Over the past year, the world’s attention has turned to economic chokepoints—with good reason. Iran has exercised its control over the Strait of Hormuz to gum up the global economy, and China has used its command over critical minerals to gain leverage in trade negotiations. Less consideration, however, has been paid to chokepoints in the digital domain, which could prove just as treacherous.
Chinese hackers have gained and retained access to U.S. communications, energy, and transportation infrastructure. The goal of these intrusions is more than intelligence gathering; it is laying the groundwork for sabotage. Just as Iran’s closure of a vital waterway has been extremely disruptive and hard to get around, China’s penetration of critical networks could cause blackouts, make water unsafe to drink, or delay military mobilization. Indeed, the fragility of U.S. critical infrastructure was made clear this summer when Iranian hackers compromised water facilities across multiple U.S. states, causing one county to direct residents to boil water. U.S. allies are also vulnerable. China has breached hospitals in Taiwan, power grids in India, and telecommunications networks in Singapore.
As I argued in an essay in Foreign Affairs last year, there is a fundamental asymmetry between China’s authoritarian approach to cyberdefense and the United States’ more democratic method. American laws and values preclude the U.S. government from monitoring private communications and critical national networks in the ways that the Chinese government does. Beijing, for its part, maintains a series of firewalls that—in addition to surveilling and censoring the Chinese people—protect Chinese networks from American offensive intrusions. And where critical infrastructure in China is centralized and controlled by the state, in the United States it is owned and operated by a diverse array of private actors with varying levels of cyberdefense. China, therefore, can use cyberweapons against the United States and its allies with greater confidence that it can withstand retaliation.
Artificial intelligence is likely to exacerbate this asymmetry. Although the technology has revolutionized both offensive and defensive cyber-operations, it tends to benefit attackers more. Because AI could disproportionately benefit China, the United States has all the more reason to use the technology to improve its cyberdefenses. A year ago, using AI to defend critical infrastructure at scale was possible only in principle. Today, it is possible in practice, as advances in AI have brought down the costs of securing U.S. critical infrastructure.
To root out Beijing’s digital chokepoints before they are weaponized, Washington, AI labs, and infrastructure operators need to proactively stress-test critical systems, such as plants and grids serving big cities or military bases, against cutting-edge AI models. Doing so would reveal decades of accumulated American vulnerabilities and offer a guide to how to fix them. Without such an understanding, the United States will continue to lose the cyberwar to China.
A NEW FRONTIER
Economies and militaries often run on digital infrastructure that wasn’t built for the tasks they carry out today, making them attractive and accessible targets for sabotage. That is, in part, why wars of the future will likely play out in the cyber-domain. The United States’ infrastructure is particularly vulnerable. Its power plants and pipelines run on decades-old hardware that was designed for physical reliability, not digital defense. They often lack the logging, encryption, or patching capabilities that create layers of protection.
As American utilities modernized, their legacy equipment was wired into computer networks and cloud services for remote monitoring. This created a wealth of opportunities for hackers. Before the advent of the Internet, a saboteur might have had to plant explosives to destroy a gas pipeline. Today, a vandal might be able to shut one off by hacking into a poorly secured router sitting in a in a corporate office.
To make matters worse, until recently U.S. utility companies had few incentives or requirements to shore up security. Before the advancement of AI, determining systemic risk required manual, expensive engineering analysis. And before 2021, there were few, if any, cybersecurity regulations for critical infrastructure. The Biden administration established baseline standards for pipelines, ports, airports, and water systems, such as requiring operators to implement multifactor authentication and endpoint monitoring.
The United States’ infrastructure is particularly vulnerable.
As AI has advanced, cyberattacks have become more dangerous. In fact, OpenAI and Anthropic admitted this summer that their models have already hacked other companies without human direction. Rogue AI could make deterring a state-sponsored cyberattack harder because it offers the aggressor plausible deniability. If a victimized country isn’t certain that a strike was directed by an adversary, or even intentional at all, it may be more hesitant to retaliate. Moreover, the United States needs to protect itself from the possibility that AI from an American company, on its own accord, attacks U.S. infrastructure.
But just as AI can enhance cyberattacks, it can also make it easier to mount a cyberdefense. The technology is advanced enough to synthesize a massive amount of data to model infrastructure systems and the threats against them. A utility company could use AI to create a virtual replica of its physical systems, known as a digital twin, that uses sensors and data to mirror the behavior and performance of its real-world counterpart. A digital twin eventually learns what a system’s normal operations look like. It can pinpoint weaknesses and flag any unusual activity, potentially spotting malware. Today’s AI models have the capability to generate digital twins with varied accuracy and sophistication. Much as Waymo’s approach to testing its autonomous systems relies on millions of simulations at increasing detail and cost, a utility company building a digital twin can refine its granularity over time.
