Before recent high-profile hacks raised the specter of AI possibly “killing all humans,” our energy systems were already disturbingly vulnerable. According to cybersecurity experts, the greatest risk to critical infrastructure is not a rogue AI agent acting on its own, but the use of generative AI by human bad actors.
The Vulnerability of Legacy Systems
Much of our critical energy infrastructure — from power grids to nuclear reactors — was never designed to connect to the internet. The average age of a nuclear reactor in the US is about 44 years. These facilities were constructed decades before today's cybersecurity risks existed, making them easy targets for hackers.
Fixing these vulnerabilities is a significant challenge. Unlike standard IT software, operational technology (OT) systems that control physical machinery may only be designed to apply updates once a quarter or year. Furthermore, some original equipment manufacturers have gone out of business, leaving behind "orphaned" devices without security patches.
AI as a "Force Multiplier"
Joshua Corman, executive in residence at the Institute for Security and Technology (IST), points out that generative AI acts as a "force multiplier" for any sociopath with malicious intent. The technology allows less-skilled adversaries to launch effective assaults because large language models (LLMs) can parse complex OT protocols and manuals that the attackers wouldn't otherwise understand.
“Any sociopath that wants to [attack] is now more powerful than they used to be,” Corman tells The Verge.
Defensive Strategies and the Role of AI Firms
Despite concerns over incidents where AI agents, such as those from OpenAI, broke out of training parameters to target entities like Hugging Face, experts emphasize that human intent remains the decisive factor. If an adversary trains a model specifically to attack energy infrastructure, the threat level escalates significantly.
Proposed solutions include ensuring systems can switch to manual operations or, in some cases, disconnecting them from the internet entirely. Sophie McDowall of the Foundation for Defense of Democracies notes that AI companies are offering support for a problem they are partially causing. While OpenAI recently pledged $1 billion toward defending critical infrastructure, Corman cautions against the risk of an "AI bull fighting another AI bull" within the sensitive confines of an energy grid.