Energy sector faces bigger threat from human hackers than AI systems
Energy infrastructure remains fundamentally exposed to human-driven cyberattacks despite recent AI-focused security narratives. Joshua Corman and other resilience experts argue that insider threats, misconfiguration, and conventional hacking still pose far greater risks than autonomous AI systems. This framing matters for AI policy: as regulators and vendors emphasize AI-specific safeguards, critical infrastructure operators face pressure to address older, more immediate vulnerabilities. The gap between perceived AI risk and actual operational risk is reshaping how security budgets and regulatory focus flow through the energy sector.
Modelwire context
Skeptical readCorman's argument isn't that AI threats don't exist, but that the policy and budget response to them is misaligned with actual operational exposure. The buried detail: this framing lets infrastructure operators and their vendors argue for lighter AI-specific compliance burdens while deferring fixes to older, cheaper problems.
This is largely disconnected from recent activity in the AI safety and policy space, where the conversation has centered on model alignment and frontier capability risks. Instead it belongs to the infrastructure resilience and regulatory capture conversation. The tension here is classic: when a new risk category (AI) enters the regulatory lens, it can crowd out unsexy but urgent ones (misconfiguration, insider threats). Corman is essentially warning that the energy sector's risk hierarchy is being reordered by narrative momentum, not by actual threat modeling.
If FERC or NERC issues new cybersecurity guidance in the next 18 months that explicitly deprioritizes AI-specific controls in favor of baseline access management and configuration audits, that confirms this framing is shifting actual policy. If instead they layer AI requirements on top of existing mandates without resource reallocation, the skeptical reading holds: the narrative serves to justify inaction on both fronts.
This analysis is generated by Modelwire’s editorial layer from our archive and the summary above. It is not a substitute for the original reporting. How we write it.
MentionsJoshua Corman · The Verge
Modelwire Editorial
This synthesis and analysis was prepared by the Modelwire editorial team. We use advanced language models to read, ground, and connect the day’s most significant AI developments, providing original strategic context that helps practitioners and leaders stay ahead of the frontier.
Modelwire summarizes, we don’t republish. The Verge - AI originally reported this story as “Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems”. The full content lives on theverge.com. If you’re a publisher and want a different summarization policy for your work, see our takedown page.