Listen to this article

Narrated by Charlotte · The Noble House

Compass — Strategic Intelligence

The narrative surrounding artificial intelligence and critical infrastructure has shifted dramatically in recent years. As computational power increases and generative models become more sophisticated, a pervasive anxiety has taken hold regarding the fear that autonomous, rogue AI systems might one day seize control of the energy grid, causing widespread blackouts or physical destruction. This fear, while dramatic, obscures a more immediate and statistically probable reality. The primary threat to energy grid cybersecurity is not the machine, but the human. Nation-states, criminal syndicates, and disgruntled insiders remain the decisive actors in the cyber landscape, leveraging AI tools to amplify their capabilities rather than being replaced by them. The energy sector’s vulnerability is rooted in human error, malicious intent, and the complex social dynamics of organizational security, not in the emergence of independent digital consciousness.

The Persistence of Human Agency in Cyber Operations

The misconception that AI operates independently in cyber warfare stems from a fundamental misunderstanding of how these technologies are deployed in the field. In reality, AI serves strictly as a force multiplier for human threat actors. Experts confirm that real-world threat actors, who are people, are still the ones pulling the strings in AI-driven cyber operations [4]cnn.comAI isn’t the biggest cybersecurity problem. People areExperts note that real-world threat actors are still the ones pulling the strings, using AI tools to amplify human-driven attacks on critical infrastructure.Open source ↗. This dynamic is particularly evident in the energy sector, where nation-states have historically been the most disciplined and capable adversaries [1]theverge.comHumans, not rogue AI, are still the biggest cybersecurity risk to energy systemsHistorically, adversarial nation-states were largely considered the biggest cybersecurity threat to energy systems, but humans remain the primary vector.Open source ↗. These state-sponsored groups do not rely on rogue algorithms to execute attacks; they utilize AI to enhance reconnaissance, automate phishing campaigns, and obfuscate their digital footprints. The agency remains firmly with the human operator, who defines the objectives, selects the targets, and makes the strategic decisions.

The distinction between the tool and the user is critical for understanding the current threat landscape. AI models are trained on existing data and lack the intrinsic motivation to act against human interests. They do not possess goals, desires, or the capacity for independent malice. When an AI system is used to compromise an energy grid, it is because a human has programmed it to do so or has exploited its vulnerabilities. The chaotic nature of current AI development has created new avenues for attack, but the intent behind these attacks is purely human [4]cnn.comAI isn’t the biggest cybersecurity problem. People areExperts note that real-world threat actors are still the ones pulling the strings, using AI tools to amplify human-driven attacks on critical infrastructure.Open source ↗. This is an evolution of traditional cyber warfare tactics. The sophistication of the tools has increased, but the nature of the threat has not fundamentally changed. The energy grid is targeted because humans want it to be disrupted, not because the grid itself has become a sentient entity.

Furthermore, the complexity of modern energy systems requires human interpretation and decision-making that AI cannot yet replicate. While AI can analyze vast amounts of data to identify anomalies, it cannot understand the geopolitical context or the strategic value of a specific substation. It cannot negotiate, deceive, or adapt to social engineering tactics in the way a skilled hacker can. The human element is essential to the attack chain, from the initial spear-phishing email to the final execution of the exploit. Without human direction, AI remains a dormant potential, not an active threat. The consensus across aggregated reporting confirms that human actors, not rogue AI, are the primary threat to energy infrastructure [6]ground.newsGround News Article: Humans, not rogue AI, are still the biggest cybersecurity risk to energy systemsAggregated reporting confirms the consensus that human actors, not rogue AI, are the primary threat to energy infrastructure.Open source ↗.

Compass Predictive Analytics

Signal gauge

57%

Evidence Reliability

5 Of 5 Validated Assertions Have Complete Exact Span And Ownership Lineage. · Positive

tracked

Quantifies the conservative evidence floor after exact-span and independent-owner checks.

100%ObservedTraceability56.6%95%Lower Bound
5 evidence references

Signal gauge

98%

Evidence Freshness

Evidence Freshness Is 98 For The Selected Signal. · Positive

tracked

Separates current evidence from aging context using a declared decay window.

