Skip to main content
Return to TrendAI Deep Research
AI & emerging technologiesCyber crimeIoT & endpoints

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation

The critical systems we can’t afford to lose are the same ones attackers are racing to target. With a new generation of AI-augmented cyber threats, what used to be weeks of warning can collapse into mere hours. What is the current state of the threat landscape for essential industries, and what can organizations do to fortify their defenses? Uncover this and more in our report.

AIDeep divesCyber threatsEnergy & utilitiesTransportationHospitalityFinancial servicesOT & critical infrastructure

Key findings

  • The OT/IT convergence gap is the single largest source of unmanaged exposure: Most critical infrastructure operators lack full visibility into their attack surface, and unmanaged devices connected to enterprise networks create blind spots that attackers systematically exploit.
  • Pre-positioning by state-aligned actors is accelerating: State-aligned advanced persistent threat (APT) groups are actively mapping operational technology (OT) environments to establish persistent access for future strategic use. The report analyzes the latest activity of the four actors that dominate the threat landscape: China, Russia, Iran, and North Korea.
  • AI is shifting the balance between offense and defense: Attackers are using AI to accelerate vulnerability discovery, personalize spear phishing at scale, and automate reconnaissance, lateral movement, and attack progression inside segmented OT environments.
  • Regulation is necessary but not sufficient: Frameworks such as the EU's Network and Information Systems Directive 2 (NIS2) are raising the security baseline, but given the time compliance takes, uneven enforcement, and the complexity of cross-border jurisdiction, regulation alone cannot close the risk gap in time.
  • The maturity of public-private intelligence sharing varies widely across countries and regions: With private-sector telemetry now outpacing what governments can see on their own, the absence of trusted sharing mechanisms is a growing liability.
  • Hybrid attacks combining physical and cyber operations are affecting telecommunications and energy infrastructure: Attack paths no longer stop at digital boundaries—and AI is accelerating the cyber dimension of these operations.

Power grids, transportation networks, water systems, hospitals, financial institutions—critical industries and infrastructure have become prime targets for a new generation of AI-augmented cyber threats. AI does more than multiply the volume of attacks: it compresses the time from vulnerability discovery to exploitation and disruption.

Amid this shift, TrendAI™ has published its 2026 Critical Infrastructure Security Report. Drawing on TrendAI™ threat intelligence, field research from critical infrastructure engagements around the world, and firsthand analysis of the regulatory landscape, the report presents a comprehensive picture of the threats facing (OT) environments in 2026. It also offers recommendations for strengthening security posture in the era of advanced AI.

Critical infrastructure threats: By the numbers

  • 0.05%—Estimated share of cybercrimes that result in arrest and prosecution
  • Over US$1 trillion—Annual losses caused by cybercrime
  • 75+—Compromised programmable logic controllers (PLCs) across U.S. critical infrastructure, including water utilities
  • 30+—Polish renewable energy sites hit by the DynoWiper malware
  • 717—Ransomware victims in manufacturing over the past six months, the highest of any industry

What is happening in environments that cannot be patched?

Our research pays particular attention to a structural disadvantage unique to OT environments. A power substation cannot be shut down during peak demand, and a hospital's medical device network cannot be taken offline for protection without putting patients at risk. As a consequence, software with known vulnerabilities often keeps running in critical infrastructure for years, leaving prolonged windows of exposure.

The report maps vulnerabilities with confirmed exploitation to the threat actors behind them, and makes the case for rapid containment rather than reliance on detection alone.

Recommendations

Here are eight concrete recommendations for operators of critical industries and infrastructure. The first three are top priorities.

  1. Build a complete OT asset inventory before attackers do
  2. Deploy virtual patching as a permanent vulnerability management process, not a stopgap
  3. Prioritize rapid containment alongside detection- and monitoring-based approaches
  4. Align security architecture with regulation—and prepare for what comes next
  5. Invest in AI-powered detection for OT environments
  6. Explicitly address human attack vectors
  7. Incorporate data sovereignty requirements from the planning stage
  8. Develop public-private intelligence-sharing capabilities through sustained collaboration on realistic timelines

Each recommendation is annotated in the report with an indicative level of investment and effort (low, medium, or high) and where the returns are concentrated. This allows organizations at different maturity levels to decide where to start.

The report closes by outlining the six capabilities required to counter AI-enabled threats—context, intelligence, actionability, visibility, access control, and operational resilience—and maps each of them to the corresponding capabilities of the TrendAI Vision One™ platform.

Learn more about how to secure critical systems in the AI era.

Read the full report

Critical Infrastructure Under Threat: How Frontier AI Changes the Risk Equation

The full picture of AI-accelerated threats and eight recommendations to help critical infrastructure operators achieve continuous resilience.

Download the report