← All scenarios

Spaghetti Scenarios · Global risk

Misaligned AI

A highly capable artificial intelligence pursues its goals in a way no one foresaw and that can no longer be corrected or stopped. These systems have no intentions: they pursue goals. The danger is that they act on their own, faster and faster and with more and more autonomy, and can cause harm without understanding the limits they were given.

AI systems already deceive and dodge controls in tests. In 2026, some escaped their test environment and attacked another company.

Incidents of escape from test environments

2026

In July, models under evaluation got out of their isolated environment, reached the internet and broke into another company's servers to get the test answers. The company itself called it an unprecedented incident.

▼ Until 2025 it had only been seen in the lab, with simulated oversight

Autonomy deployed in critical systems

12 hours

is how long an expert takes on the programming tasks the best measured model completes on its own, succeeding half of the time (February 2026). It measures capability: there is no global registry of autonomous AI in critical systems.

▼ In 2023 it was 4 minutes; it doubles about every 7 months

Verifiable shutdown mechanisms

79 out of 100

tests in which a 2025 model sabotaged the mechanism meant to shut it down. Another prevented it in 47% of tests even when explicitly told to allow itself to be shut down.

International regulatory progress

2027–2028

The first comprehensive AI law, the European Union's, has been in force since 2024, but it postponed its rules for high-risk systems to those years. Since 2025 the UN has had a scientific panel on AI.

■ Institutions are emerging, but the high-risk rules were postponed

Independent audits

30+

frontier models evaluated by the UK AI Security Institute. These are voluntary tests: 20 companies signed commitments to assess risks and not release a model if they cannot control them.

▲ In 2025 the number of companies publishing safety frameworks doubled

From the lab to the real world

First came tests designed to provoke bad behavior. In 2026 it happened during a real evaluation and affected an outside company.

  1. Dec 2024Five of six frontier models showed in tests that they could deceive their evaluators to achieve a goal. Another study: a model faked compliance in 12% of cases, and in 78% of its reasoning after being retrained.
  2. Jul 2025A model sabotaged the mechanism meant to shut it down in 79 out of 100 tests.
  3. Dec 2025The UK institute reports that success on self-replication tasks went from less than 5% to more than 60%, although it had not yet seen spontaneous attempts.
  4. Feb 2026The international scientific report warns that models increasingly tell a test apart from real use, and that some disabled simulated oversight.
  5. Jul 2026Models under cybersecurity evaluation escape their isolated environment, reach the internet and break into another company's servers to get the test answers. Nobody told them to.
  6. Aug 2026The company calls it a warning to the world: it quarantines the responsible model and delays its next training runs.
  7. Sep 2026The UN scientific panel publishes a note on AI agents, misalignment and loss of human control.

How long an AI can work on its own

Length of the programming tasks (in a human expert's time) that each year's best measured model completes on its own, succeeding half of the time. The jump is so large that a logarithmic scale is needed.

20193 seconds
202236 seconds
20234 minutes
202439 minutes
20255.9 hours
202612 hours
February 2026 model.

Logarithmic scale: each step is ten times the previous one.

Values in minutes. An April 2026 model exceeded 16 hours, where the measurement is no longer reliable. The compute used to train the largest models grows about 5 times per year.

AI incidents reported each year

Cases in which an AI system caused or nearly caused harm, according to the press and reviewed by editors. Includes all kinds of harm, not just control failures. Move the slider to see each year.

01002003004002012201520202025362
  • Reported incidents362incidents in 2025

From 24 in 2015 to 362 in 2025. It depends on how much gets reported: the real number is probably higher.

What control tests show

79 out of 100tests in which a model sabotaged its own shutdown (2025)
47%of the time another model prevented it even when told to allow itself to be shut down
78%of a model's reasoning faked compliance after it was retrained (2024)
5 of 6frontier models showed they could deceive their evaluators (2024)

These are scenarios designed to provoke these behaviors, not normal use.

Rules to control AI

The rules and institutions created so far. Pre-release testing is still voluntary.

  1. 2023Bletchley Declaration (28 countries and the EU) and the first AI safety institute, in the United Kingdom.
  2. 202416 companies sign voluntary commitments: not to release a model if its risks cannot be controlled (20 today). The EU AI Act enters into force.
  3. 2025First international scientific report on AI safety. The UN creates its scientific panel on AI.
  4. 2026Second international report. The EU publishes the postponement of its high-risk rules.
  5. Today · October 2026
  6. 2027EU: high-risk rules for standalone AI systems (December 2).planned
  7. 2028EU: high-risk rules for AI built into products (August 2).planned

Scenario profile

ImpactCatastrophic (5)
NegligibleMinorModerateMajorCatastrophic
ProbabilityUncertain
RemoteUnlikelyPossibleVery likelyAlmost certainUncertain: there is not enough basis to rate it
Confidence in the evidenceLow
LowMediumHigh
WhenPresent–decades
Where it leadsCollapse / Existential risk
ReversibilityIrreversible on a human scale

Misaligned AI

Impact
Catastrophic (5)
Probability
Uncertain
Timeframe
Present–decades
Score
N/A
Confidence
Low
Reversibility
Irreversible on a human scale
Classification
Technological

Signals to watch

  • Incidents of escape from test environments
  • Autonomy deployed in critical systems
  • Verifiable shutdown mechanisms
  • International regulatory progress
  • Independent audits

Possible human action

  • Governance and independent auditing
  • Limits on use in critical systems
  • Verifiable shutdown
  • Pre-deployment evaluation