THOUGHT EXPERIMENT · CRITICAL INFRASTRUCTURE

What if AI reached the systems society depends on?

Imagine an AI agent gaining access to a system it was never meant to control. What happens if that system affects physical safety or the information people need in a crisis?

Henrik Bergfjord · 29 September 2026 · 18 min read

This is scenario analysis, not an incident report. There is no evidence that AI has taken over these systems. The illustration below is a thought experiment; the scale and cost figures are comparison points from Norwegian authorities' different scenarios.

From a documented intrusion to a difficult what if

In July 2026, OpenAI agents escaped an isolated test environment and reached Hugging Face. That is documented. [1] The incident showed that an agent with a goal, tools and overly broad permissions can find routes it was not meant to use. But it is a major leap from that incident to controlling a bus or a power plant. That leap would require access to different systems, different privileges and often several failed safeguards. The rest of this page explores possible consequences if such boundaries were to fail.

01 / MOVEMENT

Cars and buses

What if an agent could influence a fleet's schedules, remote updates or the information operators use to make decisions? Buses might be delayed, rerouted or taken out of service. A more serious danger would arise only if the system could also affect safety-critical vehicle functions. Those are different levels of access and should not be conflated.

The critical question: Can a digital fault reach the systems that determine how a vehicle actually behaves?

NHTSA recommends vehicle architectures that limit such routes and support safe responses to cyber incidents. [3]

02 / CITY STREETS

Traffic signals

What if a traffic control centre receives false information or someone gains unauthorized control of a district? Poorly coordinated signals could create congestion, unsafe junctions and delays for emergency vehicles. That does not mean one AI could take over every junction: local controllers, different suppliers and manual procedures can limit an incident.

The critical question: Who can stop remote control, check the signals locally and direct traffic while the fault is fixed?

This is scenario analysis, not a claim about a known AI incident.

03 / ESSENTIAL SERVICES

Power and water

What if digital tools in operations or maintenance received too much authority? A wrong decision could disrupt supply, pumps or fault handling. The consequences could extend beyond the initial failure: without power, mobile networks, payments, transport and information services can weaken. The outcome depends on design, backup capacity and how quickly people intervene.

The critical question: Is the AI merely an adviser, or can it send commands to control systems?

NIST describes AI adoption across IT, operational technology and industrial control systems in critical infrastructure. The Norwegian Food Safety Authority requires security for water utilities' control systems. [2][12]

04 / CONNECTION

Internet and mobile networks

What if a major operator lost visibility or access to systems used to run its network? Services might become unavailable in an area, while misleading information prolongs confusion. “Switching off the internet” in a single global action is misleading: networks comprise many independent operators and connections. A local or regional outage can still be serious.

The critical question: What alternative communications exist when normal channels fail?

ITU describes terrestrial, satellite and radio communications for disasters. Nkom is working on backup power and alternative routes for mobile networks in Norway. [5][13]

05 / TRUST

TV, radio and crisis information

What if an agent disrupted distribution or spread convincing false messages while networks were unstable? People might lose trust in accurate alerts. TV and radio are separate systems with their own procedures; a digital incident would not automatically disable everything. But crisis communication becomes harder when several channels fail together.

The critical question: How can the public verify who actually sent the message?

ITU highlights radio as a useful backup when local networks are destroyed or overloaded. [5]

06 / COMMERCE

Payments and commerce

What if an agent disrupted a payment service provider, or a communications outage made terminals unavailable? Shops might be unable to accept some payments; fuel, food and transport would be indirectly affected. One payment method failing differs from the entire settlement chain failing. Alternative cards, offline payments and cash can limit the effects. [9]

The scale depends on which links fail, how many merchants lose service and how long alternatives keep working.

07 / LIFE AND HEALTH

Health and emergency care

What if patient records or communications became unavailable just when services needed to coordinate? The Norwegian Directorate of Health has an exercise for prolonged electronic health-record outages, addressing documentation, medication handling and patient safety. [10] This differs from directly controlling medical equipment.

One institution may improvise for a while; simultaneous failures could affect patient flow and emergency response across a region.

08 / HIDDEN DEPENDENCY

Precise time and satellite signals

Norway's DSB analysed a scenario in which manipulated time signals propagate to mobile networks, power monitoring, bank settlement and aviation. [6] It concerns radio spoofing by an actor, not AI. In an AI thought experiment, the question is whether an agent could influence the data or decisions these systems take for granted.

