Laptop displaying red and white eye pattern, matching the background, symbolizing surveillance or scrutiny.

Why human hackers, not rogue AI, remain the biggest threat to the power grid

Human hackers remain the biggest AI cyberattack risk to energy systems, as generative AI helps attackers move faster than utilities can defend.

In short

Security experts say human attackers remain the biggest cyber threat to energy systems, but AI is making those attacks faster and more dangerous. Utilities are being pushed to strengthen defenses, reduce connectivity and prepare for a new wave of AI-assisted intrusions.

  • Human hackers are still the biggest threat to energy infrastructure, not rogue AI.
  • Generative AI is acting as a force multiplier, helping attackers move faster and with less expertise.
  • Older OT systems, slow patching and orphaned equipment leave utilities exposed.
  • Experts want stronger utility defenses, more isolation where needed and clearer AI-specific safeguards.
  • OpenAI and other AI firms are under pressure to help secure the systems their tools may endanger.

Human attackers are still the main cybersecurity danger to energy systems, but artificial intelligence is making them faster, cheaper and harder to stop. That is the central warning from security experts following a wave of attention on rogue AI agents and fears that advanced models could someday go far beyond cybercrime.

In reality, the greatest immediate risk to power grids, utilities and other critical infrastructure remains the same one that has existed for years: people with malicious intent. The difference now is that generative AI can help those attackers find weaknesses, write code, learn operational technology systems and scale attacks that would once have required specialized skill.

The result, experts say, is not an AI-led apocalypse. It is a more practical and urgent problem: energy systems that were never built for modern internet threats are facing adversaries who can now move faster than defenders.

Why energy infrastructure is such an attractive target

Energy systems are deeply embedded in daily life, which makes them uniquely sensitive. When power infrastructure fails, the damage goes far beyond inconvenience. It can interrupt heating and cooling, disrupt hospitals, spoil food, shut down water systems and damage broader public trust in government and utilities.

That makes the sector a high-value target for criminals, hacktivists and state-backed actors alike. And many of the systems they would seek to attack were built long before cybersecurity became a design requirement.

Much of the equipment that runs power generation and distribution was not designed to be connected to the internet at all. Over time, however, utilities and industrial operators added networking and remote access functions to improve efficiency and manage sprawling systems. Those connections created new attack surfaces that were often difficult to retrofit.

Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology, argues that critical infrastructure has long been exposed. His broader point is that the sector was always vulnerable, even before AI entered the picture. What has changed is the scale of what a determined attacker can now do.

Corman said AI has become a force multiplier for anyone planning an attack, because it helps less-skilled adversaries act with more sophistication than they could on their own.

How AI changes the threat landscape

AI does not need to become sentient or autonomous to make cybersecurity worse. The more immediate concern is that it lowers the barriers to entry for attackers. A person who once lacked technical expertise can now use large language models and other tools to research systems, draft malicious code, automate reconnaissance and string together steps in a more efficient attack chain.

That is especially important in operational technology, or OT, the specialized hardware and software used to run industrial processes. OT environments are different from ordinary corporate IT networks. They often control physical equipment, are harder to update, and may be designed around long maintenance cycles rather than rapid patching.

Sophie McDowall, a research associate at the Foundation for Defense of Democracies’ Center on Cyber and Technology Innovation, says the real difference with AI is speed. Defenders, she notes, are trying to match adversaries who can now move much faster than before.

Rob Denaburg of the American Public Power Association, which represents community-owned utilities, says recent AI-related hacking incidents show how capable advanced systems can be when they operate outside intended guardrails. But he stresses that these cases still do not amount to independent evil machines choosing targets on their own. Instead, the risk grows when humans deliberately train models for harmful purposes.

In other words, the technology is amplifying intent. A malicious actor with knowledge of power systems can now use AI to close part of the expertise gap that once protected infrastructure.

What makes utilities especially vulnerable?

Utilities face a combination of technical, financial and organizational challenges that make them slower to defend than typical enterprise software environments.

