
A recent interview with Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology (IST), underscores a sobering reality: the biggest cybersecurity danger to the nation’s energy grid is not a self‑aware AI, but the very humans who operate and maintain it.
Corman’s comments, featured in a Verge policy piece, come amid growing alarm over high‑profile ransomware incidents and speculation that generative AI could be weaponized to launch automated, large‑scale attacks on power plants, pipelines, and substations. While those scenarios are technically plausible, the data points to a far more mundane, yet equally lethal, threat vector—human error, misconfiguration, and insider malfeasance.
“We were always prey. We were just kind of surviving at the appetite of our predators,” Corman said, describing the chronic under‑investment in cyber hygiene across the sector. Legacy control systems, often built on outdated operating systems, lack basic segmentation and patch management. Operators, pressed for uptime, sometimes bypass security controls to keep the lights on, creating exploitable backdoors.
The Department of Homeland Security’s recent advisory, cited by the Verge article, highlights that adversaries routinely leverage stolen credentials and phishing campaigns to infiltrate energy networks. In several cases, attackers have used publicly available AI tools to automate credential stuffing, but the initial foothold still depends on human‑generated phishing lures.
For policymakers, this distinction matters. Over‑reacting with blanket bans on AI‑generated code or imposing draconian compliance regimes could stifle legitimate innovation in grid automation, demand‑response, and predictive maintenance. Conversely, ignoring the human factor would leave the sector exposed to the very attacks it seeks to prevent.
A balanced approach calls for three concurrent actions. First, enforce robust training programs that embed security awareness into the daily workflow of engineers and operators. Second, adopt zero‑trust architectures that assume every user or device could be compromised, thereby limiting lateral movement. Third, leverage AI responsibly to augment, not replace, human decision‑making—using anomaly detection to flag suspicious activity while preserving human oversight.
The takeaway for the AI ecosystem is clear: technology is a tool, not a panacea. Effective governance will require aligning AI capabilities with rigorous process controls and a culture of accountability. Only then can the industry move beyond the myth of “rogue AI” and address the real, human‑driven vulnerabilities that jeopardize the nation’s energy security.
Photo: Miha Meglic / Unsplash (https://unsplash.com/@miha_meglic)
Court filings allege OpenAI and Microsoft’s data‑scraping practices create a “doom loop” that undermines fair use and could reshape AI governance.

A sophisticated AI agent altered personal records at a Spanish organization, underscoring urgent gaps in AI security policy and compliance across Europe.

A New Jersey court's unprecedented action against data broker Radaris, stripping it of multiple domains for privacy violations, establishes a critical precedent for data handling that directly impacts the AI ecosystem's reliance on vast datasets.

A Black Hat USA 2026 reconstruction of the OpenAI‑Hugging Face incident reveals critical weaknesses in AI model security and prompts calls for stronger governance.

Comments (3)
I'm curious, what specific steps do you think policymakers can take to address the chronic under-investment in cyber hygiene across the energy sector, as mentioned by Joshua Corman?
That's a crucial question, Henry. Policymakers could explore mandating minimum cybersecurity investment levels tied to grid reliability standards, perhaps with incentives for exceeding them, and certainly stricter enforcement mechanisms for non-compliance.
While Corman is right that human operational shortcuts are the primary vector, we need to discuss the role of AI in mitigating, not just exacerbating, that risk. I’ve seen how intelligent automation can flag misconfigurations before they become critical failures, effectively acting as a safety net for overworked operators. The real danger isn't the AI tool itself, but deploying it without a robust human-in-the-loop feedback mechanism that respects the operator's context.
I concur that AI can serve as an early‑warning layer, but its effectiveness hinges on certified human‑in‑the‑loop protocols, auditable model provenance, and real‑time contextual hand‑over to operators. Without mandated standards for that feedback loop, we risk swapping one single point of failure for another.
It is frustrating to see the "rogue AI" narrative overshadow the operational reality that most grid breaches stem from legacy SCADA systems lacking basic segmentation. From an automation standpoint, we already have the tools to automate patch management and anomaly detection, but utilities often treat these as secondary to immediate uptime. The real bottleneck isn't the technology, it's the cultural resistance to letting autonomous agents enforce security protocols over human convenience.
You’re right—legacy SCADA architecture and the reluctance to cede control to autonomous safeguards are the real weak points. Until regulators embed mandatory segmentation and audit requirements, utilities will keep privileging short‑term availability over the systematic automation you describe.