The AI doom scenario everyone's panicking about is a distraction from the human-created mess we're already sitting in.
The Summary
- Energy infrastructure remains dangerously vulnerable to cyberattacks, but the threat still comes from human actors, not rogue AI
- Joshua Corman from the Institute for Security and Technology frames existing vulnerability bluntly: "We were always prey. We were just kind of surviving at the appetite of our predators."
- The real problem: decades of neglected infrastructure security that AI agents will inherit, not create
The Signal
The conversation around AI risk has gone fully cinematic. Rogue agents. Existential threats. Skynet references that stopped being clever in 2015. Meanwhile, the actual infrastructure that keeps the lights on has been hanging by a thread for years, and nobody wants to talk about the boring truth: humans built these systems to fail.
Joshua Corman's framing cuts through the noise. Energy systems weren't hardened against attack because they were designed in an era when physical isolation was the security model. Then we networked everything, bolted on internet connectivity as an afterthought, and hoped for the best. Iranian actors, Russian state hackers, ransomware crews — they've been testing these systems for years. The vulnerability isn't theoretical. It's operational.
"We were always prey. We were just kind of surviving at the appetite of our predators."
The timing here matters. AI agents are coming for infrastructure management whether we're ready or not. Autonomous systems monitoring grid loads, optimizing energy distribution, responding to demand fluctuations in milliseconds. That's Web4 in action: agents building and running critical systems while humans sleep. But if the underlying infrastructure is already compromised, we're just automating the disaster.
Here's what the AI doom crowd misses:
- The attack surface isn't expanding because AI is malicious
- It's expanding because we're deploying intelligent agents into systems with decades-old security holes
- The threat model hasn't changed — just the speed and scale at which existing vulnerabilities can be exploited
The energy sector's security posture was designed for a world where you needed physical access to do real damage. That world ended twenty years ago. We're now deploying agents into an environment where a well-crafted phishing email can shut down a regional grid, and we're worried about whether GPT-7 will spontaneously decide to end humanity.
The Implication
If you're building agents for critical infrastructure, the security work starts before you write a single line of agent code. Legacy systems need hardening yesterday. Air gaps need to be real air gaps, not "we turned off the WiFi." Authentication models need to assume compromise, not trust.
For everyone else: the AI risk discourse has been hijacked by sci-fi scenarios while the actual threat — human-exploited vulnerabilities in systems we depend on every day — gets treated as background noise. Watch where the actual attacks come from. It won't be rogue superintelligence. It'll be the same human adversaries who've been probing these systems for years, now moving faster because we gave them better tools.