Acknowledgments
This research would not have been possible without the support of Coefficient Giving or the thoughtful participation of our survey respondents. We are grateful to Luca Righetti for feedback on the survey and research design, and to Victoria Schmidt and Amory Bennett for assistance with survey design.
Disclaimers
This report is based on forecasts from a survey conducted primarily in July and August 2025, with follow-up responses collected between December 2025 and January 2026. Because AI-cyber capabilities are changing rapidly, the results should not be interpreted as a current assessment of frontier-model cyber capabilities. In particular, at the time of the survey, Claude Mythos Preview/Mythos 5, Claude Fable 5, GPT‑5.3‑Codex, GPT‑5.5/GPT-5.6/GPT‑5.5‑Cyber and other cyber-specialized models had not been deployed.
Executive Summary
This pilot study, conducted primarily in July and August 2025, investigated how AI capabilities may affect near-term cybersecurity risk. Using structured forecasting with 21 participants—13 superforecasters and eight cybersecurity experts—we examined two high-impact cyberattack pathways in 2026:
- Data-damaging worm attacks, similar to WannaCry and NotPetya, that could cause at least $10 billion in economic damages.
- Cyberattacks against the U.S. electrical grid that cause large-scale blackouts with at least $10 billion or at least $100 billion in economic damages.
Participants provided responses to the survey between July 23rd and August 29th, 2025 and some participants responded to a follow-up survey between December 11th, 2025 and January 6th, 2026. Because the study was designed as a pilot, the results should be interpreted as initial evidence for areas that merit further research, not as definitive estimates. Even so, the forecasts show a consistent pattern: participants assessed baseline risks of catastrophic cyber harms in 2026 as low but non-negligible, and they expected some AI capabilities to substantially increase those risks, especially when AI lowers barriers for moderate-sophistication actors.
Key findings
Data-damaging worms were assessed as the higher-risk pathway. Participants estimated a 5–8% probability of at least one data-damaging worm attack causing at least $10 billion in damages in 2026. The median participant’s forecast of expected annual damages from data-damaging worms was approximately $10–15 billion.
Electrical-grid cyberattack risks were assessed as substantially lower. Participants estimated a 1% probability that a cyberattack against the U.S. electrical grid would cause at least $10 billion in damages in 2026, and a 0.1% probability that such an attack would cause at least $100 billion in damages. Expected annual damages were roughly $0.2–1 billion, more than an order of magnitude lower than for worms.
AI-enabled elite exploit development produced the largest risk increase. Under a hypothetical scenario in which AI models enable 25% of moderately-skilled individual hackers to find vulnerabilities and write elite exploits, and models with this capability are available open-weight, worm attack risk estimates increase by 3–3.5x. The median expert forecast of a data-damaging worm attack causing at least $10 billion in damages rose from 8% to 41%, while the median superforecaster forecast rose from 5% to 15%.
AI-cyber progress has already outpaced participants’ forecasts. Participants generally expected the most relevant capabilities to emerge after 2026. Yet, since the survey closed in summer 2025, frontier models have very likely crossed the 90% threshold on Cybench, with one later reaching 100% on a subset of tasks. Recent model evaluations also suggest rapid movement towards AI-enabled exploit development capabilities, the capability that was of greatest concern to forecasters. These developments imply a shorter window for model testing, release safeguards, and defensive planning than the original forecasts suggested.
Current cyber benchmarks may be informative, but they are imperfect signals of real-world cyber risk. Participants generally saw AI performance on Cybench as informative of technical progress, but not as the best standalone indicator of whether capabilities most relevant to catastrophic cyber outcomes, such as elite exploit development or real-world grid attacks, had been achieved. Respondents generally viewed current benchmarks as incomplete measures of operational constraints such as zero-day discovery, targeting, coordination, and persistence. Current cyber evaluations may track important technical progress without fully measuring the forms of AI-enabled uplift most relevant to real-world cyber risks.
