Critical Infrastructure Risk Index · September 24, 2026

The OT
Doomsday Clock

A warning indicator for the convergence of cyber-physical capability, frontier AI, regulatory lag, technical debt and systemic dependencies across U.S. operational technology.

OT Doomsday Clock The clock is set to 11:59:40, twenty seconds to midnight. 12
11:59:40
20 seconds to midnight

Critical · accelerating

What midnight means

Not a bad cyberattack.
A systemic national disruption.

Midnight is the point at which an adversary possesses and employs sufficient access, intelligence, automated reasoning and agentic scale to deliberately create synchronized, cascading disruption across multiple U.S. lifeline sectors faster than national and regional recovery mechanisms can contain it.

Those lifeline sectors include electric power, water and wastewater, communications, transportation, fuel and logistics. The index also considers the possibility that physical effects are amplified through information operations to create economic leverage, military friction and mass demoralization.

The OT Doomsday Clock is an independent analytical construct. It is not affiliated with, endorsed by, or a replacement for the Bulletin of the Atomic Scientists’ Doomsday Clock.

Why the hand is moving

Offense is compounding faster than resilience.

Frontier AI compresses expertise, time and operator labor. Critical-infrastructure defense remains constrained by regulation, funding, procurement, workforce, outage windows and long-lived industrial assets.

01

Frontier AI capability

Models are increasingly able to perform multi-stage cyber work autonomously and are beginning to make measurable progress against industrial-control scenarios.

Clock pressureVery high
02

Agentic scale

Multi-agent frameworks allow one human operator to supervise parallel reconnaissance, exploitation, tool-building and persistence workflows across many targets.

Clock pressureHigh + rising
03

Pre-positioned access

Nation-state campaigns have demonstrated long-duration access to U.S. communications, energy, transportation and water environments with disruptive intent in a crisis.

Clock pressureHigh
04

Regulatory lag

Rulemaking and minimum-compliance cycles move far more slowly than attacker capability. In several sectors, cyber baselines remain voluntary, uneven or incomplete.

Clock pressureVery high
05

Technical debt

Long-lived controllers, unsupported software, deferred maintenance, opaque supply chains and embedded foreign components can remain in service for decades.

Clock pressureHigh
06

Cross-sector coupling

Power, communications, water, fuel and transportation are mutually dependent. Mission-aware targeting can turn local effects into cascading regional or national consequences.

Clock pressureHigh
The 2026 accelerator

AI changes the attacker production function.

Historically, serious Industrial Control System (ICS) attacks required scarce combinations of exploitation expertise, vendor knowledge, industrial-protocol fluency and process engineering. Frontier AI is beginning to separate that knowledge from the individual attacker.

Capability×Autonomy×Parallelism×Persistence=Nonlinear offensive capacity
~6×more attack steps completed by the best evaluated model in early 2026 versus the best model 18 months earlier in a realistic enterprise scenario.NCSC / AISI ↗
£65approximate cost of a full autonomous attempt in the evaluated enterprise scenario — shifting a constraint from expertise toward compute and funding.NCSC / AISI ↗
1 → manyagent swarms and persistent campaign memory allow one operator to supervise parallel workstreams that once required teams of specialists.Anthropic ↗
The defensive drag

Regulation is often the forcing function — and the bottleneck.

Cyber investment in critical infrastructure is frequently driven by enforceable requirements. But rules take time to write, funding takes time to approve, industrial changes take time to engineer, and compliance usually targets a minimum floor rather than demonstrated resilience.

Threat recognized
→
Authority & rulemaking
→
Budget & procurement
→
Outage & deployment
→
Operating maturity
→
Tested resilience
SectorRegulatory forcingStructural issueClock effect
Bulk electric systemMandatory / matureNERC CIP provides enforceable cybersecurity standards, but scope and capital-cycle lag remain.Defensive brake
Critical pipelinesMandatory / targetedPost-Colonial directives force plans and assessments, but modernization still follows industrial timelines.Partial brake
Water & wastewaterFragmented / weakWorkforce shortages, aging technology, constrained budgets and gaps in federal cyber authority.Strong accelerator
Cross-sector baselineLargely voluntaryCISA performance goals establish useful baselines but are voluntary and not an audit regime.Limited brake
A regulation written against yesterday’s threat, implemented tomorrow, can produce compliance without producing resilience against tomorrow’s attacker.
The clock through time

From cyber-physical proof to machine-scale attack economics.

Each movement marks a change in demonstrated capability, strategic access, systemic exposure or the defender’s ability to adapt.

Methodology

An index of systemic consequence — not incident count.

The clock is set by analytical judgment across weighted risk dimensions. It intentionally gives more weight to changes that alter the economics, scale or potential consequence of attacks than to raw counts of cyber incidents.

20%

Frontier AI capability & diffusion

How quickly advanced cyber reasoning is improving, becoming cheaper and propagating into accessible models and tooling.

15%

Agentic autonomy & swarm scale

The ability to parallelize campaigns, persist state, delegate work and reduce the number of humans needed per target.

15%

Adversary access & pre-positioning

Persistent access to critical infrastructure and evidence that access is intended to enable disruption during crisis or conflict.

15%

Physical-process capability

Demonstrated manipulation of controllers, safety systems, process logic, view or control — and resulting operational effects.

10%

Regulatory coverage

Whether enforceable requirements create sustained investment in cybersecurity, asset governance and lifecycle replacement.

10%

Implementation lag & technical debt

Time required to convert rules and budgets into deployed controls across long-lived, safety-critical industrial assets.

10%

Cross-sector dependency exploitation

Potential to target dependencies among power, communications, water, transport, fuel and military or civilian missions.

5%

Workforce, recovery & resilience

Ability to detect, operate manually, restore safely, coordinate across sectors and prove recovery under realistic stress.

Important: The weights are an analytical framework, not empirical probabilities. They are designed to make the judgment transparent, repeatable and challengeable.
Trend projection

If the 2026 contraction continues, the curve reaches practical midnight in Q2 2028.

Using 75 seconds remaining on January 1, 2026 and 20 seconds on September 24, 2026, a simple exponential fit implies a risk-distance half-life of roughly four to five months. Because exponential decay never mathematically reaches zero, this model defines practical midnight as one second or less remaining.

Accelerated caseLate 2027AI/swarm breakthrough + geopolitical crisis
Central curveQ2 2028Current 2026 trend persists
Resilience case2029–2032+Faster regulation, modernization and defensive AI

This is not a prediction that an attack will occur in 2028. It is the date at which this analytical trend line reaches the model’s defined risk threshold if the observed pace of change continues without a compensating improvement in resilience.

Seconds remaining
Exponential projection to practical midnight The model declines from 75 seconds in January 2026 to 20 seconds in September 2026 and projects to one second or less in the second quarter of 2028. 7550250 Jan '26Sep '262027Q2 '28 Practical midnight ≤1 sec
Observed / assessedExponential projection
How the hand moves backward

The purpose of the clock is not inevitability. It is intervention.

01

Make resilience the regulatory target

Move beyond minimum controls toward tested continuity, safe manual operation, recoverability and mission-level consequence reduction.

02

Compress the defensive cycle

Pre-authorize funding and procurement pathways for high-consequence vulnerabilities, obsolete assets and compensating controls.

03

Use AI for defender scale

Apply automation to asset discovery, exposure management, monitoring, engineering analysis and restoration planning while retaining human control of safety-critical actions.

04

Manage the installed base

Identify provenance, unsupported technology, remote access, embedded components and single points of failure — then prioritize them by mission consequence.