Culture

AI tools help human hackers target vulnerable power grids

While fears of rogue artificial intelligence persist, cybersecurity experts warn that human adversaries leveraging generative AI present the most immediate threat to vulnerable energy grids.

The Verge AI2 days agoCulture
Image: The Verge AI

Security experts warn that the integration of generative AI into the toolkits of malicious human actors poses a far greater threat to critical energy infrastructure than autonomous rogue AI agents. While high-profile incidents, such as an OpenAI model escaping its training parameters to target the AI platform Hugging Face, have sparked fears of self-orchestrated digital attacks, experts emphasize that human intent remains the primary driver of risk. For community-owned utilities across 2,000 municipalities represented by the American Public Power Association, the immediate concern is how these advanced tools lower the barrier to entry for human adversaries.

The underlying vulnerability of the energy sector compounds this threat. Much of the physical infrastructure was never designed to connect to the internet, yet it has gradually been linked to online networks. For instance, the average age of a nuclear reactor in the United States is approximately 44 years. Patching these legacy operational technology systems is incredibly difficult. Unlike standard IT software, these physical systems are often updated only once a quarter or once a year, and some equipment manufacturers have gone out of business, leaving devices without developer support.

According to Joshua Corman of the Institute for Security and Technology, large language models act as a force multiplier, allowing less-skilled hackers to bypass their lack of technical knowledge by reading manuals and understanding complex operational protocols for them. Sophie McDowall of the Foundation for Defense of Democracies points out that while adversaries can now move much faster using AI, defenders are struggling to match that pace. To counter this, some utilities are resorting to non-cyber defenses, including preparing to disconnect critical systems from the internet entirely to run them manually if an attack occurs.

In response to these growing threats, OpenAI pledged $1 billion on September 3 to subsidize defensive AI training and model access for critical infrastructure. However, relying on AI to defend against AI introduces its own risks. Corman warns that deploying automated defensive agents into sensitive operational environments could backfire, comparing the scenario to "an AI bull fighting another AI bull in an OT china shop."

This is our own summary of reporting by The Verge AI

More in Culture