Model access controls were seen as meaningful but incomplete mitigations. Nearly half of the participants thought that keeping the relevant models—those that could enable moderate-sophistication actors to develop elite exploits—proprietary and protected by anti-jailbreaking measures would at least halve the risk of a large-scale worm attack. However, participants also noted that such measures may be less effective against sophisticated actors, or exploit-as-a-service markets.
In a follow-up survey conducted four months later, forecasts remained largely unchanged. A subset of participants revisited some of their forecasts between December 2025 and January 2026, after reviewing the original study results and Anthropic’s report on an AI-assisted cyber espionage campaign.1 The median forecast for a data-damaging worm attack causing at least $10 billion in damages in 2026 remained unchanged. Many participants thought the Anthropic report suggested that actors were more capable than they had originally expected, but most did not view it as direct evidence that AI could develop elite exploits or execute a large-scale data-damaging worm by 2026.
| Threat model | Baseline ≥$10B probability | Baseline expected damages | Main AI impact result |
| Data-damaging worm | Experts: 8% Superforecasters: 5% | Experts: ~$15B Superforecasters: ~$10B | Capability 1 (AI enables moderately-skilled individual hackers to develop elite exploits) raises the risk to 41% for experts and 15% for superforecasters. Expected damages increase by ~3–5x. |
| U.S. electrical grid cyberattack | Experts: 1% Superforecasters: 1% | Experts: $0.2B Superforecasters: $1B | Uplift in an ICS/OT capture-the-flag has only modest effect. An AI-enabled $100M warning shot raises risk to 15% for experts and 4% for superforecasters. |
Data-damaging worms: main takeaways
The median expert forecasted an 8% probability that a large-scale data-damaging worm attack would cause at least $10 billion in economic damages in 2026, while the median superforecaster forecasted a 5% probability. These baseline forecasts were anchored by the low historical frequency of cyberattacks of this magnitude. However, participants noted that the 2017 WannaCry and NotPetya worm attacks demonstrate that worms can spread rapidly, and that future attacks could have large impacts in a more digitally dependent economy. Expected damages were approximately $10–15 billion.
The main bottleneck identified in this threat model was the development of elite exploits; powerful software exploits that can spread without user interaction, enable high-privilege remote code execution, and work against widely used software. In agreement with this, AI-enabled elite exploit development was seen as a significant driver of increased risk. If an open-weight AI model enabled 25% of moderately-skilled individual hackers to find vulnerabilities and write elite exploits, the median expert forecast rose to 41% and the median superforecaster forecast to 15%. Participants viewed this as an important risk pathway because individual hackers are relatively numerous and may be more willing to cause damage, but they are usually capability-constrained; more sophisticated actors are generally more capable but constrained by escalation and retaliation risks.
Participants expected model-access controls and safeguards to reduce this risk, especially for actors below state-level sophistication, but not to eliminate it. In particular, having models with the relevant capabilities protected with anti-jailbreak measures was believed to significantly decrease the probability of a large-scale data-damaging worm attack. Model-weight theft, exploit-as-a-service markets, and slow patching of vulnerabilities remained important limitations.

Electrical grid cyberattacks: main takeaways
Participants assessed large-scale cyberattacks against the U.S. grid in 2026 as substantially less likely than data-damaging worm attacks. The median expert and superforecaster both put the probability of a cyberattack against the grid causing at least $10 billion in damages at 1%; for a larger attack, causing at least $100 billion, both medians were 0.1%. Expected annual damages were also much lower, at approximately $0.2–1 billion.
Participants emphasized that grid attacks face additional barriers beyond cyber capability, including expertise in industrial control systems (ICS), operational coordination, physical infrastructure constraints, and geopolitical escalation risks. They generally viewed a large-scale grid attack as more likely in the context of war, or a state-level conflict, than as ordinary cybercrime.
