Cybersecurity risks to energy systems continue to stem primarily from human actors rather than rogue artificial intelligence, even as recent high-profile incidents have raised concerns about AI’s potential to cause harm at scale. Long before these developments captured public attention, critical energy infrastructure was already considered disturbingly vulnerable to attack, and that risk is growing.
Concerns about state-sponsored threats have persisted for some time. A Department of Homeland Security warning previously flagged the possibility that Iranian actors and sympathisers could target the United States with cyberattacks, underscoring the ongoing exposure of essential systems that underpin daily life.
Why Energy Infrastructure Remains Exposed
According to Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology, the underlying vulnerability of energy systems predates current anxieties about artificial intelligence. He described the sector as having long operated in a precarious position, effectively surviving only at the discretion of those capable of exploiting its weaknesses.
His remark that these systems were “always prey” and “just kind of surviving at the appetite of our predators” captures the persistent fragility of the infrastructure that societies depend upon. The observation highlights that the exposure of energy networks is not a new phenomenon triggered by emerging technology, but a long-standing structural concern.
The Role of AI in Emerging Threats
While recent incidents involving rogue AI have amplified fears about the future of cybersecurity, the assessment remains that human decisions, actions and intentions are still the dominant factor behind attacks on critical infrastructure. Artificial intelligence may introduce new dimensions to the threat landscape, but it has not displaced people as the principal source of danger.
The distinction matters for how defences are prioritised. Framing AI as the central menace risks diverting attention from the human-driven attacks that have historically posed the greatest challenge to energy systems. The focus, according to this view, should remain on addressing the vulnerabilities that adversaries have long been positioned to exploit.
As discussions around artificial intelligence and security intensify heading into 2026, the enduring message is that the protection of energy systems depends on confronting familiar risks. The threat posed by human actors, including state-linked groups, continues to define the security posture of critical infrastructure, with recent AI-related incidents adding to rather than replacing existing concerns.
Source
Image: theverge.com