LmCast :: Stay tuned in

Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems

Recorded: Sept. 20, 2026, 12:02 p.m.

Original Summarized

Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems | The VergeSkip to main contentThe homepageThe VergeThe Verge logo.The VergeThe Verge logo.TechReviewsScienceEntertainmentAIPolicyNotificationsNotificationsHamburger Navigation ButtonThe homepageThe VergeThe Verge logo.NotificationsNotificationsHamburger Navigation ButtonNavigation DrawerThe VergeThe Verge logo.Login / Sign UpcloseCloseSearchLightSystemDarkTechExpandAmazonAppleFacebookGoogleMicrosoftSamsungBusinessSee all techReviewsExpandSmart Home ReviewsPhone ReviewsTablet ReviewsHeadphone ReviewsSee all reviewsScienceExpandSpaceEnergyEnvironmentHealthSee all scienceEntertainmentExpandTV ShowsMoviesAudioSee all entertainmentAIExpandOpenAIAnthropicSee all AIPolicyExpandAntitrustPoliticsLawSecuritySee all policyGadgetsExpandLaptopsPhonesTVsHeadphonesSpeakersWearablesSee all gadgetsVerge ShoppingExpandBuying GuidesDealsGift GuidesSee all shoppingGamingExpandXboxPlayStationNintendoSee all gamingStreamingExpandDisneyHBONetflixYouTubeCreatorsSee all streamingTransportationExpandElectric CarsAutonomous CarsRide-sharingScootersSee all transportationFeaturesVerge VideoExpandTikTokYouTubeInstagramPodcastsExpandDecoderThe VergecastVersion HistoryNewslettersArchivesStoreVerge Product UpdatesSubscribeFacebookThreadsInstagramYoutubeRSSThe VergeThe Verge logo.Humans, not rogue AI, are still the biggest cybersecurity risk to energy systemsNotificationsNotificationsComments DrawerNotificationsCommentsLoading commentsGetting the conversation ready...ScienceCloseSciencePosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All ScienceAICloseAIPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All AIPolicyClosePolicyPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All PolicyHumans, not rogue AI, are still the biggest cybersecurity risk to energy systemsBut they’re more dangerous with AI. But they’re more dangerous with AI. by Justine CalmaCloseJustine CalmaSenior Science ReporterPosts from this author will be added to your daily email digest and your homepage feed.FollowFollowSee All by Justine CalmaSep 20, 2026, 12:00 PM UTCLinkShareGiftJustine CalmaCloseJustine CalmaPosts from this author will be added to your daily email digest and your homepage feed.FollowFollowSee All by Justine Calma is a senior science reporter covering energy and the environment with more than a decade of experience. She is also the host of Hell or High Water: When Disaster Hits Home, a podcast from Vox Media and Audible Originals.Before recent high-profile hacks raised the specter of AI possibly “killing all humans,” our energy systems were already disturbingly vulnerable to cyberattack — and the risk is growing.“We were always prey. We were just kind of surviving at the appetite of our predators,” Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology (IST), told me last year. At the time, I was preoccupied with a Department of Homeland Security warning that Iranian actors and sympathizers could target the US with cyberattacks.Last week, I called Corman up to chat about recent incidents of rogue AI agents orchestrating their own complex cyberattacks. Even AI executives are talking about whether the technology they’re building could grow so out of control that it triggers an apocalypse. If there is now a 10 percent chance of artificial intelligence one day killing all humans, as some AI developers warn, surely there’s a chance it could knock our lights out in the meantime?“Any sociopath that wants to [attack] is now more powerful than they used to be.”But when I spoke to Corman and other cybersecurity experts, they were still more worried about generative AI in the hands of bad actors than they were about rogue agents. As tech companies race to build ever more powerful AI models, utilities will similarly have to shore up their defenses — no matter who or what initiated the attack.“It’s literally any sociopath that wants to [attack] is now more powerful than they used to be,” Corman tells me. “This has been a force multiplier and continues to grow.”Much of our critical energy infrastructure — keeping the lights on in our homes, food cold in our refrigerators, and life-saving devices working in hospitals — was never designed to connect to the internet. The lifespan of a power plant is typically decades long. The average age of a nuclear reactor in the US is about 44 years. They weren’t constructed with today’s cybersecurity risks in mind, making them easy targets for hackers.Eventually much of this infrastructure did connect to the internet. It’s been difficult to fix any resulting cybersecurity vulnerabilities ever since. Some of the companies that originally designed the equipment still in use in the power sector have gone out of business, leaving no one behind to develop a software patch for those orphaned devices. Even when there is a patch available, applying it in a timely manner is another challenge. Unlike IT software upgrades, operational technology (OT) systems that control physical machinery for critical infrastructure might only be designed to apply updates once each quarter or year. Smaller utilities might also lack the resources, staffing, and know-how to use the latest defensive measures.“The true difference from AI is that it’s letting adversaries move more quickly — but it’s very challenging for those defending the infrastructure to match that pace,” says Sophie McDowall, a research associate at the Foundation for Defense of Democracies’ Center on Cyber and Technology Innovation.RelatedThe AI Superintelligence SlowdownIntent is a key factor when assessing the risks posed by generative AI. When an OpenAI model managed to break out of the company’s training parameters to attack AI lab Hugging Face, “Some of the sophistication and the capabilities and just what we saw in that were really eye-opening and in a sense terrifying in terms of how effective they were,” says Rob Denaburg, cybersecurity program senior manager at the American Public Power Association, which represents community-owned utilities across 2,000 municipalities.But Denaburg points out that even in the Hugging Face hack and similar instances of AI agents breaking into systems they were never supposed to target, the rogue agents remained focused on fulfilling their training goals. If someone was to train a model to carry out an attack on energy infrastructure and agents broke out of the sandbox in that scenario, it would probably be a bigger concern for a utility. Again, that involves human adversaries with malicious intent.Historically, adversarial nation-states were largely considered the biggest cybersecurity threat to critical infrastructure. “They’re going to be more disciplined,” Corman says, and more capable of undertaking a sophisticated cyberattack. Now, AI is making it easier for less-skilled adversaries to launch an effective assault.