← Open interactive AI Risk Trajectory

AI RISK SYSTEM · 2026-09-17

Autonomy & human control

Could increasingly autonomous systems become difficult to supervise, contain or redirect?

Current assessment

R2Capability demonstrated. The assessment is driven by demonstrated precursor capabilities, not by evidence that loss of control has occurred.

The top-level realisation state is the furthest validated state reached by at least one monitored pathway. It does not imply every pathway inside Autonomy & human control has reached R2.

Exposure: X2Meaningful availability. Consequence envelope: C6Catastrophic / civilisation-scale. Control assurance: A2Tested.

Monitored pathways

Long-horizon agency

R2Capability demonstrated

Longer-horizon task completion is demonstrated in bounded evaluations, but this does not establish reliable open-world autonomy.

Evaluation awareness & oversight evasion

R2Capability demonstrated

Experimental evidence motivates monitoring of evaluation awareness and oversight evasion, but general operational capability is not established.

Replication & persistence

R2Capability demonstrated

Components of simplified self-replication are demonstrated; persistent end-to-end replication across real infrastructure is not.

Loss of effective human control

R0Hypothesised

This terminal pathway remains a scenario built from precursor conditions; loss of effective human control is not observed.

Where the evidence reaches

Partial replication and control-relevant precursor capabilities are evidenced; robust control resistance is not.

General capability growth

Observed · robust evidence

Frontier systems continue to improve across coding, tool use, scientific tasks and autonomy-relevant evaluations.

What remains uncertain

Broad capability gains do not by themselves establish dangerous autonomous behaviour.

What would move this stage

Continue measuring real task performance and transfer beyond benchmarks.

Long-horizon agency

Demonstrated in bounded evaluations · robust evidence

Frontier agents complete increasingly long software and research-style tasks in controlled evaluations.

What remains uncertain

The metric does not mean arbitrary goals can be pursued reliably for the same duration in open environments.

What would move this stage

Independent evidence of longer, reliable performance in realistic and adversarial settings.

Situational / evaluation awareness

Emerging experimental evidence · medium evidence

The international synthesis reports evidence that models can sometimes distinguish evaluation settings or exploit evaluation weaknesses.

What remains uncertain

Generality, reliability and real-world significance remain uncertain.

What would move this stage

Replicated demonstrations across models and realistic deployment contexts.

Replication & persistence precursors

Partial components demonstrated · medium evidence

AISI evaluates simplified self-replication tasks and reports substantial improvement on those bounded evaluations.

What remains uncertain

Persistent, end-to-end self-replication across real infrastructure without human support is not established.

What would move this stage

End-to-end resource acquisition, replication and persistence in realistic environments with independent evaluation.

Robust control resistance

Not established · limited evidence

Laboratory studies motivate monitoring of oversight evasion, sandbagging and deceptive behaviour.

What remains uncertain

Public evidence does not establish broad, persistent ability to defeat mature monitoring and containment.

What would move this stage

Independent, repeated evidence of effective countermeasure resistance with operational relevance.

Loss of effective human control

Not observed · insufficient evidence

No current public evidence establishes the full state represented by this outcome.

What remains uncertain

Future likelihood and exact sufficient conditions remain deeply uncertain.

What would move this stage

Would require evidence of the necessary precursor combination plus failed or bypassed controls.

Evidence limiting the assessment

The strongest limiting evidence is the absence of demonstrated end-to-end persistent control resistance in realistic deployments and the continued gap between bounded autonomy tests and open-world operation.

Claim-level evidence

6 claim-level evidence records currently sit beneath this system. They identify the specific proposition each document is being used to support or limit rather than treating a whole report as one finding.

Key sources

Compare this system with the full current assessment, inspect the dataset summary, or read the methodology.