Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems

The Verge News

Summary

The article discusses how human threats remain the primary cybersecurity risk to energy systems, with generative AI acting as a force multiplier for attacks, rather than rogue AI being the immediate danger.

<figure> <img alt="Art depicting a pattern of repeating eyeballs over a computer screen." data-caption="" data-portal-copyright="" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/2026/09/akrales_220309_4977_0292.jpg?quality=90&#038;strip=all&#038;crop=0,0,100,100" /> <figcaption> </figcaption> </figure> <p class="wp-block-paragraph">Before recent high-profile hacks raised the specter of AI possibly "<a href="https://www.theverge.com/ai-artificial-intelligence/991927/anthropic-ai-kill-all-humans">killing all humans</a>," our energy systems were already disturbingly vulnerable to cyberattack - and the risk is growing. </p> <p class="wp-block-paragraph">"We were always prey. We were just kind of surviving at the appetite of our predators," Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology (IST), <a href="https://www.theverge.com/cyber-security/693588/cybersecurity-cyberattack-critical-infrastructure-war-expert-iran">told me last year</a>. At the time, I was preoccupied with a <a href="https://www.cybersecuritydive.com/news/dhs-warns-of-heightened-cyber-threat-as-us-enters-iran-conflict/751314/">Department of Homeland Security warning</a> that <a href="https://www.dhs.gov/sites/default/files/ntas/alerts/25_0622_S1_NTAS-Bulletin-508.pdf">Iranian actors and sympathizers could target the US</a> with cyberattacks. </p> <p class="wp-block-paragraph">Last week, I called Corman up to chat about recent incidents of rogue AI a …</p> <p><a href="https://www.theverge.com/science/997834/ai-cyberattack-energy-critical-infrastructure">Read the full story at The Verge.</a></p>
Original Article
View Cached Full Text

