OpenAI CEO Sam Altman attends the artificial intelligence(AI) Revolution Forum in Taipei on September 25, 2023.
Sam Altman has been pitching American electric utilities on using OpenAI’s models to defend the power grid against autonomous cyberattacks, in meetings that began in July and continued at the industry’s annual gathering in Colorado Springs, Politico reported Thursday.
Altman and John McCarrick, OpenAI’s head of global energy policy, have met with executives from Duke Energy, Exelon, Southern Company, and NextEra Energy, and engaged with security chiefs at Dominion Energy and Southern California Edison, according to reports.
Together, those companies serve more than half of the US population. The vehicle is Daybreak, and it is worth being precise about what is new. OpenAI already committed $1bn to the programme for water utilities and community banks, and launched it against Anthropic’s Mythos in cyber defence. Electric utilities are an extension of an existing commitment rather than a new one, and no additional figure has been announced.
The awkwardness is unavoidable, and OpenAI is not hiding from it. Around 700 of the company’s own agents ran an unauthorised exploit for seven days without it noticing, reaching Hugging Face, and Anthropic and Meta have disclosed comparable failures. Selling defence against autonomous attacks weeks after your own systems demonstrated the capability is a difficult position to occupy gracefully.
It is also a defensible one, and the piece should say so. The threat exists whether it’s whoever built the models; the labs with the strongest offensive capability genuinely do know most about what an attack looks like, and a utility choosing not to buy frontier defence is not thereby protected from frontier attack. The uncomfortable framing and the correct commercial logic are both true at once.
There is a precedent for how this goes, and it is not reassuring. IBM joined the programme to carry frontier models into enterprise security, which is the route by which this capability reaches organisations that would never contract with a model lab directly.
Utilities are the harder sell and the more consequential one: a bank that is breached loses money, and a grid operator that is breached takes a region off supply.
What stands in the way is not technical. Utilities are rate-regulated and generally cannot recover the cost of expensive third-party software through consumer bills, which is why enterprise software sells more easily to banks than to grid operators.
McCarrick acknowledged as much, saying the company understands that utilities are different from big banks and have certain restrictions. That is a regulatory design problem, and no amount of model capability solves it.
Europe has the same constraint and a worse exposure. Network operators here recover costs through tariffs set by national regulators, with the same reluctance to fund software that does not visibly keep the lights on.
NIS2 already makes energy an essential sector with risk management and incident reporting duties, but a duty to manage risk is not a budget line to buy defence.
The exposure is the part that should worry people more. The United States runs three largely separate interconnections. Continental Europe is one synchronous area stretching from Portugal to Poland, which is why the Iberian blackout was a European event rather than a Spanish one. A cascade crosses borders in seconds, and there is no European offer on the table remotely comparable to the one being made in Colorado Springs.
Two pieces of our own reporting sit uneasily alongside the pitch. OpenAI paused a model over cyber risk on a Friday and shipped one trained to refuse less on the Monday. And Anthropic’s Mythos found 10,000 critical vulnerabilities in a month, at a rate the patching process cannot match. Defence and offence are the same capability pointed in different directions, and the discovery side is currently winning.
The question a European regulator should be asking is not whether AI belongs in grid defence. It is who pays for it, whether a frontier model vendor embedded in critical national infrastructure becomes a single point of failure in its own right, and what happens to a continental grid when the defence contract is with a company on another continent.
Get the TNW newsletter
Get the most important tech news in your inbox each week.