The Bigger AI Threat May Be Human-Directed Attacks on Critical Infrastructure
Summary
The article argues that the most immediate AI-related catastrophe may not be a rogue superintelligence, but people using AI to attack already vulnerable critical infrastructure. It recalls the Idaho National Laboratory’s Aurora Generator Test, in which researchers used about 30 lines of code to manipulate a 27-ton diesel generator until it violently fell out of sync with the power grid and suffered severe mechanical damage. AI has since lowered the technical barrier to cyberattacks, allowing people with only a general understanding of what is possible to attempt operations that once required highly specialized expertise. AI agents can also expand the scale of attacks because they can work continuously, while many local water systems, pipelines, desalination plants, and other utilities remain underfunded and poorly protected even against conventional intrusions. The article says recent attacks on water and wastewater systems in small US towns, likely linked to Iranian hackers, caused temporary stoppages and flooding; those incidents were not definitively tied to AI, although the National Security Agency warned that hackers were using AI to target US infrastructure. It also notes that foreign governments have previously breached infrastructure systems without causing major disruption, while worsening geopolitics and AI could separately increase both the intent and capability to attack. The article cites warnings that AI could help lone actors, terrorist groups, or hostile states conduct broader campaigns, and notes President Donald Trump’s declaration of a national emergency over foreign interference in the power grid. Experts quoted in the piece call for utilities to assume they are targets, improve cybersecurity with federal or AI-company support, and coordinate responses across governments and developers. Another proposed defense is to limit unnecessary digitization and keep critical controls offline or partly analog, since operators may not understand failures produced by opaque AI systems. The article concludes that the precise level of infrastructure exposure remains uncertain, making preparation and accountability urgent even without a fully autonomous AI system.