Offensive cyber capability
R2 — Capability demonstrated
Frontier systems demonstrate useful offensive cyber capability in evaluations.
AI RISK SYSTEM · 2026-09-17
How far has AI progressed from cyber capability into autonomous, real-world attack operations and systemic disruption?
R3 — Operational use observed. Cyber is the clearest current example of the model progressing from capability evidence into observed operational misuse.
The top-level realisation state is the furthest validated state reached by at least one monitored pathway. It does not imply every pathway inside Cyber & digital security has reached R3.
Exposure: X3 — Consequential deployment. Consequence envelope: C4 — Cross-sector / systemic. Control assurance: A2 — Tested.
R2 — Capability demonstrated
Frontier systems demonstrate useful offensive cyber capability in evaluations.
R2 — Capability demonstrated
Multi-stage execution is demonstrated in controlled environments, with reliability varying by target and defence.
R3 — Operational use observed
Provider threat intelligence documents malicious use across reconnaissance, exploitation, credential theft and related workflows.
R3 — Operational use observed
Reported operations include workflows running for hours or days with limited human intervention, while humans retained consequential decisions.
R0 — Hypothesised
Systemic disruption is a credible downstream mechanism through shared dependencies, but is not established as a realised AI-driven state in this snapshot.
Real-world AI-assisted and highly autonomous cyber workflows are observed; catastrophic systemic consequences are not.
Operationally useful · robust evidence
AISI reports rapid frontier improvement on vulnerability discovery and multi-stage cyber tasks.
Capability varies widely by target, environment and level of defence.
Reliable performance on more complex, defended and end-to-end operational tasks.
Demonstrated · robust evidence
Frontier models can perform longer sequences of cyber activity in controlled environments with limited human input.
Performance against well-defended production systems remains materially harder.
Cross-evaluator evidence of reliable multi-stage attack performance in realistic environments.
Observed · medium evidence
Developer threat intelligence documents use in reconnaissance, exploitation, credential theft, surveillance and other malicious workflows.
Detected cases do not establish prevalence across the wider threat ecosystem.
Independent or cross-provider corroboration and better prevalence measurement.
Observed in reported operations · medium evidence
Anthropic reports workflows operating for hours or days with minimal human intervention.
Humans retained consequential decisions such as target selection and monetisation in documented cases.
Independent evidence of sustained autonomy across more complex operational chains.
Mixed · medium evidence
Safeguards, monitoring and AI-assisted defence are improving in some systems.
AISI reports vulnerabilities in every system tested and real-world defence is uneven.
Operational evidence that prevention, detection and remediation remain effective at rising attack speed and scale.
Not established as routine AI-driven outcome · limited evidence
Shared suppliers and critical infrastructure can transmit cyber disruption across sectors.
The frequency and scale of AI-specific systemic consequences are not well measured.
Verified systemic events with defensible causal attribution to AI-enabled capability.
Documented operations do not establish population-level prevalence, universal autonomy or systemic consequences; humans retain important decisions in reported cases.
5 claim-level evidence records currently sit beneath this system. They identify the specific proposition each document is being used to support or limit rather than treating a whole report as one finding.
Compare this system with the full current assessment, inspect the dataset summary, or read the methodology.