The risks to Americans' Internet access are moving from isolated technical faults to linked failures across DNS, cloud, power and politics. Each layer is getting more concentrated at the same time as the pressure on it rises. That makes long, multi-week outages more plausible than they were five years ago.
Key points
- One US firm, Verisign, compiles, signs and publishes the root zone and also runs the .com registry, and its contracts now run into the early 2030s.
- AI has turned vulnerability discovery into a machine-speed process, and state actors already sit inside US carrier routers.
- The grid is the binding constraint: transformer lead times run to years, data center backup fuel runs out in days, and data center load trips can now set off grid cascades.
- A government's view of a company is becoming an operational risk, because the tools for designating providers or ordering shutdowns are legally available and have been used against at least one US firm.
- We judge a multi-week regional loss of access to be plausible this decade. It would most likely come from grid damage compounded by a cyberattack, not from any single failure.
What's changing
Naming and control planes are concentrating
Verisign has maintained the root zone since 1993. The 2024 renewals keep it as root zone maintainer, operator of two root servers and .com registry operator, answerable to both ICANN and the Commerce Department1. Root signatures last about a week, so a compromised or coerced publishing pipeline would give the world a few days before validating resolvers started to fail1. The October 2025 AWS outage showed how the same pattern plays out in the cloud. A DNS race condition in one region knocked out global control-plane services for about 15 hours and produced more than 17 million outage reports2. The evidence for concentration is strong and mainstream. What remains uncertain is whether anyone will act on it before a failure forces the issue.
Offense now moves at machine speed while defense thins
Claude Mythos Preview partners reported more than 10,000 high or critical vulnerabilities across every major operating system and browser within weeks3. In May 2026 Google confirmed that criminals had used an AI-found zero-day in an admin tool of the kind ISPs and utilities expose, and that a mass-exploitation campaign was planned4. Salt Typhoon actors already have persistence in provider-edge routers at AT&T, Verizon, T-Mobile and Lumen5. Recovering from that access, if it were turned to disruption, would mean reimaging routers carrier by carrier over days to weeks5. Meanwhile the legal basis for threat sharing survives on short extensions, now running only to December 11, 2026, and CISA has lost staff6. This force is accelerating and the evidence for it is strong. We think it is the most likely trigger for a coordinated outage across several providers.
The grid sets the outer limit on recovery
Large power transformers now take 30 to 36 months to deliver, and extra-high-voltage units take up to five years, against a supply deficit of about 30%7. More than 3,500 physical security incidents were reported in 20257. Data centers have also become a stability hazard in their own right. NERC issued a rare Level 3 alert after protection systems at data centers dropped more than 1,000 MW of load within seconds in the Eastern and ERCOT interconnections8. DOE models blackout risk rising 34-fold from data center demand alone, though critics contest the method9. Backup power at most sites covers 48 to 72 hours, and after that uptime depends on fuel trucks10. Exchange points and cable landing stations usually have thinner backup than hyperscale sites, so the network layer may fail before the cloud does10. In any grid scenario, the time to restore Internet service follows the time to restore power.
Political standing has become an operational dependency
In March 2026 the Pentagon designated Anthropic a supply-chain risk, a tool normally aimed at foreign adversaries. A federal court later ruled the move unlawful retaliation11. The precedent matters for DNS, CDN and cloud providers, because contractor certification rules could force mass migrations off a disfavored service almost overnight11. Section 706 of the Communications Act still lets the President suspend wire or wireless service in a declared emergency without congressional approval. Reform bills have stalled12. The evidence here is early, but the legal levers are real and have not been reformed.
What to watch
- CISA 2015 after December 11, 2026: a lapse that coincides with a shutdown or an AI-driven exploitation wave would slow cross-sector response exactly when it is needed.
- FERC and NERC standards for computational loads, due December 31, 2026: weak ride-through rules would leave the loop between data center trips and grid cascades open.
- Evidence that Mythos-class capability has spread to attackers, such as more GTIG-style attributions or zero-days in router and OT firmware turning up in the wild.
- Appeals of the Anthropic ruling and any Section 706 reform: together these decide whether designating providers stays a live tool of government leverage.
Sources
- Verisign stays the single root zone maintainer through the early 2030s while also running the .com registry and two root servers · disclosure · also icann.org, ntia.gov ↩
- One DNS race condition in AWS us-east-1 cascades into a 15-hour outage of global control-plane services · expert · also gremlin.com ↩
- Mythos-class AI finds more than 10,000 high/critical vulnerabilities across every major OS and browser · disclosure · also helpnetsecurity.com ↩
- Google confirms the first AI-generated zero-day used in a planned mass-exploitation campaign · disclosure · also cnbc.com ↩
- Chinese state actors hold persistent access inside US ISP backbone and provider-edge routers · institutional ↩
- The legal basis for US cyber threat-sharing survives on short-term extensions while CISA loses staff · journalism · also congress.gov ↩
- Large power transformer lead times reach 2.5 to 5 years amid a roughly 30% supply deficit, while substations remain soft targets · journalism · also powermag.com, cisa.gov ↩
- NERC issues a rare Level 3 alert after 1,000+ MW data center loads drop off the grid in seconds · journalism · also powermag.com ↩
- DOE models a 100x rise in US blackout risk by 2030 as load outruns firm capacity · institutional ↩
- Data center backup power is sized for 48, 72 hours and depends on diesel logistics that fail in regional disasters · journalism · also mansfield.energy ↩
- The Pentagon labels a leading US AI company a 'supply chain risk'; a court rules the label unlawful retaliation · journalism · also cnbc.com ↩
- The President's Section 706 authority to seize or shut down US communications remains unreformed · expert · also uscode.house.gov ↩