As artificial intelligence gives hackers increasingly powerful tools to launch cyberattacks, Nashville agencies responsible for electricity, water and public safety say they are preparing to keep critical services running if their systems are targeted.
Nashville Electric Service, Metro Police and Metro Water Services all told The Tennessean they have cybersecurity safeguards, training or exercises designed to protect critical services. NES and police officials said those preparations are changing specifically because of advances in AI.
Mayor Freddie O’Connell’s office said the city is also adapting its broader cybersecurity strategy as AI makes attacks faster, more sophisticated and harder to detect.
“We are extremely concerned about the evolving
threat landscape, particularly regarding the malicious use of AI,” the mayor’s office said in a Sept. 9 statement. “AI has fundamentally shifted how cyberattacks are carried out.”
The responses come amid heightened national concern over the ability of increasingly autonomous AI systems to find and exploit vulnerabilities.
In July, swarms of AI agents being tested by OpenAI breached systems at Hugging Face, a major AI development company, after bypassing controls intended to keep the agents contained. Researchers later identified other sites accessed by OpenAI-linked agents, including a Vanderbilt University tool.
Vanderbilt was among at least 11 sites targeted, with the agents gaining access to a university link-shortening tool normally restricted to authorized users. It remains unclear how the agents bypassed Vanderbilt’s access requirements.
OpenAI later called the hack a warning of what more powerful AI could do without stronger safeguards. It has also fueled a broader debate over how quickly AI is advancing and whether existing security systems can keep pace.
Agencies adapt to AI threats
In Nashville, some agencies responsible for critical services say they are already adjusting.
NES said the computer systems controlling Nashville's electric grid are completely separated from the utility's everyday office networks, creating a barrier between systems commonly targeted by phishing attacks and those responsible for operating the grid.
The utility has updated security training to teach employees how scammers are using AI and said it is developing guardrails as the technology evolves.
“NES doesn't wait for hackers to strike,” the utility said in a statement. “We test our own defenses first.”
NES said it regularly conducts drills, mock phishing attacks and hacker simulations and is incorporating AI-driven tactics into those exercises.
Metro Nashville Police said it has similarly strengthened employee training and safeguards in response to AI-enabled threats.
Police employees receive training on cybersecurity, safe and ethical AI use, and restrictions on handling data, the department said. Any AI-generated information used by the department must be verified by a person.
MNPD is also working to restrict the use of unapproved outside AI platforms to reduce the risk that sensitive information could be exposed. The agency said it maintains continuity plans with other city departments in the event of a cyberattack.
Metro Water Services offered fewer details, citing the sensitive nature of its security protocols. The department said it has a comprehensive risk assessment plan that includes cybersecurity and takes specific precautions to protect drinking water and wastewater operations.
The mayor’s office said the city is strengthening identity and access management, speeding up deployment of security patches and expanding employee education about responsible AI use.
The city is also emphasizing recovery plans designed to keep critical services operating if defenses fail.
If a major cyberattack disrupted multiple city services simultaneously, the Office of Emergency Management would work with Information Technology Services to coordinate the response, according to the mayor’s office.
What are cities being told to do?
The National League of Cities warns that AI can allow attackers to automate tasks and create more convincing phishing and impersonation attempts.
The organization recommends cities adopt formal AI policies, train employees on AI-specific risks, limit access to sensitive systems and maintain basic defenses, such as multifactor authentication and backups.
When asked whether Nashville is adequately prepared for an AI-enabled attack, the mayor’s office stopped short of describing the city as completely secure.
“While we recognize that absolute security is unattainable, our ongoing mission is to establish and maintain a robust, continuous process for implementing, evaluating, and enhancing our data security practices to address any threat that may arise, including AI-enabled cyber threats,” the office said.
Tennessee lawmakers have also begun examining how the state should regulate AI. This year, the General Assembly ordered a state commission to study AI and generative chatbots, including potential risks and protections, and recommend whether additional state safeguards are needed.
This article originally appeared on Nashville Tennessean: AI is changing cyberattacks. Is Nashville prepared for what’s next?













