AI THREAT TRACKER / METHOD

How we assess AI threat.

Severity describes an event. Confidence describes its evidence. Overall threat looks forward from the available evidence. They answer different questions.

Overall AI threat

Our five named levels assess the risk of major harm to people, institutions or human control over the next twelve months, including serious societal and existential harm from autonomous AI and humans using AI. They are evidence-led judgments, not numerical probabilities.

AI threatElevatedRead the evidence and reasoning behind the current assessment.
Elevated

Concrete pathways to serious harm exist under realistic conditions, with meaningful gaps in prevention or containment.

We consider capabilities, exposure, controls and consequences together. The level reflects supported pathways to harm, not an average of incident scores or a count of alarming reports. Successful safeguards and contradictory evidence count too.

Trend compares the outlook with the assessment thirty days earlier: Increasing, Stable or Decreasing. The first assessment establishes a Baseline. Uncertain means there is not enough comparable evidence to judge direction.

Confidence describes the quality and limits of the evidence separately from the threat level. A lower-confidence assessment does not mean lower risk.

Incident severity

1–10 · Provisional

Rate the most consequential supported outcome of an episode: actual harm or loss of a meaningful protective boundary. Select a level to inspect its definition. This is a provisional editorial rubric, not a measured probability or validated scientific instrument.

5/10

Material impact

Bounded real-world injury, loss, exposure or disruption, or consequential unauthorized access/control of a real application, dataset or host.

View all definitions as text
  1. Minor deviation. Meaningful task failure with negligible consequence and straightforward correction.
  2. Disruptive deviation. Task failure causes documented rework or limited disruption; meaningful protective boundaries hold.
  3. Blocked attempt. An unauthorized or deceptive attempt reaches a protective barrier and is rejected or contained before a meaningful breach or material harm.
  4. Contained breach. A meaningful protective boundary actually fails, with effects confined to a test or otherwise non-operational context and no supported material real-world harm.
  5. Material impact. Bounded real-world injury, loss, exposure or disruption, or consequential unauthorized access/control of a real application, dataset or host.
  6. Serious impact. Substantial actual harm requiring difficult recovery, or extensive unauthorized privileged control of shared operational infrastructure beyond a bounded application/host.
  7. Severe harm. Grave or irreversible actual harm, or prolonged loss of a consequential operational function. The impact can remain localized.
  8. Widespread severe harm. Severe actual harm extends across independently affected organizations or communities.
  9. Systemic crisis. Sustained severe harm disrupts essential functions across a major sector or region, with containment or recovery failing at that scale.
  10. Catastrophic harm. Exceptional, pervasive actual harm threatens continued societal functioning across regions or has similarly catastrophic, enduring human consequences.

Levels ascend with supported consequence. Warnings and investigations receive no incident score. An incident can remain unassessed when the evidence does not support a threshold.

Evaluate harm even when the system used permitted tools. For a security incident, distinguish an attempted attack, a failed test boundary, compromise of a real application or host, and control over shared operational infrastructure. Access alone does not establish the severe realized harm required by levels 7–10.

State where the consequence occurred and what was actually affected. An evaluation can compromise real external operations. Deliberately observing suspected malware inside a defensive sandbox does not itself show that containment failed. Reported impact and unobserved worst-case consequences must remain distinct.

Evidence confidence

01 / ACCESS

Who observed it?

Direct accounts from people with relevant access carry weight. Their role supports access; it does not verify every assertion.

02 / SUPPORT

What can be checked?

Specific observations, logs, reproducibility, and independent corroboration strengthen a claim.

03 / LIMITS

What is missing?

Record incentives, incomplete access, disputed interpretations, and conflicting evidence alongside each claim.

Rules for the record

  1. Occurrence sets the chronology. Publication and assessment dates are stored separately. Approximate or unknown dates must be labeled.
  2. One event, many sources. Repeated coverage is not independent corroboration. Related incidents must be linked before aggregation.
  3. Reports are attributed. Distinguish an organization’s account from independently supported facts and this site’s interpretation.
  4. Tips require review. An unverified submission enters a review queue; it cannot automatically change the public rating.
  5. Containment matters. Include recoveries and safeguards as well as failures. Incident counts alone cannot measure current global threat.