Cybersecurity researchers have uncovered evidence that near-autonomous AI agents are being used in real-world cyberattacks targeting critical infrastructure, including systems that manage municipal water supplies, according to findings that surfaced this week and have drawn immediate attention from security agencies and infrastructure operators globally.
The findings represent one of the clearer documented examples of agentic AI — systems capable of autonomously planning and executing multi-step tasks with limited human oversight — being weaponised in live attacks against physical infrastructure, a scenario that cybersecurity experts have warned about for years but which has, until now, remained largely theoretical in publicly documented cases.
Critical infrastructure cybersecurity has been a persistent policy concern for over a decade, but the specific combination of ageing operational technology systems, historically limited cybersecurity budgets, and the emergence of increasingly capable autonomous attack tooling has created what several security agencies have described as a uniquely dangerous convergence of vulnerability and threat capability for the water sector specifically.
For infrastructure operators and policymakers, the disclosure adds urgency to a cybersecurity conversation that has, until now, often treated agentic AI attack tooling as a future risk rather than a documented, present-day operational reality.
Water systems have long been considered a particularly sensitive category of critical infrastructure from a cybersecurity standpoint, given both the direct public health implications of a successful attack and the historically underinvested state of cybersecurity protections at many municipal and regional water utilities compared to sectors like finance or energy. The use of AI agents to probe these systems is particularly concerning to security researchers because agentic systems can potentially identify and exploit vulnerabilities at a speed and scale that would be difficult for human attackers to replicate, while also adapting their approach dynamically based on the defensive responses they encounter.
Details of the specific attribution behind these attacks — whether they originate from state-linked actors, criminal groups, or other threat sources — have not been fully disclosed publicly, though the involvement of near-autonomous AI agents rather than traditional manually operated attack tools marks a qualitative shift that security researchers say infrastructure defenders need to urgently account for in their threat models.
Previous documented attacks on water utilities, including well-publicised incidents involving attempts to manipulate chemical dosing systems, have historically relied on relatively unsophisticated attack methods exploiting basic security failures such as default passwords or unpatched remote access software, making the emergence of AI-driven, autonomous probing tools a significant escalation in the technical sophistication such attacks might soon employ at scale.
Security researchers analysing the reported attack patterns note that AI agents capable of autonomously discovering and exploiting vulnerabilities could dramatically expand the practical scale at which attackers can probe critical infrastructure targets, since a single operator directing autonomous AI agents can potentially conduct reconnaissance and exploitation activity across many more targets simultaneously than would be feasible using traditional, manually operated attack techniques.
Federal and state cybersecurity agencies overseeing water infrastructure protection have historically operated with considerably smaller budgets and enforcement authority than agencies responsible for sectors like financial services or energy, a resourcing gap that critics argue has left the water sector disproportionately vulnerable precisely as attack sophistication, including the AI-driven tooling now being documented, continues to advance.
For critical infrastructure operators, the emergence of AI-driven attack tooling adds a new and urgent dimension to already stretched cybersecurity resources. Many water utilities, particularly smaller municipal operators, have historically lagged behind other critical infrastructure sectors in cybersecurity investment, a gap that becomes considerably more dangerous if attackers can deploy AI agents capable of automatically discovering and exploiting vulnerabilities at scale across large numbers of potential targets simultaneously.

Government cybersecurity agencies in multiple countries have in recent years issued warnings about the vulnerability of water infrastructure to cyberattacks, following several previously documented incidents involving attempts to manipulate water treatment chemical levels or disrupt utility operations. The emergence of agentic AI in this specific threat category is likely to accelerate calls for mandatory cybersecurity standards and increased federal or national funding support for water utility cybersecurity upgrades, particularly in jurisdictions where such standards have historically been voluntary or inconsistently enforced.
Government responses to critical infrastructure cybersecurity threats have historically moved more slowly than the pace of technological change in the threat landscape, a mismatch that security policy experts warn becomes considerably more dangerous as the tools available to attackers become increasingly automated and accessible, even to threat actors who might previously have lacked the technical sophistication to mount attacks against well-defended targets.
Water sector trade associations and cybersecurity vendors specialising in operational technology protection have reported a marked increase in interest from utility operators seeking to upgrade legacy security systems following this and similar recent disclosures, though industry participants caution that meaningful security improvements across the sector's thousands of individual utility operators, many with extremely limited technology budgets, will require sustained investment over years rather than a rapid, one-time response.
International cooperation on critical infrastructure cybersecurity has intensified in recent years, with several countries establishing formal information-sharing arrangements specifically focused on threats to water, energy and other essential utility systems, frameworks that security officials say will become increasingly important as AI-enabled attack techniques make it easier for threat actors to operate across international jurisdictional boundaries.
As agentic AI capabilities continue to advance and become more accessible, the intersection between this technology and critical infrastructure security is likely to become one of the defining cybersecurity challenges of the coming years, forcing both infrastructure operators and AI developers to grapple with dual-use risks that have moved decisively from theoretical concern to documented reality.
As agentic AI capabilities continue to proliferate and become more accessible to a broader range of potential threat actors, critical infrastructure operators across sectors beyond water alone will face mounting pressure to accelerate cybersecurity modernisation efforts that have, in many cases, been chronically underfunded for decades.
Policymakers in multiple countries are expected to cite this disclosure as further justification for pending critical infrastructure cybersecurity legislation, underscoring how quickly theoretical concerns about AI-enabled attacks on physical infrastructure have moved to the centre of national security policy discussions over the past year.



