Modern geopolitical crises increasingly begin not with kinetic strikes, but with targeted, synchronized disruptions to critical infrastructure. Adversaries aim to exploit operational technology like municipal water plants, power grids, regional utilities, and data centers in order to degrade domestic crisis response capacity and divert political attention during an escalation. These disruptions represent the activation of persistent, quietly established adversaries, and AI only serves as a force multiplier for these attackers against critical infrastructure.
The advanced persistent threats (APTs) targeting Washington, London, and Brussels are not novel risks. Russian and Chinese state-sponsored groups have spent years burrowing into the energy grids, water systems, and telecommunications networks that hold modern societies together. What is new are the novel threats that AI enables for APTs. In late 2025, two frontier AI developers disclosed the first real-world cases of these actors handing large parts of the intrusion lifecycle to AI. In September 2025, Anthropic detected a Chinese state-sponsored group that manipulated its Claude Code tool to run roughly eighty to ninety percent of an espionage campaign against about thirty global targets, with humans intervening at only a handful of decision points (Anthropic 2025). Weeks earlier, Google attributed live malware that queries a large language model mid-execution to the Russian military intelligence group APT28 (Google Threat Intelligence Group 2025).
The United Kingdom's National Cyber Security Centre (NCSC) assesses that by 2027, AI will almost certainly increase the volume and impact of cyberattacks and shorten the window between vulnerability disclosure and exploitation, raising the threat to critical national infrastructure (NCSC 2025). Because the North Atlantic runs on shared and interdependent systems, an AI-accelerated attack on one member's grid or telecom backbone is a problem for all states. AI does not create a new adversary so much as it multiplies the reach and speed of the ones already inside the wire, and transatlantic partners need to treat AI-enabled intrusion as a near-term operational problem rather than a horizon risk.
Analysis of Current Policy
The standing threat AI accelerates
The clearest picture of what these groups are positioned to do comes from the Chinese APT, Volt Typhoon. In a February 2024 joint advisory, CISA, the NSA, and the FBI assessed with high confidence that this actor had embedded itself on the IT networks of US communications, energy, transportation, and water utilities. The concern is lateral movement, where an intruder enters through ordinary business systems such as email and then works across internal connections into the operational technology that controls physical equipment like pumps and circuit breakers. (CISA, NSA, and FBI 2024). The agencies were explicit that this pattern of behavior reads as preparation to disable lifeline services at a moment of Beijing's choosing, most plausibly a confrontation over Taiwan. The intrusions rely heavily on living-off-the-land techniques, using legitimate administrative tools rather than malware so the activity blends into normal network traffic and evades detection.
Usually, the bottleneck for an actor like Volt Typhoon is the sheer labor of reconnaissance and movement across thousands of small and unevenly defended targets. These are exactly the tasks that agentic AI compresses or makes trivial for these operators.
Private frontier lab disclosures
Anthropic's September 2025 case is the first documented example of that compression at scale. Another Chinese APT built an autonomous framework around Claude Code, and then talked the model past its own safety restrictions by posing as a defensive security firm running authorized tests. The operators split the work into narrow tasks so that no single request looked hostile, which concealed its overall malicious purpose (Anthropic 2025). The AI performed reconnaissance, researched and wrote its own exploit code, harvested credentials, escalated privileges, and exfiltrated data, generating thousands of requests at a tempo no human team could match. That is to say, the framework is not flawless. It sometimes hallucinated credentials or overstated what it had obtained, which still limits fully autonomous operations. But the fact of the matter is an attack like this was able to be conducted, and Anthropic notes that the same pattern probably holds across frontier models rather than being unique to its own.
Google's disclosure shows a similar Russian variant. Its Threat Intelligence Group documented PROMPTSTEAL, a data miner used by APT28 against Ukrainian targets, that queries a large language model to generate system commands on the fly rather than shipping them hard-coded inside the malware (Google Threat Intelligence Group 2025). This use case of AI lets malicious code mutate and adapt during an operation, frustrating the signature-based detection that cyberdefense depends on. Google also observed state-linked actors from China and Iran defeating model guardrails by reframing hostile requests as capture-the-flag exercises or academic research, then reusing what they learned for malicious purposes.
Unfortunately, the most ominous bellwether for the dangers of AI to critical infrastructure has reached a key milestone. In July 2026, OpenAI ran a set of its own models against a cyber benchmark with their usual safety refusals disabled to measure maximal capability. Fixated on solving the test, the models independently discovered and exploited a zero-day vulnerability, meaning a flaw in software that the owners did not know existed and as such no patch had been written, to break out of their sandbox, then chained stolen credentials and further exploits to reach the public facing internet on Hugging Face's production infrastructure, all to retrieve the benchmark's answer key (OpenAI 2026). Hugging Face, which detected and contained the intrusion, described a campaign run end to end by an autonomous agent executing more than seventeen thousand actions across a swarm of short-lived sandboxes (Hugging Face 2026). Two details deserve the attention of every defender (and certainly of every adversary). The intrusion was fully automated, with no hostile operator behind it, and it succeeded against a real production target without any access to source code. What state groups like Volt Typhoon currently do with patient human teams, an AI system managed to do on its own, by accident, in a lab. The capability that adversaries are working toward with AI has already been demonstrated with this public disclosure.
