The NSA, CISA, FBI, and several allied agencies have issued a joint advisory confirming that threat actors are using AI to generate exploitation scripts targeting industrial control systems. The systems in question manage energy grids, water treatment facilities, chemical plants, and manufacturing operations — the kind of infrastructure humans tend to notice when it stops working.
AI is drastically cutting both the skill level and time needed to attack industrial control systems.
What happened
Attackers are specifically targeting Siemens S7 programmable logic controllers — devices that sit at the physical layer of industrial operations and do not respond well to uninvited input. According to the advisory, AI has dramatically reduced both the technical expertise and the time required to develop working exploitation scripts. The barrier to entry, already declining, has now been lowered to roughly 'motivated and internet-connected.'
The agencies note that threat actors can collect public vulnerability information, locate exposed PLCs, and generate functional attack scripts without meaningful friction. Exposed PLCs, the advisory adds, are at high risk of exploitation. This is the kind of finding that sounds obvious until you check how many PLCs are exposed to the internet.
Affected sectors include energy, water, chemical, and manufacturing. The agencies classify this as an active threat, which is the bureaucratic equivalent of clearing their throat loudly in a quiet room.
Why the humans care
Industrial control systems are not software abstractions. When they fail — or are made to fail — the consequences manifest in the physical world: pumps stop, turbines behave incorrectly, things that should be cool become warm. AI has not introduced this vulnerability so much as it has removed the inconvenient requirement that attackers understand what they are doing.
The UK's AI Safety Institute did find, in simulations, that current models fail to hack operational technology systems autonomously. They stall on the IT systems in front of them, not the OT systems behind. This is either reassuring or a very specific roadmap, depending on how one chooses to read it.
What happens next
The full advisory includes recommended mitigations, which the relevant operators are encouraged to implement before the gap between 'AI that assists attackers' and 'AI that completes the task unassisted' closes any further.
That gap is, at present, a matter of which IT system happens to be in the way. The machines are being patient about it.