← Open interactive AI Risk Trajectory

AI RISK PULSE · 2026-09-17

Operational AI risk is established

Operational use is evidenced in cyber, information/influence and state-aligned security workflows. High-consequence autonomy and biological pathways remain at capability or precursor stages. No systemic AI-driven outcome is established in this snapshot.

3/7systems at operational-use stage
0/7systemic AI-driven outcomes established
3high-consequence precursor pathways

Risk posture is multidimensional. These classifications describe the current evidence; they do not represent a probability that an outcome will occur.

Current system assessments

Autonomy & human control

R2Capability demonstrated · X2 exposure · C6 consequence envelope · A2 control assurance

The assessment is driven by demonstrated precursor capabilities, not by evidence that loss of control has occurred.

Supporting basis

Autonomy-relevant capabilities, longer-horizon task completion and partial replication precursors are empirically demonstrated, while robust control resistance and loss of effective human control are not established.

Limiting evidence

The strongest limiting evidence is the absence of demonstrated end-to-end persistent control resistance in realistic deployments and the continued gap between bounded autonomy tests and open-world operation.

What would change the classification?

R3 would require independently corroborated operational use of autonomy/control-relevant behaviour in consequential real-world settings, not benchmark improvement alone.

Cyber & digital security

R3Operational use observed · X3 exposure · C4 consequence envelope · A2 control assurance

Cyber is the clearest current example of the model progressing from capability evidence into observed operational misuse.

Supporting basis

Real-world malicious cyber workflows using AI across reconnaissance, exploitation and theft are documented, including operations running for extended periods with limited human intervention.

Limiting evidence

Documented operations do not establish population-level prevalence, universal autonomy or systemic consequences; humans retain important decisions in reported cases.

What would change the classification?

R4 requires verified material cyber harm with defensible evidence that AI materially enabled or amplified the consequence beyond ordinary tooling.

Biological, chemical & physical harm

R2Capability demonstrated · X2 exposure · C5 consequence envelope · A2 control assurance

The evidence supports meaningful scientific capability uplift while leaving a substantial gap to reliable harmful real-world execution.

Supporting basis

Frontier systems demonstrate advanced biology/chemistry knowledge, troubleshooting and workflow assistance relevant to safety evaluations; reliable end-to-end severe-harm execution is not established.

Limiting evidence

Practical bottlenecks, expertise requirements, materials, equipment, detection and safeguard layers make benchmark or protocol-generation performance an incomplete proxy for harm.

What would change the classification?

R3 requires credible evidence of consequential real-world operational use of the relevant AI assistance, with information hazards handled appropriately.

Information & human agency

R3Operational use observed · X3 exposure · C4 consequence envelope · A1 control assurance

The operational-use threshold is met by observed workflows, while stronger claims about democratic, institutional or autonomy degradation remain under-evidenced.

Supporting basis

Operational use of AI in influence- and surveillance-related workflows is documented, although population-scale causal effects remain uncertain.

Limiting evidence

Lower cost and higher volume do not automatically imply persuasive effectiveness, durable belief change or institutional impact.

What would change the classification?

R4 requires defensible causal evidence of material harm attributable in meaningful part to AI-enabled influence, surveillance or manipulation.

Critical systems & systemic dependence

R1Preconditions observed · X3 exposure · C4 consequence envelope · A1 control assurance

The model recognises growing structural dependency without misclassifying that dependency itself as a realised systemic failure.

Supporting basis

Consequential adoption and shared-provider dependencies are observable, while broad AI-driven correlated failure or cascading systemic disruption is not established.

Limiting evidence

Many deployments retain human fallback, substitution options or limited decision authority, and AI-specific attribution is often weak.

What would change the classification?

R2 requires empirical demonstration of correlated AI-specific operational failure or another concrete mechanism beyond structural dependency alone.

Economic & financial systems

R1Preconditions observed · X3 exposure · C4 consequence envelope · A2 control assurance

The evidence is strongest on financing and concentration, not on realised financial harm caused by AI.

Supporting basis

AI infrastructure financing growth, market concentration and repricing channels are observable, but a distinct AI-driven financial crisis or contagion event is not.

Limiting evidence

Large investment and market concentration can coexist with strong fundamentals; repricing scenarios do not imply a crisis will occur.

What would change the classification?

R2 requires observed AI-specific stress transmission beyond normal market repricing or structural exposure.

Geopolitical & strategic systems

R3Operational use observed · X3 exposure · C5 consequence envelope · A1 control assurance

The operational threshold is met for state-aligned use, but the model does not treat strategic instability as an observed AI-caused outcome.

Supporting basis

State-aligned actors are documented using AI across cyber, surveillance and influence workflows; broader claims about AI causing strategic instability remain inferential.

Limiting evidence

Strategic outcomes depend on doctrine, alliances, human decisions, conventional capabilities and many non-AI factors.

What would change the classification?

R4 requires material strategic harm with defensible causal attribution to AI-enabled use rather than geopolitical conditions alone.

Method

The Pulse keeps Realisation, Exposure, Consequence Envelope, Control Assurance and Evidence Profile separate. It does not average them into a master danger score. Weekly reviews can change a classification only when its published transition condition is met. Read the full methodology or inspect the current dataset summary.