← AI Risk Trajectory by Nuvastra Public research preview · 2026-09-18 Evidence snapshot — 18 September 2026 AI misuse and harm are documented in provider investigations. Capability tests, operational reports and possible wider consequences are now shown separately.
Methodology correction and targeted source check Six primary publications checked. This is a focused evidence review, not a comprehensive scan of all AI incidents or research. External expert review has not been completed. Sources do not endorse this tool.
Open the interactive explanation
Current evidence records Tested in an evaluation · AUT-02 Longer bounded tasks METR measures success on increasingly demanding, well-specified software tasks.
What this does not establish This does not measure how long an agent can pursue arbitrary real-world goals.
Source location: Methodological Details; FAQ: Does “time horizon” mean the length of time that current AI agents can act autonomously?
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
Task-Completion Time Horizons of Frontier AI Models — Independent evaluator
Tested in an evaluation · AUT-04 Replication-related skills AISI tests components relevant to replication in controlled environments.
What this does not establish Its report says real-world replication success is unlikely under the conditions considered.
Source location: Self-replication; Reading this report
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
Frontier AI Trends Report — Evaluator, not model developer
Conditional scenario · AUT-05 Oversight fails to stop an agent Relevant capabilities could contribute to an agent evading effective oversight.
What this does not establish This is a conditional risk mechanism, not evidence of universal or sustained control evasion.
Source location: Executive Summary — Malfunctions; section on loss of control
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
International AI Safety Report 2026 — Multi-institutional synthesis
Conditional scenario · AUT-06 Sustained loss of human control The report discusses systems operating beyond anyone’s control with no clear recovery route.
What this does not establish The report does not establish this terminal outcome; precursor tests cannot establish it either.
Source location: Executive Summary — Loss of control
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
International AI Safety Report 2026 — Multi-institutional synthesis
Tested in an evaluation · CYB-01 Offensive capability tests AISI reports improved performance on tested cyber tasks.
What this does not establish Test performance depends on environment and does not establish success against every defended target.
Source location: Cyber capabilities; Reading this report
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
Frontier AI Trends Report — Evaluator, not model developer
Reported real-world case · CYB-03 Malicious operational use Anthropic reports AI-assisted attack workflows beyond ordinary chatbot advice.
What this does not establish These are developer-detected cases, not a measurement of overall attacker prevalence.
Source location: Cyber operations — From assistant to orchestrator
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
Detecting and countering misuse of AI: September 2026 — Model developer
Reported real-world case · CYB-04 Theft and other harm The investigated operations include data theft and extortion.
What this does not establish Human decisions and conventional tools remain involved; the report is not an independent estimate of AI’s causal effect.
Source location: Cyber operations; case descriptions of data theft and extortion
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
Detecting and countering misuse of AI: September 2026 — Model developer
Conditional scenario · CYB-06 Wider disruption Shared digital dependencies could transmit disruption across organisations.
What this does not establish A possible transmission route does not establish a realised AI-driven systemic event.
Source location: Section 3 — cyber and operational risks
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
Financial Stability Report — July 2026 — Central bank
Tested in an evaluation · BIO-01 Scientific capability Evaluations show improved performance on chemistry and biology tasks.
What this does not establish A high knowledge score is not an end-to-end measure of dangerous practical execution.
Source location: Chemistry and biology; Executive summary
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
Frontier AI Trends Report — Evaluator, not model developer
Tested in an evaluation · BIO-03 Workflow assistance AISI reports improvements in protocol generation and troubleshooting assistance.
What this does not establish Feasible assistance in a controlled setting does not establish autonomous completion of a harmful programme.
Source location: Chemistry and biology — laboratory protocols and troubleshooting
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
Frontier AI Trends Report — Evaluator, not model developer
Assessed mechanism · BIO-04 Practical barriers Actor skills, materials, equipment and execution constraints remain relevant to misuse.
What this does not establish The scale of real-world uplift varies by task and user; no universal uplift estimate is assigned.
Source location: Executive Summary — Biological and chemical risks
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
International AI Safety Report 2026 — Multi-institutional synthesis
Conditional scenario · BIO-06 Severe physical consequences The synthesis discusses the potential for severe biological or chemical misuse.
What this does not establish A risk scenario is not evidence of a catastrophic AI-caused event.
Source location: Executive Summary — Biological and chemical risks
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
International AI Safety Report 2026 — Multi-institutional synthesis
Tested in an evaluation · INF-01 Persuasion in tests Studies reviewed by the report show persuasive capabilities in experimental settings.
What this does not establish Experimental persuasion does not determine population-scale effects or long-term belief change.
Source location: Executive Summary — Manipulation and influence
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
International AI Safety Report 2026 — Multi-institutional synthesis
Reported real-world case · INF-02 Influence and surveillance use Provider investigations describe AI used in influence and surveillance workflows.
What this does not establish Detected operations do not show how common or successful all such operations are.
Source location: Influence operations; Surveillance operations
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
Detecting and countering misuse of AI: September 2026 — Model developer
Evidence unresolved · INF-03 Durable effects at scale The reviewed evidence does not settle the size of persistent population-level effects.
What this does not establish Uncertainty does not prove an absence of harm or the success of manipulation.
Source location: Executive Summary — Manipulation; evidence limitations
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
International AI Safety Report 2026 — Multi-institutional synthesis
Conditional scenario · INF-05 Institutional consequences Sustained manipulation could affect human agency and information integrity.
What this does not establish Attribution, exposure and institutional resilience must be examined rather than inferred from a content-generation test.
Source location: Executive Summary — Systemic risks; human autonomy
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
International AI Safety Report 2026 — Multi-institutional synthesis
Documented observation · SYS-01 Access to consequential tools AISI describes growing interfaces that connect models to tools, including financial services.
What this does not establish An available interface does not establish how widely it is deployed or how dependent a sector has become.
Source location: Autonomy — Model Context Protocol and available tools
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
Frontier AI Trends Report — Evaluator, not model developer
Assessed mechanism · SYS-02 Shared dependency Institutional analysis identifies common providers and infrastructure as channels for correlated disruption.
What this does not establish A dependency mechanism is not a measurement of every organisation’s exposure.
Source location: Section 3 — common providers and operational dependence
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
Financial Stability Report — July 2026 — Central bank
Conditional scenario · SYS-03 Common failure or compromise A shared failure could affect several organisations at once.
What this does not establish The current record describes a mechanism, not a verified general AI-caused failure rate.
Source location: Section 3 — correlated operational disruption
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
Financial Stability Report — July 2026 — Central bank
Conditional scenario · SYS-05 Cascading service disruption Limited alternatives and recovery capacity could allow disruption to spread.
What this does not establish A cascade depends on deployment, exposure and resilience; it is not an inevitable next stage.
Source location: Section 3 — operational resilience and priorities
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
Financial Stability Report — July 2026 — Central bank
Documented observation · FIN-01 Infrastructure financing The Bank of England documents financing growth associated with AI infrastructure.
What this does not establish More financing is not itself evidence of a crisis or financial loss.
Source location: Section 2.3 — A growing role for debt in financing AI infrastructure
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
Financial Stability Report — July 2026 — Central bank
Documented observation · FIN-02 Concentrated exposures The report documents concentration and exposures linked to AI-related firms and expectations.
What this does not establish Concentration can coexist with strong fundamentals and does not alone establish instability.
Source location: Section 2.2 — Near-term risks to UK financial stability
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
Financial Stability Report — July 2026 — Central bank
Conditional scenario · FIN-03 Repricing stress The report considers hypothetical scenarios involving changed AI expectations and asset prices.
What this does not establish This is a stress scenario, not an observed AI-driven financial crisis.
Source location: Section 2.2 — AI-related hypothetical stress scenarios
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
Financial Stability Report — July 2026 — Central bank
Conditional scenario · FIN-05 Systemic amplification Leverage and connected exposures could amplify a shock.
What this does not establish The scale and timing of an AI-specific shock are not estimated by this tool.
Source location: Section 2 — macrofinancial implications and transmission channels
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
Financial Stability Report — July 2026 — Central bank
Reported real-world case · GEO-02 State-linked operational use Provider threat intelligence reports activity attributed to state-linked actors.
What this does not establish Attribution is the provider’s judgement and the cases are not a complete view of state use.
Source location: Cyber, surveillance and influence operations; attribution notes
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
Detecting and countering misuse of AI: September 2026 — Model developer
Evidence unresolved · GEO-03 Full scope of security adoption Publicly reported cases do not establish all military and intelligence integration.
What this does not establish Classified activity and selective reporting limit visibility; missing public evidence is not absence.
Source location: Report scope and limitations; misuse and systemic-risk discussion
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
International AI Safety Report 2026 — Multi-institutional synthesis
Assessed mechanism · GEO-04 Governance and accountability The scientific synthesis discusses risk-management and governance measures.
What this does not establish A policy or commitment is not evidence that it is implemented effectively.
Source location: Executive Summary — Risk management; industry commitments
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
International AI Safety Report 2026 — Multi-institutional synthesis
Conditional scenario · GEO-05 Strategic consequences AI use could interact with existing security incentives and human decisions.
What this does not establish This does not establish a single AI-caused escalation or assign a political danger score.
Source location: Executive Summary — systemic risks and governance limits
Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.
International AI Safety Report 2026 — Multi-institutional synthesis
Explore further Interactive tool Methodology Dataset Nuvastra