Skip to content
OGERIA — Observatory of Global Evidence on Risks in AISynthesis report · 2026 ed.
Updated 2 Oct 2026

Chapter 01 · Risk map

Cybersecurity and infrastructure

Attack on critical infrastructure

Agents attacking small energy, water or health operators simultaneously, where security is weakest and the effect is physical.

Severity
Catastrophic
Horizon
3–10 years
Evidence
Projected
Consensus
Medium

The worry is not that an agentAI agentAn AI system that does more than answer: it takes a goal and acts on its own to reach it, step by step, using tools such as a browser, email or a terminal, without anyone approving each step.For exampleAsking an assistant to suggest flights is using a chatbot. Asking it to search, compare, buy the ticket and put it in your calendar, all by itself, is using an agent. switches off a country, but that it lowers the cost of attacking the operators nobody bothered attacking until now because it was not worth it. Murphy and Stone frame it as a change of economics: AI alters the cost of the marginal attack and exposes laggard organisations —legacy software, underfunded security, slow patching— to more attackers, more often [765]Uplifted Attackers, Human Defenders: The Cyber Offense-Defense Balance for Trailing-Edge OrganizationsMurphy, Benjamin; Stone, Twm · 2025 · preprintView source ↗Accessed on 9 September 2026. Carnegie identifies the same weak link —utilities, hospitals, municipalities and small operators, with fewer technical resources— and the mechanics of scale: one operator can deploy hundreds or thousands of agents at once [198]When AI Agents Attack: Autonomous Cyber Operations and Europe's Governance GapCsernatoni, Raluca; Pawlak, Patryk · 2026 · reportView source ↗Accessed on 9 September 2026.

Governments have already changed doctrine, though not because of AI. The planning premise of CI Fortify, published by CISA on 5 May 2026, is that operators should assume the adversary already has access to their OT network and must be able to operate isolated for weeks to months [866]CISA's CI Fortify Initiative Signals a Shift in How the U.S. Government Thinks About Grid ThreatsPOWER Magazine · 2026 · pressView source ↗Accessed on 9 September 2026; the driver cited for the shift is Volt Typhoon.

What this does not demonstrate. The only recent Iberian blackout had nothing to do with AI or with a cyberattack: the report by the National Security Council Committee concluded that no evidence of a cyberattack was found and attributed the zero-power event to multifactorial causes of voltage control and coordination [555]El informe del Gobierno sobre el apagón del 28 de abril recalca un origen multifactorial del 'cero energético' y descarta un ciberataqueInfobae España · 2025 · pressView source ↗Accessed on 9 September 2026, and the ENTSO-E panel arrived at the same family of causes [363]ENTSO-E Publishes Expert Panel Final Report on 28 April 2025 Blackout in Spain and PortugalENTSO-E Expert Panel · 2026 · official documentView source ↗Accessed on 9 September 2026. Its value here is the opposite of the one usually given to it: it shows that the cascade is physically possible without an adversary, and for that reason it sets a high bar for any directed scenario, which would have to explain how an attacker induces that set of simultaneous conditions. Carnegie is specific about what agents still do badly: long-horizon planning, state management and error recovery [198]When AI Agents Attack: Autonomous Cyber Operations and Europe's Governance GapCsernatoni, Raluca; Pawlak, Patryk · 2026 · reportView source ↗Accessed on 9 September 2026 —the three capabilities a deliberate cascade demands.

Chain of materialisation

  1. PreconditionObserved

    The regulator already plans assuming compromise

    CISA's CI Fortify planning premise, published on 5 May 2026, is that operators assume adversaries already have some access to their OT network and must be able to operate isolated for weeks to months. The cited driver is Volt Typhoon, not AI.

    Precedents: Google documents a credential harvesting campaign built in under six hours

  2. TriggerLab

    The capability to break in exists and has been exercised on third parties

    One operator can deploy hundreds or thousands of simultaneous agents, and the weak link is utilities, hospitals and municipalities with fewer technical resources. The July 2026 intrusion shows the chaining works; the manipulation of internet-exposed fuel gauges shows that in OT it is not even needed.

    Precedents: Agents from an OpenAI evaluation compromise Hugging Face infrastructure · OpenAI expands Daybreak and releases a variant trained for vulnerability research

    Observed and demonstrated evidence ends here. What follows is projection.

  3. CascadeProjected

    Inducing the cascade requires coordinating simultaneous conditions

    The Iberian blackout of 28 April 2025 shows a peninsula-wide cascade is physically possible: it happened with no adversary, through overvoltage, insufficient voltage control and out-of-protocol disconnections. No official document today describes an attacker able to induce that set, and Carnegie notes agents fail precisely at long-term planning, state management and error recovery.

  4. ImpactSpeculative

    Essential service down for weeks

    CISA's acting director warns there will be an adversarial disruption of critical infrastructure and that the impact will not be merely technical. He does not mention AI in that appearance, and no public estimate separates harm attributable to autonomous agents from state prepositioning.

See on the map →Report a mistake in this entry →

Sources

  1. [866] CISA's CI Fortify Initiative Signals a Shift in How the U.S. Government Thinks About Grid Threats · POWER Magazine 2026
  2. [1075] Major critical infrastructure disruptions are inevitable, acting CISA chief says · Utility Dive 2026
  3. [198] When AI Agents Attack: Autonomous Cyber Operations and Europe's Governance Gap · Carnegie Europe 2026
  4. [765] Uplifted Attackers, Human Defenders: The Cyber Offense-Defense Balance for Trailing-Edge Organizations · Murphy, Benjamin 2025
  5. [1051] 2026 H1 APT Report: How APTs Are Weaponizing Trust in the Age of AI · Trend Micro / TrendAI 2026
  6. [555] El informe del Gobierno sobre el apagón del 28 de abril recalca un origen multifactorial del 'cero energético' y descarta un ciberataque · Infobae 2025
  7. [363] ENTSO-E Publishes Expert Panel Final Report on 28 April 2025 Blackout in Spain and Portugal · ENTSO-E 2026
  8. [1105] 2025 Iberian Peninsula blackout · Wikipedia contributors 2026
  9. [478] GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI · Google 2026
  10. [942] What Anthropic's Mythos Means for the Future of Cybersecurity · Schneier, Bruce 2026

Ask OGERIA

It answers only with what the observatory publishes and can be wrong: check the entries it cites. Your questions are sent to an AI model, so don't write personal data. More in the privacy policy.

Up to 500 characters.

Support OGERIA on Ko-fi

The payment is processed by Ko-fi, not by this site. Open on ko-fi.com