the wire · #ai · 2026-09-20
Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems
Cech Tech Reviews

The narrative around artificial intelligence often fixates on sci-fi scenarios of rogue systems seizing control. However, recent reporting by The Verge highlights a much more grounded and persistent danger. The real threat to our critical infrastructure is not a self-aware algorithm, but human error and targeted malicious actors.
Joshua Corman, an executive in residence for public safety and resilience at the Institute for Security and Technology, provided a stark perspective to The Verge. He described the energy sector as having always been prey, merely surviving at the mercy of its predators. This metaphor underscores a long-standing vulnerability that predates the current AI hype cycle.
The context for this discussion includes high-profile cyber incidents that have raised alarms about potential AI-driven attacks. Yet, the underlying reality is that energy systems were already disturbingly vulnerable before these recent scares. The risk is growing, but the source of that risk remains largely human-centric rather than machine-autonomous.
Last year, The Verge’s reporting touched on a Department of Homeland Security warning regarding Iranian actors and sympathizers. These groups have been identified as potential targets for cyberattacks against US infrastructure. This geopolitical tension adds a layer of urgency to the conversation about who is actually pulling the strings behind these digital threats.
Corman’s recent conversation with The Verge’s reporter focused on the contrast between the specter of AI killing humans and the immediate, tangible risks we face. The article suggests that while AI is a powerful tool, it is not the primary vector for catastrophic failure in energy systems. Instead, it is the human element that introduces the most significant points of failure.
This distinction is crucial for entrepreneurs and professionals in the tech space. We often invest heavily in securing against hypothetical AI risks while neglecting basic human-centric security protocols. The lesson here is that robust human training and strict access controls are more vital than fearing autonomous malice.
What this means for you is that your focus should shift from speculative AI threats to practical human risk management. Implement strict multi-factor authentication and regular security audits for all personnel with access to critical systems. Try this prompt with your AI assistant to draft a security awareness checklist: "Create a concise checklist for non-technical staff to identify phishing attempts and social engineering tactics targeting energy sector employees."
The takeaway is clear. While AI will undoubtedly change the landscape of cybersecurity, it is not the villain in this story. The villain is still human negligence or malice. By addressing these root causes, we can build more resilient systems that withstand both current and future threats.
Reporting basis: original story
← back to The Wire