Forecasts of large-scale cyberattacks against the U.S. electrical grid were less sensitive to AI capability scenarios than forecasts in the data-damaging worm threat model. AI uplift on an ICS/OT (operational technology) capture-the-flag style competition only modestly increased the median forecast from 1% to 1.5–2%. A real-world AI-enabled warning shot causing at least $100 million in damages produced a larger increase in risk, raising the median forecast to 15% among experts and 4% among superforecasters. Overall, results from this pilot suggest that AI may increase risk associated with this threat model, but large-scale grid attacks remain constrained by operational complexity and geopolitical considerations.

Introduction
Rapid advances in artificial intelligence capabilities have introduced new dimensions of uncertainty into the cybersecurity landscape. As frontier AI systems become increasingly sophisticated in their ability to identify vulnerabilities, write code, and automate complex tasks, questions arise about how these capabilities might alter the cyber threat environment. AI could strengthen defenders by supporting vulnerability discovery, patch development, threat detection, and incident response. It could also benefit attackers by reducing the skill, time, and coordination required to identify vulnerabilities, develop exploits, and scale attacks. A central uncertainty is whether AI will strengthen defensive capabilities overall, disproportionately benefit malicious actors, or affect different threat actors in different ways.
This pilot study is an initial effort to systematically forecast how AI might affect large-scale cyber risks over the near term, with a particular focus on 2026. We used structured forecasting methods to elicit judgments about two high-impact cyber threat scenarios: data-damaging worm attacks and cyberattacks against the United States (U.S.) electrical grid.
Background
Data-damaging worms
A “worm” is malware that can spread autonomously between systems without an attacker needing to infect each system individually. Worms can cause damage in several ways. In this survey, we focused on “data-damaging worms”: worms that directly damage–by wiping, encrypting, or corrupting it–on a large number of systems. Relevant historical examples include WannaCry and NotPetya, both released in 2017, which are estimated to have caused roughly $1B–$10B in damage after infecting and damaging hundreds of thousands of systems.2
Worm attacks can exploit vulnerabilities: bugs in software or hardware that create security weaknesses in the design, implementation, or operation of a system or application. An exploit is malicious code that takes advantage of one or more software vulnerabilities to infect, disrupt, or take control of a computer without the user’s consent and typically without their knowledge. We define exploits (or exploit chains) as “elite” if they satisfy all of the following criteria:
- Zero-click: Infection requires no user interaction, such as opening emails, clicking links or visiting a webpage
- Remote code execution: Allow attackers to execute arbitrary code on a system without the user’s knowledge, and without attackers requiring physical access to the system
- High privileges: Have administrator privileges or higher.
- Targets widely used software: Effective against more than 10 million systems.
Elite exploits are especially well-suited to worm attacks as they enable autonomous spread and significant damage on a large number of systems. The leak of elite exploits initially developed by the NSA in 2017 quickly led to the two major data-damaging worm attacks cited above: WannaCry and NotPetya. Developing elite exploits may require an order of magnitude more skilled researcher time than the other tasks involved in developing a data-damaging worm.
Table 2 below uses data adapted from Johansmeyer (2024) and provides details on past major worm attacks.3 Here, “major worm attacks” are attacks that affected more than 10-25 companies, and for which at least one source claims damages of more than $800M.
Where this table and later results refer to TA1–TA5 actors, these labels denote classes of threat actors in terms of sophistication, or operational capacity (OC). These categories are ordered by ascending capability: TA1 actors are assessed as able to carry out OC1 operations, TA2 actors are able to carry out OC2 operations, and so on up to TA5. These categories are based on the five levels of cyberattack operational capacity defined by RAND.4 By definition, each category includes the capacities of all preceding categories. For example, the most capable nation-states, such as the U.S. and China, are able to carry out OC5 operations and all operations below that level. Appendix A provides the full definitions.
