By now, everybody’s seen the recent announcement that there is a possibility that AI could lead to the end of mankind. While it’s likely that this announcement is mostly hype, there are some worrisome characteristics of AI that have to be taken seriously. For example, the hack of Hugging Face showed us that AI agents can be used to break through firewalls and hack into sophisticated networks. Many security experts have been bracing themselves for the pending introduction of hacking using quantum computers, but it looks like an equally terrible threat might already be here.
It’s worth pointing out that AI agents are not anywhere close to being self-aware and are not going to run around on their own hacking networks. Somewhere behind every hacking effort is a person who set the AI agents loose. Unfortunately, whether the origin of the hacking is a malicious foreign government or an overambitious teenager, the results can be the same. While the headlines are about the possible end of the world, the real immediate threat is the ability of AI agents to disable the many trusted computer networks that are in the background of our lives.
If we have problems with AI hacking, it’s not going to look like Skynet from The Terminator. Instead, it’s going to look more like Live Free or Die Hard, where commercial networks, banking systems, and traffic lights stop working reliably. That’s going to feel a bit like the end of the world, because the things we rely on every day are at risk of being broken. Anybody who has been through a major natural disaster knows what that feels like. I’ve had first-hand experience with two catastrophic hurricanes, and it’s daunting when power, water, cellular, and broadband all die, because losing those things kills other important functions like public safety and the food supply chain. Let’s face it – we are totally dependent on cloud systems. Look at the panic that ensues when cloud programs go out of service for a few hours.
I want to examine the possibility of AI hacking by looking at the example of hacking the least-connected network we all rely on – the water system. Water systems use SCADA (Supervisory Control and Data Acquisition) software that lets water system operators collect real-time data from field sensors and lets operators adjust flow rates, tank levels, and water pressure. Wells and pump stations use PLCs and RTUs , which are computers and software that automatically react to local sensor data. Water processing and sewerage plants have become increasingly automated.
If you go back just thirty years, practically nothing in a water system was computer-assisted outside of some customer billing. But we’ve been busy over the last several decades introducing software that increased efficiency and reduced the need for people. It’s ironic that, faced with the possibility of AI hacking, the improvements we’ve implemented in recent decades might now become the biggest vulnerability. We’re all vulnerable if our water network is disabled.
The obvious fix for AI hacking is to isolate a network from outside interference. We’ve been trying to do that for the last decade by placing networks behind firewalls and using a range of cybersecurity measures to fend off hackers. The scary scenario we’re suddenly facing is that those cybersecurity measures might be worthless if the hacker is a series of AI agents. I think the announcement by AI executives that AI could indeed go amok is really an admission that AI can likely overcome existing cybersecurity measures and break through firewalls.
If we can’t rely on existing firewalls and other cybersecurity measures, there are two alternatives. The old school way would be to go retrograde and return to the practices of thirty years ago when there were no computers and software anywhere in a water network. That’s pretty extreme, and I suspect that most water operators wouldn’t know how to go about disassembling computer controls without crashing the water system.
The other fix is to completely air-gap a water network, which means completely eliminating all outside connections to the system. That’s also a drastic step. It would mean cutting broadband lines and disabling the ability of smartphones or tablets to interface with the network. It means eliminating all cloud-based software and loading all software needed to operate the network locally. It probably means building a small data center to control the network locally. It means cutting off electronic links to neighboring water networks. It means more manual effort to accomplish tasks that have been automated.
If I operated a water or electric utility, I’d be having this conversation soon. The warning that AI could bring my current network down might means that all my current cybersecurity measures might be inadequate. The recent announcements of rogue AI agents, even if mostly hype, change everything related to network security.