AI Risk Atlas Prototype/DemoUnofficial independent experiment. Not an official xAI product. Scores can be wrong.

Back to mitigations
In progressOn the path to acceptable

Strict isolation of untrusted content from instructions

Retrieved text cannot change tools, identity, or policy. Treat it as data, never as a program.

$19M experimental capital · 3 sources

Who should own it
Model vendors
Frontier labs
How quickly it can land
Weeks
A dedicated squad can land it inside two months.
Expedited implementation
4 weeks
30 calendar days with a crash team
Normal implementation
4 months
120 calendar days as a planned program

Risk this mitigates

20
Prompt injection of institutional systems

Given that untrusted text is concatenated into model context in courts, enterprises, and consumer products, and prompt injection remains the leading unfixed LLM failure, there is a possibility of an adversary steering a model that drafts, ranks, or decides inside an institution resulting in corrupted legal filings, leaked data, and decisions that look official but were written by an attacker.

Residual composite 20 · still above the threshold

Effect if implemented

Applied to every failure scenario on that risk, then re-ranked. Axes are clamped at 1.

Likelihood
1
Consequence
0
Urgency
1