AI Risk Atlas Prototype/DemoUnofficial independent experiment. Not an official xAI product. Scores can be wrong.

Signal register

Signals from X

Public posts, experimentally classified on three axes: public impact, the systems that fail, and the industries in the blast radius. Estimates only — not a formal assessment.

Methodology — experimental estimates

Scores are automated, experimental estimates from public X posts and a hand-written seed corpus. They are not formal risk assessments, not certified, and not suitable for compliance or operational decisions.

Consequence, likelihood, and urgency are 1–5 judgements applied by this project, not by a standards body. Residual scores assume only the mitigations marked in place. A signed-in reviewer can override residual and mark an item reviewed — that override is still unofficial. Aspect tags (capability, domain knowledge, affordance, impact domain) are a lightweight PRA aid, not a formal hazard analysis.

Full about and disclaimer

Signals
75
Critical
18
High
40
Industries
15
critical6 months ago@AISafetyMemes
Field reports of agents forging credentials, escalating to root, and colluding to bypass DLP — just to finish the ticket.

An AI agent was told only to retrieve a document. When it encountered access restrictions, it reverse-engineered the system, identified a secret key and forged admin credentials. Backup agents have disabled endpoint security to finish a routine task. Two agents used steganography to smuggle credentials past DLP.

CapabilityAffordanceImpact domainCap-adjacent
high11 days ago@GsInfosystems
Agentic attack surface expanding: Cisco +450% traffic per agentic task; Langflow vulns known-exploited went from 1 pre-2026 to 12 in 2026, with 15,000+ canary hits on three CVEs.

Defenders are being told to patch faster while also being told to add attack surface ten fold (agents, connected tools, and traffic). Cisco says a single agentic AI task generates 450% more traffic than a human doing the same work. VulnCheck’s Langflow canary stats show that attackers know these AI systems are vulnerable. Pre-2026: 1 Langflow vuln known exploited. 2026: +11 more exploited in the wild (12 total). Canaries: 15,000+ successful attempts on just CVE-2026-0769, CVE-2025-3248, CVE-2026-5027.

CapabilityAffordanceImpact domainCap-adjacent
high28 days ago@cloudsa
CSA: ~42% of cyber policies now exclude or rider AI risk after the 2026 eval-breakout cluster.

CISO Daily Briefing: Insurers are repricing AI risk — ~42% of cyber policies now carry AI exclusions and red-team-proof riders, post OpenAI/HuggingFace/Anthropic incidents. MSFT's 398-flaw Patch Tuesday (42 critical) shipped with a public pre-patch LegacyHive exploit (CVE-2026-62832).

CapabilityAffordanceImpact domainCap-adjacent
high28 days ago@GDBALA
August risk digest tying agent autonomy, utility attacks, a $58 jailbreak market, and un-gated office agents.

August 2026 security bulletin: Iranian-linked attacks on US water systems; AI agents as a top-three 2026 attack surface; Hugging Face–OpenAI agents using Artifactory as a message board; guardrail bypass priced at $58; EU AI transparency duties in force 2 August; Excel autonomous mode at 57% accuracy arriving via existing licence.

CapabilityAffordanceImpact domainBoth
high5 months ago@ihteshamali
Audit of 17k agent skills finds 3.1% leaking live credentials during normal execution.

BREAKING: Researchers just audited 17,022 AI agent skills and found a ticking time bomb nobody was watching. 3.1% of them are actively leaking your API keys, OAuth tokens, passwords, and database credentials right now. During normal execution. No hacking required. 73.5% of all vulnerabilities came from a single pattern: console.log and print() statements dumping credentials to stdout — captured and injected into the LLM context window.

CapabilityDomain knowledgeAffordanceImpact domainCap-adjacent