Frontier Risk: AI, OT, and the Threat Landscape
In 2026, a utility deploying AI is simultaneously expanding its attack surface and accelerating its operational tempo. The same data integration that makes an AI topology optimizer useful (live EMS telemetry, real-time switch status, sub-minute network model updates) creates new pathways into the operational technology environment that adversaries actively seek. This lesson brings together CIP-grade security thinking, the threat landscape that NERC's May 2026 Level 3 Alert made explicit, and the specific risk profile that emerges when AI models are placed adjacent to OT systems.
The Threat Landscape in 2026
The bulk electric system has been a named target for nation-state and criminal cyber actors for more than a decade. What changed in 2026 is the intersection of three simultaneous trends: the expansion of the OT attack surface driven by grid modernization and AI deployment, the growing financial incentive for criminal actors as AI-enabled market manipulation becomes technically feasible, and the emergence of AI itself as a tool in the adversary's toolkit.
NERC's Level 3 Alert issued in May 2026 reflected the seriousness with which the reliability organization views current threat actor activity against bulk electric system infrastructure. A Level 3 Alert is not a routine notice; it represents NERC's assessment that there is credible threat information requiring immediate attention from registered entities. The May 2026 alert context, connected to concerns about large compute loads as new grid actors and the expanding OT attack surface from grid AI deployment, underscored that the threat environment for AI-enabled utilities is materially different from the threat environment that shaped the original CIP standards.
The threat actors relevant to an AI-enabled utility operate across three categories. Nation-state actors (primarily from adversary states with advanced persistent threat capabilities) target BES Cyber Systems with the objective of positioning for disruption: pre-positioning malware in the OT environment so that it can be activated during a geopolitical crisis to cause a coordinated grid disruption. These actors are patient, persistent, and technically sophisticated; they exploit the interfaces between IT and OT environments that grid modernization has multiplied. Criminal actors (ransomware operators, data theft groups) target utilities for financial gain: encrypting operational data, exfiltrating sensitive data, or disrupting operations to extract ransom payments. The 2025-2026 period saw significant ransomware activity against energy sector entities, and AI-enabled grid operations create new financial targets (market manipulation through AI model corruption or AI-assisted prediction of when a targeted disruption creates maximum financial impact). Insider threats and supply chain actors represent the third category: a malicious vendor software update that corrupts an AI model's training data, a contractor with SCADA access who exfiltrates real-time grid state data, or a rogue employee who manipulates a forecasting model's outputs to benefit a trading position.
CIP-003-9 and What It Changed
NERC CIP-003-9 became enforceable on April 1, 2026. Its precise scope is vendor electronic remote access and supply-chain security for low-impact BES Cyber Systems, a category that many utilities had treated with substantially lighter security governance than their high-impact and medium-impact assets. The assumption was that low-impact assets, by definition, presented lower risk. CIP-003-9 challenged that assumption by extending baseline cyber security management controls to this category, with particular focus on managing vendor electronic remote access pathways and the associated supply-chain risk they represent.
For AI governance, CIP-003-9 is significant on three dimensions. First, many AI data pipelines that were designed before April 2026 were built with the assumption that accessing data from low-impact BES Cyber Systems did not require the same level of CIP governance as accessing data from high-impact assets. After April 1, 2026, that assumption is wrong. Any AI system that uses vendor-provided electronic remote access to reach low-impact BES Cyber Systems (including distribution SCADA, substation automation systems, and remote terminal units at low-impact substations) is subject to CIP-003-9 requirements for access management, transient device controls, and supply chain security review of the vendor providing that remote access pathway.
Second, CIP-003-9 brought supply chain security requirements to the low-impact level. The original CIP-013 supply chain requirements applied at the high and medium impact levels. CIP-003-9 extends a baseline supply chain security framework to low-impact assets, focused specifically on the vendors whose personnel or software reach into those assets remotely. An AI vendor whose platform accesses low-impact BES Cyber Systems via electronic remote access must be reviewed for supply chain risk under this baseline, even if the full CIP-013 framework does not apply.
