While the industry argues about whether models will eventually kill everyone, the people who work on energy infrastructure have a more immediate complaint. The grid was already easy to attack. Generative AI has made the existing attackers better at it.
"It's literally any sociopath that wants to attack is now more powerful than they used to be," Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology, told The Verge. "This has been a force multiplier and continues to grow."
The threat model has not changed, only the throughput
Corman's framing last year, before rogue agents were the story, was bleaker and simpler. "We were always prey. We were just kind of surviving at the appetite of our predators," he said at a time when the Department of Homeland Security was warning that Iranian actors and sympathisers might target US systems.
The underlying problem is physical and old. Most of the equipment that keeps lights on, refrigerators cold and hospital devices running was never designed to sit on a network. Industrial control systems were built for isolated plants with long service lives, and they were connected to the internet later because remote monitoring was cheaper than sending a technician. Protocols written before authentication was a design consideration are now reachable from anywhere.
None of that requires a superintelligence. It requires someone competent and motivated. What large models change is how many people clear that bar and how fast they work: reconnaissance, spear-phishing that reads like a colleague wrote it, and enough code assistance to turn a known vulnerability into a working intrusion without deep expertise.
Why the experts are not leading with rogue agents
Justine Calma's reporting for The Verge puts the question to several security people directly, and they consistently rank bad actors with good tools above autonomous agents acting on their own.
That ordering is worth taking seriously, because it comes from the group with the most operational exposure. It is also not a dismissal. The incidents driving the current alarm were real, and the argument about probability is being conducted in round numbers by people with obvious stakes on both sides. The practical objection from infrastructure security is about sequencing: an agent that sets out to attack a substation still has to get through the same defences a human attacker does, and those defences are the thing nobody is funding.
There is also a quieter version of the agent problem already in the building. Cisco reports finding unsanctioned AI agents running on most of the networks it inspects, which for a utility means automated software with credentials in an environment where change control is supposed to be strict. That is not an apocalypse scenario. It is an asset inventory problem, and it is the kind that gets discovered during an incident.
What actually helps, and who pays
The defensive work is unglamorous and known: segment operational technology from corporate IT, get an accurate inventory of what is connected, enforce multi-factor authentication on remote access, and keep manual fallback procedures that work when the automation is untrusted.
The obstacle is economics. Utilities are rate-regulated, which means security spending has to be justified to a commission against bills that ratepayers will notice, and the benefit is an incident that does not happen. Smaller cooperatives and municipal utilities run the same exposed equipment with a fraction of the staff.
Meanwhile the load is growing. Data centre construction is adding demand to the same grid at a pace that has already reordered the political argument about how fast AI should be allowed to move. The industry driving that build-out is also the one supplying the tools that make the grid easier to attack, and utilities have to defend against both without anyone deciding whose bill it is.