AI and Critical Infrastructure: Who’s Guarding the Systems We Depend On?
The grid, the water supply and the banking system are already running AI. Federal auditors say the risk-assessment process meant to watch that is still incomplete.
Opening Brief
The grid, the water supply and the banking system now run partly on AI
AI and critical infrastructure is the file that asks the question underneath every other AI-power file in this series: what happens when the systems that keep water running, power flowing and money moving start depending on models that can be fooled, break silently, or get exploited by someone else entirely. This is not a hypothetical. Federal auditors have already found the government's own risk-assessment process for AI in critical infrastructure incomplete, and hostile state-linked hackers have already been caught inside the control systems that run American water utilities.
Earlier files in this route tracked who builds AI, who profits from it and who might lose control of it. This file tracks something narrower and more physical: the industrial control systems, financial clearing networks and utility operators that were never designed with AI in mind, and are now being asked to trust it anyway.
What This File Tracks
Where AI meets the systems people can't do without
Operational Technology Exposure
How AI is being layered onto the industrial control systems that run water treatment, power grids and pipelines.
Government Oversight Gaps
What federal auditors found when they checked whether agencies actually assessed AI risk in critical sectors.
Financial System Dependency
How banks and regulators are treating AI as both a fraud-fighting tool and a new systemic risk.
Documented Intrusions
What is already confirmed about hostile actors probing the control systems AI is now being added to.
The Oversight Gap
Washington's own watchdog found the risk assessments incomplete
In December 2024, the Government Accountability Office reviewed how the agencies responsible for critical infrastructure sectors — the ones covering energy, water, finance, transportation and more — were assessing the risks of AI inside their own domains. The finding was blunt: none of the sector risk assessments submitted to the Department of Homeland Security fully addressed the six activities GAO considers necessary for a sound AI risk evaluation, including measuring both the likelihood and the severity of potential harm.
DHS had already issued updated guidance and a revised risk-assessment template in August 2024, and GAO's recommendation was for the department to move faster on closing the remaining gaps before the next required round of sector assessments. The practical meaning is straightforward: as of the most recent public audit, the government's own process for knowing where AI creates dangerous new failure points in the systems Americans depend on to survive was still under construction.
Contested zone: an incomplete risk-assessment process is not proof of an unmanaged system. Agencies can still respond to specific incidents even without a mature AI-specific framework. But it does mean the public has no complete, verified map of where AI-driven failure is most likely inside the country's critical infrastructure.
The Control-System Layer
The equipment AI is being layered onto was not built for this
This is the equipment layer where AI adoption is landing. CISA's April 2026 advisory — updated as recently as July 2026 — documents an Iranian-affiliated group exploiting internet-exposed programmable logic controllers made by Rockwell Automation, Schneider Electric and Siemens across the government-facilities, water-and-wastewater and energy sectors, manipulating human-machine-interface and SCADA displays to cause operational disruption. That advisory does not describe an AI-driven attack. It describes the baseline: the control systems now being asked to host AI copilots and automated response tools are the same ones already being probed and, in some cases, successfully breached by human operators using conventional tools.
Washington's Answer: Fail-Safes, Not a Pause
Eight governments told operators how to add AI, not whether to
On December 3, 2025, CISA and the NSA's AI Security Center published joint guidance with the FBI and cyber authorities from Australia, Canada, Germany, the Netherlands, New Zealand and the United Kingdom: "Principles for the Secure Integration of Artificial Intelligence in Operational Technology." The document does not tell operators to hold off on AI. It tells them how to add it without losing control of the plant.
Eight governments agreeing on the same four principles in the same month is itself a signal: none of them concluded that AI belongs nowhere near critical operational technology, but all of them concluded that it cannot go in unsupervised. That is a narrower and more cautious position than the marketing language usually attached to "AI-powered grid management" or "AI-driven water treatment optimization."
The Money Layer
Regulators now treat AI as both a defense and a systemic risk
Financial infrastructure is critical infrastructure, and it is already running production AI at scale — in fraud detection, credit decisioning, trading and customer service. In March 2024, the Treasury Department published "Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector," based on outreach across the industry. Its core concern was not that AI would fail dramatically, but that the sector was converging on a small number of AI vendors and cloud providers, creating a concentration risk where one outage or one compromised model provider could ripple across many institutions at once.
| Sector | Documented AI-Adjacent Risk | Source |
|---|---|---|
| Water / Wastewater | PLC exploitation on the same control layer AI tools are being added to | High |
| Energy Grid | SCADA exposure documented; joint AI-OT guidance issued in response | High |
| Financial Services | Vendor and cloud-provider concentration flagged by Treasury | Medium / High |
| Government Facilities | Smaller municipal operators, thinner security staffing | Medium / High |
Join The Briefing
Get new files first
Get new investigations, corrections, and subscriber-only extras before they show up anywhere else on the site. No spam, no schedule pressure — just the signal when there is something worth sending. Join The Briefing →
Evidence Ledger
Verified, contested, and unresolved claims
GAO-25-107435 documents the specific gaps and DHS's partial August 2024 guidance update without claiming no risk work has occurred at all.
The joint CISA/NSA/FBI and allied-agency publication sets out these specific operational principles as guidance, not law.
CISA Advisory AA26-097A names the affected sectors and controller manufacturers; it does not describe an AI-driven attack method.
The Treasury report is based on industry outreach and frames this as a sector-level concern, not a confirmed incident.
The absence of such an advisory in the current public record does not prove no AI-linked incident has occurred, only that none has been publicly attributed.
The allied joint guidance endorses AI adoption only conditioned on human oversight and fail-safes, reflecting disagreement about the technology's net effect absent those controls.
Final Assessment
The systems are exposed; the AI-specific verdict is still open
It is verified that the control systems running American water, energy and financial infrastructure are already targets, that the government's own AI-specific risk-assessment process was incomplete as of the last public audit, and that eight governments felt the need to jointly tell operators, in writing, not to let an AI model take a dangerous action without a human able to stop it. It is not verified that AI has yet caused a confirmed outage in the wild.
That gap between "the guardrails are still being built" and "nothing bad has happened yet" is the honest state of this file. The agencies writing the guidance are not alarmists; several of the same agencies are actively encouraging AI adoption in these sectors for its defensive value, from faster anomaly detection to better fraud screening. The concern in the record is narrower and more specific: AI is being added to systems with a documented history of exposure, faster than the oversight process built to evaluate that risk.
The next file in this route follows that same tension into a domain where the fail-safe cannot simply be "a human can intervene" — because the decision being automated is not a valve setting or a fraud flag. It is who gets targeted with lethal force.
Sources
Primary and institutional source trail
- 01Dec 18, 2024GAO-25-107435 - AI: DHS Needs to Improve Risk Assessment Guidance for Critical Infrastructure SectorsGovernment Audit
- 02Apr 7, 2026CISA Advisory AA26-097A - Iranian-Affiliated Cyber Actors Exploit PLCs Across US Critical InfrastructureCybersecurity Advisory
- 03Dec 3, 2025CISA/NSA/FBI and Allied Agencies - Principles for the Secure Integration of AI in Operational TechnologyJoint Government Guidance
- 04Mar 27, 2024US Treasury - Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services SectorGovernment Report
- 05Jan 26, 2023NIST - AI Risk Management FrameworkGovernment Framework
- 06Dec 4, 2025Cybersecurity Dive - US, Allies Urge Critical Infrastructure Operators to Carefully Plan and Oversee AI UseNews Report
Continue the Chain
Follow the frontier AI risk route