Why Critical Infrastructure Can’t Survive the Next Stuxnet Without New Rules
In February 2021, an attacker remotely accessed the control systems of a water treatment plant in Oldsmar, Florida, using compromised TeamViewer credentials and bypassed single-factor authentication to increase sodium hydroxide levels to dangerous extremes. The intrusion was only thwarted by an alert human operator who noticed the manipulation in real time.1 This was not a fictional scenario; it was a stark, real-world wake-up call. It demonstrated how easily digital vulnerabilities in critical infrastructure can be exploited to cause physical harm, revealing the profound inadequacy of our current security paradigms for an increasingly automated world. If a relatively simple control system can be compromised to this extent, what happens when more complex and opaque AI systems are integrated into our power grids, financial markets, and nuclear arsenals?
This analysis examines the escalating security risks of integrating artificial intelligence into critical national infrastructure, now amplified by a volatile geopolitical landscape. The central argument is clear: without a deliberate, robust, and internationally coordinated approach to AI security, we risk a future of unprecedented and potentially catastrophic systemic risk, especially as great-power competition incentivizes speed over safety.
The Unthinkable Risk
Nowhere are the stakes higher than in the domain of nuclear weapons. Experts in nuclear security and arms control have issued stark warnings that the integration of AI into nuclear command, control, and communications (NC3) systems is becoming “functionally inevitable.”2 Nations may pursue AI integration for perceived advantages in early warning, situational awareness, and decision support, creating a dangerous escalatory spiral.
This path carries immense risks. An AI system is only as reliable as its data and its code. Adversarial attacks could poison training data to create hidden biases, causing an AI to misinterpret a solar flare as a missile strike. The speed of AI-driven warfare could compress decision timelines from hours to seconds, creating the potential for “flash wars” similar to the 2010 algorithmic stock market crash3 and removing the human judgment that prevented catastrophe during events like the 1983 Stanislav Petrov false alarm.4 A direct cyberattack, like the Stuxnet malware that targeted Iranian nuclear centrifuges in 2010,5 could seize control of an AI-enabled system to initiate an unauthorized launch. In an NC3 context, a software error is a potential civilization-ending event.
A Brittle Foundation
While the nuclear scenario is the most extreme risk, the immediate threat is to the sprawling systems that underpin society. Recent policy shifts have exacerbated these dangers. The pressure to prioritize rapid AI deployment in critical infrastructure, even before robust security standards are met, lands on an already brittle foundation. The 2017 NotPetya attack, which caused an estimated $10 billion in damages,6 and the surreptitious insertion of the xz backdoor in 2024 showed how a single vulnerability can cause global disruption.7 The massive CrowdStrike outage of July 2024 further proved how dependency on a single service creates a catastrophic point of failure.8 A recent Government Accountability Office (GAO) report found federal agencies have still not completed key requirements for managing AI risks,9 a gap that is now far more dangerous. We are building our AI-powered future on fragile foundations at the precise moment a geopolitical race encourages us to ignore the cracks.
The New Arms Race
The challenge of securing AI is inherently international, but the landscape is defined by competition, not cooperation. Three divergent models are creating a complex and unstable security dilemma:
- United States: The U.S. prioritizes innovation speed and competitive advantage, accepting higher security risks to outpace rivals. This approach relies on the dynamism of its private sector but risks deploying insecure systems into critical infrastructure.
- China: Beijing is aggressively integrating AI into its military, state surveillance, and industrial base with few of the legal or ethical constraints present in the West. This state-directed model enables rapid, large-scale deployment, creating immense pressure on the U.S. to keep pace.
- European Union: Through its landmark AI Act, the EU is creating a rights-focused regulatory framework, establishing global standards through the “Brussels Effect.” While this promotes safety, its slower, more deliberative process is seen by some in the U.S. and China as a competitive disadvantage.
This geopolitical rivalry creates a perilous “race to the bottom,” where nations may consciously sacrifice safety and security to avoid falling behind, creating shared vulnerabilities that adversaries can exploit.
A Framework for Action
Addressing this challenge requires a multi-layered policy framework grounded in security, transparency, and accountability, adapted for an era of competition.