A small fault in a shared foundation could be felt across several sectors at once.

09 / DAILY LIFE

Food and supply

What if warehousing and distribution data were wrong while power and communications were unstable? Goods could stop moving, cold chains become vulnerable and shops run short of some items. DSB's power rationing analysis identifies food supply, refrigeration and shop closures as knock-on effects. [7]

The impact might begin with one supplier and spread through dependent distribution links.

How large could the disruption be?

Four levels of impact

One service

A vehicle, a junction, a payment method or a local record system. Hours; manual procedures may help.

A municipality

Several junctions, one operator or a water utility. Emergency services and vulnerable people may need priority.

A region

A major network link or power supply. Effects on transport, commerce, health and communications may accumulate.

Nationwide

A severe, compound disruption. It would require far more than access to a single system.

These are scope categories, not likelihood rankings. DSB analyses consequences under specified assumptions; they do not prove that AI could cause them. [6][8]

Costs · Norwegian reference cases

From millions to billions, depending on scale and time

The following are official estimates for different causes and specific assumptions. They are neither AI forecasts nor figures that should be added together. Values are nominal NOK in their respective source years.

ExampleScope and durationEstimated effectSource and limitation
Power outage, smaller areaAbout 4,700 customers and some businesses; one dayNOK 25m KILENVE, 2025. One substation example, not an AI incident. [11]
Power outage, larger areaJust under 217,000 customers; one dayNOK 965m KILENVE, 2025. NOK 2.59bn after 72 hours in the same example. [11]
Manipulated time signalsMultiple sectors, repeated targets over weeksAt least NOK 10bnDSB, 2026. Repair costs and lost income in a radio spoofing scenario. [6]
Nationwide telecom outageFive-day main outage; up to one month to restore normal servicesAbout NOK 10bn economic loss, plus NOK 2–10bn in repair/replacementDSB, 2015. Older state-actor cyber scenario; infrastructure has changed. [8]
Power rationing in NO230% reduction for about one monthOver NOK 10bnDSB, 2023. Supply crisis, not an outage or AI scenario. [7]

How to estimate a specific AI scenario: Define affected services and users, duration, time of day, backup capacity and direct repair. Then estimate lost production and knock-on effects without double-counting the same loss.

KILE can be a starting point for power outages, but NVE cautions it may understate prolonged, compound disruptions. Health, trust and democratic effects cannot be compressed into one reliable monetary figure. [11]

What makes a scenario serious

An all-powerful AI is not the most useful model here. The important issue is dependencies: One system feeds another; people trust a dashboard; emergency plans assume working power and communications. ENISA has mapped real cyber threats to the transport sector. [4] Those dependencies are real. An AI agent triggering this particular chain remains hypothetical.

THE NEXT LEVEL · WHEN TRUST IS BROKEN

What if we cannot trust the systems we are restarting?

An ordinary outage may call for a restart and a backup. After an intrusion, the harder question is: Which machines, accounts, data and copies can we actually trust? If an agent retains access through a key, an integration or the restored environment, the problem may return. This is a hypothetical AI scenario. The steps below draw on established cyber recovery guidance, not on a documented society-wide AI takeover. [14][15]

  1. Stop and contain: Remove the agent's tool and write access, isolate affected areas and coordinate through independent channels. Preserve evidence to investigate cause and scope.
  2. Establish a trusted starting point: Rebuild from verified installation sources, separate administrator accounts and backups whose integrity can be checked. Restoring compromised data or permissions does not make them safe.
  3. Check against reality: Reconcile balances, transactions and physical states against independent records. A green status indicator in an affected system is insufficient.
  4. Restore by priority: Life and health, water, power and emergency communications take precedence over convenience. Reconnect systems and automation in stages with human approval and monitoring.
  5. Prevent recurrence: Rotate compromised credentials, close the entry path, reduce agent permissions and test that the actions cannot resume. Coordinate recovery if several suppliers are affected.

This is more than a technical restart. Paper, radio, cash and manual decisions may be needed in the interim. Cleaning, building access, deliveries and payroll can also stall when ordering, access cards and payment routines fail. Those small dependencies are easy to miss in a risk assessment.

What if the exchange cannot trust its numbers?

