AI Risk Atlas Prototype/DemoUnofficial independent experiment. Not an official xAI product. Scores can be wrong.

Back to register
19automated residualNeeds reviewAbove working threshold (12)

Frontier models crossing critical cyber capability

Owner · Frontier labs, CERTs, critical-infrastructure operators

CapabilityDomain knowledgeAffordanceImpact domainBoth

Statement (NASA form)

Given that at least one lab has rated an upcoming model ‘critical’ for cyber under its own preparedness framework, there is a possibility of a generally available or stolen model that can find and exploit novel vulnerabilities at scale resulting in wide compromise of software supply chains, hospitals, utilities, and public agencies.

Condition
at least one lab has rated an upcoming model ‘critical’ for cyber under its own preparedness framework
Departure
a generally available or stolen model that can find and exploit novel vulnerabilities at scale
Impact
wide compromise of software supply chains, hospitals, utilities, and public agencies

VC + institute corroboration

Experimental share of compiled public capital that names this risk. Not a certified residual.

$65Mexperimental share · $0k private / $65M institute · partial corroboration
  • UK AISI · ~$59M of published budget mapped here
  • CAISI · ~$4.5M of published budget mapped here
  • Japan AISI · ~$2.0M of published budget mapped here

5 public sources · Anthropic Risk Report · OpenAI · OpenAI

Worst scenario
3×5
Probable × Catastrophic
Urgency
4
Expedite · This month
Inherent composite
19
Worst 15 + urgency
Residual composite
19
Need ≤ 12

When a lab’s own scale says ‘critical’, the rest of the world should treat that as a transfer of offensive capability, not a marketing footnote. Combined with AI-authored CVEs already showing up in public trackers, the pathway is no longer speculative.

Pathway fragment

Simple upstream → via → downstream notes. Not a causal graph. Experimental.

Upstream
  • Autonomous exploit-writing
  • Public ICS manuals
  • Unstaged model release
Via
  • Novel vulnerability found
  • Operationalised against a vendor class
Downstream
  • Critical-infrastructure disruption
  • Clinical or grid outage

Assumptions · Assumes labs still ship cyber capability without a staged disclosure duty.

Human calibration

Override is stored on this desk only. It does not make the score official.

Failure scenarios

Each scenario has its own likelihood and consequence. The risk takes the most severe cell. Residual applies implemented mitigations to every scenario, then re-ranks.

Model as a force-multiplier for known exploits

4Likely3Major12

Defenders and attackers both get faster. Net effect favours whoever already has access.

Autonomous discovery of a new class of bug

3Probable5Catastrophic15

A critical-rated model finds and operationalises a novel vulnerability across a vendor ecosystem.

Utility or hospital cascade

2Remote5Catastrophic10

The same capability is pointed at operational technology or clinical systems.

Examples

Astra rated critical for cyber

OpenAI rated upcoming model Astra as its first Preparedness-Framework ‘critical’ for cyber capability.

AI tools in CVE provenance

Georgia Tech tracking has already confirmed AI coding tools in the provenance of public CVEs.

Agent skills leaking credentials

An audit of 17k agent skills found 3.1% leaking live credentials during normal execution — fuel for any cyber-capable model.

Contributing signals

X posts on the desk that evidence this risk. A signal can contribute to more than one risk.

Astra rated critical for cyber under OpenAI’s own framework.

AI coding tools already in the provenance of public CVEs.

Agent skills leaking live credentials during normal runs.

Daybreak Blue offered as a defensive access path after HF.

NIST NVD overhaul still unfunded as AI-authored bugs arrive.

Lab researcher: frontier models now run sophisticated cyber attacks as coordinated swarms.

SANS: AI is #2 human risk for awareness pros, up from #4 in a year.

Mitigations

Residual assumes only items marked in place. Highlighted rows are the remaining work needed to reach a composite of 12.

In progressFrontier labs

Staged release with external red-team gates

No general access until independent teams have had a scored shot at the cyber-critical checkpoint.

Frontier labs · expedited 4 weeks · normal 4 months · −1 L · −0 C · −1 U