AI-Powered Cyberattacks Now Threaten US Power Grids and Water Systems
Nation-state hackers and criminals are using artificial intelligence to breach critical infrastructure that was already dangerously vulnerable.
Nearly two decades ago, researchers at Idaho National Laboratory demonstrated how vulnerable America's power infrastructure could be. Using just 30 lines of code in the Aurora Generator Test, they hacked a 27-ton diesel generator and destroyed it in front of utility executives, forcing the machine to tear itself apart through corrupted safeguards.
Today, artificial intelligence has made that kind of attack dramatically easier to execute—and the targets remain largely unprotected.
The New Threat Landscape
Cyberattacks on critical infrastructure were once rare, requiring highly specialized technical knowledge. Nation-states like China, Iran, and Russia possessed the capability but generally avoided causing visible disruption. Criminal hackers focused on financial gain rather than physical damage.
AI has fundamentally changed that calculus. The technology has eliminated the expertise barrier, allowing almost anyone with basic knowledge to generate code capable of breaching infrastructure systems. According to Alvaro Cardenas, a computer science professor at UC Santa Cruz, attackers no longer need highly skilled technical expertise—just a general idea of what's possible.
The threat is compounded by AI agents that can operate continuously without human limitations. "They don't sleep; they don't get tired; and they don't get sick," said Andy Bochman, an infrastructure resilience expert at West Yost.
Already Under Attack
Last month, dozens of water and wastewater systems in small towns nationwide were attacked by hackers likely associated with Iran, causing temporary water stoppages and flooding. The National Security Agency subsequently warned that hackers are actively using AI to target US infrastructure. President Donald Trump declared a national emergency over foreign interference in the power grid weeks later.
Jason Healey, a cybersecurity scholar at Columbia University, describes the converging dangers: "Geopolitics is eroding the idea that those with capability lack the intent, and AI is eroding the other part of it, that those with the intent lack the capability."
Why it matters
Most discussions of AI risk focus on hypothetical scenarios of rogue superintelligence. But the immediate danger is far more prosaic: AI making it trivially easy for hostile nations, terrorist groups, or lone actors to disrupt the electrical grids, water systems, and other infrastructure that modern life depends on. Many of these systems—particularly local water utilities—lack basic cybersecurity protections due to limited funding and aging equipment.
Preparing for What's Coming
Experts disagree on solutions, but several themes emerge. Bochman advocates pulling critical systems offline where possible, returning to analog controls and manual monitoring to eliminate digital attack surfaces. "The screen is the thing that is infinitely manipulatable," he said.
Healey calls for coordinated responses between government and AI companies, including international cooperation with countries like China. Utilities need to assume they will be targeted and improve cybersecurity accordingly, ideally with federal funding or support from AI companies themselves.
The fundamental problem remains: neither policymakers nor AI developers fully understand how to prevent the technology from being misused. As Bochman warns, when attacks escalate, "no one will know what to do or why because they're black boxes; the people that make them don't know what's going on inside."
These details were first reported by Sara Herschander for Vox.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