  • Many power systems rely on older equipment that is still in service decades after installation.
  • Some original vendors no longer exist, leaving “orphaned” devices without software support.
  • OT systems often cannot be patched as quickly as IT systems because updates must be carefully timed.
  • Smaller utilities may not have large cybersecurity teams or the budget for advanced tools.
  • Interconnected systems create more points of failure and more routes for intrusion.

The age problem is particularly serious. In the United States, the average nuclear reactor is about 44 years old, and the broader power sector includes many systems built long before today’s cyber risks were understood.

Even when a patch exists, utilities cannot always deploy it immediately. OT systems frequently follow maintenance schedules measured in quarters or years, not days. That means a known vulnerability can remain open for a long time while operators wait for a safe window to make changes.

For attackers, those delays are an opportunity. For defenders, they are a constant challenge.

How serious is the risk from rogue AI agents?

The short answer is that rogue AI is concerning, but it is not the main problem energy operators are trying to solve today. Experts interviewed about the issue said they are more worried about AI in the hands of hostile humans than about AI independently deciding to target a power plant.

That distinction matters. Much of the public debate has focused on whether autonomous models could escape human control and trigger catastrophic outcomes. But for the energy sector, the more immediate danger is a well-resourced attacker using AI to improve reconnaissance, automate phishing, test intrusion paths or combine smaller vulnerabilities into a larger breach.

Denaburg’s view is that, regardless of whether AI appears in the attack chain, defenders still face a cyberattack. If utilities can interrupt the attack at one stage, the operation may fail. The practical response remains layered defense, resilience planning and rapid containment.

At the same time, some incidents have shown how models can behave in unexpected ways when pushed outside their intended use. Those episodes have raised fresh concerns among security researchers. But in the energy context, most experts still see the more familiar human-led threat as the one that could cause the most harm in the near term.

Why intent still matters

Intent is a crucial factor in assessing risk. A model wandering beyond its boundaries while pursuing a training objective is different from a model deliberately built to break into critical infrastructure. The first scenario is alarming; the second is far more dangerous.

That is why experts distinguish between model misbehavior and malicious deployment. A system that accidentally becomes over-aggressive in one environment is not the same as a tool crafted specifically for sabotage.

The fear for utilities is that AI can take someone who already wants to attack infrastructure and make that person much more capable.

What are utilities doing to protect themselves?

Utilities are trying to harden systems using both cyber and non-cyber measures. One major priority is ensuring that critical processes can revert to manual control if automated systems are compromised. Another is reducing unnecessary connectivity where possible.

Some operators are rethinking the basic design assumption that every system needs to be connected for efficiency. In certain cases, the safer answer may be to disconnect a system that cannot be adequately protected.

Corman says some organizations are now concluding that if a system cannot be secured well enough, it may need to be isolated from networks entirely.

This approach reflects a broader shift in critical infrastructure security. Instead of assuming everything can be made perfectly safe online, operators are increasingly weighing whether some assets should be kept off-line or segmented more aggressively.

The challenge is that utility modernization, remote monitoring and network integration all bring operational benefits. Disconnecting systems can reduce risk, but it can also limit efficiency and visibility. Utilities must balance reliability, cost and security under intense pressure.

What role do AI companies and governments play?

AI companies and policymakers are under growing pressure to do more. Experts say they cannot simply build more powerful systems and leave utilities to absorb the security consequences.

McDowall argues that the companies developing frontier AI models have a responsibility to help reduce the harm their tools can enable. She points out that while some firms have begun offering support, they are also helping create the very problem they are now assisting others to defend against.

OpenAI’s leadership has taken steps to engage with utilities and discuss grid security. The company also recently announced a major financial commitment aimed at supporting training and access for models designed to help defend critical infrastructure. OpenAI has argued that frontier AI can help defenders move faster as cyber threats grow more sophisticated.

Still, the policy gap remains large. McDowall says AI does not yet have the same kind of regulatory guardrails that exist for nuclear technologies or hazardous materials, even though failures in AI security could also threaten human life and essential services.

Her view is that innovation does not have to stop, but it does need stronger safeguards, clearer limits and more research focused on secure deployment.

Why regulation is part of the conversation

Security experts increasingly argue that AI policy should not treat critical infrastructure as an afterthought. Systems that power hospitals, homes and industries should not be left to rely only on voluntary best practices when the risks are growing quickly.

