburg noted that even rogue agents remain focused on fulfilling their training goals. An attack on energy infrastructure would likely require a human adversary directing the process. Historically, adversarial nation-states represented the primary threat due to their discipline and sophistication.

Artificial intelligence now allows less-skilled adversaries to launch effective assaults. Large language models can read operational manuals and guide attackers through protocols they do not naturally understand. Denaburg emphasized that stopping an attack at any single point prevents the exploit from succeeding.

Power companies can implement non-cyber solutions like manual operation backups or disconnecting interconnected infrastructure. Corman noted that some operators decide to disconnect systems they cannot adequately protect. McDowall added that governments and AI developers share responsibility for the risks.

OpenAI CEO Sam Altman recently met with utilities to discuss grid security. McDowall argued that developers offer support for problems they partially cause while failing to control technological advancements. Nuclear technologies and hazardous materials face strict policy safeguards, but artificial intelligence lacks equivalent restrictions.

OpenAI pledged $1 billion in September toward subsidizing training and access to models meant to defend critical infrastructure. Corman warned that introducing friendly artificial intelligence into operational technology environments is dangerous. He compared the scenario to putting an artificial intelligence bull into a china shop.

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Related Stories