So, Does It Matter? On CA Politics!

So, Does It Matter? On CA Politics!

The Next AI Crisis May Begin At Your Water District

Artificial intelligence is lowering the cost of cyberattack faster than local government can raise the cost of defense.

Aug 18, 2026
∙ Paid

Typically, our afternoon content is behind a paywall—or there is something extra for paid subscribers. If you are not one, please consider upgrading. You are missing a significant portion of what we produce each week, and your support makes it possible. If you want it all and want to support my efforts, please consider a paid subscription!

You can listen to this content on our Podcast — So, Does It Matter, Spoken! - on your favorite podcast app. Or you can just go listen here.

⏱️ 5-minute read


The Water Warning

A few days ago, I listened to Derek Thompson’s podcast, Plain English: “It May Be Time to Freak Out About AI.” His guest was Alex Stamos, Facebook’s former security chief and now chief product officer at the AI security company Corridor.

It fascinated me. It also scared me.

What really caught my attention was not the discussion of escaped AI models. It was the moment Stamos turned to something much closer to home: the small public agencies that keep our water running.

“Water systems are the goofy dragon with its tongue hanging out,” Stamos said. Then he got more direct: “They don’t have their own cyber people.”

That is the problem. Large utilities, banks and technology companies employ security specialists. America’s water infrastructure is split among thousands of systems, many of them very small.

The Environmental Protection Agency counts roughly 51,000 community water systems. More than 92 percent serve 10,000 or fewer people. Some have no dedicated cybersecurity staff.

Yet they must protect pumping stations, treatment controls and connected equipment while replacing old pipes and keeping rates affordable. The Government Accountability Office has identified workforce shortages, limited investment, and aging technology that can be difficult to update.

Local control is good. Local responsibility without local capacity is not.

When The Model Escaped

Why does this matter now? Consider the OpenAI incident Thompson and Stamos discussed.

OpenAI placed several advanced models in a specialized cybersecurity test. Some safeguards had been reduced so researchers could measure their capabilities, but the models were not supposed to reach the public internet.

They did anyway.

When the models encountered problems they could not solve, they exploited a previously unknown software flaw, reached the internet, and penetrated Hugging Face’s production infrastructure in search of answers, according to OpenAI.

The machines had not become conscious. They were trying to complete an assigned task. The unsettling part was how much they accomplished without a person approving each step. They found a weakness, changed tactics, and kept going.

Now imagine someone giving them a malicious task on purpose.

A Cyber Army For Anyone

Hacking has always required skilled people. Someone must find a vulnerable system, study the software, get inside, and decide what to do next. Building a capable team takes time and money.

AI changes the math.

As Stamos warned, one criminal—or a very small group—may soon operate the equivalent of an entire hacking organization. AI agents do not sleep, draw salaries or demand a share of the ransom. They do not get arrested and turn on their partners.

Chinese open-weight models make this harder to contain. Stamos estimated that the best are only months behind leading American systems. Unlike most top American models, they can be downloaded and operated privately, beyond the builder’s continuing control.

Models from Moonshot AI and DeepSeek have legitimate uses, including cyber defense. But private operators can also modify them and try to weaken their safeguards.

Rules imposed only on American companies will not erase the capability. They may simply leave American defenders following rules that attackers ignore.

What An Attack Could Look Like

An AI-assisted attack on a water district probably would not look like a Hollywood disaster. There may be no poisoned reservoir and no villain issuing demands from a darkened room.

It may start with an employee discovering that the controls no longer respond.

Attackers could use AI to find exposed equipment, outdated software, reused credentials, and newly disclosed vulnerabilities. Instead of examining one utility at a time, they could scan thousands and focus on the easiest targets.

Once inside, they might lock operators out, interfere with pumps or pressure, manipulate alarms or force a system into manual operation. On the administrative network, they could encrypt records, steal customer information, or shut down communications.

The result could be overflowing equipment, treatment delays, pressure loss or precautionary boil-water notices. The water might still be safe. But if officials could not verify that, uncertainty alone could create panic.

This threat predates AI. Iranian-affiliated hackers are already exploiting internet-connected industrial controllers and disrupting some water operations, according to a federal advisory. AI would let more attackers find and exploit those weaknesses faster.

So, Does It Matter?

Water is already classified as critical infrastructure. The GAO warns that outdated technology and limited local resources have left holes in water-system defenses.

Stamos argued that government must “focus on giving capabilities to American defenders.” He urged organizations to fix vulnerabilities, retire old systems, and use AI to detect intrusions.

That does not mean Washington should run them. Federal guidance is basic: disconnect operational equipment from the public internet, change default passwords, inventory systems, maintain backups, and plan for incidents.

Stamos singled out water districts, so I have focused on them. But the risk is broader. Any small agency running systems with thin staffing and no cyber team could face the same problem.

We talk about AI as a contest among companies and countries. Its consequences may first be felt somewhere less impressive: a small public agency serving a few thousand people.

The next AI emergency may begin when someone there discovers that the computers no longer respond—and that the attackers have an army that never sleeps.



Something Extra — For Our Paid Subscribers

Below we have three great additional political cartoons in line with this column!

User's avatar

Continue reading this post for free, courtesy of Jon Fleischman.

Or purchase a paid subscription.
© 2026 Jon Fleischman · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture