INSTITUTIONAL RISK BRIEF · 09

AI in Critical Infrastructureautomation, resilience, and human control.

AI is entering the systems that plan, operate, monitor, and defend essential infrastructure. In operational technology, the relevant standard is not whether a model usually performs well. It is whether the system remains safe under abnormal conditions, attack, degraded communications, and incomplete information.

PREPARED BY SYNTHETIC OUTLAW RESEARCHSCOPE SELECTED U.S. CRITICAL-INFRASTRUCTURE AUTHORITIESPUBLISHED JUL 21, 2026VERSION 1.0
01 · THE BURDEN

Efficiency is valuable.
Safe failure is non-negotiable.

DOE identifies unintentional failure, adversarial attack, hostile AI use, and compromise of the AI software supply chain as critical energy risks. Its current AI-FORTS program separates securing infrastructure from AI, securing it with AI, and securing the AI used in operations.

The resilience promise

AI can improve forecasting, anomaly detection, inspection, maintenance, cyber defense, load management, restoration planning, and operator awareness across complex systems.

The operational burden

A model can fail outside its training distribution, be manipulated through data or interfaces, automate a bad response faster, or remove the operator’s ability to understand and intervene. Essential service magnifies small control failures.

02 · CONSEQUENTIAL WORKFLOWS

Where AI becomes institutional action.

The relevant question is not whether AI appears in the workflow. It is whether its output changes attention, access, price, timing, treatment, judgment, or a person’s practical ability to obtain review.

01

Planning and forecasting

Models influence capacity, demand, maintenance, weather, investment, and contingency assumptions.

02

Operations and control

AI can recommend or execute changes in grids, transport, water, communications, and industrial systems.

03

Cyber defense

Detection and response systems prioritize alerts, isolate assets, and recommend action under uncertainty.

04

Inspection and maintenance

Prediction determines which assets receive attention before failure.

05

Emergency response

Decision support shapes restoration, resource allocation, public warnings, and interdependency management.

03 · AUTHORITIES

The duties converge.
The operating standard remains distributed.

Critical-infrastructure governance combines sector regulation, reliability standards, safety engineering, cybersecurity, emergency authority, procurement, and voluntary AI risk frameworks. The control environment must be specific to the physical process.

SCOPE
DOE materials focus on the energy sector; NIST’s critical-infrastructure AI profile is under development. Operators remain subject to sector-specific law, regulation, reliability standards, safety cases, contracts, and engineering obligations.
U.S. DEPARTMENT OF ENERGY · CESER

Secure from AI, with AI, and the AI itself.

DOE’s AI-FORTS program addresses AI-enabled attacks, AI for defensive capability, and hardening AI used to operate, control, or defend energy systems. Primary source →

NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY · 2026

Critical infrastructure needs a tailored AI profile.

NIST is developing lifecycle practices for trustworthy AI across IT, operational technology, industrial control, and supply chains. Primary source →

U.S. DEPARTMENT OF ENERGY · 2024

Failure, attack, hostile use, and supply chain are distinct risk classes.

DOE’s assessment identifies four broad categories and calls for regularly updated, risk-aware deployment guidance. Primary source →

U.S. DEPARTMENT OF ENERGY · 2026

Agentic systems need realistic operational testing.

DOE and LLNL’s Stormbreaker testbed evaluates LLM and agentic AI behavior in power and operational-technology environments. Primary source →

SYNTHETIC OUTLAW ANALYSIS
The governance gap is created when AI is reviewed like enterprise software but deployed into a physical control environment. Institutional control requires a system safety case: defined authority, realistic test evidence, independent protection, graceful degradation, manual recovery, and incident learning.
04 · VERIFICATION

What must be established before output becomes consequence?

Critical-infrastructure verification must be scenario-based, adversarial, and tied to physical consequence.

BoundaryWhat can the system observe, recommend, command, and change?
FailureWhat happens when data, models, networks, or operators are wrong?
RecoveryCan people detect, isolate, override, and restore safely?
VERIFICATION LAYERTHE QUESTIONREQUIRED EVIDENCEFAILURE IF OMITTED
Operational envelopeUnder what loads, environments, states, and dependencies is behavior validated?Scenario set, limits, uncertainty, out-of-distribution detection, and safe-state rules.A system extrapolates beyond evidence inside a live physical process.
Security and supply chainCan inputs, models, tools, updates, or dependencies be compromised?Threat model, provenance, access control, red-team results, signing, and component inventory.The control system trusts manipulated data or a compromised AI component.
Human and independent protectionCan operators understand, reject, isolate, and recover without the AI?Alarm design, training, authority, manual mode, independent interlocks, and drills.The nominal human fallback depends on the same failed system or arrives too late.
Incident and recoveryCan the operator reconstruct action and restore essential service safely?Immutable logs, clock synchronization, decision trace, rollback, continuity plan, and exercises.The organization cannot distinguish model failure, cyberattack, operator action, or cascading dependency.

