English

PLUS ULTRASecurity

Generative AI Acts as Force Multiplier for Cyberattacks on Energy Infrastructure

PLUS ULTRA by Amenoyomi

The increasing capability of generative AI is providing a "force multiplier" for human adversaries aiming to attack critical energy infrastructure. Cybersecurity experts, including Joshua Corman from the Institute for Security and Technology (IST), suggest that while rogue AI agents are a topic of debate, the more immediate threat is malicious actors using AI tools to increase the sophistication and speed of their attacks.

Much of the energy infrastructure—including power plants—was designed decades ago and was not built with modern internet-connected risks in mind. Many systems rely on operational technology (OT), which controls physical machinery. Experts note that updating these systems is often difficult due to long lifespans and the specialized nature of OT, which may only allow updates quarterly or yearly.

AI assists attackers by bridging knowledge gaps. A human adversary who lacks deep expertise in specific OT protocols can use Large Language Models (LLMs) to understand manuals and technical networks, allowing them to conduct more effective assaults. This capability lowers the barrier to entry for less-skilled actors to target essential services.

In response to these evolving threats, OpenAI has pledged $1 billion to subsidize training and access to models designed to help defend critical infrastructure. However, some experts warn against relying solely on AI-driven defense in sensitive OT environments, noting the complexity of introducing rapid technological changes into such critical systems.

PLUS ULTRAby Amenoyomi

Critical energy infrastructure relies on operational technology (OT) that was often designed decades ago, long before modern internet connectivity and its associated risks. Because these systems control physical machinery, their lifespans are measured in decades—with some U.S. nuclear reactors averaging 44 years of age. This legacy creates a structural vulnerability where original equipment manufacturers may no longer exist to provide software patches, and existing update cycles are often limited to quarterly or yearly intervals.

This structural rigidity creates a sharp asymmetry when generative AI is introduced. For attackers, AI acts as a force multiplier that bridges expertise gaps; an adversary who does not understand specific OT protocols can use large language models to analyze technical manuals and automate the exploitation process. While attackers can accelerate their operations using these tools, those defending the infrastructure find it challenging to match that pace due to the slow update cycles and limited resources of smaller utilities.

Introducing autonomous AI-driven defenses into these environments presents its own set of physical risks. In the sensitive confines of an OT system, introducing rapid and frequent technological changes can lead to unpredictable behavior in the machinery being controlled. As Joshua Corman of the Institute for Security and Technology notes, relying on autonomous AI agents to fight malicious ones in such a fragile environment is akin to having "an AI bull fighting another AI bull in an OT china shop."

Sources

  1. Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems (The Verge AI, 2026-09-20)
  2. DHS