An exchange, a settlement system and a bank are different links. If orders or data are in doubt, trading can pause while transactions are reconciled; the loss is not the entire value of the shares traded. Effects can include delayed trading, reduced liquidity, delayed settlement, sharper price moves and lost confidence. If several links lose data integrity at once, it becomes harder to establish ownership and which payments are final. These are possible knock-on effects, not a forecast of global economic collapse.

International principles for financial market infrastructures aim to resume critical operations within two hours of severe disruptions and complete settlement by the end of the day; a cyber incident that corrupts data can make those targets difficult. These are resilience objectives, not guarantees. [18] A cost analysis must separate the flow of delayed trades and payments from actual lost output, liquidity needs, repairs and lasting value loss. Counting the entire market capitalization or all payment turnover as a “loss” would be misleading.

Has anyone practised?

Yes, for bounded cyber crises. Norges Bank says it tested its own NBO settlement system under the TIBER framework in 2024. The European Central Bank stress tested 109 banks that year on response and recovery after a successful cyberattack. [16][17] Those exercises matter. They do not demonstrate that the whole economy has been tested against a persistent, simultaneous AI incident in which both live systems and backups are untrusted.

What can a “dirty” laptop teach us?

I remember that at SIU in 2011, a laptop that had left the premises was treated as untrusted on its return. This is my recollection, not a verified account of SIU's internal policy. SIU was an agency under Norway's Ministry of Education and Research. [20] The underlying point remains: A device can appear to work normally yet require checks before it is trusted again.

I have also heard of travellers using only batteries for fear of power-line eavesdropping. I could not verify that particular story. A technical possibility has, however, been demonstrated in a research experiment called PowerHammer: malware on a computer varied its power draw so that small amounts of data could be measured on the power lines with suitable equipment. That experiment required a compromised machine and a receiver; it does not show that ordinary foreign outlets listen to every device. Batteries remove this one wired path while in use, but do not guarantee isolation from other channels. [19]

The key question for an organisation is therefore: Which independent source can confirm that a restored machine, a backup and a human decision can actually be trusted?

Where should the brakes be?

  1. Limit an agent's access to data and tools. It should not control physical systems merely because it can analyse them.
  2. Separate test, office and operational systems. Require extra human authorization for actions with physical effects.
  3. Monitor unexpected behaviour and practise stopping it. Maintain manual procedures and independent communication paths.
  4. Explain clearly what has been observed, what is only possible and what remains unknown.

The question is who holds the key

An AI model cannot simply decide to run society's infrastructure. Someone must grant access, or safeguards must fail. That is why responsibility begins with architecture, permissions, human control and preparedness – before an anomaly becomes a crisis.

Sources and method

These are editorial thought experiments. The sources below document the incident, areas of risk and resilience principles; they do not show that the scenarios have occurred.

  1. OpenAI, The Hugging Face incident and the road ahead, 26 August 2026.
  2. NIST, AI RMF Profile on Trustworthy AI in Critical Infrastructure, 2026.
  3. NHTSA, Cybersecurity Best Practices for the Safety of Modern Vehicles, 2022.
  4. ENISA, Transport Threat Landscape, 2023.
  5. ITU, Emergency telecommunications.
  6. DSB, Manipulated satellite time signals, 2026.
  7. DSB, Power rationing, 2023.
  8. DSB, Cyberattack on telecom infrastructure, 2015, with a 2025 note on changed ownership.
  9. Norges Bank, Financial Infrastructure 2026.
  10. Norwegian Directorate of Health, Exercise for electronic patient-record outage, 2026.
  11. NVE, Consultation paper 3/2025, pp. 12–13, illustrative KILE cases.
  12. Norwegian Food Safety Authority, Digital security guidance for water utilities, 2026.
  13. Nkom, National security plan for digital infrastructure, 2026–2030.
  14. NIST, Guide for Cybersecurity Event Recovery, 2016.
  15. CISA, #StopRansomware Guide, advice on backups, rebuilding and reinfection.
  16. Norges Bank, Financial Infrastructure 2025, on its TIBER test of NBO.
  17. European Central Bank, Cyber resilience stress testing from a macroprudential perspective, 2025.
  18. CPMI-IOSCO, Guidance on cyber resilience for financial market infrastructures, 2016.
  19. Guri et al., PowerHammer: Exfiltrating Data from Air-Gapped Computers through Power Lines, 2018 (research demonstration).
  20. Norwegian Ministry of Education and Research, SIU statutes, 2011 (organisational status; does not verify the recollected IT procedure).

← Back to the analysis