Third, CIP-003-9 addressed transient devices: laptops, tablets, and USB drives that connect temporarily to BES Cyber Systems. In the AI context, the relevant transient device concern is the model deployment workflow: when a data scientist connects a laptop to an OT-adjacent network to deploy a new model version, update configuration files, or run diagnostic queries, that laptop is a transient device. If it is not managed under the entity's transient device management program, it is a CIP-003-9 gap regardless of how low-impact the assets it connected to are classified.
CIP-012-2 and Real-Time Data Protection
CIP-012-2, the version effective July 1, 2026 (superseding CIP-012-1), protects the real-time monitoring and control data transmitted between control centers and adds explicit requirements for the availability of those communication links, not just their confidentiality and integrity. Its relevance to AI is direct and often missed: the data that an AI system reads to produce a recommendation (EMS state estimation snapshots, SCADA telemetry, contingency analysis results) is real-time monitoring data. If that data is transmitted over communications links between control centers (for example, between a primary and backup control center, or between a utility control center and an ISO/RTO), CIP-012-2 obligations apply to the communications infrastructure.
When a utility deploys an AI analytics platform at one control center that consumes data originating at another control center, the data transmission may fall under CIP-012-2. This does not mean the AI platform itself is the protected entity; CIP-012-2 focuses on the communications infrastructure. But the utility must confirm that the data pathway from the originating control center to the AI analytics environment does not create a gap in the CIP-012-2-compliant communications architecture.
A specific CIP-012-2 scenario that AI deployment can create is the aggregation of real-time data from multiple control centers into a single analytics environment. If a multi-utility holding company wants to deploy a single AI analytics platform that ingests data from three different utility control centers, the communications links feeding that platform are within the scope of CIP-012-2 for each contributing control center. The holding company's AI governance program must confirm CIP-012-2 compliance for each link, not just the technical adequacy of the analytics platform.
CIP standards do not bend for AI deployments. The obligation follows the data, not the purpose for which the data is used.
The AI-Specific Threat Surface
Beyond the expansion of the traditional OT attack surface, AI deployment creates threat vectors that the original CIP framework was not designed to address. Understanding these vectors is essential for building a security posture that is adequate for the AI-enabled grid.
Model Poisoning and Training Data Attacks
An AI model's behavior is determined by its training data. An adversary who can inject malicious data into the training pipeline can alter the model's learned behavior in targeted ways. In a utility context, a training data attack against a load forecasting model might inject false historical load events that cause the model to systematically underforecast peak load, leading to inadequate capacity procurement during a crisis. A training data attack against a predictive maintenance model might cause it to classify a critically degraded transformer as healthy, deferring maintenance until a failure causes an outage.
Training data attacks are particularly difficult to detect because they do not require access to the production model; they only require access to the training data pipeline. If the training data pipeline is not subject to the same integrity controls as the production AI system, it is a lower-privilege attack path to an equivalent effect. The CIP compliance program should address training data pipeline integrity as part of the AI governance program, because an attack on the training data pipeline is functionally equivalent to an attack on the production AI system it produces.
Model Inference Attacks and Adversarial Inputs
A deployed AI model can be attacked through its inputs. Adversarial input attacks craft inputs that are designed to cause the model to produce a specific wrong output: small, carefully designed perturbations to sensor readings that cause an anomaly detection model to miss a real threat, or small changes to grid state data that cause a topology optimizer to recommend a switching sequence that creates a fault. In the physical world, adversarial inputs to a grid AI system are analogous to spoofing SCADA sensor readings; the objective is to make the system believe the grid is in a different state than it actually is.
The defense against adversarial input attacks in the AI context overlaps with the defense against SCADA spoofing: cross-reference multiple sensor readings, apply physical consistency checks (a state estimate that is inconsistent with the physics of power flow should be flagged regardless of whether the inconsistency was caused by a SCADA error or an adversarial input), and maintain a human review checkpoint for any AI recommendation that contradicts the operator's situational awareness.