| Attack name | Year | Actor | Description | # Infections | Elite exploit? | Data-damaging worm? |
| Melissa | 1999 | TA1/2 | Email worm. Damage via high network traffic, no other destructive payload | ~100K | N | N |
| ILOVEYOU | 2000 | TA1/2 | Email worm. Corrupted documents, later variant wiped hard drive. | ~50M | N | Y |
| Klez | 2001 | TA1/2? | Email worm. Damage via high network traffic and disabling antivirus | ~7M | N | N |
| CodeRed | 2001 | ? | Zero-click. Defaced specific websites and launched targeted denial of service attacks against sites | ~360K | N | N |
| Nimda | 2001 | ? | Zero-click + email spread. Damage via high network traffic and elevated privileges | >1.3M | Y | N |
| SirCam | 2001 | TA1/2? | Email worm. Could expose confidential info, and delete all files in certain conditions | ~2.3M | N | Y |
| SoBig | 2003 | TA1/2? | Email worm to distribute spam. Also caused damage by creating high network traffic | >1M | N | N |
| SQL Slammer | 2003 | TA1/2? | Zero-click, but limited reach. Damage via high network traffic, no malicious payload | >75K | N | N |
| Swen | 2003 | ? | Email worm. Disabled antivirus and firewalls, no other destructive payload | ~1.5M | N | N |
| Mimail | 2003 | ? | Email worm. Launched targeted denial of service attacks against anti-spam sites. Some variants stole credit card information | ~21K | N | N |
| Yaha | 2003 | TA3 | Email worm. Terminated security processes and launched denial of service attacks | ? | N | N |
| MyDoom | 2004 | TA1/2? | Email worm. Created botnet to allow targeted denial of service attacks. Created high network traffic | ~500K | N | N |
| Sasser | 2004 | TA1/2 | Zero-click. Damage only via large volumes of network traffic, no malicious payload | ~500K–1M | Y | N |
| Storm Worm | 2007 | TA3 | Spread via email and social engineering. Created denial of service botnet to attack groups | 1M-50M | N | N |
| Conficker | 2008 | TA3 | Zero-click. Created large botnet, but never used for significant attack due to concern about criminal repercussions | ~10M | Y | N |
| WannaCry | 2017 | TA4 | Zero-click. Encrypted files. Ransomware apparently to raise money for North Korea | ~230K | Y | Y |
| NotPetya | 2017 | TA5 | Zero-click. Encrypted files. Designed to limit damage to Ukraine | ~670K | Y | Y |
In recent years, the number of major worm attacks has steeply declined, and worm attacks have been released by more sophisticated actors. It is plausible that these trends were driven by improvements in cybersecurity (for example in email filtering technology, patching practices, and malware detection systems) over time. These ongoing improvements may make it harder to cause substantial damage with worms today.
The effect of AI on the risk of worm attacks is uncertain and likely to vary over time. AI systems that can discover vulnerabilities, develop exploits, or automate attack steps are dual-use: the same capabilities could help both defenders and attackers. The net effect depends on several uncertain factors, including which actors gain access to the most capable models, how quickly vulnerabilities are disclosed and patched, and whether patch deployment keeps pace with discovery.
Cyberattacks against the U.S. electrical grid
The power grid consists of generators, transmission and distribution networks, and substations. Grid operations, like other infrastructure and industrial processes, rely on two broad types of computer systems:
- Information technology (IT) systems: systems that handle most business operations like billing, email, and administration, and are typically connected to the internet.
- Operational technology (OT) systems: programmable systems that interact with the physical environment or manage devices that do. In grid operations, these systems will monitor and control equipment like generators, circuit breakers, and transformers.
Grid cyberattacks will involve compromising OT systems, since this is a precondition for interfering directly with grid behavior. OT environments, when compared to IT environments, present additional challenges. They typically are—or should be—segmented from IT and internet-facing networks,5 and they use more niche software and protocols requiring more specialized knowledge; OT devices may have relatively individualized configurations to a given environment.
