Nearly two decades ago, researchers at the Idaho National Laboratory conducted a secret experiment known as the Aurora Generator Test on a large diesel generator. Using just 30 lines of code, they hacked into the generator’s control system, disabling its safety mechanisms and causing it to malfunction. The generator, weighing 27 tons, violently shook and emitted dark smoke as its internal components rapidly failed. The test was conducted in front of electrical utility executives and energy department officials, showcasing how a simple digital attack could cause physical destruction to critical infrastructure. Lead researcher Michael Assante later told journalist Andy Greenberg that the experiment offered a glimpse of the future, where a few lines of code could cause significant damage to essential systems. This concern has resurfaced as leading AI developers and executives have suggested that AI could be as likely to end humanity as the New York Jets are to make the playoffs this season. However, the exact way AI could lead to such an outcome remains unclear. AI may not need to be all-powerful to pose a threat to critical infrastructure. Experts say a new era of AI-assisted, human-directed hacking is already here. Many of the nation’s most sensitive systems, such as water treatment plants and power grids, are surprisingly vulnerable to attack. In a worst-case scenario, a small-scale attack—such as targeting a water tower or a local generator—could trigger a chain reaction, disrupting the systems we rely on for daily life. Before AI, highly skilled technical expertise was required to launch such attacks, but now, even a basic understanding of what is possible can be enough. Following the Aurora Generator Test, the federal government required electrical utilities to improve their cybersecurity practices. However, much of America’s critical infrastructure, including gas pipelines, water desalination plants, and cargo terminals, remains unprepared for even conventional cyberattacks, let alone those enabled by AI. Cyberattacks like the one simulated in the Aurora Generator Test have been rare, as they are more about disruption than financial gain, making them less appealing to most hackers. However, AI has lowered the barrier to entry, making it easier for almost anyone to hack into online accounts or, in theory, target a local reservoir or power grid. AI agents can also continuously scan for vulnerabilities, as they do not get tired or sick. In the past, even those who wanted to attack infrastructure lacked the technical know-how to do so. While countries like China, Iran, and Russia have breached many of our systems, they have not caused major disruptions once inside. However, cybersecurity scholar Jason Healey notes that geopolitical tensions are making it more likely that nations with the capability will also have the intent to act. AI is also making it easier for individuals or groups to cause damage that was previously impossible. Last month, dozens of water and wastewater systems in small towns were attacked by hackers likely linked to Iran, causing temporary water stoppages and flooding. These attacks were not definitively linked to AI, but the National Security Agency warned shortly after that hackers are using AI to target U.S. infrastructure. President Donald Trump later declared a national emergency over foreign interference in the power grid, highlighting the growing cybersecurity threat. Most water systems are extremely local and highly exposed to attacks, said Andy Bochman, an infrastructure resilience expert. These systems are often too small and underfunded to implement strong cybersecurity measures. Addressing deferred maintenance is often seen as more urgent than improving cybersecurity. Whether the threat comes from rogue hackers or hostile nations, experts say the nation’s critical infrastructure must be prepared for the worst. Bochman suggests that moving away from full digitization and returning to more analog systems—such as manually operated substations and landline communications—might be the safest path. Healey, who has advised the Biden administration on cybersecurity, emphasizes the need for a coordinated response involving the federal government, AI companies, and other countries. Utility systems must also assume they are targets and improve their security practices, ideally with federal funding or support from AI companies. Currently, nobody knows exactly how vulnerable America’s infrastructure is to AI, in part because both policymakers and AI developers are unsure how to prevent the technology from being misused. For now, the solution may be to reduce the number of critical systems connected to the internet, making them less accessible to AI and those who might exploit it.