The news
Recent high-profile incidents have revived talk of artificial intelligence launching independent attacks on critical infrastructure. Energy systems, however, already sat in a state of chronic exposure long before those incidents. Joshua Corman of the Institute for Security and Technology described the prior condition plainly: operators were “always prey” and survived only at the tolerance of potential attackers.
The Department of Homeland Security had already issued warnings about Iranian actors and sympathizers targeting U.S. infrastructure. Those warnings predated any prominent AI-related events. Corman’s remarks, first given last year and revisited last week, frame the current risk as an extension of that earlier pattern rather than a sudden leap driven by new technology.
Context
Energy grids and related control systems have relied on the same basic architecture for decades. Many components were never designed for constant external connectivity, yet they now sit on networks that face routine scanning and probing. The arrival of public discussion around rogue AI has not altered those underlying conditions; it has mainly shifted attention toward speculative future threats.
Before the recent focus on autonomous machine aggression, federal agencies tracked repeated campaigns by state-linked human operators. These efforts exploited known gaps in access controls, unpatched equipment, and weak segmentation. Corman’s assessment last year centered on that reality, and his follow-up conversation last week reaffirmed the same point: the appetite of existing human actors continues to set the practical limit on system safety.
No reporting in the source material shows AI systems independently planning or executing large-scale energy disruptions. The documented record instead points to human operators using familiar tools against familiar weaknesses.
Details
Corman serves as executive in residence for public safety and resilience at the Institute for Security and Technology. In that role he has tracked how public warnings from the Department of Homeland Security translate into operational risk for utilities and related sectors. His comments emphasize continuity: the same exposure that existed last year persists, and incremental improvements in basic defenses remain the primary lever available to operators.
The Verge article that captured these remarks notes that attention on hypothetical AI scenarios has drawn focus away from the human-driven incidents already occurring. Corman’s phrasing—“surviving at the appetite of our predators”—captures the passive posture many asset owners have adopted. That posture predates current AI capabilities and does not require new breakthroughs in machine autonomy to become untenable.
Federal warnings about Iranian actors and sympathizers supplied concrete examples of the threat environment Corman described. Those warnings addressed both direct state activity and loosely affiliated sympathizers who could act with varying degrees of coordination. The pattern aligns with earlier incidents in which human operators probed industrial control systems for reachable devices, default credentials, and exposed remote-access portals.
Reactions / counterpoints
The source material does not present competing expert views that contradict Corman’s assessment. It records his statements alongside the Department of Homeland Security warning and the timing of recent AI-related coverage. No data in the reporting indicates that AI has yet displaced human operators as the dominant vector against energy assets.
Why it matters
Resources directed at speculative AI defenses will not close the access-control and patching gaps that human attackers already use. Operators still face the same requirement to reduce reachable attack surface, enforce least-privilege access, and maintain basic asset inventories. Until those steps receive sustained attention, the limiting factor on system compromise remains the restraint or capability of existing human adversaries rather than any future autonomous system.
The record of warnings and observed incidents shows that measurable hardening of current infrastructure produces clearer risk reduction than monitoring for hypothetical AI breakthroughs. Energy owners who continue to treat basic hygiene as secondary to advanced-threat theater leave their systems in the same exposed state Corman described last year. That state is not new, and it will not be solved by waiting for a different class of attacker to appear.
---
Sources:
{"word_count": 682, "sources_used": 1}
No comments yet