Sep 21, 2026
ManyPress

Advertisement

Artificial Intelligence

While concerns about rogue AI agents exist, cybersecurity experts say generative AI tools in the hands of malicious human actors remain the primary threat to critical energy infrastructure.

ManyPress

ManyPress

ManyPress Editorial

3 min readSource:The Verge AI
Cybersecurity Experts Warn Humans Using AI Pose Greater Threat to Energy Grids

Key facts

  • The average age of a nuclear reactor in the US is approximately 44 years, complicating efforts to secure them against modern cyber threats.
  • Generative AI allows attackers to access and utilize technical manuals and protocols for operational technology networks, increasing the effectiveness of less-skilled hackers.
  • The American Public Power Association represents community-owned utilities across 2,000 municipalities.
  • OpenAI pledged $1 billion in September to subsidize training and access to models designed to help defend critical infrastructure.
  • Operational technology systems often have limited update cycles, sometimes receiving patches only once per quarter or year.

Cybersecurity experts warn that critical energy infrastructure remains highly vulnerable to cyberattacks, with generative AI acting as a force multiplier for bad actors. While fears of rogue AI agents persist, professionals emphasize that human adversaries using AI to exploit outdated systems pose the most immediate danger to power grids and utilities.

By the numbers

44 years
average age of a US nuclear reactor
2,000
number of municipalities represented by the American Public Power Association
$1 billion
amount pledged by OpenAI for critical infrastructure defense

Vulnerabilities in Aging Infrastructure

Much of the energy infrastructure currently in use was not originally designed for internet connectivity, creating significant security challenges. The average age of a nuclear reactor in the United States is approximately 44 years, and many power plants rely on equipment from manufacturers that are no longer in business, making it difficult to obtain software patches. Furthermore, operational technology systems that control physical machinery are often designed to receive updates only quarterly or annually, leaving them exposed for longer periods than standard IT systems.

AI as a Tool for Adversaries

Experts note that generative AI allows less-skilled attackers to conduct sophisticated operations by providing them with knowledge of operational technology protocols and networks that they might otherwise lack. By automating the process of chaining vulnerabilities together, AI enables adversaries to move faster than defenders can respond. While some AI models have demonstrated the ability to break out of training parameters, experts like Rob Denaburg of the American Public Power Association suggest that these agents typically remain focused on their training goals unless specifically directed by a human to target infrastructure.

Defensive Strategies and Policy

To mitigate these risks, utilities are increasingly considering non-cyber solutions, such as reverting to manual operations or disconnecting critical systems from the internet entirely. Sophie McDowall of the Foundation for Defense of Democracies argues that while companies like OpenAI are beginning to engage with utilities, there is a need for stronger regulatory guardrails similar to those governing nuclear or hazardous materials. OpenAI recently pledged $1 billion to support the development of AI models aimed at defending critical infrastructure, though some experts warn that introducing AI-driven defenses into sensitive operational environments could create additional instability.

Advertisement

This article was independently rewritten by ManyPress editorial AI from reporting originally published by The Verge AI.

Artificial Intelligence