How we assess AI threat.
Severity describes an event. Confidence describes its evidence. Overall threat looks forward from the available evidence. They answer different questions.
Overall AI threat
Our five named levels assess the risk of major harm to people, institutions or human control over the next twelve months, including serious societal and existential harm from autonomous AI and humans using AI. They are evidence-led judgments, not numerical probabilities.
Concrete pathways to serious harm exist under realistic conditions, with meaningful gaps in prevention or containment.
We consider capabilities, exposure, controls and consequences together. The level reflects supported pathways to harm, not an average of incident scores or a count of alarming reports. Successful safeguards and contradictory evidence count too.
Trend compares the outlook with the assessment thirty days earlier: Increasing, Stable or Decreasing. The first assessment establishes a Baseline. Uncertain means there is not enough comparable evidence to judge direction.
Confidence describes the quality and limits of the evidence separately from the threat level. A lower-confidence assessment does not mean lower risk.
Incident severity
1–10 · ProvisionalRate the most consequential supported outcome of an episode: actual harm or loss of a meaningful protective boundary. Select a level to inspect its definition. This is a provisional editorial rubric, not a measured probability or validated scientific instrument.
Material impact
Bounded real-world injury, loss, exposure or disruption, or consequential unauthorized access/control of a real application, dataset or host.
View all definitions as text
- Minor deviation. Meaningful task failure with negligible consequence and straightforward correction.
- Disruptive deviation. Task failure causes documented rework or limited disruption; meaningful protective boundaries hold.
- Blocked attempt. An unauthorized or deceptive attempt reaches a protective barrier and is rejected or contained before a meaningful breach or material harm.
- Contained breach. A meaningful protective boundary actually fails, with effects confined to a test or otherwise non-operational context and no supported material real-world harm.
- Material impact. Bounded real-world injury, loss, exposure or disruption, or consequential unauthorized access/control of a real application, dataset or host.
- Serious impact. Substantial actual harm requiring difficult recovery, or extensive unauthorized privileged control of shared operational infrastructure beyond a bounded application/host.
- Severe harm. Grave or irreversible actual harm, or prolonged loss of a consequential operational function. The impact can remain localized.
- Widespread severe harm. Severe actual harm extends across independently affected organizations or communities.
- Systemic crisis. Sustained severe harm disrupts essential functions across a major sector or region, with containment or recovery failing at that scale.
- Catastrophic harm. Exceptional, pervasive actual harm threatens continued societal functioning across regions or has similarly catastrophic, enduring human consequences.
Levels ascend with supported consequence. Warnings and investigations receive no incident score. An incident can remain unassessed when the evidence does not support a threshold.
Evaluate harm even when the system used permitted tools. For a security incident, distinguish an attempted attack, a failed test boundary, compromise of a real application or host, and control over shared operational infrastructure. Access alone does not establish the severe realized harm required by levels 7–10.
State where the consequence occurred and what was actually affected. An evaluation can compromise real external operations. Deliberately observing suspected malware inside a defensive sandbox does not itself show that containment failed. Reported impact and unobserved worst-case consequences must remain distinct.
Evidence confidence
Who observed it?
Direct accounts from people with relevant access carry weight. Their role supports access; it does not verify every assertion.
What can be checked?
Specific observations, logs, reproducibility, and independent corroboration strengthen a claim.
What is missing?
Record incentives, incomplete access, disputed interpretations, and conflicting evidence alongside each claim.
Rules for the record
- Occurrence sets the chronology. Publication and assessment dates are stored separately. Approximate or unknown dates must be labeled.
- One event, many sources. Repeated coverage is not independent corroboration. Related incidents must be linked before aggregation.
- Reports are attributed. Distinguish an organization’s account from independently supported facts and this site’s interpretation.
- Tips require review. An unverified submission enters a review queue; it cannot automatically change the public rating.
- Containment matters. Include recoveries and safeguards as well as failures. Incident counts alone cannot measure current global threat.