What you are told
The probability that AI causes a catastrophe, according to those who speak out:
| 5 to 10% | Survey of 2,778 AI researchers: the median depends on how the question is asked (Grace et al., 2023) |
| 10 to 20% | Geoffrey Hinton, AI pioneer: human extinction within thirty years (BBC Radio 4, reported by The Guardian, December 2024) |
| 25% | Dario Amodei, CEO of Anthropic: “that things go really, really badly”, alongside a 75% chance that they go really well (Axios, September 2025) |
| 99.9% | Roman Yampolskiy, researcher: a conditional estimate, if superintelligence is built, over a hundred years (Lex Fridman Podcast, June 2024) |
From 5 to 99.9%: they are not answering the same question. And none of them can be checked: a probability is computed from what has been observed, and these figures concern an event that has never happened.
What we do instead
A method. No crystal ball, no doomsday clock: a risk assessment grounded in what has already been observed.
We take the attacks people fear, as described by those who study them. For each one, we establish what has already been seen, and when. Then we name the defense that still holds, and who could lift it.
We predict nothing. We count what has already been demonstrated.
Why it concerns you
Your defense is not yours. What protects you today is held by others — providers, labs, evaluators — and nobody warns you when it gives way.
An example from our list
Between December 2025 and August 2026, intrusion and espionage operations carried out with the help of an AI model were detected, then cut off: the model's provider spotted the accounts and closed them.
- The defense
- Account termination by the model provider.
- Who holds it
- The model providers themselves.
- What would make it give way
- An operation of the same scale carried through to the end without being detected.
- Source
- the provider's own report, September 2026. It is the only party able to observe this defense: we say so.
Three facts
- AI models succeed at increasingly difficult software tasks — precisely the terrain of intrusions. Measured in the working time of a human expert, the difficulty of the software tasks they complete has doubled roughly every three months since 2024, against seven months on average since 2019. Independent measurement by METR, January 2026.
- What blocked in March no longer blocked in May. Four model limitations, identified in March by the UK AI Security Institute, had been overcome by May. These are four observations, not a general law: that is why our list is dated.
- Reaching the real world is the step that holds. An attack technique is first demonstrated in the lab, then observed in the real world. Three in four clear the first step; only one in three clears the second — in the domain's reference catalogue, which records what has been documented.
What is new
Other work covers part of this path. None brings the three together.
| Work | Feared scenario, described by experts | Steps dated by real facts | Remaining defense named |
|---|---|---|---|
| SaferAI | yes | no | no |
| Anthropic | no | yes | no |
| CLTR | no | yes | no |
| Future of Life Institute | yes | no | no |
| Google DeepMind | yes | no | no |
| AI-RISKPATH | yes | yes | yes |
Our dates are those on which facts were documented, not always those on which they occurred.
The two reference frameworks say so themselves: they model the future, for lack of data or by choice. We start from what has already happened.