Technology
The Verge

Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems

Source Entity

Justine Calma

September 22, 2026
Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems

Despite fears surrounding rogue AI, human error and systemic vulnerabilities remain the primary cybersecurity threats to critical energy infrastructure. Experts emphasize that the energy sector has long been susceptible to exploitation, necessitating a shift in focus toward foundational resilience.

The Persistent Human Element in Cybersecurity

While contemporary public discourse is increasingly dominated by the existential dread of rogue artificial intelligence orchestrating sophisticated cyber-assaults, the reality for critical infrastructure remains far more grounded. As noted by Joshua Corman, an executive in residence at the Institute for Security and Technology, our energy systems have long existed in a state of precarious survival, constantly exposed to the appetites of digital predators. The fixation on AI-driven doomsday scenarios often obscures a more mundane, yet far more dangerous, truth: the most significant cybersecurity risks to energy grids are rooted in human fallibility and systemic architectural weaknesses.

Historical Vulnerability vs. Modern Hysteria

The energy sector’s vulnerability is not a new phenomenon born of the AI age. Historically, these systems were built for reliability and operational longevity rather than digital defense. This 'security debt' has accumulated over decades, leaving the grid as a target for state-sponsored actors and opportunistic hackers alike. When the Department of Homeland Security issues warnings regarding foreign actors—such as Iranian sympathizers—targeting the U.S. power grid, it is rarely an AI-led operation. Instead, it is a calculated exploitation of existing, human-managed vulnerabilities that have been left unpatched for years.

The Illusion of AI-Centric Threats

Recent narratives surrounding AI-orchestrated cyberattacks have created a distraction from the underlying security failures that Corman highlights. By focusing on the hypothetical 'rogue agent' capable of autonomously dismantling a power grid, stakeholders often neglect the basic hygiene required to protect industrial control systems. The energy sector has essentially been 'prey' for a long time, not because of superior machine intelligence, but because of a lack of proactive resilience. The threat is not that AI will suddenly gain agency, but that humans will continue to leave the digital 'front door' unlocked.

Systemic Risk and Public Safety

The implications for public safety are profound. Energy systems are the backbone of modern civilization; their failure leads to cascading effects on healthcare, transportation, and emergency services. If the focus remains on futuristic AI threats rather than the current human-centric reality, the sector risks losing precious time that should be spent on hardening infrastructure. The transition to smart grids and digital monitoring only expands the attack surface, making the human element—both in terms of staff training and defensive oversight—the most critical variable in the security equation.

Future Trends in Infrastructure Defense

Looking ahead, the industry must pivot from a reactive posture to one of 'resilience by design.' This involves acknowledging that total prevention of cyberattacks is impossible in a hyper-connected world. Instead, the focus should shift toward incident response, rapid recovery, and limiting the blast radius of any successful intrusion. As long as human error, misconfiguration, and legacy software remain the primary vectors of attack, the debate over AI will remain a secondary concern compared to the imperative of securing the fundamental architecture of our energy systems.

Verification Required?

Read the full report from the primary source

Go to The Verge