97.9%TimeDecayed Fres
5 evidence references
The Persistence of Human Agency in Cyber Operations The misconception that AI operates independently in cyber warfare stems from a fundamental misunderstanding of how these technologies are deployed in the field.
The Persistence of Human Agency in Cyber Operations The misconception that AI operates independently in cyber warfare stems from a fundamental misunderstanding of how these technologies are deployed in the field.

The Pre-existing Vulnerability of Energy Infrastructure

The focus on AI as a novel threat often overlooks the fact that energy systems were already disturbingly vulnerable before the recent high-profile hacks raised the specter of AI possibly "killing all humans" [5]linkedin.comAndrás László Tölgyes' PostBefore recent high-profile hacks raised the specter of AI possibly 'killing all humans,' our energy systems were already disturbingly vulnerable to cyberattack — and the risk is growing.Open source ↗. The energy grid is a legacy system, often built on decades-old technology that was never designed with cybersecurity in mind. These systems are frequently isolated or "air-gapped," but this isolation is increasingly porous due to the integration of digital monitoring and control systems. The vulnerability predates the AI hype cycle, with human error and malicious intent remaining the core risk factors [7]printingpressai.comPrinting Press AI: Before recent high-profile discussions about AI’s potential for existential risksThe energy grid's vulnerability predates the AI hype cycle, with human error and malicious intent remaining the core risk factors.Open source ↗.

This pre-existing fragility is exacerbated by the sheer scale and complexity of the energy sector. A single point of failure in a critical component can cascade into a widespread outage. Human operators, under pressure and fatigue, are prone to making mistakes that can be exploited by adversaries. Insider threats, whether motivated by ideology, financial gain, or coercion, pose a significant risk because they have legitimate access to sensitive systems. These insiders can bypass many of the external defenses that AI-driven attacks would struggle to penetrate. The fallibility of human operators and the malicious intent of insider threats remain the most significant vulnerabilities in AI-augmented security environments [3]forbes.comWhy The Biggest AI-Driven Cyber Threat Is Still Human NatureThe fallibility of human operators and the malicious intent of insider threats remain the most significant vulnerabilities in AI-augmented security environments.Open source ↗.

Moreover, the energy sector is a prime target for nation-states seeking to exert geopolitical pressure. The ability to disrupt energy supplies can destabilize economies and influence political outcomes. This strategic value ensures that the energy grid remains a high-priority target for human adversaries. The use of AI in these attacks is a tactical choice, not a strategic necessity. Adversaries use AI to scale their operations and reduce the cost of entry, but the decision to attack is always human. The vulnerability of the energy grid is not a function of AI development; it is a function of the sector’s reliance on interconnected, legacy infrastructure and the constant presence of motivated human attackers. Human threat actors continue to dominate the landscape of critical infrastructure targeting, with AI serving as an enabler rather than a primary agent [2]forbes.comA Mid-2026 Primer On Cybersecurity And Addressing New ThreatsHuman threat actors continue to dominate the landscape of critical infrastructure targeting, with AI serving as an enabler rather than a primary agent.Open source ↗.

Compass Predictive Analytics

Signal gauge

100%

Independent Source Breadth

Independent Source Breadth Is 100 For The Selected Signal. · Positive

tracked

Shows how many genuinely independent owners support the evidence after syndication collapse.

5IndependentOwners5EffectiveOwners
5 evidence references

Analytic module

5Support0Risk

module

Signal Pressure Matrix

Validated independent claim-owner cells resolve to 5 support and 0 risk pressure.

5 evidence references
The Pre-existing Vulnerability of Energy Infrastructure The focus on AI as a novel threat often overlooks the fact that energy systems were already disturbingly vulnerable before the recent high-profile hacks raised the specter of AI possibly "killing all humans".
The Pre-existing Vulnerability of Energy Infrastructure The focus on AI as a novel threat often overlooks the fact that energy systems were already disturbingly vulnerable before the recent high-profile hacks raised the specter of AI possibly "killing all humans".

The Critical Turning Point in Cybersecurity

The cybersecurity landscape in 2026 is at a critical turning point, with breaches becoming daily occurrences [10]forbes.comCybersecurity 2026: The Year AI Became The Battlefield And What Comes NextIn 2026, cybersecurity has transformed into a critical operational environment, where AI is a tool for human attackers rather than an autonomous threat.Open source ↗. This frequency underscores the inadequacy of current defensive measures. The integration of AI into both offensive and defensive operations has created a new arms race, but the outcome of this race is determined by human skill and strategy. Cybersecurity has transformed into a critical operational environment, where AI is a tool for human attackers rather than an autonomous threat [10]forbes.comCybersecurity 2026: The Year AI Became The Battlefield And What Comes NextIn 2026, cybersecurity has transformed into a critical operational environment, where AI is a tool for human attackers rather than an autonomous threat.Open source ↗. This transformation requires a shift in how we perceive and manage risk.