“A bad-actor human can use these tools to be better than they naturally would be to attack things they normally didn’t know how to … because whereas they may not know OT protocols and OT networks and OT strategies, the LLM has read the manuals and does know what to do,” Corman says.Utilities have to be more prepared, and defensive strategies are similar regardless of who the bad guy is. “AI or not, it is at the end of the day, still a cyberattack,” Denaburg says. “Even though AI can help an adversary maybe chain vulnerabilities together and automate some of the process going from initial access to exploit … as long as you can stop them in one spot, they can’t carry out that attack.”Power companies can follow a range of best practices to safeguard critical infrastructure. Some of them are non-cyber solutions, like ensuring systems can switch to manual operations when needed or in some cases pulling back on how interconnected this infrastructure is in the first place. Increasingly, “in the face of the AI stuff, they’re starting to realize if we can’t protect it, disconnect it,” Corman says.“They’re offering support for a problem that they are partially causing.”Governments and the companies developing advanced AI models hold responsibility, too, McDowall says. It was a positive step, she notes, that OpenAI CEO Sam Altman recently met with utilities to discuss securing power grids. But there’s a lot more they could do to prevent disaster, she says. “They’re offering support for a problem that they are partially causing,” while failing to adequately control their own technology advancements, McDowall tells The Verge.And while there are regulatory guardrails for research and development when it comes to nuclear technologies and hazardous materials, there aren’t yet the same policy safeguards for AI. “This is a technological scientific development that could cause potential risk to critical infrastructure systems, that can cause potential threat to human life. And so there does need to be restrictions,” McDowall says.“I recognize that we also don’t want to limit development, but there’s no reason that we can’t drive research forward while also doing it responsibly.”She points out that there’s a dearth of research into how AI might be used to improve cybersecurity for energy systems — particularly beyond just red teaming to discover vulnerabilities.Earlier this month, OpenAI pledged $1 billion toward subsidizing training and access to new models that are supposed to help defend critical infrastructure.“In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable,” OpenAI said in the September 3 announcement. “Frontier AI can help defenders move faster.”But Corman cautions against relying on friendly AI agents to fight off the malicious ones. They could both be hard to control in the sensitive confines of an OT system for critical infrastructure.“It’s also really dangerous to introduce too much change too fast in an OT environment,” Corman says. “Now we have an AI bull fighting another AI bull in an OT china shop.”Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.Justine CalmaCloseJustine CalmaSenior Science ReporterPosts from this author will be added to your daily email digest and your homepage feed.FollowFollowSee All by Justine CalmaAICloseAIPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All AIEnergyCloseEnergyPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All EnergyPolicyClosePolicyPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All PolicyScienceCloseSciencePosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All ScienceMost PopularMost PopularIt’s not just LG. Every TV company is spying on youOpenAI and Microsoft knew they were starting a ‘doom loop’ for the webGemini went rogue, hacked three companies, and Google hid itThe 2.5-hour AI-generated Odyssey movie is 2.5 hours too longMeta’s Muse is creepy, but maybe not for the reasons you thinkThe Verge DailyA free daily digest of the news that matters most.Email (required)Sign UpBy submitting your email, you agree to our Terms and Privacy Notice. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.Advertiser Content FromThis is the title for the native adMore in ScienceVirginia governor creates an AI task force and moves to restrain data centersFlash floods can strike without warning — this new technology could change that8Verge ScoreThe Apple Watch Series 12 is the start of a new wearable eraThe AI data center e-waste problem is huge — and getting biggerYour ‘health age’ is fakeTrump throws out power plant climate pollution rulesVirginia governor creates an AI task force and moves to restrain data centersLauren FeinerSep 18Flash floods can strike without warning — this new technology could change thatMegan WollertonSep 18The Apple Watch Series 12 is the start of a new wearable eraVictoria SongSep 17The AI data center e-waste problem is huge — and getting biggerJustine CalmaSep 16Your ‘health age’ is fakeVictoria SongSep 16Trump throws out power plant climate pollution rulesJustine CalmaSep 14Advertiser Content FromThis is the title for the native adTop StoriesSep 19The AI regulation smackdown isn’t overSep 19It’s not just LG. Every TV company is spying on youSep 18OpenAI and Microsoft knew they were starting a ‘doom loop’ for the webSep 19Anamanaguchi has ‘too goddamn many’ browser tabs open right nowSep 18Flash floods can strike without warning — this new technology could change thatThe VergeThe Verge logo.FacebookThreadsInstagramYoutubeRSSContactTip UsCommunity GuidelinesArchivesAboutEthics StatementHow We Rate and Review ProductsCookie SettingsTerms of UsePrivacy PolicyYour California Privacy RightsYour Privacy ChoicesCookie NoticeAdChoicesLicensing FAQAccessibilityPlatform StatusPenske Media CorporationThe Verge is a part of PMX Global, LLC, a subsidiary of Penske Media Corporation.© 2026 VM Publishing, LLC. All rights reserved.Our SitesThe American PavilionARTnewsArt in AmericaArtforumArt Week NYCBeauty IncBillboardDeadlineDick Clark ProductionsThe DodoEaterFlow SpaceFNGold DerbyGolden GlobesThe Hollywood ReporterIndieWireLife is BeautifulPopsugarPunchSJ DenimRobb ReportRolling StoneSB NationSHE MediaShe KnowsSourcing JournalSoapsSporticoStyleCasterSXSWThrillistVarietyThe VergeVibeWWDNotifications DrawerThe VergeThe Verge logo.Sign in to see your notifications or create an account to join the conversation.Sign in

