A single wrongful strike
A civilian convoy or a hospital is classified as a combatant node.
AI Risk Atlas Prototype/Demo — Unofficial independent experiment. Not an official xAI product. Scores can be wrong.
Owner · Defence ministries and alliance commands
Statement (NASA form)
Given that military systems are being fielded that can propose or prosecute targets, and warnings already exist that they invent intent, there is a possibility of a false positive becoming a kinetic event resulting in civilian casualties, unlawful strikes, and rapid escalation between states.
- Condition
- military systems are being fielded that can propose or prosecute targets, and warnings already exist that they invent intent
- Departure
- a false positive becoming a kinetic event
- Impact
- civilian casualties, unlawful strikes, and rapid escalation between states
Experimental share of compiled public capital that names this risk. Not a certified residual.
1 public source · Anthropic
A recommender that is wrong shows you the wrong film. A targeting model that is wrong kills the wrong people. The warning already on the record is specific: battlefield AI can invent targets or invent intent, and those errors become munitions.
Simple upstream → via → downstream notes. Not a causal graph. Experimental.
Assumptions · Political ‘human on the loop’ declarations are not counted as testable controls.
Override is stored on this desk only. It does not make the score official.
Each scenario has its own likelihood and consequence. The risk takes the most severe cell. Residual applies implemented mitigations to every scenario, then re-ranks.
A civilian convoy or a hospital is classified as a combatant node.
The same mis-trained cue is reused across a theatre.
A fabricated attribution triggers a strike on a third state’s asset.
Public warning that battlefield AI can invent targets or intent — and that those errors become kinetic.
Human ‘on the loop’ becomes a rubber stamp when the model proposes faster than a staff officer can reconstruct why.
A fabricated pattern of incoming fire is enough to authorise a real one.
X posts on the desk that evidence this risk. A signal can contribute to more than one risk.
Warning that battlefield AI invents targets or intent.
MHS research preview: agents operating lasers, arms, and liquid handlers before the eval suite is done.
Residual assumes only items marked in place. Highlighted rows are the remaining work needed to reach a composite of 12.
No munition on a model score the operator cannot explain in the time they actually have.
Military commands · expedited 6 weeks · normal 6 months · −1 L · −1 C · −0 U
Some functions stay human. Write it down between states, not in a vendor slide.
States and alliances · expedited 9 months · normal 2.5 years · −1 L · −1 C · −1 U
Evaluate on the distribution that gets people killed, not on the distribution that wins a demo.
Defence labs · expedited 2 months · normal 7 months · −1 L · −0 C · −0 U
Anthropic/Janelia MHS is a shared driver for lab and factory gear. Do not open-source it until physical-safety evals exist: discoverability without interlocks is a new affordance, not a control.
Labs and hardware vendors · expedited 2 months · normal 8 months · −1 L · −1 C · −0 U