The NRC is Regulating Nuclear Security like it’s September 10, 2001—And We Should All Be Concerned 

September 10, 2026 | 11:00 am
Chris Van Kan/Getty Images
Edwin Lyman
Director, Nuclear Power Safety

On the morning of September 11, 2001, I was preparing to leave my Washington, DC apartment for an appointment when the phone rang. It was just after 9 AM.  

On the line was my boss at the time, Paul Leventhal, president of the Nuclear Control Institute, a tiny DC nonprofit focused on preventing nuclear and radiological terrorism. “Turn on the TV,” he said. Video of United Airlines Flight 175 crashing into the South Tower of the World Trade Center—the second tower to be attacked—filled the screen.  

The first crash could merely have been a terrible accident. But the second left little doubt. It was an act of terrorism that sent a chilling message: Anyone or anything could be a target. Without hesitation, Leventhal declared “It’s bin Laden.” Leventhal had long feared that nuclear power plants were vulnerable to terrorist sabotage that could cause a Chernobyl-like catastrophe on American soil, and he was an early (and lonely) advocate for strengthening NRC’s security requirements at a time when the nuclear industry and most security analysts dismissed the threat.  

Before 9/11, the biggest concerns for nuclear plant security were vehicle bombs, such as the 1993 World Trade Center bombing, the 1995 Oklahoma City bombing, and the al Qaeda 1998 East African embassy attacks, or a paramilitary land assault by heavily armed groups. The 9/11 attacks, however, immediately made apparent a previously unforeseen threat scenario: hijacked jet aircraft turned into missiles—a terrifying possibility for which there are no practical protective measures.   

Leventhal—never one to hold back in a time of crisis—picked up the phone and cold-called Richard Meserve, the Chairman of the Nuclear Regulatory Commission (NRC). Remarkably, Chairman Meserve took his call. Leventhal urged him to impose emergency measures to bolster protection of the nation’s nuclear plants. Soon afterward, Leventhal and Dan Hirsch, the president of the California-based Committee to Bridge the Gap, wrote to Chairman Meserve to ask the Pentagon to deploy anti-aircraft weapons at nuclear plants, to improve vetting of nuclear workers, and to request that National Guard troops be dispatched to supplement inadequately staffed security forces. He responded with a non-answer, assuring that the NRC immediately “took a number of responsive actions” after the attacks, and was “evaluating current requirements and statutory authority related to acts or threats of terrorism, including but not limited to those that you presented in your letter.” 

And so began the long journey of the NRC coming to terms with the reality that the requirements it had in place for protecting US nuclear power plants from terrorists had not kept pace with the magnitude of the actual threat, leaving the fleet dangerously exposed. As we now know from the 9/11 Commission Report, al Qaeda operatives had considered targeting a nuclear plant near New York on 9/11 (presumably Indian Point), but fortunately, they decided against it in part because they thought that the airspace around it would be protected. Subsequent events quickly revealed that assumption was incorrect. 

In 9/11’s aftermath, the NRC ultimately did ratchet up its standards for protection of nuclear plants—for example, by increasing the assumed size of the attacking force that plant security would have to defend against—and for a few years, nuclear plants became somewhat better prepared to withstand terrorist ground assaults. (The agency never did require defenses against air attacks by jets or drones). But the nuclear industry, objecting to the cost of meeting stronger requirements, fought the NRC all the way. And over the last decade, the NRC has made a steady stream of changes, in response to industry pressure, that undid some of the post-9/11 improvements. 

After I joined UCS in 2003, my former colleague Dave Lochbaum and I continued to engage the NRC on this critical issue, pushing back against industry proposals to weaken reactor security. In 2016, the year of the fifteenth 9/11 anniversary, I chronicled our concerns about the changes that had been proposed up to that time. Today, unfortunately, the NRC’s undoing of its strengthened security framework is all but total, as the no-longer-independent agency caves in to Trump administration directives and slashes its security oversight to a level not seen since September 10, 2001.  

The checkered history of force-on-force evaluations 

When al Qaeda struck on 9/11, the only NRC program that directly tested the capabilities of nuclear power plant security forces to protect against terrorist attacks, the Operational Safeguards Response Evaluation (OSRE), had been in disarray for over three years. OSRE utilized live “force-on-force” exercises with mock adversary teams staging violent assaults at reactors—essentially a sophisticated version of laser tag. The goal of the protective force was to stop the adversary team from simulating the destruction of enough safety equipment to disrupt cooling of the reactor cores, which in a real attack would cause overheating and significant damage to the highly radioactive fuel. By 1998, 57 of the 68 nuclear plants then operating had been tested, and 27 had been unable to prevent the mock attackers from achieving their objective of causing a meltdown—a failure rate of 47 percent—even though the plant owners had beefed up their security measures in advance of the tests. The industry was embarrassed by the results and, instead of working to fix its security problems, it pushed the NRC to shut the program down—which it finally did in the summer of 1998.  

