TL;DR — Key Takeaways

  • Technology can improve warning, coordination and response, but it cannot guarantee different outcomes. The article stresses humility when considering what modern tools might have changed on September 11.
  • Important lessons from 9/11 have already produced practical improvements, including better responder communications, stronger building-code practices and more resilient emergency procedures.
  • AI and increasingly connected infrastructure create new risks as well as new capabilities. Preparedness now requires fallback operations, containment, enforceable limits and genuine human accountability

My wife is going to New York to participate in the September 11 ceremonies at Ground Zero, honoring her sister, who lost her life in the towers. It is a difficult day for our family. Twenty-five years have not changed that.

For much of the country, this anniversary marks a quarter-century since an event that changed America. For families like ours, it marks another year without someone we love. The history and the personal loss exist together, but they are experienced differently.

I have been thinking about those twenty-five years through the lens of the industry I cover. Technology has transformed how we communicate, work, find information, and make decisions. We carry capabilities in our pockets that would have seemed extraordinary in 2001. We are now giving artificial intelligence responsibilities that, until recently, belonged entirely to people.

What would any of that have meant on that horrible morning? Could today’s technology have helped prevent the attacks? Could it have helped more people escape? And with everything we have built since then, are we better prepared to protect people from the dangers ahead?

These are difficult questions to ask when the loss is personal. They are also questions worth asking.

What We Can and Cannot Know

I cannot tell you that a smartphone, a better radio, or an AI system would have saved my sister-in-law. Nobody can responsibly make that claim about her or any other individual who died that day.

There were physical limits that information could not overcome. The 9/11 Commission found that all three stairwells in the North Tower became impassable from the 92nd floor upward. No software could recreate an escape route that had been destroyed. 

We also have to distinguish between preventing the plot from responding to the attacks and helping people survive them. Each presents different possibilities. Changing one piece of the picture does not tell us how everything else would have unfolded.

What we can examine is where people lacked information, where institutions failed to act, and where better preparation might have created more options.

That requires humility toward those who made decisions under conditions the rest of us can study with the terrible advantage of knowing the outcome.

Information Has to Reach Someone Who Can Act

The 9/11 Commission documented missed opportunities involving information sharing, watchlists, investigations, and coordination. Its findings extended across failures of imagination, policy, capabilities, and management. The country had warning signs, but institutions did not assemble and act on them effectively.

It is reasonable to ask whether modern analytical tools could have helped investigators connect scattered records, translate material, or recognize relationships sooner. AI offers possibilities here.

But the leap from “could help find a connection” to “would have prevented September 11” is enormous.

An analytical system needs access to relevant information. Its findings need scrutiny. Someone must determine whether a pattern warrants investigation and have the authority to act. Institutional barriers do not disappear because the software improves.

Neither does the danger of mistaking an innocent person for a threat. Collecting more information about everyone is not a substitute for sound intelligence work.

That same relationship between information and action became painfully consequential during the emergency response. The Commission found that evacuation decisions were not consistently conveyed to emergency operators and dispatchers. People calling for help and people directing rescue efforts did not always have the same understanding of conditions.

Today, we can imagine shared building plans, verified reports from inside a structure, and instructions distributed through multiple channels. Those capabilities could help people make decisions while there is still time.

But a phone needs a working connection. A message needs to be accurate. A faster network can distribute bad guidance faster, too.

We already have a documented example of communications changing events that morning. On Flight 93, phone calls informed passengers and crew about the other attacks. Their resistance prevented the hijackers from reaching their intended target.

The calls brought information. The people aboard found the courage to act on it. That observation carries no judgment about anyone on the other flights, whose circumstances and opportunities were different.

It reminds us what technology can make possible, and what still depends on people.

We Have Made Progress

There have been meaningful improvements since September 11, many driven by the problems exposed that day.

FirstNet grew out of the need for better public safety communications. Its network gives emergency responders priority for calls, texts, and data, including precedence over other traffic when necessary. That addresses a practical problem: People responding to an emergency need to communicate when everyone else is trying to communicate, too.

NIST’s investigation also informed model-code changes involving protected stairways, fireproofing, sprinkler reliability, luminous exit markings, and radio coverage inside buildings. Those changes do not mean every existing building was retrofitted. They do show that lessons were translated into concrete improvements.

Some of the most valuable progress is easy to overlook. A protected stairway. A radio that works inside a building. An evacuation procedure people have practiced.

In technology, we spend considerable time celebrating new capabilities. We should give comparable attention to whether those capabilities remain useful when power fails, equipment is damaged, networks are overloaded, and the person who normally runs everything is unavailable.