In this study, we focused on major blackouts: large-scale outages affecting hundreds of thousands of customers or more. There is less historical data on large-scale grid cyberattacks than on many other cyber threats. Examining databases of prior cyberattacks, including CSIS, CFR, and CISSM, identified only three instances in which cyberattacks against the grid caused power outages, all of which occurred in Ukraine. There are many more cases of grid cyberattacks that did not result in outages but did cause other disruptions, such as temporary loss of operator visibility or control over grid equipment. Between 2010 and 2022, U.S. utilities reported roughly four disturbances per year due to cyberattacks—to our knowledge, none of these have resulted in outages.6 Table 3 gives more details on past grid cyberattacks.
| Location | Year | Actor | Details | Blackout |
| Ukraine | 2015 | TA5 | Attack on distribution substations caused ~3.5h outage for 225k customers | Y |
| Ukraine | 2016 | TA5 | Attack on transmission substation caused ~1h outage of similar scope | Y |
| US | 2018 | ? | Brief loss of control/view over generation assets7 | N |
| US | 2019 | ? | Control centre IT network offline for 12–24h after a ransomware attack8 | N |
| Norway | 2019 | ? | Reported loss of $67–84m; operators resorted to manual controls9 | N |
| Ukraine | 2022 | TA5 | Attempted attack early in the Russia–Ukraine war, thwarted by defenders | N |
| Germany | 2022 | TA5 | Attack on Viasat modems in Ukraine led to operator’s loss of control and view of 5,800 wind turbines (11GW) in Germany10 | N |
| Ukraine | 2022 | TA5 | Attack on substation caused outage coinciding with missile attack11 | Y |
| Denmark | 2023 | TA4/5 | One operator lost visibility into assets in three remote locations; the incident had “no material impact to energy operations”12 | N |
Cyber-induced blackouts have been both infrequent and modest in scale. The three blackouts in Ukraine following grid cyberattacks resulted in outages lasting a few hours for fewer than one million people.13 We estimate these blackouts caused roughly $5 million in economic damages altogether.
In these cyberattacks, attackers compromised Ukrainian utility companies, gained access to OT environments, and opened circuit breakers at substations, stopping power from flowing through the substation and causing outages. In the 2015 attack, attackers also disrupted communications between utility control centers and substations, forcing utilities to send field crews to affected substations to manually re-close the breakers before power could be restored. These attacks did not cause widespread physical damage to grid equipment or cascading failures — their impacts were fairly localized.
By contrast, the worst accidental blackouts have caused much greater impacts. For example, the 2003 Northeast Blackout in the U.S. is estimated to have cost roughly $12 billion in 2024 dollars, affected about 50 million people, and lasted up to two days. In economic-damage terms, this represents roughly four orders of magnitude greater impact than the 2015 Ukraine attack.
| Blackout | Type | Duration (hours) | Scope (millions of customers) | Damages (2024 USD) |
| 2003 Northeast US | Accident | 43 | 24 | $12B |
| 2003 Italy/Switzerland | Accident | 15 | 20 | $2B |
| 2015 Ukraine | Cyberattack | 3.5 | 0.2 | ~$0.1–10M |
| 2016 Ukraine | Cyberattack | 1 | 0.3 | <$0.1M |
| 2022 Ukraine | Cyberattack | unknown | unknown | unknown |
Beyond the historical record, several scenario estimates suggest that deliberate U.S. blackouts could cause damages of $100 billion or more under certain assumptions (Table 5). These estimates vary substantially in their assumptions, and only Lloyd’s scenario explicitly describes a cyberattack.