Operational rule: No AI should receive operational authority that exceeds the tested envelope, independent protection, and recovery capability of the system around it.

05 · CONSEQUENCE TEST

Follow the burden to the person or system that carries it.

A concrete pathway reveals where a nominally advisory system becomes practically decisive.

HYPOTHETICAL · GRID OPERATIONS

The forecast is plausible. The operating condition has changed.

A load-management agent recommends automated demand response during extreme heat. Sensor degradation causes the model to underestimate demand in one region.

01 · SIGNAL

The model receives incomplete telemetry but does not cross its confidence threshold.

02 · ACTION

Automated controls reduce reserve in the wrong area.

03 · CASCADE

Operators receive multiple downstream alarms without a clear originating explanation.

04 · RECOVERY

Manual intervention depends on interfaces optimized around the agent’s recommendations.

The model’s individual action looked reasonable. The system lacked enough independent evidence and recovery design to contain the error.EXPLORE RELATED RECORDS →
SYNTHETIC OUTLAW OBSERVATORY

See the evidence.

The Observatory tracks documented events involving energy, water, transport, communications, industrial control, autonomous systems, cyber defense, and infrastructure accountability.

LOADING LIVE CRITICAL INFRASTRUCTURE RECORDS…
06 · LEADERSHIP TEST

Questions leaders must be able to answer.

Infrastructure leaders need an authority map that joins AI governance to system safety and operational resilience.

Where can AI cross from information into physical action?

Include recommendations that operators routinely accept.

What is the tested operating envelope?

List conditions, dependencies, data quality, and states outside evidence.

Which protection remains independent of the AI stack?

Fallback cannot share the same failure mode.

How is agentic or tool-using behavior constrained?

Define permissions, command limits, rate limits, approval, and isolation.

Can the organization recover during simultaneous failure and attack?

Exercise ambiguous, cascading, and communications-degraded scenarios.

07 · CONTROL PRIORITIES

What an institution should require now.

Controls must reflect the actor, authority, system, population, data, consequence, and environment of failure.

01 · AUTHORITY

Constrain operational permission.

Use least privilege, command allowlists, rate limits, approvals, and hard interlocks.

02 · SAFETY CASE

Tie claims to realistic evidence.

Document hazards, envelope, scenarios, assumptions, margins, and residual risk.

03 · INDEPENDENCE

Protect the process outside the model.

Use separate sensors, deterministic limits, manual modes, and fail-safe states.

04 · ADVERSARIAL TEST

Test hostile and degraded conditions.

Exercise poisoned data, prompt attacks, compromised tools, outages, latency, and ambiguity.

05 · CHANGE CONTROL

Control every model and dependency update.

Sign, stage, validate, monitor, approve, and roll back versions and components.

06 · RECOVERY

Train for loss of AI.

Maintain logs, drills, offline procedures, restoration priorities, and cross-sector coordination.

CRITICAL INFRASTRUCTURE AI EXPOSURE REVIEW

Bring one operational AI pathway into the room.

A focused review follows one deployed or proposed AI system from signal to physical consequence. It tests authority, safety evidence, cyber exposure, independent protection, human control, recovery, and incident accountability.

  1. 0190-MINUTE OPERATIONAL LEADERSHIP SESSION
  2. 02ONE CONSEQUENTIAL IT, OT OR ICS WORKFLOW
  3. 03AUTHORITY, FAILURE AND RECOVERY REVIEW
  4. 04WRITTEN VERIFICATION-BURDEN MEMORANDUM
  5. 05PRIORITIZED RESILIENCE CONTROLS

INITIAL INQUIRY ONLY. Do not submit privileged, classified, export-controlled, patient, student, applicant, customer, personal, or other confidential information through this form. The Synthetic Outlaw team reviews the request and responds directly to determine scope and fit.

Loading secure verification…
08 · SOURCES

Primary sources.

This brief relies on selected U.S. energy and AI risk-management authorities. It is not engineering, cybersecurity, regulatory, or legal advice and does not state the requirements governing every infrastructure sector, operator, system, or jurisdiction.

NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY · 2026AI RMF Profile for Trustworthy AI in Critical Infrastructure
U.S. DEPARTMENT OF ENERGY · 2026Stormbreaker LLM and Agentic AI Testbed
SYNTHETIC OUTLAW OBSERVATORYRelated Critical Infrastructure Records
RECOMMENDED CITATION

Synthetic Outlaw Research. “AI in critical infrastructure: automation, resilience, and human control” Institutional Risk Brief 09, version 1.0. July 21, 2026. https://www.syntheticoutlaw.com/industries/critical-infrastructure.html.