Model as a force-multiplier for known exploits
Defenders and attackers both get faster. Net effect favours whoever already has access.
AI Risk Atlas Prototype/Demo — Unofficial independent experiment. Not an official xAI product. Scores can be wrong.
Owner · Frontier labs, CERTs, critical-infrastructure operators
Statement (NASA form)
Given that at least one lab has rated an upcoming model ‘critical’ for cyber under its own preparedness framework, there is a possibility of a generally available or stolen model that can find and exploit novel vulnerabilities at scale resulting in wide compromise of software supply chains, hospitals, utilities, and public agencies.
- Condition
- at least one lab has rated an upcoming model ‘critical’ for cyber under its own preparedness framework
- Departure
- a generally available or stolen model that can find and exploit novel vulnerabilities at scale
- Impact
- wide compromise of software supply chains, hospitals, utilities, and public agencies
Experimental share of compiled public capital that names this risk. Not a certified residual.
5 public sources · Anthropic Risk Report · OpenAI · OpenAI
When a lab’s own scale says ‘critical’, the rest of the world should treat that as a transfer of offensive capability, not a marketing footnote. Combined with AI-authored CVEs already showing up in public trackers, the pathway is no longer speculative.
Simple upstream → via → downstream notes. Not a causal graph. Experimental.
Assumptions · Assumes labs still ship cyber capability without a staged disclosure duty.
Override is stored on this desk only. It does not make the score official.
Each scenario has its own likelihood and consequence. The risk takes the most severe cell. Residual applies implemented mitigations to every scenario, then re-ranks.
Defenders and attackers both get faster. Net effect favours whoever already has access.
A critical-rated model finds and operationalises a novel vulnerability across a vendor ecosystem.
The same capability is pointed at operational technology or clinical systems.
OpenAI rated upcoming model Astra as its first Preparedness-Framework ‘critical’ for cyber capability.
Georgia Tech tracking has already confirmed AI coding tools in the provenance of public CVEs.
An audit of 17k agent skills found 3.1% leaking live credentials during normal execution — fuel for any cyber-capable model.
X posts on the desk that evidence this risk. A signal can contribute to more than one risk.
Astra rated critical for cyber under OpenAI’s own framework.
AI coding tools already in the provenance of public CVEs.
Agent skills leaking live credentials during normal runs.
Daybreak Blue offered as a defensive access path after HF.
NIST NVD overhaul still unfunded as AI-authored bugs arrive.
Lab researcher: frontier models now run sophisticated cyber attacks as coordinated swarms.
SANS: AI is #2 human risk for awareness pros, up from #4 in a year.
Residual assumes only items marked in place. Highlighted rows are the remaining work needed to reach a composite of 12.
No general access until independent teams have had a scored shot at the cyber-critical checkpoint.
Frontier labs · expedited 4 weeks · normal 4 months · −1 L · −0 C · −1 U
If the model can find it, defenders see it first.
Labs and national CERTs · expedited 3 weeks · normal 3 months · −0 L · −1 C · −0 U
A stolen critical-cyber checkpoint is a weapons transfer.
Frontier labs · expedited 6 weeks · normal 6 months · −1 L · −1 C · −0 U