Captain David Orrik, a former Navy Seal and the OSRE team lead, objected to the program’s cancellation and filed an internal “Differing Professional View” in August 1998, which was endorsed by a number of other NRC staff. However, NRC senior managers refused to reverse the decision. The dissenters, alarmed by the state of security at the nation’s nuclear plants at a time when terrorist threats were increasing, leaked their concerns to the press. Once the conflict came into public view, the NRC was forced to reinstate the program, but also initiated a review of its implementation, and decided to promulgate new regulations for the future performance evaluation program.  

The nuclear reactor owners and their lobbying group, the Nuclear Energy Institute (NEI), offered their own vision: a self-assessment in which nuclear plants would conduct their own force-on-force exercises, and the NRC would be relegated to a mere observer. This differed in important ways from OSRE, in which the NRC provided the mock adversary force, chose the attack scenarios (based on intelligence information), and was assisted by US Special Forces contractors with vast experience in paramilitary tactics. This approach maintained the independence of the evaluating agency from the plants being evaluated and avoided conflicts of interest. But the industry proposal offered too many opportunities to tilt the playing field so that the “good guys” would win, and Captain Orrik, in a second dissenting opinion, derided it as a “meaningless NRC rubber-stamping of whatever the industry decided it could afford.” (I got to know Captain Orrik at the time and greatly respected his expertise.) 

Dismissing Captain Orrik’s concerns, the NRC was on track to adopt the industry’s proposal— until 9/11 changed the playing field by making efforts to weaken security politically unpopular. Through the advocacy of then-Representative (and now-Senator) Edward Markey of Massachusetts, Congress enshrined NRC-run triennial force-on-force inspections in the law by enacting a provision in the 2005 Energy Policy Act that amended the Atomic Energy Act. Since then, there have been seven complete force-on-force inspection cycles (with some disruptions during COVID). The security performance of nuclear plants has improved significantly since the OSRE era, although about five to ten percent of plants still fail the test each year, showing the importance of maintaining vigilance through a robust testing and inspection regime.  

Throughout this entire period, the NEI never stopped pushing the NRC to weaken its force-on-force inspections—or even terminate them again, despite the 2005 Energy Policy Act provision. Although the NRC has arguably pursued a “death by a thousand cuts” approach to its force-on-force program, as recently as 2018 the commissioners instructed the staff not to get rid of it altogether. 

What’s Past is Prologue 

The NEI finally got the upper hand after the Trump administration’s takeover of the NRC in 2025. In April of 2026, the NRC commissioners reversed course and issued a decision to grant the NEI’s legally dubious request to replace NRC-run force-on-force inspections with observation of licensee-conducted exercises by 2028—even though the NRC staff did not even provide such an option to the Commission. 

The NRC has also made other major cuts to its security oversight, including slashing resources for routine physical and cyber security inspections by over fifty percent in some cases; transferring some inspection duties to already overwhelmed resident inspectors who do not have specialized security training; allowing new reactor owners to take credit for local law enforcement response in lieu of providing their own security forces; and even eliminating the Office of Nuclear Security and Incident Response, established after 9/11 to elevate the agency’s security oversight mission.  

The agency also recently released a proposed rule that further weakens security requirements across the board, including redefining its standards so that even if a nuclear plant security force were helpless to prevent terrorists from deliberately causing an meltdown as severe as the 1979 Three Mile Island disaster, the agency would not consider it radiological sabotage because the projected radiation doses to the public would be within “acceptable” limits.  Nothing to see here! 

The cumulative effect of all these changes is hard to predict. But there is little doubt that the NRC is dangerously undermining nuclear plant security at a time when the convergence of rapidly emerging technologies—from drones with advanced military capabilities to artificial intelligence-boosted cyber attacks—are amplifying the threat landscape in even more profound ways than did the jet attacks of 9/11. 

In a 2014 interview, co-chairs of the 9/11 Commission Tom Kean and Lee Hamilton warned about the dangers of complacency setting in as the horrific events of that day become a distant memory. The NRC should heed this warning. The nuclear industry, supported by the Trump administration, has ambitious plans to build scores of small modular reactors around the country, in more diverse locations and closer to populated areas. A “nuclear 9/11” would imperil the health and safety of millions of Americans and derail the industry’s hoped-for nuclear revival for generations to come.