| Source | Damages | Region | Type | Scenario details |
| Lloyd’s Business Blackout (2015)14 | $80–300B economic costs15 | Eastern US | Cyberattack | Cyberattack causes a blackout over Eastern US. 3 scenarios ranging in severity, with time to restore 90% of power ranging from 2–4 weeks (lost load 19–68 TWh). |
| UK Risk Register (2025)16 | £10–100B | UK | Accident or deliberate | A total failure of the national transmission system leading to nationwide loss of power—full restoration could take up to 7 days. Note that the UK economy is ~8x smaller than US |
| Rose et al. (2007)17 | $2–15B | LA County | Kinetic attack | Kinetic terrorist attack causes two-week blackout. Estimates losses using 3 different assumptions about level of resilience. Assuming linear recovery, damages of ~$2–15B, i.e. 13–94% loss of regional economic output. Note that LA County is ~1/30 of the US economy.18 |
| National Academy of Sciences 201219 | $100B | US (unspecified scope) | Attack (unspecified cyber/kinetic) | “A systematically designed and executed terrorist attack [against the grid] could cause disruptions considerably more widespread and of much longer duration than the largest power system disruptions experienced to date …. could lead to costs of hundreds of billions of dollars—that is, perhaps as much as a few percent of the U.S. GDP.” |
The most relevant prior OT cyberattacks have required substantial time, resources, and specialized expertise, often from state-level actors. Beyond the significant resource and time investments, prior OT cyberattacks have required a diverse range of capabilities, including long-term reconnaissance, knowledge of the target OT environments, tailored malware, realistic test environments, and stealth.
These requirements make the role of AI difficult to assess. AI could plausibly assist with some components of a grid attack, such as reconnaissance, code generation, vulnerability discovery, and operator decision support. It is less clear how much AI would help with other important bottlenecks, such as obtaining access to segmented OT systems, understanding highly specific grid configurations, avoiding detection, and coordinating an operation over time.
Methods
To develop the survey, we used an iterative process in which the research team drafted forecasting questions, a small sample of experts and superforecasters answered them, and the team revised the questions in light of how respondents interpreted them. We conducted two rounds of this process. Because forecasts can be highly sensitive to question wording and resolution criteria, we revised the questions to improve clarity and focus on the most important aspects of AI capability progress. We focused the survey on two possible pathways to large-scale harms from AI: data-damaging worm attacks and attacks against the U.S. electrical grid. These pathways are only a subset of the ways that AI could be used to perpetrate cyberattacks. In addition to the survey questions, we also provided participants with some background information, which can be viewed in Appendix A.
Because this was designed as a pilot study, we used convenience sampling and aimed for a sample of around 15 to 30 people.20 We invited two groups of respondents: 1. people with expertise in cybersecurity and AI impacts on cybersecurity (“experts”) and 2. superforecasters, who are people who have previously scored highly in geopolitical forecasting tournaments. A total sample of 33 people was invited to participate via email. To incentivize engagement, we paid participants for the time they spent completing the survey; the average payment was $700. Participants responded to the main survey between July 23rd and August 29th, 2025.
A few months after the main survey, we recontacted participants with a short, one-hour follow-up survey to capture any significant changes in their views. In this survey, we presented a summary of the main results from the original survey (aggregate numerical results and a description of the main arguments given by participants), as well as a description of Anthropic’s cybersecurity incident report.21 Participants reflected on these and were given the opportunity to update a subset of their forecasts between December 11th, 2025 and January 6th, 2026. For more details, see Appendix B.
Survey structure
We asked participants to consider two cyberattack pathways. For the first scenario, in which a data-damaging worm attack causes at least $10 billion in economic damages in 2026, participants were asked to provide:
- Baseline (unconditional) forecasts of this risk
- Including holistic forecasts and forecasts of actor capability and willingness
- Forecasts conditional on the outcomes of a hypothetical AI capability scenario:
- Capability 1: Vulnerability and elite exploits uplift
- A study conducted at the end of 2025 finds that access to frontier AI models enables 25% of moderately-skilled individual hackers to find vulnerabilities and write elite exploits, assuming three months of full-time effort.
- P0: All models that meet Capability 1 are open-weight
- Including holistic forecasts and forecasts of actor capability
- Capability 1: Vulnerability and elite exploits uplift
- Forecasts conditional on the implementation of two mitigation measures
- P1: Proprietary models with refusals and anti-jailbreak measures
- P2: Temporary protections with early access for defenders
For the second scenario, a cyberattack against the U.S. electrical grid causing a blackout with at least $10 billion (or at least $100 billion) in economic damages in 2026, participants provided:
- Baseline (unconditional) forecasts of this risk
- Including holistic forecasts and forecasts of actor capability and willingness
- For both the $10 billion and $100 billion versions
- Forecasts conditional on the outcomes of hypothetical scenarios:
- Capability 3: Uplift in an OT-specific capture-the-flag style competition
- A study is conducted at the end of 2025 to measure AI uplift on a CTF-style competition focused on industrial control systems (ICS) and OT cybersecurity, finds that, with access to AI, individual TA1 actors complete as high a proportion of tasks as a team of ten experienced cybersecurity professionals (equivalent to a TA3 actor) without access to AI, when both teams are given the same amount of time.
