By Rob Denaburg, cybersecurity program senior manager, American Public Power Association
Artificial intelligence is rapidly changing the cybersecurity landscape for electric utilities — both in terms of defensive capabilities and as a force multiplier for cyberthreat actors. While network defenders have long relied on machine-learning-supported security tools, recent advances in generative AI and large language models introduce new risks, opportunities, and strategic questions that utilities need to understand.
Enhanced Attacks
One of the most immediate cybersecurity risks of AI is its ability to advance the scale, speed, and sophistication of attacks. Generative AI tools allow threat actors — ranging from loosely organized criminal groups to nation-state adversaries — to automate tasks that once required significant expertise or manual effort. This includes writing phishing emails that are more convincing and context-aware, generating functional malware or exploit code, and rapidly adapting attack techniques in response to defenses.
One particular concern for the electric sector is how AI can help less sophisticated attackers develop malware that targets industrial control systems. Traditionally, ICS-specific malware required deep expertise in specialized protocols, engineering processes, and site‑specific operations. Today, AI-based tools can assist attackers by rapidly analyzing publicly available protocol specifications, generating syntactically valid control messages, and automating reconnaissance across industrial environments.
At their current level of sophistication, AI‑assisted attacks are more likely to cause noisy disruptions, trigger alarms, or fail rather than cause damage to the physical grid. However, the potential proliferation of ICS-specific malware could greatly increase the cyber risk for electric utilities — especially those still struggling with poor cyber hygiene.
AI also enables more effective reconnaissance and targeting. Attackers can use AI to analyze large volumes of leaked data, network information, or open-source intelligence to customize attacks for specific utilities or even individual employees. For electric utilities — where legacy operational technology systems and limited staffing may coexist — an increase in attacker efficiency shortens the time between vulnerability discovery and exploitation.
AI as a Target
In addition to using AI as a tool to improve attack capabilities, adversaries are increasingly interested in targeting AI systems as a means of compromising organizations. This includes data poisoning, prompt injection, model manipulation, and exploiting weaknesses in AI-enabled applications. As utilities begin using AI for forecasting, asset monitoring, customer engagement, or cyber detection, these systems could become attractive targets for manipulation or abuse.
For example, corrupted data inputs could skew operational insights, suppress alerts, or undermine trust in automated decision-support tools. These risks underscore the importance of treating AI systems as critical digital assets, subject to governance, monitoring, and security controls just like other IT and OT systems.
Empowering Defenders
Utilities can leverage AI in defending their networks, helping small teams detect threats faster and focus attention where it matters most. AI in cyber defense is not a new concept; many security tools that utilities already rely on — including anomaly detection, intrusion detection systems, spam filtering, and behavioral analytics — have used machine learning to identify suspicious activity.
What has changed for the better is the capability of AI models. Modern AI systems can correlate far more data, reason across complex environments, and assist human analysts by summarizing alerts, prioritizing risks, and accelerating response.
Advanced Vulnerability Discovery
One of the most significant recent developments is the emergence of AI models that are capable of very sophisticated vulnerability discovery. Frontier models can review code, configurations, and system behavior to identify weaknesses, sometimes chaining multiple low-severity issues into viable exploits. This dramatically compresses the window between vulnerability discovery and real-world exploitation.
As with AI adoption more broadly, these capabilities can benefit both attackers and defenders. Adversaries can find new attack paths more quickly, but defenders can also use the same technology to uncover weaknesses before they are exploited and to prioritize remediation based on actual risk. The challenge for utilities is not just detection, but organizational readiness — having processes, staffing, and patching mechanisms fast enough to keep up with AI-accelerated discovery.
To minimize exposure, utilities should approach AI adoption with the same discipline applied to other critical systems: Maintain visibility into AI use, protect sensitive data, apply defense-in-depth, and ensure AI outputs support — rather than replace — human decision-making.
Preparing for an AI-Accelerated Future
AI is reshaping the cyberthreat landscape for electric utilities whether they actively adopt it or not. Threat actors, including those which might target utilities, are increasingly adopting AI tools to enhance their cyberattack efficiency and capabilities. This creates an imperative for utilities to adopt AI-enabled defensive tools capable of combating these increasingly sophisticated threats. The key risk is not AI itself but failing to understand how quickly both attackers and defenders are evolving. Utilities that invest early in governance, awareness, and realistic expectations — while leveraging AI’s strengths for defense — will be better positioned to manage cyber risk in an increasingly automated threat environment.