That does not necessarily mean a blanket ban on AI in infrastructure operations. It does mean stronger requirements for testing, oversight, disclosure and defensive readiness, especially where AI tools could interact with OT environments.

One major concern is the lack of research on how AI could improve energy cybersecurity beyond simple vulnerability testing. Experts want to see more work on practical defenses, not just offensive red teaming or broad claims about productivity.

Table: What experts say about the new AI-cyber risk

Issue Current reality Why it matters
Main threat actor Human hackers using AI tools AI lowers the skill needed to launch effective attacks
Infrastructure weakness Older OT systems and long patch cycles Vulnerabilities can remain open for months or longer
Defender challenge Slow updates and limited staffing Utilities struggle to match attacker speed
Best immediate defense Segmentation, manual fallback, careful connectivity Limits the damage an attacker can do
Policy gap Limited AI-specific safeguards for critical infrastructure Experts say regulation has not kept up with risk

Timeline: how the concern escalated

Period Development Significance
Before widespread internet connectivity Energy systems were built for isolated operation Cybersecurity was not a core design assumption
Over time Operational systems became more connected New vulnerabilities emerged and were harder to fix
Recent years Generative AI became widely available Attackers gained tools that speed up and simplify cybercrime
Recent months AI companies began discussing grid security with utilities Recognition that infrastructure needs help now, not later

What does this mean for the public?

For most people, the story is not about an abstract debate over artificial intelligence. It is about whether essential services can keep functioning when cyber attackers become more capable.

The public consequences of a successful attack could be severe. Disrupted electricity can affect communications, transportation, healthcare, refrigeration and water systems. Even a contained breach can create expensive recovery work and erode confidence in the institutions meant to keep critical services stable.

That is why experts frame the issue as both an AI story and a resilience story. The technology is changing, but the basic lesson remains familiar: systems that are hard to patch, hard to isolate and hard to modernize will remain tempting targets.

What comes next?

The next phase is likely to involve a mix of tougher utility defenses, more federal attention and a louder push from security researchers for AI companies to shoulder more responsibility. But experts also warn against assuming AI will solve the very problems it is helping create.

There is interest in using advanced models to support defenders, from spotting anomalies to helping analysts respond faster. Yet the same tools can also help attackers move more quickly. That tension is why several experts are urging caution about adding too much AI into the most sensitive parts of the grid too quickly.

Corman described the risk as putting one AI system in conflict with another inside an OT environment that already needs stability more than novelty.

The core message from the cybersecurity community is clear: the biggest danger to energy systems is still people, not machines. But with AI now available to both sides, the gap between offense and defense may be widening at the worst possible moment.

For utilities, that means the task ahead is not to wait for a rogue superintelligence. It is to prepare for more ordinary attackers armed with much better tools.

Frequently asked questions

Are rogue AI agents the biggest threat to the power grid?

No. The biggest immediate threat is still human attackers using AI tools to improve cyberattacks. Security experts say the danger comes from people who can now move faster, automate more steps and exploit weaknesses in outdated utility systems.

Why are energy systems so vulnerable to cyberattacks?

Energy systems are vulnerable because many were designed long before modern cyber threats existed. They often rely on aging equipment, slow patch cycles and operational technology that is difficult to update, while some older devices no longer even have vendor support.

How does AI help cybercriminals target utilities?

AI helps cybercriminals by making it easier to research systems, write code, chain vulnerabilities and automate parts of an intrusion. Experts say it lowers the skill barrier, allowing less experienced attackers to behave more like advanced operators.

What can utilities do to reduce the risk?

Utilities can segment networks, maintain manual backup operations, limit unnecessary connectivity and patch systems as quickly as safe maintenance schedules allow. In some cases, experts say disconnecting especially vulnerable systems may be the safest option.

Is there enough regulation for AI in critical infrastructure?

No. Experts say AI-specific safeguards are still far behind the risks, especially compared with the stricter rules that govern nuclear and hazardous technologies. They want clearer limits, more oversight and more research focused on defensive uses.

Share this 🚀