On the morning of September 11, 2001, just after 9 AM, I was getting ready to leave my Washington, DC apartment when the phone rang.
It was my boss, Paul Leventhal, president of the Nuclear Control Institute, a small DC nonprofit dedicated to preventing nuclear and radiological terrorism. “Turn on the TV,” he instructed. The screen showed United Airlines Flight 175 crashing into the South Tower of the World Trade Center, the second tower to be hit.
The initial crash could have been a horrific accident, but the second attack confirmed it was terrorism, suggesting that anyone or anything could be a target. Without hesitation, Leventhal stated, “It’s bin Laden.” He had long been concerned about the vulnerability of nuclear power plants to terrorist attacks that could lead to a catastrophe similar to Chernobyl on U.S. soil. He was an early advocate for strengthening the Nuclear Regulatory Commission’s (NRC) security requirements when many in the nuclear industry and security circles dismissed the threat.
Before 9/11, nuclear plant security focused on threats like vehicle bombs, reminiscent of the 1993 World Trade Center bombing, the 1995 Oklahoma City bombing, and the 1998 East African embassy attacks by al Qaeda, or paramilitary land assaults by armed groups. The 9/11 attacks highlighted a new threat: hijacked aircraft used as missiles, a scenario with no viable protective measures.
In response, Leventhal contacted Richard Meserve, Chairman of the NRC, urging him to implement emergency measures to protect nuclear plants. Remarkably, Meserve took the call. Leventhal and Dan Hirsch, president of the California-based Committee to Bridge the Gap, wrote to Chairman Meserve, suggesting that the Pentagon deploy anti-aircraft weapons at nuclear sites, improve the vetting of nuclear workers, and have the National Guard bolster the security forces. Meserve’s response was non-committal, stating that the NRC had taken responsive actions and was evaluating current requirements and authority related to terrorism threats.
This marked the beginning of the NRC’s realization that its security measures for U.S. nuclear plants were inadequate for the actual threat level, leaving them vulnerable. According to the 9/11 Commission Report, al Qaeda had considered targeting a nuclear plant near New York on 9/11 but chose not to, believing the airspace was protected—a belief proven incorrect.
Following 9/11, the NRC enhanced nuclear plant security standards, such as increasing the size of expected attacking forces. For a few years, nuclear plants were better prepared for ground assaults, although no measures were required for air attacks by jets or drones. The nuclear industry, citing costs, resisted stronger requirements, leading to NRC changes over the past decade that reversed some post-9/11 improvements.
In 2003, after joining UCS, my colleague Dave Lochbaum and I continued to engage the NRC, opposing industry efforts to weaken reactor security. By 2016, on the fifteenth anniversary of 9/11, I documented our concerns about the proposed changes. Currently, the NRC’s security framework has largely been dismantled, as the agency succumbs to directives from the Trump administration, reducing its oversight to pre-9/11 levels.
The checkered history of force-on-force evaluations
At the time of the 9/11 attacks, the NRC’s Operational Safeguards Response Evaluation (OSRE) program, tasked with testing nuclear plant security forces against terrorist attacks, had been in disarray for over three years. It involved “force-on-force” exercises with mock adversary teams simulating assaults on reactors, aiming to prevent them from causing enough damage to disrupt reactor cooling, which would result in overheating and significant radioactive fuel damage. By 1998, out of 68 nuclear plants tested, 27 failed to prevent simulated meltdowns—a 47% failure rate—even though security measures had been strengthened before tests. The industry, embarrassed, pushed the NRC to shut down the program, which happened in the summer of 1998.
Captain David Orrik, a former Navy Seal and OSRE team lead, opposed the program’s cancellation, filing an internal “Differing Professional View” in August 1998, supported by other NRC staff. Despite this, senior managers did not reverse the decision. The dissenters, worried about nuclear plant security amid increasing terrorist threats, leaked their concerns to the press. Public exposure forced the NRC to reinstate the program and review its implementation, leading to new regulations for future evaluations.
The Nuclear Energy Institute (NEI) proposed nuclear plants conduct their own force-on-force exercises, with the NRC as observers, differing from OSRE, where the NRC provided adversary forces and attack scenarios. This approach risked conflicts of interest and bias, allowing industry to ensure “good guys” won. Captain Orrik’s second dissenting opinion criticized it as a “meaningless NRC rubber-stamping” of industry-decided affordability.
Ignoring Captain Orrik’s concerns, the NRC was prepared to adopt the industry’s proposal until 9/11 made weakening security politically untenable. Thanks to advocacy by then-Representative Edward Markey of Massachusetts, Congress mandated NRC-run triennial inspections in the 2005 Energy Policy Act, amending the Atomic Energy Act. Since then, seven complete inspection cycles have occurred (with some COVID disruptions), significantly improving nuclear plant security. However, five to ten percent of plants still fail annually, underscoring the importance of rigorous testing and inspections.
Throughout, the NEI persistently lobbied to weaken or terminate force-on-force inspections, despite the 2005 Energy Policy Act. Though the NRC has gradually eroded the program, as recently as 2018, the commissioners directed staff to retain it.
What’s Past is Prologue
The NEI gained the upper hand following the Trump administration’s takeover of the NRC in 2025. In April 2026, the NRC commissioners reversed course, deciding to allow NEI’s contentious request to replace NRC-run inspections with licensee-conducted exercises by 2028, despite NRC staff not offering this option to the Commission.
The NRC also made significant cuts to security oversight, including reducing resources for routine physical and cyber inspections by over 50%; assigning inspection duties to overwhelmed resident inspectors lacking specialized training; allowing new reactor owners to rely on local law enforcement instead of their own security; and eliminating the Office of Nuclear Security and Incident Response, established post-9/11.
Recently, the agency released a proposed rule further weakening security standards, redefining them so that even if a security force fails to prevent a meltdown as severe as the 1979 Three Mile Island disaster, it isn’t considered radiological sabotage if public radiation doses remain “acceptable.”
The overall impact of these changes is unpredictable, but it’s evident that the NRC is compromising nuclear plant security amidst rapidly emerging threats like drones with military capabilities and AI-boosted cyberattacks, creating a threat landscape more complex than 9/11’s jet attacks.
In a 2014 interview, 9/11 Commission co-chairs Tom Kean and Lee Hamilton warned against complacency as memories of that day fade. The NRC should heed this caution. The nuclear industry, backed by the Trump administration, plans to build numerous small modular reactors nationwide, closer to populated areas. A “nuclear 9/11” could endanger millions of Americans and hinder the industry’s potential revival for generations.

