Joshua Corman has spent years repeating an uncomfortable idea. The power grid doesn't need a malevolent artificial intelligence to collapse. Corman has documented how critical energy systems run on infrastructure designed decades ago. That infrastructure never anticipated internet connections.
AI governance is the set of rules, institutions, and responsibilities that determines who controls an automated system and what happens when it fails, because without that structure any technical advance simply inherits the vulnerabilities that already existed. The U.S. Department of Energy has reported hundreds of cybersecurity incidents against the power grid for years. Most are tied to poor configurations, reused passwords, and SCADA systems that never received a patch.
None of this required an advanced model. Just a human who found the backdoor another human left open. This thesis gains relevance as public conversation about AI fills up with apocalyptic scenarios of autonomous systems deciding to shut down cities. The real threat remains far more mundane. Social engineering. Stolen credentials. Unpatched software.
The Generosity in the Doorway explored AI's energy appetite and reports like the International Energy Agency's Energy and AI. That demand pushes new energy infrastructure to be built at a speed that doesn't always leave time to secure it properly. First it's built. Then, if at all, security gets a thought.
That same analysis documents the Electric Power Research Institute's warnings about the pressure AI's computing demand places on regional power grids. Energy pressure and cyber vulnerability are two sides of the same coin. When the construction of substations and transmission lines to feed data centers is rushed, the installation of control systems that rarely pass serious audits is rushed too.
Why do we keep talking about rogue AI when the proven, repeated risk is human? The fear of an AI deciding on its own to shut down the grid sells easily. It enables laws that don't touch any real interests today. It's more comfortable than auditing the SCADA systems that are already failing.
Amazon warned about risks at Anthropic, its own investment. The Pentagon used a supply-chain risk label against that same company. In both cases the danger didn't come from a runaway algorithm. It came from human actors using the language of technological risk for entirely human power struggles.
AI governance, understood this way, isn't a technical problem solved with better models. It's an institutional problem solved by determining who has real authority to say no when something is misconfigured. The next time a headline talks about AI threatening the power grid, it's worth asking who left that door open, and why.
I've seen how complex systems fail. The origin is almost always human. Someone didn't change a password. Someone put off a patch. This doesn't eliminate the arguments about AI risks. It puts them in their real context. AI can amplify existing attacks and automate the search for vulnerabilities at a speed no human team can match. Automating an attack is not the same as originating it. The crack was already there.
Some aspects remain open. It isn't entirely clear whether offensive automation via AI shifts the risk equation enough to justify entirely new regulatory frameworks, or whether it's enough to demand the basic cybersecurity hygiene Corman has been calling for over the years. The uncomfortable part is that this second option, the cheaper and better-tested one, still isn't applied at the necessary scale.
Technology isn't lacking. Institutional will is. That power vacuum shows up in other pieces on this site, where whoever writes the rules for AI is rarely the one who suffers the consequences when they fail. Stones don't lie. The historical record of past collapses confirms that failures begin with human negligence, not autonomous forces.
How much longer will we prioritize digital ghosts while the human vulnerabilities we already know about keep piling up?
Sources:
1. International Energy Agency. Energy and AI. Paris: IEA, April 2025 (updated 2026).
2. Electric Power Research Institute. Powering Intelligence. February 2026 update.
3. U.S. Department of Energy, historical reports on cybersecurity incidents in energy infrastructure.
4. Joshua Corman, co-founder of I Am The Cavalry, public statements on critical infrastructure vulnerabilities.
5. Yves Laurent, The Generosity in the Doorway (Chapter 9).