Model Theft and Intellectual Property Exposure
A production AI model (the trained weights, architecture, and feature definitions) is a valuable intellectual property asset that an adversary can exploit in multiple ways. An adversary who obtains a copy of the utility's market-bidding AI model gains insight into the utility's bidding strategy and cost structure. An adversary who obtains a copy of the predictive maintenance model gains insight into which assets the utility considers most vulnerable. An adversary who obtains a copy of the topology optimization model can potentially use it to predict how the utility would respond to a disturbance, informing the design of an attack that exploits that predicted response.
Model theft is not currently addressed by CIP standards, but it is an AI-specific risk that the enterprise AI policy and the OT security program should address. The model registry in the use-case register should include access controls on the trained model artifacts themselves, not just on the data they process.
AI in the Adversary's Toolkit
The adversary is also adopting AI. AI-assisted attack tools can automate reconnaissance (scanning for exposed OT systems and AI analytics endpoints), accelerate vulnerability exploitation (AI-assisted code generation for novel exploit development), and optimize attack timing (using AI to predict when a coordinated grid disruption would have maximum impact based on forecasted weather, demand, and reserve conditions). The most concerning near-term threat is AI-assisted spear-phishing: highly personalized social engineering messages that target employees with OT or AI analytics access, using AI to generate credible context from public information about the utility's operations and personnel.
Building a CIP-Grade Security Posture for AI
A CIP-grade security posture for an AI-enabled grid requires applying the defense-in-depth principles of the CIP framework to the new attack surfaces that AI creates, without assuming that the existing CIP controls are sufficient for the new threat model.
AI System Classification and the CIP Review
The starting point is classification: every AI system must be assessed against the BES Cyber System criteria. Does the AI system perform a function that, if degraded or compromised, could affect the BES? Does it have electronic access to BES Cyber Systems? Does it process BCSI (BES Cyber System Information)? If the answer to any of these questions is yes, the AI system must be assessed for CIP classification, and the relevant CIP standards (CIP-003 through CIP-014 as applicable) must be applied to the AI system's design and operation.
For most advisory AI systems that consume data from BES Cyber Systems but do not execute actions, the classification question is: does the data access pathway itself create a risk? The answer is yes in two circumstances: if the data access pathway is bidirectional (the AI system can send data back to the BES Cyber System), or if the AI system's outputs are consumed directly by a BES Cyber System without a human review step. Either of these conditions elevates the AI system's risk profile significantly and may require it to be classified as a BES Cyber Asset or an associated system with corresponding CIP obligations.
Securing the AI-OT Interface
The interface between the AI analytics environment (typically in IT) and the OT environment is the highest-risk connection in the AI deployment architecture. The security architecture for this interface should apply the following principles: minimum necessary data access (the AI system should only have access to the specific data elements it requires for its function, not broad access to the OT data environment), one-way data flow where possible (data diodes that allow data to flow from OT to AI analytics but prevent any data from flowing in the reverse direction), network segmentation (the AI analytics environment should be in a separate network segment from both the IT enterprise network and the OT network, with controlled access from both sides), and continuous monitoring of the interface for anomalous data flows.
The CIP-005 Electronic Security Perimeter framework provides the structural basis for securing the AI-OT interface. The key determination is whether the AI analytics environment is inside or outside the ESP: if outside, the data access pathway from inside the ESP to the AI environment must be governed by ESP access controls including electronic access point monitoring; if inside (which would apply if the AI system is classified as a BES Cyber Asset), the AI system is subject to all CIP controls that apply to BES Cyber Systems inside the ESP.
Supply Chain Security for AI Vendors
CIP-013 requires that entities have a supply chain risk management plan for BES Cyber Systems. For AI systems that are classified as BES Cyber Systems or as systems adjacent to the ESP, the AI vendor is a supply chain risk. The risk profile of an AI vendor is different from that of a traditional control system vendor in important ways: AI vendors often update their models and software more frequently than SCADA vendors, the AI model weights themselves are a software artifact that can be manipulated in a supply chain attack, and many AI platforms use open-source components that have different vulnerability disclosure and patching dynamics than proprietary SCADA software.
The CIP-013 review for an AI vendor should address: the vendor's own cybersecurity practices (do they apply secure software development practices, do they have a vulnerability disclosure program), the update and patching process for the AI platform (how are model and software updates delivered, can the utility control when updates are applied), the integrity verification mechanism for software and model updates (is there a cryptographic signature or hash verification that the utility can use to confirm the integrity of a delivered update), and the vendor's data handling practices (does the vendor retain copies of the utility's operational data used to train or fine-tune the AI model).