The emphasis on AI as the primary threat distracts from the need for robust human-centric security practices. Training, awareness, and rigorous access controls are more effective against the current threat landscape than hypothetical defenses against rogue AI. The United Arab Emirates recently fended off a coordinated, multi-vector cyberattack campaign targeting its aviation, energy, and education sectors, highlighting the persistent threat of human-led cyber campaigns [9]techtimes.comUAE Fends Off Third Sector-Targeting Cyberattack of 2026; Finance First, Now Aviation, EnergyThe United Arab Emirates repelled a coordinated, multi-vector cyberattack campaign targeting its aviation, energy, and education sectors, highlighting the persistent threat of human-led cyber campaigns.Open source ↗. This example illustrates that sophisticated, multi-stage attacks are still driven by human coordination and planning. The attackers used a variety of tools, including AI-generated content, to confuse defenses, but the core of the operation was human-directed.

This turning point also reveals the importance of international cooperation and information sharing. Nation-states often operate with impunity, and the energy sector relies on shared intelligence to stay ahead of threats. However, the lack of trust between nations complicates these efforts. The cybersecurity landscape is fragmented, with different regions and sectors adopting varying standards and practices. This fragmentation creates gaps that human adversaries can exploit. The solution is not to fear AI, but to address the human and organizational weaknesses that allow these attacks to succeed. The evidence clearly supports the conclusion that humans, not rogue AI, are still the biggest cybersecurity risk to energy systems [6]ground.newsGround News Article: Humans, not rogue AI, are still the biggest cybersecurity risk to energy systemsAggregated reporting confirms the consensus that human actors, not rogue AI, are the primary threat to energy infrastructure.Open source ↗.

Compass Predictive Analytics

Analytic module

5Sources5Exact Spans5Owners

module

Evidence Density

5 source links, 5 exact spans, and 5 independent owners support this signal.

10 evidence references

Analytic module

Support 100% · Risk 0%

module

Cross Pressure

Support and risk pressure differ by 100 points.

5 evidence references
The Critical Turning Point in Cybersecurity The cybersecurity landscape in 2026 is at a critical turning point, with breaches becoming daily occurrences.
The Critical Turning Point in Cybersecurity The cybersecurity landscape in 2026 is at a critical turning point, with breaches becoming daily occurrences.

Mitigating the Human Risk Through Skill and Strategy

Addressing the human threat requires a fundamental change in approach. It is not enough to rely on technology alone; human skill development is paramount. CISA Learning offers no-cost online cybersecurity training on topics such as cloud security, ethical hacking and surveillance, risk management, and malware analysis, emphasizing the need for human skill development [8]niccs.cisa.govCISA Learning - NICCSCISA Learning offers no-cost online cybersecurity training on topics such as cloud security, ethical hacking and surveillance, risk management, and malware analysis, emphasizing the need for human skill development.Open source ↗. This focus on education and training is essential for building a resilient workforce capable of detecting and responding to sophisticated attacks.

The energy sector must prioritize the development of a security-conscious culture. This involves regular training, simulated attacks, and clear protocols for reporting suspicious activity. Employees must understand their role in protecting critical infrastructure and the consequences of their actions. Insider threats, in particular, require careful management. Background checks, continuous monitoring, and a positive workplace culture can help mitigate the risk of malicious insiders. The goal is to make the human element a strength, not a weakness.

Furthermore, the energy sector must adopt a zero-trust architecture. This approach assumes that any user or device, whether inside or outside the network, could be compromised. By verifying every request and limiting access to the minimum necessary, the impact of a breach can be contained. This strategy is effective against both human and AI-driven attacks, as it reduces the attack surface and limits the ability of adversaries to move laterally within the network.

The role of AI in defense is also evolving. AI can assist in detecting anomalies and automating responses, but it must be guided by human operators. The synergy between human expertise and AI capabilities is the key to effective defense. Humans provide the context and judgment that AI lacks, while AI provides the speed and scale that humans cannot match. This collaborative model is more effective than relying on either technology alone.

