How AI Could Be Turned Against Americans

Western intelligence agencies are warning that the threat AI poses to critical infrastructure may be arriving sooner than many expected—and recent actions by the Trump administration underscore how seriously governments are beginning to take the risk.

The U.S. government imposed restrictions on access to Anthropic’s Fable 5 and Mythos 5 frontier AI models, citing concerns that their advanced capabilities for identifying software vulnerabilities could be misused to accelerate cyberattacks.

The move marked one of the clearest signals yet that Washington now views some cutting-edge AI systems not merely as commercial products, but as technologies with significant national-security implications.

Read More on News

Against that backdrop, the Five Eyes intelligence alliance—the United States, United Kingdom, Canada, Australia and New Zealand—issued a joint advisory on June 22 warning that AI is rapidly transforming the cyberthreat landscape. The agencies said advanced models are lowering the barriers to sophisticated attacks, allowing malicious actors to discover vulnerabilities, automate reconnaissance and scale operations at speeds previously impossible.

For security officials, the concern is no longer a distant, theoretical risk. It is that AI may compress cyberattack timelines from years to months, giving adversaries unprecedented ability to probe and potentially disrupt critical infrastructure ranging from power grids and water systems to hospitals and transportation networks.

Hamed Hassani, a professor in the Department of Electrical and Systems Engineering at the University of Pennsylvania, told Newsweek that AI is fundamentally changing the balance between attackers and defenders.

“Anyone working in the area of AI safety/security should be deeply concerned,” Hassani said. “AI fundamentally shifts the advantage toward the attacker by compressing the timeline of an attack.”

The concern has become serious enough that U.S. officials have begun treating some frontier AI systems as national-security technologies, imposing export controls on certain advanced models amid fears they could be misused.

The June 22, 2026 Five Eyes warning, published by the National Security Agency, said “the evolving landscape of artificial intelligence (AI) is rapidly transforming cyber risk, and we must act swiftly to remain ahead.”

Analysts say AI is already being deployed across the cyberattack life cycle—from reconnaissance and vulnerability discovery to phishing campaigns, social engineering and adaptive malware.

The concern is not theoretical. Nation-state hackers have repeatedly targeted critical infrastructure, and experts fear AI will make those operations faster, cheaper and easier to scale.

AI Is Compressing Attack Timelines

A report from cyberintelligence firm KELA found that half of all ransomware incidents in 2025 targeted critical sectors including healthcare, energy, manufacturing and transportation.

Officials warn that as infrastructure becomes more digitized—linking operational technology such as power grids and water systems to internet-connected networks—the potential impact of cyberattacks grows.

The World Economic Forum has described this trend as creating a “massive new attack surface.”

Staff work in the control room at the INFORM (Information for Motorists) Transportation Management Center on Long Island in New York.

Experts warn that AI-driven reconnaissance tools can now scan enormous numbers of internet-connected devices simultaneously, identifying exposed industrial control systems, remote monitoring platforms and vulnerable software.

Tasks that once required skilled operators spending weeks manually probing networks can increasingly be automated. The result, intelligence officials warn, is that attackers may be able to move from discovery to exploitation far more quickly than defenders can respond.

Sectors Most Vulnerable to Attack

Chart showing the distribution of critical infrastructure industry sectors targeted by cyber incidents in 2024 | Statista

Hassani said that “in general, any industry dealing with sensitive data (such as healthcare, finance) could be among the first targets of AI cyber attacks…Moreover, industries operating physical infrastructure could be another target, such as power grids, transportation, etc.”

Critical Infrastructure Security and Resilience (CISA) says that there are 16 critical infrastructure sectors that, if under threat, could have “potentially debilitating national security, economic, and public health or safety consequences.”

Experts highlighted the following critical infrastructure sectors as particularly exposed:

  • Energy (power grids, oil, and gas): Energy and utilities are increasingly targeted because of their critical role in national infrastructure
  • Water and wastewater systems: Water and wastewater systems are often under?secured and reliant on remote industrial control systems, making them susceptible to intrusion.
  • Healthcare: Healthcare is becoming increasingly dependent on digital systems, increasing its attack surface. Ransomware attacks can disrupt services and threaten patient safety, with incidents rising sharply in recent years. In fact, the FBI found that healthcare was the top sector targeted for cyber threats in 2025, according to the American Hospital Association (AHA).
  • Financial services: Financial services are one of the core critical infrastructure sectors essential to economic security. They are among the most frequently targeted sectors globally, accounting for 45 percent of cyber incidents in 2024.
  • Transport and logistics: Ports, airports, and supply chains are becoming increasingly digitized, creating opportunities for cyber-based disruption.
  • Government and defense systems: Any government-related system can become a high-priority target. Nation?state actors routinely target critical infrastructure for espionage, disruption, and geopolitical advantage.

