Reading mode AI and Critical Infrastructure: Who’s Guarding the Systems We Depend On? #20921 01 / Opening Brief
Truth Files / Evidence-Led Investigation

AI and Critical Infrastructure: Who’s Guarding the Systems We Depend On?

The grid, the water supply and the banking system are already running AI. Federal auditors say the risk-assessment process meant to watch that is still incomplete.

Updated 17 Sep 2026 Verdict Contested
Evidence classification
Contested
Editorial strengthGovernment audits and joint agency guidance verified; AI-specific incident attribution unresolved
Evidence basisSource trail present
Source recordInspect sources
Updated17 Sep 2026
File#20921
File roleInvestigative Dossier
Updated17 Sep 2026
DomainFrontier AI Risk
VerdictContested

Opening Brief

The grid, the water supply and the banking system now run partly on AI

AI and critical infrastructure is the file that asks the question underneath every other AI-power file in this series: what happens when the systems that keep water running, power flowing and money moving start depending on models that can be fooled, break silently, or get exploited by someone else entirely. This is not a hypothetical. Federal auditors have already found the government's own risk-assessment process for AI in critical infrastructure incomplete, and hostile state-linked hackers have already been caught inside the control systems that run American water utilities.

Earlier files in this route tracked who builds AI, who profits from it and who might lose control of it. This file tracks something narrower and more physical: the industrial control systems, financial clearing networks and utility operators that were never designed with AI in mind, and are now being asked to trust it anyway.

What This File Tracks

Where AI meets the systems people can't do without

Operational Technology Exposure

How AI is being layered onto the industrial control systems that run water treatment, power grids and pipelines.

Government Oversight Gaps

What federal auditors found when they checked whether agencies actually assessed AI risk in critical sectors.

Financial System Dependency

How banks and regulators are treating AI as both a fraud-fighting tool and a new systemic risk.

Documented Intrusions

What is already confirmed about hostile actors probing the control systems AI is now being added to.

The Oversight Gap

Washington's own watchdog found the risk assessments incomplete

In December 2024, the Government Accountability Office reviewed how the agencies responsible for critical infrastructure sectors — the ones covering energy, water, finance, transportation and more — were assessing the risks of AI inside their own domains. The finding was blunt: none of the sector risk assessments submitted to the Department of Homeland Security fully addressed the six activities GAO considers necessary for a sound AI risk evaluation, including measuring both the likelihood and the severity of potential harm.

DHS had already issued updated guidance and a revised risk-assessment template in August 2024, and GAO's recommendation was for the department to move faster on closing the remaining gaps before the next required round of sector assessments. The practical meaning is straightforward: as of the most recent public audit, the government's own process for knowing where AI creates dangerous new failure points in the systems Americans depend on to survive was still under construction.

Contested zone: an incomplete risk-assessment process is not proof of an unmanaged system. Agencies can still respond to specific incidents even without a mature AI-specific framework. But it does mean the public has no complete, verified map of where AI-driven failure is most likely inside the country's critical infrastructure.

The Control-System Layer

The equipment AI is being layered onto was not built for this

Water and WastewaterTreatment plants run on programmable logic controllers that manage pumps, valves and chemical dosing.
Energy GridSubstations and generation sites depend on supervisory control and data acquisition (SCADA) systems tied to the same class of controllers.
Government FacilitiesMunicipal utilities often run smaller, thinner-staffed IT and OT security teams than private-sector peers.

This is the equipment layer where AI adoption is landing. CISA's April 2026 advisory — updated as recently as July 2026 — documents an Iranian-affiliated group exploiting internet-exposed programmable logic controllers made by Rockwell Automation, Schneider Electric and Siemens across the government-facilities, water-and-wastewater and energy sectors, manipulating human-machine-interface and SCADA displays to cause operational disruption. That advisory does not describe an AI-driven attack. It describes the baseline: the control systems now being asked to host AI copilots and automated response tools are the same ones already being probed and, in some cases, successfully breached by human operators using conventional tools.

Washington's Answer: Fail-Safes, Not a Pause

Eight governments told operators how to add AI, not whether to

On December 3, 2025, CISA and the NSA's AI Security Center published joint guidance with the FBI and cyber authorities from Australia, Canada, Germany, the Netherlands, New Zealand and the United Kingdom: "Principles for the Secure Integration of Artificial Intelligence in Operational Technology." The document does not tell operators to hold off on AI. It tells them how to add it without losing control of the plant.