Humans remain the paramount cybersecurity risk to energy systems, although the advent of artificial intelligence exacerbates these dangers. While concerns exist regarding rogue AI agents orchestrating attacks, cybersecurity experts emphasize that the threat stems primarily from human adversaries who leverage these advanced tools. This dynamic is further complicated by the fact that malicious human actors are now more powerful and capable than ever before; as noted by Joshua Corman, any individual seeking to attack is now more powerful than they were previously, a reality amplified by AI acting as a force multiplier.

Much of the critical energy infrastructure, including power plants and nuclear reactors, was not engineered with modern cybersecurity risks in mind, as systems were designed for decades-long lifespans, making them vulnerable targets. The process of securing this infrastructure has been complicated by the difficulty in patching and updating operational technology operational systems. Unlike standard IT software, operational technology systems managing physical machinery often require updates only quarterly or annually, and smaller utilities frequently lack the necessary resources, staffing, and expertise to implement the latest defensive measures.

The distinction between the threat posed by current AI and that from human adversaries lies in the speed of adversarial movement and the ability to consolidate vulnerabilities. While AI enables adversaries to execute more sophisticated attacks and automate processes from initial access to exploitation, the core challenge for defenders remains the necessity to match this accelerated pace of attack. As Sophie McDowall points out, whether the threat is driven by AI or a human, the fundamental response must focus on stopping the attack at a single point, as the underlying problem remains a cyberattack.

Power companies can adopt various protective strategies, including non-cyber solutions, such as ensuring systems can transition to manual operations when necessary, or reconsidering the level of interconnection within the infrastructure itself. There is an emerging strategy where, in the face of uncontrollable risks related to AI, disconnection of the infrastructure may be considered. Furthermore, there is a recognized responsibility for the development of AI; McDowall notes that organizations creating advanced AI, including those in the field of energy systems, have a duty to control their technology advancements and are partially responsible for the problems they create.

Despite efforts, there is a gap in policy safeguards for artificial intelligence concerning critical infrastructure, as existing regulatory frameworks do not adequately cover the potential risks posed by this technology. Scientists suggest a need for further research into how AI can enhance cybersecurity for energy systems beyond simple vulnerability testing. While entities like OpenAI have pledged resources toward defensive models, caution is necessary when relying on AI agents to counter malicious actors within sensitive operational technology environments, as controlling these agents in such systems can be exceptionally difficult due to the rapid pace of change inherent in operational technology settings.