Frequently asked questions

Short answers, each with its source. Every answer links to the page that goes further.

Could AI bring about the end of humanity?

Nobody knows, including those who put a figure on it. Public estimates run from less than 0.01%, a figure attributed to Yann LeCun, to 99.9%, Roman Yampolskiy's conditional estimate over a hundred years. None of them can be checked: they concern an event that has never happened.

What can be checked is what has already happened. Attacks carried out with the help of AI have begun, and some defenses still hold. That is what we measure. See the current picture →

What is “P(doom)”?

Short for “probability of doom”: the figure a public figure gives when asked how likely it is that AI leads to a catastrophe, or even to human extinction.

The term has a flaw: everyone puts a different question into it. Extinction or catastrophe, within thirty years or a hundred, conditional or not. And none of these figures can be checked.

Why do experts disagree?

First, because they are not answering the same question. Second, because no data can settle it: a probability is computed from what has been observed, and the feared catastrophe has never happened. Yann LeCun says so himself: these estimates are “pulled out of thin air” (X, April 2026).

Are AI-assisted attacks already happening?

Yes. Between December 2025 and August 2026, intrusion and espionage operations carried out with the help of an AI model were detected, then cut off by the model's provider, which closed the accounts (Anthropic report, September 2026). The MITRE ATLAS catalogue also documents real attacks against AI systems.

Who are the malicious actors?

Reports published by model providers cite espionage groups linked to China and Russia, activity attributed to North Korea, financially motivated cybercriminal groups, and state-backed influence operations (Google, September 2026).

They are moving from simple prompts to agents that work on their own: in the second quarter of 2026, attackers used agents to run a mass credential-harvesting campaign in under six hours, according to the same report. These findings come from what each provider sees on its own platform: they show the phenomenon, they do not measure it worldwide.

What is MITRE ATLAS?

MITRE ATLAS is a public knowledge base of attack techniques targeting AI systems, built from real-world attacks and demonstrations by security teams. It is maintained by MITRE, an American non-profit that also maintains ATT&CK, the reference for conventional cyberattacks.

Each technique carries a grade: feasible, demonstrated in the lab, or realized in a real attack. It is our starting point. How we use it →

Who are the main players in AI safety?

What is “a defense that still holds”?

We call it a lock: a defense that still holds, meaning what is missing for an attack to become possible. An example from our list: account termination by a model provider, which cut off the intrusion operations mentioned above. It is held by the providers themselves, and it would give way if an operation of the same scale ran to completion without being detected.

Every lock in the list states what is missing, what type of defense it is, where it is written, and who could lift it.

Are there safeguards at the UN and state level?

Yes, but they are recent and mostly non-binding.

Why so little? A treaty applies only after states ratify it, one by one, and that takes years. The texts adopted quickly bind no one.

Do all countries take part?

Not to the same degree. At the New Delhi summit in February 2026, the final declaration was endorsed by 92 countries and international organisations. But most of the specific commitments gathered only around twenty signatories (Government of India, March 2026). Attending a summit and committing to something are two different things.

Is my organisation concerned?

As soon as it uses an AI model or agent, yes: part of its defenses is held by others — model, compute or service providers. That is the finding at the heart of our work: your defense is not yours, and nobody warns you when it gives way. See the example →

What can a decision-maker do right now?

Why don't you give your own probability?

Because it would be as uncheckable as the others. We publish what can be checked: what has already been observed, when, and what still holds.

Why don't you publish the details of attacks?

For obvious reasons: an entry never says how to get around a defense. We name what blocks, never the way through. When a piece of information cannot be reworded without becoming a manual, it is neither published nor kept. The rule in detail →

What do you contribute to AI safety research?

Did AI take part in this work?

Yes. Source gathering, computation and analysis are carried out by AI agents, under the direction of Franck Bardol, who designs the method, takes the decisions and answers for the conclusions. Every step is logged. Who we are →

What gets an entry accepted or refused?

An entry is accepted if a public source names the defense, if that defense falls under a single type, if we know who holds it, and if the state described carries its date. It is refused if, to be useful, it would have to say how to get around the defense. These rules were written before any counting. How we sort →

How do I cite AI-RISKPATH?

For the method and the negative result: Bardol, F. (2026). A Negative Result on State-Chaining over MITRE ATLAS. Zenodo. doi:10.5281/zenodo.22893444. The founding article will get its own identifier when it is published. For the site, give the date of the state: “AI-RISKPATH, as of 26 September 2026”.

Where are your data and code?

Already public: the method note and the dated commitments, deposited on Zenodo. On publication day: the list of defenses and the code of the trend calculation, in the public GitHub repository. The labelled vocabulary of our first tool stays private: the deposited commitments let anyone check any claim about it without disclosing it.

I want to contribute: how?

From publication day, through the public GitHub repository: propose a source, report an error, challenge an entry. Until then, write to contact@airiskpath.org.

A contribution is accepted if the defense is named in a public source. It is set aside if it describes a way to get around a defense.