Share with your CISO
AI is making bad humans more dangerous, and that’s the more urgent threat to energy infrastructure than rogue autonomous agents. Cybersecurity experts at the Institute for Security and Technology and the American Public Power Association tell The Verge that generative AI functions as a force multiplier for low-skill attackers, giving them fluency in operational technology (OT) protocols they never had to learn. OpenAI pledged $1 billion in September to subsidize AI-assisted grid defense, while experts warn that deploying AI agents inside fragile OT environments may create as many problems as it solves.
What this means for your business
The 44-year average age of a US nuclear reactor tells you most of what you need to know about the attack surface. Energy infrastructure was built for physical isolation and got connectivity bolted on later, often with no vendor left alive to issue patches. If your organization depends on grid reliability, whether as a utility itself or as an enterprise with significant operational exposure, the question isn’t whether AI changes the threat model. It does. The question is which layer of your defense breaks first when the attacker has an LLM coaching every move.
The framing that “it’s still just a cyberattack, AI or not” is correct as a defensive principle but dangerously easy to misread as reassurance. What AI actually changes is the attacker’s skill floor. OT protocols like Modbus or DNP3 (the communication languages that tell industrial machines what to do) were obscure enough to filter out casual adversaries. An LLM trained on publicly available industrial manuals removes that filter entirely. Nation-state actors were already capable; now a motivated individual with a laptop and API access is closing that gap fast. Defenders, constrained by quarterly patch cycles and understaffed security teams at smaller utilities, cannot match that acceleration without structural changes that go well beyond buying a new tool.
OpenAI’s $1 billion pledge and Sam Altman’s meetings with utility executives look more like liability management than genuine partnership when you hold them against the company’s simultaneous acceleration of model capability, and security researchers who depend on lab cooperation have obvious incentives to treat the gesture generously. The harder problem is that deploying AI defensively inside an OT environment introduces its own instability. Joshua Corman’s “AI bull fighting another AI bull in an OT china shop” isn’t a colorful metaphor; it’s a real failure mode where two autonomous systems with imperfect situational awareness interact inside infrastructure that was designed for predictable, human-supervised control. If your vendor is pitching AI-native grid defense this budget cycle, the deployment-risk question deserves as much scrutiny as the threat model it’s meant to solve.
Concept deep-dive: Operational Technology (OT)
OT refers to the hardware and software that monitors and controls physical equipment, think the systems that open valves, regulate voltage, or spin turbines, as distinct from IT systems that process data. OT was designed for reliability and longevity, not connectivity, which is why a 30-year-old programmable controller still running a substation was never meant to receive a security patch. When OT connects to internet-facing networks, it inherits cyber exposure without the update cadence that IT security depends on.
Based on reporting from Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems, originally published 2026-09-20 08:00:00.