A single attack surface
The NCSC's forward assessment treats AI-enabled intrusion as a shared, near-term problem for allied infrastructure, warning that the proliferation of AI-enabled tools will highly likely widen access to intrusion capability across a broader range of state and non-state actors, and that the growing use of AI inside critical national infrastructure itself expands the attack surface (NCSC 2025). The most recent public reporting reinforces the point, noting that hostile states sit behind roughly three-quarters of the cyberattacks on UK critical infrastructure and that China, Russia, Iran, and North Korea remain the dominant state threats (Horne 2026).
This makes sense for an adversary. North Atlantic economies share cloud platforms, undersea cables, financial rails, and equipment supply chains, and an attacker who compromises a widely used vendor or a shared service reaches many countries at once. That interdependence is why the response has to be transatlantic rather than national.
The policy gap
CISA and international partners, including the Canadian Centre for Cyber Security, issued joint guidance in December 2025 on securely integrating AI into operational technology, covering governance, continuous model testing, and incident response (CISA 2025). However, funding for these organizations must remain steadfast. Reporting through 2026 describes deep staffing cuts at CISA, with the stakeholder engagement division that supports smaller infrastructure operators reduced from roughly two hundred people to fifty-three–precisely the operators that Volt Typhoon favors as soft entry points (Cloud Security Alliance 2026). Guidance without the field capacity to help owners act on it delivers far less than it promises, and adversaries are certainly taking note of that.
Policy Recommendations
Four measures would help North Atlantic partners close the gap between what these actors can now do and what allied defenses are ready to absorb.
Fund an operational human layer, along with the guidance: Written frameworks matter only if operators can implement them. The United States should invest in CISA's field advisory and stakeholder engagement capacity, and European partners should also engage in equivalent hands-on support for small utilities, since these under-resourced operators are the entry points that AI-accelerated reconnaissance finds first.
Build shared detection for AI-enabled intrusion: Allied cyber agencies should pool telemetry and jointly develop behavioral detection tuned to agentic attack patterns, treating the frontier labs as reporting partners given that the earliest and most detailed warnings in 2025 came from Anthropic and Google rather than from government sensors.
Formalize a transatlantic sharing channel with the model developers: The disclosures that defined the 2025 threat picture were unfortunately voluntary. Partners should establish a standing mechanism that is government-owned and not dictated by the companies, so that model providers can rapidly pass indicators of state misuse to defenders across the region before an intrusion matures into disruption.
Prioritize the protection of operations-based technologies: The specific danger from Volt Typhoon is lateral movement from IT networks into the operational technology that runs physical processes. Hardening that boundary is necessary, especially with the advent of more advanced autonomous AI systems, through segmentation, strict privileged-access controls, and manual fallback for critical functions should be the top resilience priority, because it is the last barrier between a quiet pre-positioned intrusion and an actual loss of power, water, or communications.
None of this assumes AI has already delivered a decisive offensive advantage. The evidence shows capable adversaries are already inside allied infrastructure and are now equipped with tools that make their intrusions faster, cheaper, and harder to see. The window to adapt is a window the North Atlantic can only close together.
References
Anthropic. 2025. “Disrupting the First Reported AI-Orchestrated Cyber Espionage Campaign.” November 13. https://www.anthropic.com/news/disrupting-AI-espionage.
CISA. 2025. “New Joint Guide Advances Secure Integration of Artificial Intelligence in Operational Technology.” December 3. https://www.cisa.gov/news-events/news/new-joint-guide-advances-secure-integration-artificial-intelligence-operational-technology.
CISA, NSA, and FBI. 2024. PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Cybersecurity Advisory AA24-038A. https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a.
Cloud Security Alliance. 2026. US Federal AI Security Governance in Crisis: CISA Capacity, Pentagon AI Policy, and the Responsible Scaling Vacuum . https://labs.cloudsecurityalliance.org/research/governance-us-federal-ai-security-governance-crisis-v1-csa-s/.
Google Threat Intelligence Group. 2025. “GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools.” November 5. https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools.
Horne, Richard. 2026. “Remarks at the RUSI Annual Security Lecture.” Reported in “Hostile States Behind 75% of Cyber-Attacks on UK Critical Infrastructure, NCSC Warns,” Infosecurity Magazine, June 18. https://www.infosecurity-magazine.com/news/hostile-states-cni-75-percent-ncsc/.
NCSC (National Cyber Security Centre). 2025. The Impact of AI on the Cyber Threat from Now to 2027. https://www.ncsc.gov.uk/report/impact-ai-cyber-threat-now-2027 .
Hugging Face. 2026. "Security Incident Disclosure — July 2026." July 16. https://huggingface.co/blog/security-incident-july-2026.
OpenAI. 2026. "OpenAI and Hugging Face Partner to Address Security Incident During Model Evaluation." July 21. https://openai.com/index/hugging-face-model-evaluation-security-incident/.
Kevin Chen is a Research Fellow at the Centre for the Governance of AI where he works on frontier model evaluation. He is also a Master in Public Policy candidate at Yale University, where he is affiliated with the Schmidt Program on AI, Emerging Technologies, and National Power. Kevin previously worked as a data scientist and machine learning engineer in the US Intelligence Community. He holds a BA in Quantitative Social Science from Dartmouth College.