Human-in-the-LoopAI models should never be able to take a potentially dangerous action inside OT without a human able to intervene.
Fail-SafesSystems should be built to fail gracefully rather than default to an unsafe or unmonitored state.
Vendor AccountabilityOperators are told to hold AI vendors to explicit security expectations before deployment, not after an incident.
Continuous ValidationCompliance and incident-response plans need updating on an ongoing basis, not as a one-time certification.

Eight governments agreeing on the same four principles in the same month is itself a signal: none of them concluded that AI belongs nowhere near critical operational technology, but all of them concluded that it cannot go in unsupervised. That is a narrower and more cautious position than the marketing language usually attached to "AI-powered grid management" or "AI-driven water treatment optimization."

The Money Layer

Regulators now treat AI as both a defense and a systemic risk

Financial infrastructure is critical infrastructure, and it is already running production AI at scale — in fraud detection, credit decisioning, trading and customer service. In March 2024, the Treasury Department published "Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector," based on outreach across the industry. Its core concern was not that AI would fail dramatically, but that the sector was converging on a small number of AI vendors and cloud providers, creating a concentration risk where one outage or one compromised model provider could ripple across many institutions at once.

SectorDocumented AI-Adjacent RiskSource
Water / WastewaterPLC exploitation on the same control layer AI tools are being added toHigh
Energy GridSCADA exposure documented; joint AI-OT guidance issued in responseHigh
Financial ServicesVendor and cloud-provider concentration flagged by TreasuryMedium / High
Government FacilitiesSmaller municipal operators, thinner security staffingMedium / High

Join The Briefing

Get new files first

Get new investigations, corrections, and subscriber-only extras before they show up anywhere else on the site. No spam, no schedule pressure — just the signal when there is something worth sending. Join The Briefing →

Evidence Ledger

Verified, contested, and unresolved claims

GAO found in December 2024 that no critical-infrastructure sector risk assessment submitted to DHS fully addressed the six activities needed for effective AI risk evaluation
Verified

GAO-25-107435 documents the specific gaps and DHS's partial August 2024 guidance update without claiming no risk work has occurred at all.

CISA, the NSA and cyber authorities from seven allied nations jointly published AI-in-OT integration principles in December 2025 centered on human-in-the-loop control and fail-safes
Verified

The joint CISA/NSA/FBI and allied-agency publication sets out these specific operational principles as guidance, not law.

CISA documented Iranian-affiliated actors exploiting internet-exposed PLCs across water, energy and government-facility sectors in an advisory current as of July 2026
Verified

CISA Advisory AA26-097A names the affected sectors and controller manufacturers; it does not describe an AI-driven attack method.

Treasury's March 2024 report identified AI-vendor and cloud-provider concentration as a specific emerging risk in financial services
Verified

The Treasury report is based on industry outreach and frames this as a sector-level concern, not a confirmed incident.

No public CISA or DHS advisory reviewed for this file attributes a confirmed critical-infrastructure outage directly to an AI-driven attack as of September 2026
Unresolved

The absence of such an advisory in the current public record does not prove no AI-linked incident has occurred, only that none has been publicly attributed.

Whether integrating AI into operational technology control loops produces a net safety gain or a net new risk for critical infrastructure
Contested

The allied joint guidance endorses AI adoption only conditioned on human oversight and fail-safes, reflecting disagreement about the technology's net effect absent those controls.

Final Assessment

The systems are exposed; the AI-specific verdict is still open

It is verified that the control systems running American water, energy and financial infrastructure are already targets, that the government's own AI-specific risk-assessment process was incomplete as of the last public audit, and that eight governments felt the need to jointly tell operators, in writing, not to let an AI model take a dangerous action without a human able to stop it. It is not verified that AI has yet caused a confirmed outage in the wild.

That gap between "the guardrails are still being built" and "nothing bad has happened yet" is the honest state of this file. The agencies writing the guidance are not alarmists; several of the same agencies are actively encouraging AI adoption in these sectors for its defensive value, from faster anomaly detection to better fraud screening. The concern in the record is narrower and more specific: AI is being added to systems with a documented history of exposure, faster than the oversight process built to evaluate that risk.

The next file in this route follows that same tension into a domain where the fail-safe cannot simply be "a human can intervene" — because the decision being automated is not a valve setting or a fraud flag. It is who gets targeted with lethal force.

ContinueOpening Brief
Dossier link copied