Security1 publisher3 min readPublished
Grid's AI buildout adds attack surface and China dependency faster than old holes get closed
A Washington panel says electrotech widens the grid's attack surface while deepening reliance on Chinese components. One state's answer is an AI cybersecurity officer in every agency.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The Institute for Critical Infrastructure Technology (ICIT) held a panel on AI and industrial strategy in Washington on June 10, 2026.
- Panel participants included David Mussington, a University of Maryland professor, and Phoebe Vencill, a fellow at Carnegie Mellon University's Institute for Strategy and Technology.
- The panel focused on "electrotech," a broad category of technologies including batteries, virtual power plants and other digitally enabled systems increasingly underpinning energy infrastructure, transportation, communications and defense.
- Panelists said the same technologies that could improve grid security could also expand the grid's attack surface and increase dependence on components sourced from China.
- Experts said policymakers must carefully manage cybersecurity and supply chain risks as the country becomes increasingly dependent on digitally connected energy technology.
Compiled by The WatchSomething wrong?How this is made
Why it matters
An Institute for Critical Infrastructure Technology panel held in Washington on June 10, 2026 made the case that the digitally connected energy hardware going in to serve rising demand widens the grid's attack surface at the same time it deepens dependence on components sourced from China [1][4]. That is a procurement and engineering problem, and the policy response described in the same reporting is a staffing one: an initiative that mandates an AI cybersecurity officer inside every state agency and stands up an AI cyber defense program in the state's Cybersecurity Integration Center [7].
The panel's subject was "electrotech," which the discussion defined broadly enough to include batteries, virtual power plants and other digitally enabled systems that increasingly sit underneath energy infrastructure, transportation, communications and defense [3]. That is four sectors sharing one category of kit [9]. Panelists included David Mussington, a University of Maryland professor, and Phoebe Vencill, a fellow at Carnegie Mellon University's Institute for Strategy and Technology [2]. Their framing was not that these technologies are bad for security. It was that the same systems capable of improving grid security also expand what an attacker can reach and increase reliance on Chinese-sourced parts [4]. Both effects arrive on the same purchase order.
Experts on the panel said policymakers have to manage the cybersecurity and supply chain risk deliberately as the country grows more dependent on digitally connected energy technology [5]. The sequencing point in the source is the sharper one: critical infrastructure operators need to close the cybersecurity weaknesses they already have before attackers use AI to exploit them at scale [6]. Operators know what those weaknesses look like. Flat networks, unpatchable controllers, remote access paths for vendors, and asset inventories that were last accurate two acquisitions ago. Nothing about a virtual power plant deployment makes those easier. Every new distributed asset is another endpoint, another vendor relationship, and another firmware update path that has to be trusted.
Against that, the state initiative is a thin instrument. An officer title in each agency creates an owner and a reporting line, which is worth something, but it does not change a bill of materials, and the AI cyber defense program sits in a state integration center rather than at the utilities and distribution operators that hold the assets [7]. Worth noting: the source material does not name the state or the initiative, so the scope of the mandate cannot be checked from it [8].
Watch whether the officer mandate comes with procurement authority over grid-adjacent purchases, or whether it is reporting only. Watch whether any electrotech supply chain rules attach to the interconnection and buildout wave rather than to state agency IT. And watch for the first incident that runs through a distributed energy asset instead of a control room, because that is where these two risk lines meet.