Forget Rogue AI: Humans Are Still the Grid's Biggest Threat
When the lights go out, our first instinct in the modern era might be to blame a sophisticated, autonomous AI gone rogue. It’s a compelling, cinematic...

When the lights go out, our first instinct in the modern era might be to blame a sophisticated, autonomous AI gone rogue. It’s a compelling, cinematic narrative—a supercomputer deciding humanity is obsolete and shutting down the power grid. But according to cybersecurity experts, this dystopian fear misses the mark entirely. The real threat to our energy systems doesn't come from lines of self-aware code; it comes from the people sitting behind the keyboards.
The energy systems that power our daily lives are indeed under constant threat, but the vulnerabilities are deeply rooted in legacy technology and human behavior. Joshua Corman, a public safety and resilience expert at the Institute for Security and Technology (IST), starkly summarized the situation: critical infrastructure has long been in a state of extreme vulnerability. As he put it, we have always been "prey," effectively surviving only at the appetite of our predators.
Government agencies, including the Department of Homeland Security, frequently issue warnings about cyberattacks targeting critical infrastructure. Yet, these warnings are rarely about sentient algorithms. They are about human hackers, state-sponsored groups, and cybercriminals looking to exploit basic security flaws for geopolitical leverage or financial gain.
Why does this distinction matter? Because misidentifying the threat leads to misallocated defenses. AI is undoubtedly changing the cybersecurity landscape. It acts as a powerful force multiplier for bad actors, allowing them to automate vulnerability scanning or draft highly convincing phishing emails at scale. However, in these scenarios, AI is merely a tool—a highly efficient crowbar used to pry open a window. The burglar orchestrating the break-in is still human.
Furthermore, the vulnerabilities that allow these attacks to succeed are overwhelmingly human. The vast majority of successful breaches in critical infrastructure boil down to human error: an employee falling for a social engineering scam, a delayed software patch, or a poorly secured network endpoint connecting an old power plant to the modern internet.
The fear of an AI apocalypse taking down the power grid makes for great fiction, but it is a dangerous distraction in reality. Securing our energy future requires us to focus on the unglamorous, foundational work of cybersecurity: training personnel, updating legacy systems, and enforcing strict access controls. Until we fix our own operational blind spots, blaming the machines is simply an excuse for human negligence.
Key Points
- Public fear often centers on autonomous AI attacking critical infrastructure, but experts say this is a distraction.
- The real danger lies in human hackers and state-sponsored cyberattacks exploiting existing vulnerabilities.
- Energy systems are already highly vulnerable, largely due to legacy technology and routine human error.
- While AI is used by bad actors as a tool to accelerate attacks, humans remain the orchestrators.
Why It Matters
Misidentifying the primary source of cyber threats can lead to misguided security strategies, leaving basic human vulnerabilities and legacy systems dangerously unpatched.
Sources:
更多专栏

Your Next Coworker is a Blob That Orders Burritos
For decades, enterprise software has been synonymous with sterile dashboards, en...

The Midnight Bill: Why AI Agents Demand Hard Budget Caps
The dream of artificial intelligence is to have a tireless digital assistant wor...

Beyond Transformers: How Mamba is Rewriting the Rules of AI Memory
Think about how a human reads a sprawling, thousand-page fantasy series. You don...