That is a demanding test. Buying equipment is only part of meeting it.

The Dangers We Are Building Around Ourselves

Could we face a catastrophe originating in our digital systems?

The concern behind the phrase “digital 9/11” deserves serious consideration. I am uncomfortable with how easily September 11 can become shorthand for someone else’s prediction. The people we lost deserve more care than that.

Still, our dependence on connected infrastructure creates responsibilities we cannot ignore. When digital disruption reaches electricity, communications, water, or hospital operations, the consequences can become physical.

There is evidence of hostile interest in those systems. In January 2024, the Justice Department described a campaign by the group known as Volt Typhoon targeting critical infrastructure. U.S. officials assessed that the activity involved positioning for potential disruption during a conflict. The same announcement detailed a successful operation against the botnet used to conceal that hacking. 

Both parts matter. The threat was serious, and defenders took effective action. That historical evidence does not establish that every intrusion remains active or that a national catastrophe is imminent.

Consider a planning scenario: A prolonged power disruption also weakens communications, making it harder for hospitals to coordinate transfers and obtain supplies. The concern is how failures interact and obstruct recovery. Organizations can prepare for their own outages and still discover that they depend on someone else’s untested backup plan.

AI adds capability on both sides. The UK’s National Cyber Security Centre assessed in May 2025 that AI would improve parts of cyber intrusion operations, including vulnerability research, while also helping defenders secure systems. It warned of an uneven divide between organizations able to keep pace and those left more exposed. Those were assessments, not guarantees about how events would unfold. 

As we give AI agents access to systems and permission to act, we also need to consider what happens when they are compromised or behave unexpectedly. Serious harm does not require a machine to become conscious. Access, authority, and inadequate safeguards can be enough to create dangerous conditions.

In an emergency, authenticity becomes another concern. A fabricated instruction or an impersonated official could interfere with response. We should treat that as a scenario to prepare for, without pretending it proves a particular attack is coming.

I remain optimistic about technology, including AI. I also believe optimism brings an obligation to do the work that makes its benefits dependable.

What Protecting People Requires

We should begin with a basic question for every essential service: What happens when the digital system stops working?

The answer needs to include practiced fallback operations, independent communications where feasible, and recovery procedures that people can actually execute. A plan sitting in a system nobody can access during an outage is of limited use.

We also need to contain failures. One compromised account, supplier, or agent should not open a path through everything an organization operates. Connections that create convenience deserve scrutiny for the consequences they could carry.

This is where I come back to a human at the helm. Someone must be accountable, understand what the system is doing, and possess the authority to intervene. Putting a person in front of a dashboard does not satisfy that responsibility.

Nor can we assume a person will react quickly enough to every automated action. Technical boundaries have to constrain what systems can do. The NCSC’s August 2026 agentic AI guidance emphasizes safeguards, controlled environments, monitoring, and the ability to stop activity. These are practical engineering responsibilities.

Preparedness also needs to cross organizational boundaries. Utilities, hospitals, telecommunications companies, technology providers, and public agencies should practice shared emergencies. That is how they can discover conflicting assumptions before those assumptions cost lives.

We have to fund this work, including in smaller institutions with limited resources. Maintenance and training are continuing commitments. So are trustworthy channels for emergency information.

And protecting people includes protecting their rights. Surveillance and automated decisions need accountability. Fear should not give either government or industry unlimited authority over the people they claim to protect.

The People Behind the Questions

When my wife participates in the ceremonies at Ground Zero, she is there to honor her sister. Our family’s loss does not become smaller because the world has become more technologically advanced.

I cannot look back across twenty-five years and offer a technological answer to that absence.

I can ask whether we are taking what we have learned seriously enough. Whether we are supporting the people responsible for our safety. Whether the systems we depend on have been built and tested with their human consequences in mind.

We owe those questions sustained attention, beyond this anniversary.

We remember the people whose lives were taken and those who risked everything trying to save others. We can honor them by giving someone else a better chance to receive a warning, find a way out, get help, and come home.

Frequently Asked Questions

Could today’s technology have prevented the September 11 attacks?
No one can responsibly say that. Better analytics, information sharing and communications might have created additional opportunities to act, but technology cannot overcome every physical, institutional or human limitation.
What public-safety improvements followed 9/11?
The article highlights FirstNet’s priority communications for emergency responders and building-code changes involving protected stairways, fireproofing, sprinkler reliability, exit markings and in-building radio coverage.
What does protecting people require in an AI-driven world?
Organizations need practiced fallback procedures, independent communications where possible, containment of failures, enforceable technical limits, human accountability and coordinated emergency planning across critical sectors.