Humans Remain the Primary Cyber Threat to Energy Infrastructure
As technology companies race to advance AI, critical power infrastructure remains vulnerable to human-led attacks, raising questions about modern defense strategies and systemic fragility.

The Persistent Vulnerability of Energy Grids
Before recent high-profile hacks raised the specter of AI possibly “killing all humans,” our energy systems were already disturbingly vulnerable to cyberattack — and the risk is growing. According to Joshua Corman, an executive in residence for public safety and resilience at the Institute for Security and Technology, the energy sector has long functioned as prey for sophisticated predators. This structural weakness stems from the fact that much of our critical energy infrastructure was never designed to exist in an interconnected digital environment.
The operational lifespan of critical power equipment often spans decades, meaning systems currently in use may predate modern cybersecurity standards. For example, the average age of a nuclear reactor in the United States is approximately 44 years. These legacy systems were constructed long before internet connectivity became a standard requirement, making them highly susceptible to modern digital threats.
AI as a Force Multiplier for Human Adversaries
The focus of current cybersecurity discourse has shifted toward the potential for rogue agents. However, experts like Corman emphasize that generative AI in the hands of bad actors is the more immediate concern. The technology allows malicious individuals to bypass their natural limitations, as Large Language Models (LLMs) can parse complex operational technology (OT) manuals and protocols that a human attacker might not understand otherwise.
Rob Denaburg, a senior manager for the cybersecurity program at the American Public Power Association, notes that while instances of autonomous agents orchestrating their own attacks have been observed in research settings, the core risk remains centered on intent. If a model is specifically trained to breach energy infrastructure, the resulting threat is driven by the human adversary guiding that process.
Operational Barriers to Defense
Protecting critical infrastructure is hampered by a lack of available software updates for orphaned devices, as some original equipment manufacturers have exited the market. Even when patches exist, applying them to OT systems is complex. Unlike IT environments, OT updates are often restricted to quarterly or annual windows to maintain the stability of physical machinery. Smaller utility providers, in particular, may lack the resources and technical staffing to keep pace with these rigorous maintenance requirements.
Sophie McDowall, a research associate at the Foundation for Defense of Democracies’ Center on Cyber and Technology Innovation, highlights the disparity between attacker and defender speeds. AI allows adversaries to move quickly by automating the process of chaining vulnerabilities together, a pace that existing grid defenses are currently struggling to match.
Calls for Regulation and Responsibility
As AI companies continue to develop more powerful models, some AI executives are openly questioning if the technology could eventually grow out of control. Despite these discussions, critics argue that these same companies must take accountability for the risks their advancements pose to national infrastructure. McDowall notes that while OpenAI has taken steps to engage with utilities, there is a lack of comprehensive policy safeguards comparable to those governing nuclear technologies or hazardous materials.
There is a growing consensus that while defensive measures like manual operation protocols are essential, disconnecting vulnerable systems remains a viable strategy. As industry stakeholders look toward the future, the integration of AI must be met with more rigorous research into cybersecurity defense, rather than focusing solely on red-teaming to identify flaws in existing infrastructure.
Sources
- The VergeHumans, not rogue AI, are still the biggest cybersecurity risk to energy systems