1. Mandate a Secure AI Development Lifecycle
Just as the software world adopted the Secure Software Development Lifecycle (SSDLC), we must mandate a similar framework for AI. This would require developers of AI systems used in critical applications to embed security at every stage, including rigorous data vetting, continuous model testing against adversarial attacks, formal verification where possible, and comprehensive red-teaming before deployment.
2. Secure the Global AI Supply Chain
We must mandate transparency in the AI supply chain, which is now a major geopolitical battleground. Critical system operators need an AI Bill of Materials (ABOM) detailing a model’s provenance, training data, and known vulnerabilities. This is complicated by two factors: the immense concentration of advanced semiconductor manufacturing in Taiwan, creating a critical single point of failure, and U.S. export controls on AI chips. While intended to slow adversaries, these controls also fragment the global market, potentially driving rivals to develop their own opaque, insecure AI ecosystems outside of U.S. oversight.
3. Enforce Robust Human-in-the-Loop and Human-on-the-Loop Requirements
For high-consequence decisions, AI should augment, not replace, human judgment. Policy must mandate meaningful human control. For critical systems, this means a “human-on-the-loop” approach, where a human operator actively supervises the AI and can intervene at any time. For the most irreversible decisions, such as the use of force, a strict “human-in-the-loop” requirement—where a human must give explicit, affirmative consent—is non-negotiable.
4. Pursue Pragmatic International Coordination
While geopolitical tensions make grand treaties unlikely, the U.S. must lead a pragmatic effort to establish stability norms. This includes creating crisis communication channels with rivals like China to de-escalate AI-related incidents, sharing information on major vulnerabilities, and defining clear red lines for attacks on AI-enabled critical infrastructure, particularly nuclear command and control. The goal is not just cooperation, but strategic stability in a world where AI is a vector of conflict.
Conclusion: The Time for Action is Now
The attempted attack on the Oldsmar water plant was a warning of tactical vulnerabilities. The current geopolitical race to AI dominance creates a strategic crisis. With U.S. policy now prioritizing speed, the risks of a catastrophic failure—whether from an adversary, a software flaw, or a supply chain collapse—have grown exponentially. Every new AI system integrated into our critical infrastructure without robust security guarantees is not an advancement, but the introduction of a systemic vulnerability.
The choice is not whether to innovate, but how to manage the immense risks of a technology that is central to both national security and global stability. A failure to act decisively is a policy choice that accepts catastrophic risk. Securing our AI-powered future is the defining infrastructure and security challenge of our time, and the work must begin in earnest today. Congress should attach ABOM language to FY 2026 NDAA, and the EU AI Act’s high-risk requirements take effect in 2026, providing a global framework for action.
References
1. FBI, “Compromise of U.S. Water Treatment Facility,” PIN Number 20210208-001, February 2021. https://www.cisa.gov/news-events/ics-advisories/icsa-21-042-02
2. Nuclear Threat Initiative, “A New Era: The Dangers of AI and Nuclear Weapons,” August 2023. https://www.nti.org/wp-content/uploads/2023/08/A-New-Era-The-Dangers-of-AI-and-Nuclear-Weapons.pdf
3. SEC/CFTC, “Findings Regarding the Market Events of May 6, 2010,” September 2010. https://www.sec.gov/news/studies/2010/marketevents-report.pdf
4. Wikipedia, “1983 Soviet nuclear false alarm incident,” https://en.wikipedia.org/wiki/1983_Soviet_nuclear_false_alarm_incident
5. Wikipedia, “Stuxnet,” https://en.wikipedia.org/wiki/Stuxnet
6. WIRED, “The Untold Story of NotPetya, the Most Devastating Cyberattack in History,” August 2018. https://www.wired.com/story/notpetya-cyberattack-ukraine-russia-code-crashed-the-world/
7. Ars Technica, “The xz backdoor: A timeline of events,” April 2024. https://arstechnica.com/security/2024/04/the-xz-backdoor-a-timeline-of-events/
8. CISA, “Widespread IT Outage Due to CrowdStrike Update,” July 19, 2024. https://www.cisa.gov/news-events/alerts/2024/07/19/widespread-it-outage-due-crowdstrike-update
9. U.S. Government Accountability Office, “Artificial Intelligence: Agencies Have Begun Implementation but Need to Complete Key Requirements,” GAO-24-106356, May 2024. https://www.gao.gov/products/gao-24-106356
