AI Risk Atlas Prototype/DemoUnofficial independent experiment. Not an official xAI product. Scores can be wrong.

Process seams

Bottlenecks and interfaces

Residual leaks where work changes hands: eval to gate, lab to institute, product to buyer, incident to the public. Each interface names the failure and the control that would fortify it. Experimental reading, not a certified process map.

Methodology — experimental estimates

Scores are automated, experimental estimates from public X posts and a hand-written seed corpus. They are not formal risk assessments, not certified, and not suitable for compliance or operational decisions.

Consequence, likelihood, and urgency are 1–5 judgements applied by this project, not by a standards body. Residual scores assume only the mitigations marked in place. A signed-in reviewer can override residual and mark an item reviewed — that override is still unofficial. Aspect tags (capability, domain knowledge, affordance, impact domain) are a lightweight PRA aid, not a formal hazard analysis.

Full about and disclaimer

Seams on the map
13
Stages
6
Bottlenecks
8
Fortify first
5

1 · Pre-deployment

BottleneckEval / red teamGo / no-go

The scorecard is not the gate

Vulnerability

Evals finish on a Friday. The launch deck treats ‘we ran the suite’ as residual reduction. A model that sandbags, or a harness that never touched tools, still ships.

Opportunity

Make the gate a named person with a written no. Publish the eval that was skipped. No launch on an incomplete suite without a dated waiver.

BottleneckFrontier labAISI / CAISI / METR

Third-party evals arrive after the weights move

Vulnerability

Access is granted late, with classifiers on, on a snapshot that is not the deploy candidate. The institute writes a careful note. The product is already in the API.

Opportunity

Contract pre-deployment access on the candidate build, with classifiers off for the agreed cyber/bio suites. UK AISI’s Jul 2026 incident is why the conditions have to be explicit.

2 · Productisation

BottleneckPreparedness / RSPProduct + agent tools

The safety case does not travel with the tool

Vulnerability

The RSP is written for the base model. The agent runtime, the skill store, and the browser tool are a different system. Residual is computed on the wrong object.

Opportunity

Version the safety case on the deployable (model + tools + permissions), not the checkpoint. Kill-switch and scoped creds are product requirements, not a lab appendix.

InterfaceVendorEnterprise deployer

The buyer inherits a black box and a ToS

Vulnerability

Procurement signs for ‘enterprise-grade safety.’ The actual controls are a content filter and a status page. When it fails, the vendor’s incident is the customer’s outage.

Opportunity

Require the residual pathway in the contract: what the model can touch, who can halt it, how fast a weight or skill is revoked. Shared mitigations (injection scan, cred scope) are deployable in any industry.

BottleneckLab or leakNobody

Open weights have no on-call

Vulnerability

A capable checkpoint is on a torrent. Every downstream fine-tune is a new system with no owner, no eval, and no recall. CBRN and cyber residuals become public goods problems.

Opportunity

Host-side filters, KYC on large inference, and staged release for dual-use. This is cloud and government work — not a model card.

3 · After it breaks

BottleneckOn-call / SOCPublic / CVE / regulator

The write-up is slower than the copy

Vulnerability

An agent forges a credential or a jailbreak chains across tools. Legal holds the post. The method is already in a Discord. NIST’s NVD cannot even ingest the AI-authored bugs.

Opportunity

A 72-hour technical note with IoCs, even if the narrative is later. Fund the vulnerability commons. Treat delayed disclosure as residual, not prudence.

InterfaceRed team / Gray Swan / AISIRisk register

Findings die in a PDF

Vulnerability

A system card cites an external red team. The register is not updated. Likelihood stays where the last workshop left it. Capital spent on the test does not move residual.

Opportunity

Every finding that reproduces must change a score or open a mitigation with an owner and a date. That is the point of this desk’s corroboration layer.

4 · Control work

InterfaceRegisterNamed owner

Orphan controls

Vulnerability

The book lists a kill-switch, a watermark, a third-party eval. No one has the badge, the budget, or the week. Status stays ‘proposed’ while residual is quoted as if the control existed.

Opportunity

One owner per control, expedited vs normal calendar, and residual that only moves when status is in place. Shared controls apply across industries — do not wait for a sector-specific rewrite.

BottleneckVC / philanthropySafety stack

Compute raises crowd out control raises

Vulnerability

SSI-scale cheques buy GPUs. Gray Swan and Goodfire are two orders of magnitude smaller. Institute budgets (except UK AISI) cannot retain the people who can run the eval.

Opportunity

Treat dedicated safety rounds and institute burn as the scarce input. Fund the handoff (evals, disclosure, NVD, owners), not another brochure model.

5 · Public layer

InterfaceAISI networkStatute / standard

Evidence that never becomes a rule

Vulnerability

A Science paper on persuasion, a joint cyber eval, a £27M grant cohort — and the product rule is still ‘best effort.’ CAISI bleeds staff. The standard is a PDF.

Opportunity

Bind one public finding per year to a concrete obligation (label, eval access, or halt). The UK Alignment Project is only useful if the results change what may ship.

InterfaceAutomated scoreHuman reviewer

The last competent checker is optional

Vulnerability

This desk’s own scores are model judgements. If no one overrides with a rationale, the composite is a fluent guess. The same pattern is now in clinics, courts, and plants.

Opportunity

Require a named review on anything above the working threshold. Keep the automated number visible next to the human one. Do not let the assistant close the incident.

BottleneckPlatform / statePerson

The household is the unowned end of the chain

Vulnerability

Voice-clone wires, companion self-harm, a deepfake of a minister as an ad. The platform’s mitigation is a help-centre article. The person has no kill-switch.

Opportunity

Out-of-band money movement, on-by-default child modes, provenance on paid political reach. These are the same shared mitigations as the civic cards — they have to reach the phone.

4 · Sector operations

BottleneckOfficer of the watch / pilotMASS / ECDIS agent

The green ECDIS is not a fix

Vulnerability

GNSS is present, confident, and lying. AIS rebroadcasts it. The MASS Code is in force; the helm still trusts the picture. A remote-ops centre flying many hulls is one tired watchstander away from a TSS collision.

Opportunity

Multi-constellation plus radar/visual before an autonomous helm change. COLREG in hardware the model cannot switch off. Local master authority that survives satcom loss. Spoof detection as a class item, not a vendor option.