The White House has issued an executive order prohibiting the acquisition of foreign-made technology used in bulk-power systems, citing concerns over potential cyber backdoors and supply-chain vulnerabilities. The order, signed by President Donald Trump, declares that certain foreign actors are increasingly exploiting weaknesses in these systems, which manage electricity and power generation.
The executive order specifically targets technology for energy transmission lines rated at 69,000 volts or higher, as well as substations, control rooms, power generating stations, and reactors. It also encompasses associated software and firmware that could be remotely accessed or updated by foreign governments. The administration characterized foreign-made bulk-power system electric equipment as an "unusual and extraordinary threat" to the United States.
President Trump stated that during his first term, he identified the bulk-power system as a potential target for malicious acts, including cyber activities, due to the significant risks a successful attack would pose to the economy, public health and safety, and national defense.
The directive mandates that the Departments of Defense, Commerce, and Energy scrutinize transactions involving bulk-power system electric equipment. Federal agencies are also empowered to impose conditions on previously purchased equipment, provided that suitable replacements are available. A list of pre-qualified equipment and vendors is slated for publication.
Senior officials have 120 days to establish rules and regulations, and to identify countries that warrant particular scrutiny under the order's provisions. Agencies are also required to identify existing at-risk bulk-power system electric equipment and submit plans to the White House for its identification, inventory, isolation, monitoring, or replacement as soon as feasible.
While the White House did not specify the immediate catalyst for the executive order, it follows a series of reported cyberattacks on critical infrastructure. Last month, water utilities in at least 12 states experienced cyberattacks, and the federal cyber defense agency observed malicious activity targeting over 100 internet-exposed systems in the water and wastewater sector. Additionally, a small British power plant was reportedly shut down for four days by hackers.
The National Security Agency and FBI recently issued an advisory concerning an artificial intelligence-powered "active threat" to a specific brand of operational technology used across the energy, water, and agricultural sectors. Although no specific countries were officially blamed for these incidents, some experts have pointed to Iranian hackers. U.S. officials have previously attributed critical infrastructure attacks to Russian and Chinese hackers, with the FBI recently disrupting a Chinese botnet reportedly used to breach the Federal Reserve, NASA, and other federal agencies managing critical infrastructure.
Cybersecurity experts and government agencies have consistently warned about the deployment of artificial intelligence by state-backed hackers in attacks on critical infrastructure, which could simplify potentially devastating assaults. Following the executive order, major tech and finance companies, including OpenAI and Google, issued a joint warning that there is a "limited window to strengthen cyber defenses" before AI-enabled cyberattacks become "far more widespread and sophisticated." They emphasized that critical public services, from hospitals to water treatment plants, are at risk and that security teams for critical infrastructure have historically been under-resourced. These companies urged governments to coordinate cyber defense efforts at local, national, and international levels, and to enhance the sharing of actionable threat intelligence.