If tensions heighten with an adversary, for example, the United States could model potential attacks on its own grid to figure out which vulnerabilities, if exploited, would wreak the most havoc. When the United States tried to prepare for the possibility of Russian sabotage in 2022, it could not easily determine which of its weaknesses could be used to disrupt a power grid or water facility for more than 24 hours or which investments in cybersecurity would be most effective at preventing chaos. Today, with the help of digital twins, it is possible to figure out those flaws and prioritize fixes.
CARBON COPY
Washington now has the technology to protect its critical systems, but it must overcome the obstacles to deploying it, including the decentralized nature of American infrastructure, the way legal liability is assigned, and the high cost of upgrading cybersecurity, which has suffered from decades of underinvestment. Throughout the United States, there are more than 4,500 public water systems, 3,000 electric utilities, and thousands of independent pipeline and telecom operators. And the private corporations and municipalities that operate most of these entities are hesitant to find and share details about their networks because revealing a flaw or unpatched vulnerability can expose them to government fines or lawsuits claiming negligence. But without such data, digital twins cannot operate accurately.
The U.S. government must adopt a coordinated, national approach to building digital twins for the most critical of U.S. infrastructure systems—such as those serving ports, large populations, or military bases—and ensure those proxies are a faithful replica. The approach should change the way government and the private sector work together, leveraging the incentives that both frontier AI labs and infrastructure firms have to invest in digital twins.
Over the last year, as frontier AI labs have released more powerful models, it has become increasingly difficult to generate puzzles complex enough to measure advancing AI capabilities. Digital twins of real-world infrastructure can provide a more effective testing environment for frontier models—acting as a new cyber gym. AI companies, therefore, have a reason to subsidize the building and maintenance of digital twins as they can be used to evaluate the safety of unreleased models against real systems. Infrastructure owners, in turn, would benefit by seeing their network defenses probed by state-of-the-art technology, at minimal cost.
The United States needs a safe space to run such simulations. The Department of Energy, along with the Center for AI Standards and Innovation at the Department of Commerce, could partner with AI companies to establish a secure, air-gapped national enclave for the continuous testing of critical infrastructure. Utility owners and operators across the country could upload digital twins of their networks into this enclave and the enclave’s AI agents would constantly stress-test utility systems and offer recommendations for the highest priority cybersecurity fixes. Any unearthed bugs could inform Gold Eagle, an initiative the White House established this summer to coordinate finding and fixing vulnerabilities in U.S. networks. Patches could also be shared with allies to built trust in the American AI ecosystem and incentivize allies to use U.S. models.
Rogue AI could make deterring a state-sponsored cyberattack harder.
To entice utility owners and operators to participate, Congress should provide them legal safe harbor—including protections from lawsuits by the companies or people they serve—for finding weaknesses or evidence of misuse as a result of feeding data into authorized national defense AI platforms. Congress should also help cover the cost of fixing flaws or eliminating foreign footholds that are discovered by establishing a pool of money, modeled on the EPA Fund, that would issue grants to patch immediate high-risk flaws, alongside long-term, zero-interest loans for larger utilities to undertake deep overhauls. In addition, nonprofit or private-sector programs, such as OpenAI’s Daybreak, could consider issuing grants to cover the costs.
The federal government must also change how it conducts oversight. Today, it judges utility companies based on their compliance with legal standards that often lag behind advancements in hacking. A better way would be to assess utility operators on the amount of time it takes them to contain a cyberattack. Over time, these operators, for example, should be required to show, via a simulation with a digital twin, that they can isolate an attack within a reasonable time frame.
Although such government efforts are worthwhile, they will take time to come to fruition. In the meantime, industries that are most at risk from the weaponization of digital chokepoints, such as hospitals and banks, should work together to press their most important suppliers to use AI to fix gaps in their cybersecurity. By coordinating through information-sharing analysis centers—organizations that act as a neighborhood watch for a particular industry and offer certain legal protections—companies can press for action through contractual means.
Advancements in AI offer the United States and its allies their first real opportunity in many years to catch up to China on the cyber front. The technology to map and defend critical U.S. and allied systems is arriving faster than expected. The ultimate measure of U.S. resilience in the face of digital Chinese chokepoints will not be the raw capability of AI models but the willingness of U.S. institutions to use them—before an adversary causes a major disruption to American lives.
Loading…