Mitigating the Human Risk Through Skill and Strategy Addressing the human threat requires a fundamental change in approach.
Mitigating the Human Risk Through Skill and Strategy Addressing the human threat requires a fundamental change in approach.

Decisive Conclusions on the Primary Threat

The evidence is clear: humans, not rogue AI, are still the biggest cybersecurity risk to energy systems. The fear of autonomous AI taking control is a distraction from the real and immediate dangers posed by nation-states, criminals, and insiders. These human actors are disciplined, capable, and motivated to disrupt the energy grid for political, financial, or ideological reasons. They use AI as a tool to enhance their attacks, but the agency and intent remain human.

The energy sector’s vulnerability is rooted in its legacy infrastructure and the complexity of its operations. This vulnerability is exacerbated by human error and the lack of a unified security culture. Addressing these issues requires a focus on human-centric security practices, including training, awareness, and zero-trust architectures. The integration of AI into defense strategies must be guided by human expertise, ensuring that technology serves to augment, not replace, human judgment.

The threat to the energy grid is not a science fiction scenario of rogue AI; it is a present and ongoing reality of human-driven cyber warfare. The energy sector must stop looking for a mythical villain in the machine and start addressing the real villains in the room. By focusing on human risk, the sector can build a more resilient and secure future. The time for action is now, and the focus must be on the people who pose the greatest danger.

Bibliography

  1. [1] The Verge. "Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems." September 20, 2026. Accessed September 21, 2026. https://www.theverge.com/science/997834/ai-cyberattack-energy-critical-infrastructure. theverge.com
  2. [2] Brooks, Chuck. "A Mid-2026 Primer On Cybersecurity And Addressing New Threats." Forbes, July 31, 2026. Accessed September 21, 2026. https://www.forbes.com/sites/chuckbrooks/2026/07/31/a-mid-2026-primer-on--cybersecurity-and-addressing-new-threats/. forbes.com
  3. [3] Forbes Technology Council. "Why The Biggest AI-Driven Cyber Threat Is Still Human Nature." Forbes, July 29, 2026. Accessed September 21, 2026. https://www.forbes.com/councils/forbestechcouncil/2026/07/29/why-the-biggest-ai-driven-cyber-threat. forbes.com
  4. [4] CNN. "AI isn’t the biggest cybersecurity problem. People are." August 9, 2026. Accessed September 21, 2026. https://www.cnn.com/2026/08/09/tech/ai-cybersecurity-people. cnn.com
  5. [5] Tölgyes, András László. "András László Tölgyes' Post." LinkedIn, September 20, 2026. Accessed September 21, 2026. https://www.linkedin.com/posts/tolgyeslaszlo_humans-not-rogue-ai-are-still-the-biggest-activity-7507431616026238976-IxEo. linkedin.com
  6. [6] Ground News. "Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems." Accessed September 21, 2026. https://ground.news/article/humans-not-rogue-ai-are-still-the-biggest-cybersecurity-risk-to-energy-systems. ground.news
  7. [7] Printing Press AI. "Before recent high-profile discussions about AI’s potential for existential risks, our energy grids were already disturbingly vulnerable." Accessed September 21, 2026. https://www.printingpressai.com/article/generative-ai/humans-not-rogue-ai-are-still-the-biggest-cybersecurity-risk-to-energy-systems. printingpressai.com
  8. [8] CISA. "CISA Learning." National Initiative for Cybersecurity Careers and Studies, accessed September 21, 2026. https://niccs.cisa.gov/training/cisa-learning. niccs.cisa.gov
  9. [9] TechTimes. "UAE Fends Off Third Sector-Targeting Cyberattack of 2026; Finance First, Now Aviation, Energy." August 10, 2026. Accessed September 21, 2026. https://www.techtimes.com/articles/323799/20260810/uae-fends-off-third-sector-targeting-cyberattack-2026-finance-first-now-aviation-energy.htm. techtimes.com
  10. [10] Forbes. "Cybersecurity 2026: The Year AI Became The Battlefield And What Comes Next." Forbes, September 3, 2026. Accessed September 21, 2026. https://www.forbes.com/sites/cognitiveworld/2026/09/03/cybersecurity-2026-the-year-ai-became-the-battlefield-and-what-comes-next/. forbes.com