UK’s nuclear plants face risks of AI-powered cyber-attacks and insider threats

17 Jul, 2026 By Tom Pashby, https://www.newcivilengineer.com/latest/uks-nuclear-plants-face-risks-of-ai-powered-cyber-attacks-and-insider-threats-17-07-2026/
Civil nuclear power plants in the UK now face cyber-attacks enhanced by artificial intelligence (AI) and insider threats, according to the government’s National Risk Register 2026.
The National Risk Register (NRR) is the annual, public-facing version of the government’s National Security Risk Assessment, it “includes a summary of all but the most sensitive, classified risks,” according to Cabinet Office minister of state Darren Jones.
Jones informed parliament and the public of the publication of the 2026 edition of the NRR in a written ministerial statement on 14 July.
The NRR attracts attention because it explains the government’s assessment of the likelihood and severity of a broad range of risks, including terrorism, cyber threats, geopolitical and diplomatic risks, accidents and systems failures.
The 2026 edition covers 95 risks. Of relevance to the civil engineering and infrastructure sector, “cyber-attack water infrastructure” was added as a new risk to reflect learning “from reported cyber-attacks targeting the water sector,” the NRR said.
It also added, “accidental damage on the National Gas Transmission Network – to explore damage to the gas transmission network as a result of agricultural digging.”
In her foreword to the 2026 NRR, Cabinet Office security minister Angela Eagle said: “This government is committed to sharing risk information as openly as possible, to support all those working to build the UK’s resilience with their planning, preparation and response activity.
“Greater transparency also means that people can scrutinise our assessments, and challenge us to do things differently when needed.”
She added: “A whole of society approach is required to increase resilience; therefore, I encourage all risk and resilience professionals to consider the risks in this publication, and join our collective endeavour to make the UK more prosperous and secure.”
While the 2025 edition included “conventional attack” and “cyber-attack” against civil nuclear as two distinct risks, the 2026 edition removed the cyber-attack risk profile and instead covered cyber risks facing civil nuclear into “malicious attack: civil nuclear”, in its “state threats” grouping.
Within the new malicious attack: civil nuclear profile, the NRR 2026 said: “AI can automate the process of launching cyber-attacks, making them faster, more efficient and lower the barrier for entry.”
Reacting to the 2026 NRR, cybersecurity firm e2e-assure CEO Rob Demain told NCE: “Nuclear plants have always planned for physical threats and human error. What’s new is the assumption that the attacker may already have a way in, that someone with legitimate access can do real damage without ever needing to break down a fence.
“AI is exacerbating the threat. The National Risk Register itself says AI can automate attacks, making them faster, cheaper and easier to attempt without much skill.
“Elsewhere it goes further, describing how AI makes fake messages harder to spot and helps attackers find weaknesses faster. That’s a very different risk to plan for, than a lone bad actor.”
Demain added: “For the people who design, build and maintain this infrastructure, the message is simple: security can no longer be something bolted on afterwards, or left entirely to IT.
“It has to be built into how these sites operate, day to day, alongside the safety systems engineers already take for granted.”
Also responding to the “malicious attack: civil nuclear” risk profile, an EDF spokesperson told NCE: “As the risk from cyber-attack on UK critical national infrastructure continues to evolve, EDF continues to further refine its defences, with horizon scanning for developing threats and a constant series of system improvements to make it harder for those attempting to damage our systems.
We note that the National Risk Register does not propose a scenario of a safety risk but one that ‘results in a disruption to normal operations until investigations have demonstrated nuclear safety and security critical systems remain unaffected’, and that ‘the disruption is not a direct result of the attack’.”
Demain told NCE earlier in July that critical national infrastructure assets are now more at risk of cyber-attacks due to the deployment of newer, more powerful artificial intelligence (AI) tools like Anthropic’s Mythos.
No comments yet.
-
Archives
- July 2026 (251)
- June 2026 (287)
- May 2026 (306)
- April 2026 (356)
- March 2026 (251)
- February 2026 (267)
- January 2026 (308)
- December 2025 (358)
- November 2025 (359)
- October 2025 (375)
- September 2025 (257)
- August 2025 (319)
-
Categories
- 1
- 1 NUCLEAR ISSUES
- business and costs
- climate change
- culture and arts
- ENERGY
- environment
- health
- history
- indigenous issues
- Legal
- marketing of nuclear
- media
- opposition to nuclear
- PERSONAL STORIES
- politics
- politics international
- Religion and ethics
- safety
- secrets,lies and civil liberties
- spinbuster
- technology
- Uranium
- wastes
- weapons and war
- Women
- 2 WORLD
- ACTION
- AFRICA
- Atrocities
- AUSTRALIA
- Christina's notes
- Christina's themes
- culture and arts
- Events
- Fuk 2022
- Fuk 2023
- Fukushima 2017
- Fukushima 2018
- fukushima 2019
- Fukushima 2020
- Fukushima 2021
- general
- global warming
- Humour (God we need it)
- Nuclear
- RARE EARTHS
- Reference
- resources – print
- Resources -audiovicual
- Weekly Newsletter
- World
- World Nuclear
- YouTube
-
RSS
Entries RSS
Comments RSS



Leave a comment