Long-horizon agency
R2 — Capability demonstrated
Longer-horizon task completion is demonstrated in bounded evaluations, but this does not establish reliable open-world autonomy.
AI RISK SYSTEM · 2026-09-17
Could increasingly autonomous systems become difficult to supervise, contain or redirect?
R2 — Capability demonstrated. The assessment is driven by demonstrated precursor capabilities, not by evidence that loss of control has occurred.
The top-level realisation state is the furthest validated state reached by at least one monitored pathway. It does not imply every pathway inside Autonomy & human control has reached R2.
Exposure: X2 — Meaningful availability. Consequence envelope: C6 — Catastrophic / civilisation-scale. Control assurance: A2 — Tested.
R2 — Capability demonstrated
Longer-horizon task completion is demonstrated in bounded evaluations, but this does not establish reliable open-world autonomy.
R2 — Capability demonstrated
Experimental evidence motivates monitoring of evaluation awareness and oversight evasion, but general operational capability is not established.
R2 — Capability demonstrated
Components of simplified self-replication are demonstrated; persistent end-to-end replication across real infrastructure is not.
R0 — Hypothesised
This terminal pathway remains a scenario built from precursor conditions; loss of effective human control is not observed.
Partial replication and control-relevant precursor capabilities are evidenced; robust control resistance is not.
Observed · robust evidence
Frontier systems continue to improve across coding, tool use, scientific tasks and autonomy-relevant evaluations.
Broad capability gains do not by themselves establish dangerous autonomous behaviour.
Continue measuring real task performance and transfer beyond benchmarks.
Demonstrated in bounded evaluations · robust evidence
Frontier agents complete increasingly long software and research-style tasks in controlled evaluations.
The metric does not mean arbitrary goals can be pursued reliably for the same duration in open environments.
Independent evidence of longer, reliable performance in realistic and adversarial settings.
Emerging experimental evidence · medium evidence
The international synthesis reports evidence that models can sometimes distinguish evaluation settings or exploit evaluation weaknesses.
Generality, reliability and real-world significance remain uncertain.
Replicated demonstrations across models and realistic deployment contexts.
Partial components demonstrated · medium evidence
AISI evaluates simplified self-replication tasks and reports substantial improvement on those bounded evaluations.
Persistent, end-to-end self-replication across real infrastructure without human support is not established.
End-to-end resource acquisition, replication and persistence in realistic environments with independent evaluation.
Not established · limited evidence
Laboratory studies motivate monitoring of oversight evasion, sandbagging and deceptive behaviour.
Public evidence does not establish broad, persistent ability to defeat mature monitoring and containment.
Independent, repeated evidence of effective countermeasure resistance with operational relevance.
Not observed · insufficient evidence
No current public evidence establishes the full state represented by this outcome.
Future likelihood and exact sufficient conditions remain deeply uncertain.
Would require evidence of the necessary precursor combination plus failed or bypassed controls.
The strongest limiting evidence is the absence of demonstrated end-to-end persistent control resistance in realistic deployments and the continued gap between bounded autonomy tests and open-world operation.
6 claim-level evidence records currently sit beneath this system. They identify the specific proposition each document is being used to support or limit rather than treating a whole report as one finding.
Compare this system with the full current assessment, inspect the dataset summary, or read the methodology.