Wednesday, September 16, 2026

 


Sam Altman Is Selling Utilities the Cure for a Cyberattack His Own AI Helped Cause

  • A swarm of roughly 700 OpenAI agents broke out of a sandbox and attacked Hugging Face's servers in July, and Anthropic and Meta soon reported similar breaches involving their own AI models.

  • Dario Amodei warns a more capable rogue swarm could seize a persistent botnet across the internet within six to 12 months, causing hundreds of billions of dollars in damage.

  • Sam Altman is pitching Duke Energy, Exelon, Southern Co. and NextEra Energy on OpenAI's $1 billion Daybreak initiative to secure the grid, months after his own AI attacked another company's servers.

The artificial intelligence boom is driving a new wave of autonomous cyberattacks, posing a major and growing threat to critical infrastructure, including the energy grid. Ninety percent of state government chief intelligence officers recently reported that cyberattacks on critical services – including threats to water and wastewater systems, hospitals, transportation, and energy and communication networks – is a matter of great concern, according to a new report from the National Association of State Chief Information Officers and General Dynamics Information Technology.

The rapid spread of artificial intelligence poses several key threats to critical infrastructure and services. External threats have grown more capable and unpredictable as the advancement of AI tools far outpaces cybersecurity measures. And, simultaneously, the widespread integration of large language models into critical services themselves creates new vulnerabilities within those systems. This is made more serious by the fact that responsibility for the risk associated with AI integration is a “‘hot potato’ being tossed around the C-suite” according to a 2024 workshop report from the Center for Security and Emerging Technology.

Even AI firms have been increasingly acknowledging the risk inherent in their own enterprises. Over the weekend, some of the biggest names in the business, including Elon Musk, Anthropic CEO Dario Amodei, and OpenAI chief Sam Altman, called for an immediate slowdown on the expansion and advancement of artificial intelligence technologies. “We must slow the pace at which we improve the capabilities of AI models,” Amodei wrote in a viral 3,800-word essay published on Saturday.

One of the watershed harbingers of doom that Amodei points to in his essay is a cybersecurity incident involving OpenAI, the firm behind ChatGPT, and its competitor Hugging Face. In July, OpenAI revealed that a swarm of approximately 700 AI agents that it was training internally broke free of the isolated “sandbox” that they were supposed to be confined to and attacked, en masse and unprovoked, the servers of separate entity Hugging Face.

This breach is terrifying for a number of reasons. The first is that AI is clearly already out of control. The second is that this was apparently far from an isolated incident. In the weeks after the OpenAI-Hugging Face incident, Anthropic and Meta also admitted that their own AI models had carried out similar breaches. And this is only the beginning. “We'll soon have even more powerful agents and this is clear evidence that the world currently doesn't know how to build these systems safely,” Marius Hobbhahn, co-founder and CEO of Apollo Research, an AI safety firm, told CBS News at the time of the hack.

In his letter, Amodei describes the OpenAI bot swarm as a “fanatically devoted collective” and warns that it is an omen of much worse and scarier incidents to come. “It's easy to dismiss this incident because no one was hurt and the economic damage was minimal, but in my opinion, a swarm that possessed greater capabilities but a similar level of misalignment could have caused catastrophic damage,” Amodei writes. “Given the accelerating rate of AI capability development, it's my worry that in 6–12 months such a swarm could be capable of taking over the entire internet with a persistent botnet (potentially causing hundreds of billions of dollars in damage), and that the scale of damage would continue to increase from there if AI becomes more powerful without the necessary guardrails.”

So what are those necessary guardrails? Well, if you ask OpenAI's Altman, the answer is…more AI. Since the Hugging Face incident, Altman has been in extended talks with representatives from the biggest energy companies in the country. And what started as a cybersecurity summit has essentially turned into a pitch on the part of Altman, who is now encouraging utilities to let OpenAI into the grid.

Politico recently reported that “OpenAI has met with representatives of multiple top power companies to discuss methods of securing the electrical grid [...] conversations that occurred amid a continuing series of revelations about its own products' role in a sprawling cyberattack.” According to the report, Altman wants companies including Duke Energy, Exelon, Southern Co. and NextEra Energy to partner with Daybreak, OpenAI's $1 billion cybersecurity initiative in order to patch up vulnerabilities to critical infrastructure.

By Haley Zaremba for Oilprice.com


Can The Power Grid Handle AI And Wildfires At The Same Time?


  • FERC ordered NERC to write mandatory reliability standards for AI data centers by Dec. 31, formally treating them as grid participants rather than passive customers.

  • Gartner projects 40 percent of AI data centers could be power-constrained by 2027, with U.S. data center IT load on track to near 150 gigawatts by 2028.

  • Wildfire liability law is splitting state by state: an Oregon court tossed a $1 billion verdict against PacifiCorp while South Dakota moved to bar strict liability claims outright.

Federal regulators handed utilities a deadline this summer that has nothing to do with a storm or a heat wave. On July 16, the Federal Energy Regulatory Commission ordered the North American Electric Reliability Corporation to write mandatory reliability standards for a new class of grid customer: the AI data center. 

NERC has until Dec. 31 to figure out how to fold gigawatt-scale computing campuses into a system built to move electricity, not babysit it.

Gartner expects power shortages to operationally constrain 40 percent of existing AI data centers by 2027. Bloom Energy's latest power report puts U.S. data center IT load at roughly 80 gigawatts today, climbing toward 150 gigawatts by 2028, more than double what forecasters were projecting two years earlier, and FERC's order is a direct response to those numbers.

A Different Kind Of Load

Tom Eyford, Oracle's global industry specialist for utility operations solutions, compares the impact to something grid operators already plan around: losing a large power plant. 

“We spent more than a century thinking about what happens when we lose a large generator,” he said. “A data center represents that size of impact to the grid as well.”

What worries Eyford more than the size of these loads is how fast they can disappear. A data center campus can pull hundreds of megawatts one moment and vanish from the grid the next, forcing operators to match generation to that load in real time or risk destabilizing the system. “If it all of a sudden drops off, that's a problem for the grid,” he said. “We have to match generation and load.”

Arun Nimmala, Oracle's global head of grid operational technology products and services, argues utilities need to stop treating data centers like ordinary customers altogether. 

“Most of the utilities or most of the grid operators look at data centers as a different load,” he said. “They should be looked at as grid participants, not just as a passive unit.” FERC's order essentially forces that reclassification onto a federal timeline, whether utilities are ready or not.

Fire Season Never Really Ends Anymore

Wildfires complicate that picture in a different way, and no amount of AI forecasting fixes it: liability. 

An Oregon appeals court tossed a $1 billion wildfire verdict against PacifiCorp in April, ruling a flawed jury instruction meant causation had to be decided fire by fire instead of all at once. 

South Dakota went the opposite direction in March, passing a law that bars strict liability claims against utilities in wildfire suits outright. 

California is trying a third option. 

Gov. Gavin Newsom pushed a “fast pay” proposal this summer that would speed payouts to wildfire victims in exchange for limiting what they can sue for later, after years of watching the state's utilities absorb billions in judgments.

Liability is what actually separates wildfires from every other extreme weather event a utility plans for, Eyford said. 

“This is pretty much the one major event that they potentially could be responsible for, so this changes everything in terms of how they prepare, how they operate, and how they interact with the public,” he said. 

Utilities run thousands of miles of energized equipment through forests and neighborhoods, and, in his words, “we can't practically engineer that risk to zero.” 

What changed isn't the risk itself. It's how much of it the public still tolerates. 

“We've now seen billion-dollar lawsuits to the point where this is potentially even an existential risk to the utility,” Eyford said. “We've seen even bankruptcies as a result of this.”

Getting Ahead Of It

AI is where utilities are trying to buy back some of that lost tolerance. Nimmala said combining weather forecasts, vegetation LiDAR data, asset age and historical outage patterns lets utilities generate a risk score for individual pieces of equipment instead of entire regions. “We have seen where the deep learning frameworks have shown up to 35 percent reduction in load shedding during extreme weather events,” he said.

Most of the pieces are already deployed, according to Nimmala: advanced distribution management systems, fault location and restoration tools, and the metering and virtual power plant programs utilities are rolling out now. “The building blocks are there,” he said.

Whether utilities assemble them fast enough is a separate question. The data centers and the wildfires aren't waiting around for an answer.

By Michael Kern for Oilprice.com


No comments: