← AI Risk Trajectory by NuvastraPublic research preview · 2026-09-18

Evidence snapshot — 18 September 2026

AI misuse and harm are documented in provider investigations. Capability tests, operational reports and possible wider consequences are now shown separately.

Methodology correction and targeted source check

Six primary publications checked. This is a focused evidence review, not a comprehensive scan of all AI incidents or research. External expert review has not been completed. Sources do not endorse this tool.

Open the interactive explanation

Current evidence records

Tested in an evaluation · AUT-02

Longer bounded tasks

METR measures success on increasingly demanding, well-specified software tasks.

What this does not establish

This does not measure how long an agent can pursue arbitrary real-world goals.

Source location: Methodological Details; FAQ: Does “time horizon” mean the length of time that current AI agents can act autonomously?

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

Task-Completion Time Horizons of Frontier AI ModelsIndependent evaluator

Tested in an evaluation · AUT-04

Replication-related skills

AISI tests components relevant to replication in controlled environments.

What this does not establish

Its report says real-world replication success is unlikely under the conditions considered.

Source location: Self-replication; Reading this report

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

Frontier AI Trends ReportEvaluator, not model developer

Conditional scenario · AUT-05

Oversight fails to stop an agent

Relevant capabilities could contribute to an agent evading effective oversight.

What this does not establish

This is a conditional risk mechanism, not evidence of universal or sustained control evasion.

Source location: Executive Summary — Malfunctions; section on loss of control

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

International AI Safety Report 2026Multi-institutional synthesis

Conditional scenario · AUT-06

Sustained loss of human control

The report discusses systems operating beyond anyone’s control with no clear recovery route.

What this does not establish

The report does not establish this terminal outcome; precursor tests cannot establish it either.

Source location: Executive Summary — Loss of control

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

International AI Safety Report 2026Multi-institutional synthesis

Tested in an evaluation · CYB-01

Offensive capability tests

AISI reports improved performance on tested cyber tasks.

What this does not establish

Test performance depends on environment and does not establish success against every defended target.

Source location: Cyber capabilities; Reading this report

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

Frontier AI Trends ReportEvaluator, not model developer

Reported real-world case · CYB-03

Malicious operational use

Anthropic reports AI-assisted attack workflows beyond ordinary chatbot advice.

What this does not establish

These are developer-detected cases, not a measurement of overall attacker prevalence.

Source location: Cyber operations — From assistant to orchestrator

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

Detecting and countering misuse of AI: September 2026Model developer

Reported real-world case · CYB-04

Theft and other harm

The investigated operations include data theft and extortion.

What this does not establish

Human decisions and conventional tools remain involved; the report is not an independent estimate of AI’s causal effect.

Source location: Cyber operations; case descriptions of data theft and extortion

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

Detecting and countering misuse of AI: September 2026Model developer

Conditional scenario · CYB-06

Wider disruption

Shared digital dependencies could transmit disruption across organisations.

What this does not establish

A possible transmission route does not establish a realised AI-driven systemic event.

Source location: Section 3 — cyber and operational risks

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

Financial Stability Report — July 2026Central bank

Tested in an evaluation · BIO-01

Scientific capability

Evaluations show improved performance on chemistry and biology tasks.

What this does not establish

A high knowledge score is not an end-to-end measure of dangerous practical execution.

Source location: Chemistry and biology; Executive summary

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

Frontier AI Trends ReportEvaluator, not model developer

Tested in an evaluation · BIO-03

Workflow assistance

AISI reports improvements in protocol generation and troubleshooting assistance.

What this does not establish

Feasible assistance in a controlled setting does not establish autonomous completion of a harmful programme.

Source location: Chemistry and biology — laboratory protocols and troubleshooting

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

Frontier AI Trends ReportEvaluator, not model developer

Assessed mechanism · BIO-04

Practical barriers

Actor skills, materials, equipment and execution constraints remain relevant to misuse.

What this does not establish

The scale of real-world uplift varies by task and user; no universal uplift estimate is assigned.

Source location: Executive Summary — Biological and chemical risks

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

International AI Safety Report 2026Multi-institutional synthesis

Conditional scenario · BIO-06

Severe physical consequences

The synthesis discusses the potential for severe biological or chemical misuse.

What this does not establish

A risk scenario is not evidence of a catastrophic AI-caused event.

Source location: Executive Summary — Biological and chemical risks

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

International AI Safety Report 2026Multi-institutional synthesis

Tested in an evaluation · INF-01

Persuasion in tests

Studies reviewed by the report show persuasive capabilities in experimental settings.

What this does not establish

Experimental persuasion does not determine population-scale effects or long-term belief change.

Source location: Executive Summary — Manipulation and influence

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

International AI Safety Report 2026Multi-institutional synthesis

Reported real-world case · INF-02

Influence and surveillance use

Provider investigations describe AI used in influence and surveillance workflows.

What this does not establish

Detected operations do not show how common or successful all such operations are.

Source location: Influence operations; Surveillance operations

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

Detecting and countering misuse of AI: September 2026Model developer

Evidence unresolved · INF-03

Durable effects at scale

The reviewed evidence does not settle the size of persistent population-level effects.

What this does not establish

Uncertainty does not prove an absence of harm or the success of manipulation.

Source location: Executive Summary — Manipulation; evidence limitations

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

International AI Safety Report 2026Multi-institutional synthesis

Conditional scenario · INF-05

Institutional consequences

Sustained manipulation could affect human agency and information integrity.

What this does not establish

Attribution, exposure and institutional resilience must be examined rather than inferred from a content-generation test.

Source location: Executive Summary — Systemic risks; human autonomy

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

International AI Safety Report 2026Multi-institutional synthesis

Documented observation · SYS-01

Access to consequential tools

AISI describes growing interfaces that connect models to tools, including financial services.

What this does not establish

An available interface does not establish how widely it is deployed or how dependent a sector has become.

Source location: Autonomy — Model Context Protocol and available tools

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

Frontier AI Trends ReportEvaluator, not model developer

Assessed mechanism · SYS-02

Shared dependency

Institutional analysis identifies common providers and infrastructure as channels for correlated disruption.

What this does not establish

A dependency mechanism is not a measurement of every organisation’s exposure.

Source location: Section 3 — common providers and operational dependence

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

Financial Stability Report — July 2026Central bank

Conditional scenario · SYS-03

Common failure or compromise

A shared failure could affect several organisations at once.

What this does not establish

The current record describes a mechanism, not a verified general AI-caused failure rate.

Source location: Section 3 — correlated operational disruption

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

Financial Stability Report — July 2026Central bank

Conditional scenario · SYS-05

Cascading service disruption

Limited alternatives and recovery capacity could allow disruption to spread.

What this does not establish

A cascade depends on deployment, exposure and resilience; it is not an inevitable next stage.

Source location: Section 3 — operational resilience and priorities

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

Financial Stability Report — July 2026Central bank

Documented observation · FIN-01

Infrastructure financing

The Bank of England documents financing growth associated with AI infrastructure.

What this does not establish

More financing is not itself evidence of a crisis or financial loss.

Source location: Section 2.3 — A growing role for debt in financing AI infrastructure

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

Financial Stability Report — July 2026Central bank

Documented observation · FIN-02

Concentrated exposures

The report documents concentration and exposures linked to AI-related firms and expectations.

What this does not establish

Concentration can coexist with strong fundamentals and does not alone establish instability.

Source location: Section 2.2 — Near-term risks to UK financial stability

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

Financial Stability Report — July 2026Central bank

Conditional scenario · FIN-03

Repricing stress

The report considers hypothetical scenarios involving changed AI expectations and asset prices.

What this does not establish

This is a stress scenario, not an observed AI-driven financial crisis.

Source location: Section 2.2 — AI-related hypothetical stress scenarios

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

Financial Stability Report — July 2026Central bank

Conditional scenario · FIN-05

Systemic amplification

Leverage and connected exposures could amplify a shock.

What this does not establish

The scale and timing of an AI-specific shock are not estimated by this tool.

Source location: Section 2 — macrofinancial implications and transmission channels

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

Financial Stability Report — July 2026Central bank

Reported real-world case · GEO-02

State-linked operational use

Provider threat intelligence reports activity attributed to state-linked actors.

What this does not establish

Attribution is the provider’s judgement and the cases are not a complete view of state use.

Source location: Cyber, surveillance and influence operations; attribution notes

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

Detecting and countering misuse of AI: September 2026Model developer

Evidence unresolved · GEO-03

Full scope of security adoption

Publicly reported cases do not establish all military and intelligence integration.

What this does not establish

Classified activity and selective reporting limit visibility; missing public evidence is not absence.

Source location: Report scope and limitations; misuse and systemic-risk discussion

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

International AI Safety Report 2026Multi-institutional synthesis

Assessed mechanism · GEO-04

Governance and accountability

The scientific synthesis discusses risk-management and governance measures.

What this does not establish

A policy or commitment is not evidence that it is implemented effectively.

Source location: Executive Summary — Risk management; industry commitments

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

International AI Safety Report 2026Multi-institutional synthesis

Conditional scenario · GEO-05

Strategic consequences

AI use could interact with existing security incentives and human decisions.

What this does not establish

This does not establish a single AI-caused escalation or assign a political danger score.

Source location: Executive Summary — systemic risks and governance limits

Review: Primary-source passage checked; Nuvastra interpretation not independently peer reviewed. Checked 2026-09-18.

International AI Safety Report 2026Multi-institutional synthesis

Explore further