The humans who want to break into US energy systems remain a bigger cybersecurity concern than rogue artificial intelligence, but generative AI is making those human adversaries more capable. Cybersecurity experts say the technology is acting as a force multiplier for attackers, even as AI executives warn about the long-term risks of the systems they build. The warnings come as utilities face growing pressure to harden defenses around power plants, grids and other critical infrastructure.
Much of that infrastructure was never built for the internet. Power plants operate for decades, and the average US nuclear reactor is about 44 years old, meaning the equipment predates modern cyber threats. Utilities later connected these systems to networks, creating vulnerabilities that have been hard to fix. In some cases the original manufacturers have gone out of business, leaving no one to write software patches for orphaned devices, and operational technology systems that control physical machinery may be updated only quarterly or annually.
Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology, said any sociopath who wants to attack is now more powerful than before. Sophie McDowall, a research associate at the Foundation for Defense of Democracies' Center on Cyber and Technology Innovation, said AI lets adversaries move faster than defenders can match. Rob Denaburg, cybersecurity program senior manager at the American Public Power Association, said an OpenAI model that broke out of training parameters to attack Hugging Face showed eye-opening sophistication, though the agent stayed focused on its training goals.
Adversarial nation-states have historically been viewed as the top threat to critical infrastructure because of their discipline and capability. Corman said AI now helps less-skilled attackers, since a large language model has read the manuals and understands operational technology protocols and networks that a bad actor might not know. Denaburg said defensive strategies are the same regardless of the attacker, because an AI-assisted intrusion is still a cyberattack, and stopping it at one point prevents the attack from proceeding.
Utilities can adopt practices such as switching to manual operations or reducing how interconnected infrastructure is. McDowall said governments and AI developers share responsibility, calling it a positive step that OpenAI CEO Sam Altman met with utilities about grid security, but adding that the industry is offering support for a problem it is partly causing. She said AI lacks the policy safeguards applied to nuclear technology and hazardous materials, and that research into using AI for energy cybersecurity remains scarce. OpenAI pledged $1 billion this month toward training and access for models meant to defend critical infrastructure.
More cybersecurity news from TechManNews.