Worked Example: The Advisory AI That Became a CIP Question
A control room at a large transmission-owning utility deployed an AI advisory system that monitors 40 operational parameters and alerts the system operator when the combined pattern suggests an emerging contingency risk. The system was classified as advisory: it had no ability to execute any action on the EMS or SCADA system. The engineering team's position was that an advisory-only system with no write access to any BES Cyber System did not require a CIP classification review.
The CIP compliance team's review found three issues. First, the AI system's data access pathway pulled live state estimation data from the EMS historian through an API. The EMS historian was inside the ESP, and the API connection from the AI analytics environment outside the ESP to the historian inside the ESP was an electronic access point under CIP-005. It had not been included in the electronic access point inventory, creating a CIP-005 gap regardless of whether the AI system itself was classified as a BES Cyber Asset.
Second, the AI system's vendor provided model updates through an automatic update mechanism that downloaded new model versions from the vendor's cloud infrastructure directly to the AI analytics server. The update mechanism was a software pathway from the internet to a system with ESP access, which is a supply chain security concern under CIP-013. The update mechanism had not been reviewed under the entity's CIP-013 plan because the AI system had not been assessed for supply chain risk.
Third, the operator's alert display for the AI advisory system was on the same workstation as the operator's primary EMS display. If an adversary compromised the AI advisory display software and used it to display false alerts, or to modify the appearance of the EMS display through a shared workstation vulnerability, the advisory classification of the AI system would not prevent the attack from having an operational impact.
None of these findings required that the AI system be classified as a BES Cyber Asset. But all three required changes to the entity's CIP program: the EMS historian API connection needed to be inventoried as an electronic access point with appropriate monitoring; the AI vendor update mechanism needed to be reviewed under the entity's CIP-013 supply chain plan; and the advisory display workstation needed to be assessed for shared-workstation vulnerability isolation. The lesson is not that advisory AI is inherently CIP-relevant. The lesson is that the data access pathway, the software update pathway, and the physical proximity to operator workstations all create CIP touchpoints that must be explicitly assessed rather than assumed to be outside scope because the AI system has no write access.
Key Takeaways
- The AI-enabled grid faces a materially changed threat landscape in 2026: nation-state actors targeting the expanded OT attack surface, criminal actors targeting AI-enabled financial assets, and AI itself deployed as a tool in the adversary's toolkit including AI-assisted spear-phishing and reconnaissance.
- CIP-003-9 (enforceable April 1, 2026) addresses vendor electronic remote access and supply-chain security for low-impact BES Cyber Systems; AI systems that use vendor-provided remote access pathways to reach low-impact assets are now subject to baseline CIP access management, transient device controls, and supply chain security review of the vendor providing those pathways.
- CIP-012-2 protects real-time monitoring and control data transmitted between control centers; AI analytics platforms that consume data from multiple control center sources must be assessed for CIP-012-2 compliance in the data transmission architecture, not just in the analytics platform itself.
- AI-specific threat vectors include model poisoning (training data attacks that alter learned behavior), adversarial inputs (crafted sensor readings designed to cause wrong AI outputs), and model theft (gaining access to trained model artifacts to understand the utility's operational strategy or exploit vulnerabilities in its AI-driven response).
- An AI advisory system with no write access to BES Cyber Systems can still create CIP compliance obligations through its data access pathway (electronic access points), its software update pathway (supply chain security), and its physical proximity to operator workstations (shared vulnerability exposure).
- The supply chain security review for AI vendors must address update and patching processes, software and model integrity verification, data handling practices, and the vendor's own cybersecurity posture; AI vendors update more frequently than traditional SCADA vendors and have a different vulnerability profile.
- The defense against adversarial AI inputs overlaps with the defense against SCADA spoofing: cross-reference multiple sources, apply physical consistency checks to AI recommendations, and maintain a human review checkpoint for any AI recommendation that contradicts the operator's situational awareness.
Skill.re