Key Takeaways

  • AI-driven detection can identify and locate grid attacks with up to 95% accuracy in near real time.
  • Sandia's C2E2 and griDNA projects combine automation, network telemetry, and physical grid measurements.
  • Utilities still need hardened AI models, operational safeguards, and established NIST security practices.

Electric-grid cyber defense is gaining a more operational form of artificial intelligence. The Department of Energy's Office of Cybersecurity, Energy Security, and Emergency Response, known as CESER, and Sandia National Laboratories are applying AI-driven cyber-physical detection to help utilities identify and locate attacks with up to 95% accuracy in near real time.

That distinction matters. Conventional cybersecurity monitoring can flag suspicious network activity, but electric utilities also need to understand whether an alert corresponds to an actual change in grid behavior. A compromised control command, equipment malfunction, and legitimate operational adjustment may produce overlapping signals. Combining digital telemetry with physical measurements can give operators more context before they intervene.

CESER's AI-FORTS program focuses on applying AI to operational technology and industrial control systems. Its objectives include improving energy-sector threat detection and helping operators maintain grid functions during cyber incidents. Rather than treating cybersecurity as a separate IT exercise, the program places detection closer to the equipment and processes responsible for delivering electricity.

At Sandia National Laboratories, the C2E2 initiative addresses a less dramatic but persistent problem: preparing power-grid data for analysis. Its use of generative AI and large language models has reduced data-engineering cycles from two months to a few hours, according to the research summary. That faster preparation supports high-precision localization of potential cyber threats.

Faster data preparation represents a fundamental operational advantage. Grid environments generate information from protective relays, control systems, sensors, network devices, and operating applications. If those sources cannot be normalized and analyzed quickly, a technically accurate detection method may still arrive too late to help an operator. Automating portions of that work could shorten the path from abnormal signal to actionable location.

Sandia's griDNA platform takes the approach toward the network edge. The platform fuses network telemetry with physics-based power measurements, then classifies events as cyber, physical, or cyber-physical. That can help utilities detect anomalies earlier across transmission and distribution networks. It also raises a practical question: How much confidence should operators place in an AI classification during a fast-moving grid disturbance?

Not all the risk sits outside the model. Attackers may attempt to manipulate training data, inputs, or model behavior, particularly as AI becomes more closely connected to infrastructure operations. DOE has funded $750,000 in research under its Genesis Mission to harden AI models used in power-grid operations against adversarial attacks. The investment is modest relative to the scale of the grid, but it highlights an important design issue. An AI security layer can itself become a target.

Commercial implementation will also shape adoption. Dragos, Claroty, and Nozomi Networks already provide OT and industrial-control monitoring used in utility environments. Sierra Nevada Corporation is testing Sandia's autoencoder-based AI on its Binary Armor cybersecurity device for grid settings. Such testing can help determine whether laboratory techniques remain useful when exposed to legacy equipment, constrained computing resources, and the uneven data quality found in operating networks.

Established governance still has a role. The National Institute of Standards and Technology published the NIST Framework for Improving Critical Infrastructure Cybersecurity, Version 2.0 in 2024, while NIST SP 800-82, Guide to Industrial Control Systems Security, remains a widely used 2015 reference for OT architecture and controls. AI detection can complement those practices, but it does not replace asset inventories, segmented networks, controlled remote access, incident planning, or human review.

For utility leaders, the near-term value is likely to come from decision support rather than autonomous control. AI can help correlate signals, narrow the suspected location, and reduce preparation time. Operators can then validate findings against grid conditions and established procedures. That said, the reported 95% accuracy ceiling is encouraging. The larger test will be whether utilities can sustain similar performance across varied equipment, evolving threats, and real operational pressure.