
The security threat
Along with the potential impact of cognitive offloading on health and safety, AI raises fresh concerns when it comes to the cyber security of critical national infrastructure (CNI).
Cyber security remains a key concern for operators of CNI, as the high-profile hack of an unnamed peaker plant in August and a surge in cyber-attacks on water and wastewater plants in the US earlier in the summer demonstrated.
These were just a couple of the more well-documented incidents. The chief executive of the National Cyber Security Centre (NCSC), Dr Richard Horne, recently said more than 200 cyber incidents affecting the UK’s critical national infrastructure and its supporting ecosystem were managed by the NCSC in the year to May 2026, with around 75% of those believed to be linked to state actors. Cyber security consultancy Bridewell also found in a study published this year that 93% of CNI organisations experienced a cyber-attack in the past 12 months.
Number of cyber-attacks against critical infrastructure managed by the NCSC in the year to May
Proportion of these attacks believed to be linked to state actors
Proportion of critical infrastructure companies that have experienced a cyber-attack in the past 12 months
There are many more cyber-attacks on CNI taking place than those that make the news, points out Graeme Stewart, director of public sector sales at Check Point Software Technologies (he believes “breach fatigue” from the sheer number of attacks is responsible). When an incident does make headlines, such as the attack on carmaker Jaguar Land Rover, it’s because it’s a big deal. “There was a report that said the JLR attack was so big, it actually had a fundamental effect on the GDP of the country. I've been involved in cyber for nearly 30 years, and the idea that a cyber-attack would have a material, measurable effect on UK GDP is mind-blowing.
“My fear is that at some point there will be a successful attack on something in the CNI.” A lack of energy supplies could lead to a meltdown of law and order within 24 hours, Stewart suggests.
He says AI can be used as a tool by hackers to enable them to access areas they might otherwise struggle to get into. It may also help those with little hacking proficiency to become effective operators, while ratcheting up the scale of attacks. “It is speeding up the creation of attacks, but it's also speeding up the orchestration of the attacks.” (In the US, the expression ‘quarterbacking’ is now used to refer to a single coordinator or lead strategist managing multiple moving parts using AI.)
Stewart says: “The orchestration of a cyber-attack can be controlled using these AI tools. And frankly, someone with a little bit of knowledge can suddenly become exponentially more dangerous.
“The flipside to this is that the cybersecurity industry is using AI to rapidly improve the quality of the cybersecurity tools we deploy, as well as providing guardrails and controls for AI. We’ve got a whole section of our technology portfolio that is just focused on AI because the bad guys are using it as well.”
Networks are well-aware of this. “We have always known it was coming down the line,” says a security expert at one electricity network. He highlights the public announcement that Anthropic’s Claude Mythos model is capable of discovering hard to detect vulnerabilities (known as ‘zero-day’ vulnerabilities, or security flaws that no one knows about) in software. This prompted Anthropic to share the technology with AWS, Microsoft, Apple and other tech giants to develop defensive capabilities earlier this year.
But the Anthropic revelation also means hostile nation states and criminals are aware of the hacking potential of systems like Mythos. “There are already China-based organisations that are delivering tools like that,” the security expert says. “That means criminals can scan all your public-facing applications to find out how many vulnerabilities there are where you are not protected.
“That is the biggest threat to most CNI organisations: the pace of discovery. They can find out vulnerabilities in a matter of hours. We will not get patches in a matter of hours. Because of the pace of discovery, it has become even more important for CNI organisations to have mature cyber governance and incident response in place.”
The first port of call for organisations that want to ensure they are as protected as possible is the NCSC site, says Graeme Stewart. The NCSC Cyber Essentials programme helps organisations protect themselves against common online threats, providing a baseline level of security to work up from.
Companies should consider all people, processes and technology that could impact on security, and what to do in the event that they are hacked. ‘Wargaming’ scenarios can help organisations identify how they would respond if the worst happens. Stewart adds that it is also a good idea to consider the cyber security credentials of the supply chain. “Your supply lines are your weakest point.”
Like Waine, he stresses the positive impact of AI. “In the right hands, it's this incredibly valuable tool that will deliver productivity gains and autonomous thinking and creativity.
“In the wrong hands, it's a weapon.”
The ‘5 Ds’ of cognitive offloading risk patterns:
- Dependency – cognitive offloading may degrade engineering judgment and capability.
- Disengagement – cognitive offloading may reduce opportunities to reorganise how attention is focused on systems.
- Drift – cognitive offloading may allow professional understanding to fall behind the AI system status.
- Data – cognitive offloading may change what information is valued by an organisation.
- Disconnection – cognitive offloading disconnects social relationships, professional collaboration, and training.