Real?World Examples: When and How Attacks Have Happened

A member of staff works in the Northern States Power Company's Distribution Operations Center in downtown Minneapolis.

The Utility Breach That Went Undetected for 10 Months

One of the clearest examples of the threat, as a pre-AI manual benchmark, involved the Chinese-linked hacking group Volt Typhoon and the Littleton Electric Light and Water Department in Massachusetts.

According to reporting by The Record, attackers first gained access in February 2023 and remained inside the utility’s network for approximately 10 months before being discovered. This is wholly different to the swiftness of current-day attacks.

During that time, investigators said the hackers used a technique known as “living off the land”—leveraging legitimate administrative tools already present inside the network rather than deploying obvious malware.

The approach allowed them to blend into normal activity while mapping operational technology systems and identifying potential points of disruption.

The utility and security teams moved quickly to contain the threat, including:

  • Isolating affected systems
  • Removing unauthorized access points
  • Reconfiguring network architecture to close vulnerabilities

While no customer data was compromised, the incident demonstrated the ability of state-linked actors to remain undetected inside critical infrastructure for long periods.

Security officials viewed the intrusion as especially alarming because the objective appeared to be reconnaissance rather than theft. Investigators concluded the attackers were gathering information that could potentially be used in a future disruption of critical services.

Water Systems: Small Utilities, Big Risks

Water and wastewater systems are increasingly viewed as one of the most vulnerable parts of U.S. critical infrastructure because many small utilities rely on remote monitoring equipment, industrial-control software and aging networks that were never designed to withstand modern cyber threats.

The danger is that AI-assisted attackers can now automate the discovery process. Rather than manually hunting for targets, reconnaissance tools can scan the internet for exposed remote-access systems, identify outdated software, map network architecture and prioritize vulnerable facilities in minutes.

Security experts warn that this dramatically increases the number of potential targets attackers can evaluate simultaneously.

Recent incidents illustrate the problem. According to reporting by The Texas Tribune, hackers gained remote access to industrial-control systems used by several Texas water utilities, including systems serving Muleshoe.

In one case, attackers manipulated controls and caused a water tank to overflow for approximately 30 to 45 minutes before operators intervened. Although no major damage occurred, the incident highlighted how relatively small municipal systems can become entry points for broader infrastructure disruption.

Healthcare: A Preview of What Large-Scale Disruption Looks Like

While utility breaches often attract national-security attention, healthcare offers a glimpse of what widespread operational disruption can look like when cyberattacks succeed.

In 2024, ransomware operators infiltrated Change Healthcare, one of the nation’s largest healthcare transaction processors. The company was forced to shut down critical systems after attackers stole sensitive information and deployed ransomware.

Because Change Healthcare sits at the center of billing and insurance verification for thousands of hospitals, pharmacies and medical providers, the disruption cascaded across the healthcare sector.

Pharmacies struggled to process prescriptions, providers faced payment delays and hospitals lost access to critical administrative systems.

The breach ultimately affected 192.7 million Americans and cost UnitedHealth Group over $2.4 billion. It succeeded simply because of a lack of basic multifactor authentication (MFA).

Security officials increasingly worry that AI could allow future attacks of this scale to be planned faster and executed across multiple targets simultaneously.

Why Intelligence Agencies Say Time Is Running Short

Stock image: a man studies the control desk of an aircraft carrier.

The Five Eyes warning argues that traditional cybersecurity timelines may no longer apply in an AI era.

Historically, organizations often had months—or even years—to identify vulnerabilities, detect intrusions and respond. Intelligence agencies increasingly believe that window is shrinking rapidly.

AI systems can automate reconnaissance, vulnerability discovery, social-engineering campaigns and malware development simultaneously.

Tasks that once required large teams can now be performed faster and at greater scale. That means defenders may have significantly less time to detect and stop intrusions before attackers establish persistence inside critical systems.

In response, agencies are urging organizations to accelerate monitoring, improve intelligence sharing and prepare for incidents before they occur rather than after attackers gain access.

Defenders May Need AI to Fight

Hassani said the response must be equally sophisticated: “There are multiple layers of security to be imposed, beginning with the deployment of autonomous, AI-driven defense systems across critical infrastructure and robust intelligence sharing between the public and private sectors.”

He added that governments and industry must also invest in cybersecurity talent and workforce development to keep pace with rapidly evolving threats.

The technical recommendations outlined in the joint statement from the Five Eyes intelligence alliance include measures such as secure-by-design strategies, defense-in-depth, and CISA’s tightened patch mandates.

The Bottom Line

The most important warning from Western intelligence agencies is not that AI could eventually become a cybersecurity problem. It is that the technology is already changing the economics and speed of cyber warfare.

The concern is that attackers may soon be able to identify, probe and compromise critical infrastructure faster than organizations can defend it.

For utilities, hospitals, transportation networks and local governments, officials increasingly believe the challenge is measured in months—not years.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *