Five US Agencies Say AI Is Writing the Exploit Code Being Aimed at Water Utilities
A joint advisory describes AI-generated attack scripts disguised as legitimate monitoring tools, pointed at industrial controllers in water, energy and manufacturing. The honest version is narrower than the headlines and more worrying than the reassurance.
Outspoken Digest Technology Desk
Saturday, August 22, 2026/4 min read

A joint advisory from the National Security Agency, the Cybersecurity and Infrastructure Security Agency, the FBI, the Department of Energy and the Environmental Protection Agency has warned that threat actors are conducting reconnaissance against industrial controllers in United States critical infrastructure, and are using AI-generated exploitation scripts disguised as legitimate monitoring tools to do it.
CISA's own framing was unusually blunt. This is not a theoretical risk, it said. It is an active threat.
What is actually being targeted?
Programmable logic controllers, and specifically ones reachable from the open internet.
A PLC is the small industrial computer that opens a valve, runs a pump, holds a tank at a set level or keeps a production line in sequence. They are built for reliability across decades rather than for security, many run software that has not been updated in years, and a great many of them are connected to the internet by an integrator who needed remote access and did not think of it as an exposure.
The advisory names Siemens installations specifically. The sectors listed include water and wastewater systems, energy, critical manufacturing, chemical, food and agriculture, and commercial facilities.
How does AI change the attack?
It compresses the slow parts, and that is the accurate way to put it.
Finding exposed controllers has not required AI for years. Attackers use ordinary internet scanning services such as Censys and ZoomEye to enumerate devices running outdated or poorly protected software. That step was already cheap.
What AI does is accelerate what follows: reconnaissance at scale, exploit development, and generating malware variants at machine speed. Work that previously needed a skilled operator and days of effort can be produced faster and in greater volume, which lowers the level of expertise required to run a credible campaign.
The disguise detail is the part worth sitting with. Scripts presented as legitimate monitoring tools are difficult to catch precisely because industrial networks are full of legitimate monitoring tools, and the people running them are plant engineers rather than security analysts. Establishing what a piece of code actually is, and where it came from, is the same provenance problem that watermarking tries to solve for AI-generated media, and it is no easier here.
Is AI autonomously attacking power grids?
No, and it matters that the answer is no.
The picture in 2026 is that AI is an accelerant, not an agent. AI-accelerated attacks on critical infrastructure are documented across several countries. Autonomous AI systems independently deciding to hijack a grid remain a scenario rather than an observed event.
Conflating the two damages the response in both directions. It invites dismissal from operators who correctly notice that the apocalyptic version has not happened, and it directs attention towards a speculative threat while the real one is an unpatched controller with a default password facing the public internet.
The pattern of AI lowering the cost of an attack rather than inventing a new one is the same lesson that came out of the agent-driven intrusion earlier this year.
Why is water the recurring example?
Because it is the sector least equipped to defend itself.
Water and wastewater in most countries is delivered by a very large number of small utilities. A system serving a few thousand people may have no dedicated IT staff at all, let alone anyone responsible for industrial control security, and its budget is set by a local authority weighing it against roads and schools.
The consequence is a sector with a high count of independent targets, low average defensive capability, and severe physical consequences if something is altered. It is the combination rather than any single factor that makes it attractive.
In April, CISA and the FBI had already warned about Iran-affiliated groups attacking internet-exposed PLCs across water, energy and government targets, so this advisory extends an existing pattern rather than opening a new one.
What actually reduces the risk?
Unglamorous work that has been the advice for a decade.
Take controllers off the public internet. Put remote access behind a VPN with multi-factor authentication. Change default credentials. Segment the control network from the business network. Keep an offline copy of the controller logic so a plant can be restored rather than negotiated over.
None of that is new, and none of it is defeated by an attacker using AI. That is the genuinely useful thing to take from the advisory: the tooling on the offensive side has improved sharply, and the defensive gap it is exploiting is the same one that was there before.
What has changed is the margin for delay. When developing an exploit took a specialist weeks, an exposed and unpatched device was a risk that might not be found. When exploit generation is fast and cheap, it will be.
Published in The Outspoken Digest
Editorial desk
Outspoken Digest Technology DeskSoftware, hardware, artificial intelligence and what they change for everyone else.
Newsletter
The Digest, in your inbox
One edition, sent when it is ready. No noise, and your address is never passed on.
Read Next
More Technology →
Nevada Approved Up to 8,000 Robotaxis. Tesla's Own Cybercab Engineer Says It Might Manage 2,500.
Aug 22, 2026/3 min read

The Telescope Launching This Month Sees a Patch of Sky a Hundred Times Wider Than Hubble's
Aug 21, 2026/3 min read

China Is Sending a Lander, a Rover and a Hopper to the Lunar South Pole on Monday
Aug 21, 2026/3 min read

The Grades Went Up and the Knowledge Went Down. A Study of 3.2 Million Problems Caught Both at Once
Aug 18, 2026/5 min read