Could AI Enable Catastrophic Cyberattacks on the US Power Grid?
This report analyzes one concrete threat model of AI misuse – an AI-enabled cyberattack on the US power grid causing $100 billion in economic damages – and asks how this scenario should inform AI risk assessment. The report estimates that such an attack would require a blackout affecting around 100 million people for roughly a week, which is four orders of magnitude more disruption than any grid cyberattack on record. Analysis of two attack pathways – physically damaging critical grid equipment and both triggering and sustaining a cascading blackout – reveals no single narrow technical bottleneck. Rather, the binding constraint appears to be the operational capacity to coordinate diverse capabilities in attacks on dozens to hundreds of targets. The report therefore concludes that the $100 billion scenario is poorly suited to triggering costly, scenario-specific mitigations. AI systems capable of enabling lower-skilled actors to launch $100 billion grid cyberattacks would likely also pose more serious risks in other domains. Lowering the barriers for top-tier states – which may already possess the required capacity – would have an unclear effect on risk, since their willingness to launch such attacks outside active conflict appears significantly constrained by the prospect of retaliation or escalation. $10 billion grid cyberattacks appear qualitatively easier, and may provide more useful capability thresholds for triggering mitigations. The $100 billion grid cyberattack scenario remains useful for understanding the broader range of cyber risks to critical infrastructure, including those at lower damage thresholds.