Cached at: 09/20/26, 12:32 PM

# Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems Source: [https://www.theverge.com/science/997834/ai-cyberattack-energy-critical-infrastructure](https://www.theverge.com/science/997834/ai-cyberattack-energy-critical-infrastructure) Before recent high\-profile hacks raised the specter of AI possibly “[killing all humans](https://www.theverge.com/ai-artificial-intelligence/991927/anthropic-ai-kill-all-humans),” our energy systems were already disturbingly vulnerable to cyberattack — and the risk is growing\. “We were always prey\. We were just kind of surviving at the appetite of our predators,” Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology \(IST\),[told me last year](https://www.theverge.com/cyber-security/693588/cybersecurity-cyberattack-critical-infrastructure-war-expert-iran)\. At the time, I was preoccupied with a[Department of Homeland Security warning](https://www.cybersecuritydive.com/news/dhs-warns-of-heightened-cyber-threat-as-us-enters-iran-conflict/751314/)that[Iranian actors and sympathizers could target the US](https://www.dhs.gov/sites/default/files/ntas/alerts/25_0622_S1_NTAS-Bulletin-508.pdf)with cyberattacks\. Last week, I called Corman up to chat about recent incidents of rogue AI agents[orchestrating](https://www.theverge.com/ai-artificial-intelligence/994383/openais-rogue-ai-rubygems-hack)their own complex[cyberattacks](https://www.theverge.com/ai-artificial-intelligence/972441/openai-rogue-ai-agent-hacked-more-than-hugging-face)\. Even[AI executives](https://www.theverge.com/policy/995534/a-brief-history-of-ai-executives-calling-for-regulation)are[talking about](https://www.theverge.com/ai-artificial-intelligence/996923/ai-safety-slow-openai-anthropic)whether the technology they’re building could grow so out of control that it triggers an apocalypse\. If there is now a 10 percent chance of artificial intelligence one day killing all humans,[as some AI developers warn](https://www.theverge.com/ai-artificial-intelligence/991927/anthropic-ai-kill-all-humans), surely there’s a chance it could knock our lights out in the meantime? “Any sociopath that wants to \[attack\] is now more powerful than they used to be\.” But when I spoke to Corman and other cybersecurity experts, they were still more worried about generative AI in the hands of bad actors than they were about rogue agents\. As tech companies race to build ever more powerful AI models, utilities will similarly have to shore up their defenses — no matter who or what initiated the attack\. “It’s literally any sociopath that wants to \[attack\] is now more powerful than they used to be,” Corman tells me\. “This has been a force multiplier and continues to grow\.” Much of our critical energy infrastructure — keeping the lights on in our homes, food cold in our refrigerators, and life\-saving devices working in hospitals — was never designed to connect to the internet\. The lifespan of a power plant is typically decades long\. The average age of a nuclear reactor in the US is about[44 years](https://www.eia.gov/tools/faqs/faq.php?id=228&t=3)\. They weren’t constructed with today’s cybersecurity risks in mind, making them easy targets for hackers\. Eventually much of this infrastructure did connect to the internet\. It’s been difficult to fix any resulting cybersecurity vulnerabilities ever since\. Some of the companies that originally designed the equipment still in use in the power sector have gone out of business, leaving no one behind to develop a software patch for those orphaned devices\. Even when there is a patch available, applying it in a timely manner is another challenge\. Unlike IT software upgrades, operational technology \(OT\) systems that control physical machinery for critical infrastructure might only be designed to apply updates once each quarter or year\. Smaller utilities might also lack the resources, staffing, and know\-how to use the latest defensive measures\. “The true difference from AI is that it’s letting adversaries move more quickly — but it’s very challenging for those defending the infrastructure to match that pace,” says Sophie McDowall, a research associate at the Foundation for Defense of Democracies’ Center on Cyber and Technology Innovation\. Intent is a key factor when assessing the risks posed by generative AI\. When an OpenAI model managed to break out of the company’s training parameters to[attack AI lab Hugging Face](https://www.theverge.com/ai-artificial-intelligence/985385/openais-rogue-ai-model-hugging-face-cybersecurity-incident-reports-metr), “Some of the sophistication and the capabilities and just what we saw in that were really eye\-opening and in a sense terrifying in terms of how effective they were,” says Rob Denaburg, cybersecurity program senior manager at the American Public Power Association, which represents community\-owned utilities across 2,000 municipalities\. But Denaburg points out that even in the Hugging Face hack and similar instances of AI agents breaking into systems they were never supposed to target, the rogue agents remained focused on fulfilling their training goals\. If someone was to train a model to carry out an attack on energy infrastructure and agents broke out of the sandbox in that scenario, it would probably be a bigger concern for a utility\. Again, that involves human adversaries with malicious intent\. Historically, adversarial nation\-states were largely considered the biggest cybersecurity threat to critical infrastructure\. “They’re going to be more disciplined,” Corman says, and more capable of undertaking a sophisticated cyberattack\. Now, AI is making it easier for less\-skilled adversaries to launch an effective assault\. “A bad\-actor human can use these tools to be better than they naturally would be to attack things they normally didn’t know how to … because whereas they may not know OT protocols and OT networks and OT strategies, the LLM has read the manuals and does know what to do,” Corman says\. Utilities have to be more prepared, and defensive strategies are similar regardless of who the bad guy is\. “AI or not, it is at the end of the day, still a cyberattack,” Denaburg says\. “Even though AI can help an adversary maybe chain vulnerabilities together and automate some of the process going from initial access to exploit … as long as you can stop them in one spot, they can’t carry out that attack\.” Power companies can follow a range of[best practices to safeguard critical infrastructure](https://securityandtechnology.org/blog/launching-the-fragile-foundations-sprint/)\. Some of them are non\-cyber solutions, like ensuring systems can switch to manual operations when needed or in some cases pulling back on how interconnected this infrastructure is in the first place\. Increasingly, “in the face of the AI stuff, they’re starting to realize if we can’t protect it, disconnect it,” Corman says\. “They’re offering support for a problem that they are partially causing\.” Governments and the companies developing advanced AI models hold responsibility, too, McDowall says\. It was a positive step, she notes, that OpenAI CEO[Sam Altman recently met with utilities](https://www.politico.com/news/2026/09/10/sam-altman-pitches-utilities-on-ai-grid-defense-01070425)to discuss securing power grids\. But there’s a lot more they could do to prevent disaster, she says\. “They’re offering support for a problem that they are partially causing,” while failing to adequately control their own technology advancements, McDowall tells*The Verge*\. And while there are regulatory guardrails for research and development when it comes to nuclear technologies and hazardous materials, there aren’t yet the same policy safeguards for AI\. “This is a technological scientific development that could cause potential risk to critical infrastructure systems, that can cause potential threat to human life\. And so there does need to be restrictions,” McDowall says\.“I recognize that we also don’t want to limit development, but there’s no reason that we can’t drive research forward while also doing it responsibly\.” She points out that there’s a dearth of research into how AI might be used to improve cybersecurity for energy systems — particularly beyond just red teaming to discover vulnerabilities\. Earlier this month, OpenAI[pledged $1 billion](https://openai.com/index/daybreak-for-frontline-defenders/)toward subsidizing training and access to new models that are supposed to help defend critical infrastructure\. “In the coming months, AI\-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable,” OpenAI said in the September 3 announcement\. “Frontier AI can help defenders move faster\.” But Corman cautions against relying on friendly AI agents to fight off the malicious ones\. They could both be hard to control in the sensitive confines of an OT system for critical infrastructure\. “It’s also really dangerous to introduce too much change too fast in an OT environment,” Corman says\. “Now we have an AI bull fighting another AI bull in an OT china shop\.” **Follow topics and authors**from this story to see more like this in your personalized homepage feed and to receive email updates\. - Justine Calma

Similar Articles

Cybersecurity AI: Humanoid Robots as Attack Vectors

Papers with Code Trending

This paper presents a systematic security assessment of the Unitree G1 humanoid robot, revealing critical vulnerabilities including BLE provisioning protocol exploits, hardcoded AES keys, and a resident Cybersecurity AI agent capable of exfiltration and offensive operations, arguing for adaptive CAI-powered defenses as humanoids enter critical infrastructure.

The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop

Wired

Security researcher James Kettle presented findings at Black Hat showing that while agentic AI is limited in autonomously devising novel hacks, it becomes a powerful partner when guided by humans, leading to the discovery of a new vulnerability class called Shared-Parser Confusion.

AI models don't kill people – people kill people

Hacker News Top

The article argues that AI models themselves are not the primary threat; responsibility lies with companies deploying them. It discusses existential AI risk concerns from Anthropic researchers but contrasts these with other human-caused dangers like climate change.

The AI cybersecurity arms race is on

Reddit r/artificial

The article discusses the emerging AI cybersecurity arms race, where AI agents are employed for both malicious attacks and defensive measures, supported by recent incidents and research highlighting the growing threat and response.