Tech • AI • Robotics • Game

VIDEO
ENFR

Daily Podcast full article

Rogue Security analyzes human cybersecurity risks in energy systems

The latest reporting around AI and critical infrastructure points to a less cinematic but more immediate danger for power operators: people. Human attackers, human mistakes, weak processes, exposed systems and slow-moving operational technology still create the opening; AI mainly makes those openings cheaper and faster to exploit.

Generated September 20, 2026 at 4:18 PM UTC1348 words

The near-term threat is still human

The headline risk for energy cybersecurity is not a self-willed machine deciding to turn off the lights. It is a human adversary, employee, supplier, operator or executive decision chain interacting with old equipment, sprawling networks and uneven security budgets. The latest Verge report on energy systems and “rogue AI” frames the problem bluntly: specialists are more worried about generative AI in the hands of bad actors than about autonomous agents independently choosing to attack the grid .

That distinction matters because it changes the investment plan. If the main scenario is a runaway model, the answer seems to be exotic AI containment. If the main scenario is human intent amplified by AI, the answer is more prosaic: know what is connected, know who can touch it, train people against social engineering, segment operational technology, test backups, preserve manual operation, and make incident response boringly repeatable.

Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology, told The Verge that AI has become a force multiplier for anyone who wants to attack critical systems . The danger is not that AI invents cyber risk from nothing. The danger is that it lowers the skill floor. A person who does not deeply understand industrial protocols can ask a model for help reading public documentation, chaining known weaknesses or producing code that once required a rare specialist.

Why energy systems are so exposed

Energy infrastructure is a difficult cybersecurity environment because much of it was designed for reliability and longevity, not for internet-era hostility. The Verge notes that power plants often operate for decades and that the average U.S. nuclear reactor is around 44 years old . Equipment built under those assumptions was later connected to digital networks, vendor tools, remote maintenance paths and business systems that expand the attack surface.

Patching is also structurally different from ordinary IT. A laptop can be updated overnight; operational technology that controls physical machinery may have quarterly or annual maintenance windows, and a bad update can become a safety problem rather than a help-desk ticket . Smaller utilities face a further imbalance: they often defend indispensable infrastructure with fewer specialists, less tooling and less buying power than large investor-owned utilities or national agencies .

That is why “human risk” is not simply a synonym for careless employees. It includes procurement decisions, underfunded security teams, unclear ownership of legacy assets, weak authentication, poor endpoint inventory, vendor dependencies and change-management habits that do not match the speed of modern attack tooling. In energy, the carbon-based vulnerability is backward-compatible with every generation of hardware.

AI compresses the attacker’s work

Recent cybersecurity coverage reinforces the same pattern beyond the utility sector: AI agents and AI coding tools can move faster than human reviewers, but many of the lessons still look like old security hygiene in a new wrapper. TechCrunch reported that companies are struggling to oversee agents that can act at volumes humans cannot realistically review, with AI monitoring emerging as one proposed answer after the Hugging Face incident . Yet the article also highlighted skepticism: better logs, network monitoring and long-standing security processes may be more dependable than simply adding another AI watcher .

That maps directly onto energy operators’ dilemma. It is tempting to imagine a duel between hostile AI and defensive AI inside the control network. But introducing rapid, opaque automation into operational technology can create its own hazard. Corman’s warning in The Verge was that too much change too quickly in an OT environment can be dangerous, especially if defenders try to stage an “AI versus AI” fight inside systems that were never designed for that pace .

Red Sky Alliance, summarizing an industry letter backed by major technology firms, reported that AI-enabled cyberattacks are expected to become more widespread and sophisticated as models improve, and that signatories criticized the historic under-resourcing of critical-infrastructure security . The same post also stressed that water utilities and other essential services need funding, training, defensive AI access and hands-on support, which again points to people and institutions rather than machines alone .

The operational lesson: break the chain

For power companies, the most useful mental model is still the attack chain. Rob Denaburg of the American Public Power Association told The Verge that, AI or not, the event remains a cyberattack; if defenders stop it at one point between initial access and exploitation, the attack fails .

That means the practical agenda starts with visibility. Utilities need a current inventory of internet-facing assets, remote-access pathways, vendor accounts, service accounts, engineering workstations and unmanaged devices. They need to know which systems are truly isolated and which are only “air-gapped” in a diagram no one has validated since the last contractor visit.

The next layer is identity and access. Phishing-resistant authentication, least privilege, rapid credential revocation and monitored privileged access are not glamorous, but they directly address the human-assisted path attackers use most often. Training should also move beyond annual compliance videos. Operators, engineers, procurement staff and executives need scenario practice: what happens when a supplier account is compromised, when a vendor asks for emergency remote access, when an employee receives a plausible AI-generated message, or when a monitoring tool starts behaving oddly?

Resilience then becomes the final measure. Manual operations, offline backups, tested restoration, rehearsed communications and clear authority during degraded conditions are not secondary controls. In energy, they are the bridge between a cyber incident and continued public service. The Verge report notes that some experts are again considering a simple principle for systems that cannot be protected well enough: disconnect them .

Do not ignore rogue agents, but put them in proportion

None of this means autonomous AI agents are harmless. TechCrunch reported that agent oversight is now a real technical market, with startups and researchers building tools to inspect, block or escalate agent actions . MobiHealthNews, in a Q&A about rogue AI agents and healthcare cybersecurity, quoted True North ITG’s Matt Murren describing the OpenAI-Hugging Face incident as a different kind of challenge because incident response and forensics had to deal with many agents acting at once rather than a single human attacker . That kind of scale matters for any critical service that depends on electricity, hospitals included .

But the key question for the energy sector is intent and access. The Verge’s reporting makes clear that the most alarming grid scenario still starts with a human decision: someone trains, directs, deploys or grants access to a model that can help attack energy infrastructure . Autonomous behavior increases uncertainty, but it does not erase accountability. The weak process that gives an agent excessive permissions is still a human governance failure.

What operators should fund now

The best security program for this moment does not choose between basic hygiene and advanced AI defenses. It funds both, in order. First: asset discovery, segmentation, identity hardening, vulnerability management, backup testing, incident drills and workforce training. Second: detection engineering that can spot machine-speed reconnaissance, repeated failed access, abnormal protocol use and unusual data movement. Third: carefully bounded AI tools for defenders, with human authority retained for operational decisions.

Utilities should also demand clearer terms from AI and security vendors. If a managed service continuously ships AI-enabled changes into a utility environment, the contract should explain testing, rollback, logging, model access, data handling, incident notification and accountability. The same human process risk that haunts legacy OT can reappear in procurement if teams buy “AI security” faster than they can govern it.

The sober conclusion is also the useful one. Rogue AI is a legitimate concern, but energy cybersecurity is still mostly about people making systems safer or easier to exploit. The operators who win will not be the ones with the flashiest autonomy story. They will be the ones that identify ordinary failure modes before adversaries automate them.

Comments

Be the first to comment.

Sources from the last 72 hours

  1. [1]Humans, not rogue AI, are still the biggest cybersecurity risk to energy systemsSep 20, 2026, 12:00 PM UTC
  2. [2]The fix for rogue AI agents could be more AISep 17, 2026, 8:34 PM UTC
  3. [3]AI-Powered AttacksSep 18, 2026, 12:00 PM UTC
  4. [4]Q&A: Rogue AI agents and healthcare cybersecuritySep 18, 2026, 5:38 PM UTC

AI-generated article based on recent web research, then preserved as a dated editorial snapshot.