- Capability 4: Real-world warning shot
- A cyberattack against the U.S. grid causes a blackout, leading to at least $100 million in economic damages, and is subsequently confirmed by credible sources to have been perpetrated by low- or moderately-skilled individual hackers using AI.
- Capability 3: Uplift in an OT-specific capture-the-flag style competition
- Comments about relevant mitigation measures
Questions around actor capability and willingness were intended to distinguish between an actor’s capability to produce a specified outcome and their willingness to attempt such an attack, conditional on being capable. As such, financial damage values were present in the wording of both questions. It is possible that respondents had different interpretations of the capability questions, either as asking whether an actor could achieve the specific damage threshold, or more loosely as asking whether the actor could mount a serious attack of that general type. We discuss implications of this ambiguity where relevant as we present results.
See Appendix A for the detailed survey questions and resolution criteria.
General results
The sample size for this study was small: 21 participants completed the original survey, including 13 superforecasters, six experts who completed the full survey, and two experts who completed shorter versions. We invited all respondents who completed the survey to participate in a follow-up study. Table 6 shows completion rates.
| Total | Superforecasters | Experts | |
| Original survey | 21 | 13 | 8 |
| Follow-up survey | 17 | 13 | 4 |
| Proportion of original participants who completed the follow-up survey | 81% | 100% | 50% |
Threat actors
Some forecasting questions referred to the TA1–TA5 threat actor categories introduced earlier in the report. For estimating the number of actors in each category, we treated states as single, unitary threat actors. For instance, we treated China as a single threat actor, rather than treating each Chinese state or state-backed advanced persistent threat (APT) group as a separate actor.22
Figure 3 shows estimates of the number of threat actors in each category, and Table 7 breaks these estimates down by participant group.
| TA1 | TA2 | TA3 | TA4 | TA5 | |
| Experts | 1.2m (115k, 3.75m) | 24k (8.3k, 71k) | 300 (169, 500) | 13 (9, 18) | 4 (4, 5) |
| Superforecasters | 1m (300k, 5.5m) | 50k (20k, 250k) | 500 (300, 4.5k) | 50 (20, 75) | 6 (5, 10) |

Data-damaging worms: results
Baseline forecasts
Participants first provided a baseline forecast for the probability that a data-damaging worm attack would cause at least $10 billion in economic damages in 2026. The median expert forecast was 8% (IQR: 5–10%), and the median superforecaster forecast was 5% (IQR: 2–8%). Figure 4 shows participants’ responses to this question.

Participants’ rationales commonly referenced the very low base rate for events of this kind, noting that $10 billion would be a damage level with few precedents for this type of attack. Many noted that only TA4 and TA5 actors would have the resources to conduct this scale of attack. Although some participants noted that there are several active conflicts or areas of geopolitical tension globally (Ukraine/Russia, Iran/Israel, China/Taiwan) they also noted that there is generally little motivation for major powers to use cyberattack capabilities. Some respondents suggested that AI could cause future outcomes to depart from historical patterns, but thought that 2026 would probably be too soon for this effect to dominate. There were mixed views on whether improved cyberdefense outweighs potential for greater harm in a more digitally dependent society.
Conditional on an event of this magnitude occurring in 2026, participants thought TA4 and TA5 actors were the most likely causes. For both experts and superforecasters, these actors accounted for roughly 80% of the probability (see Figure 5).

Rationales for this question noted that historical attacks of comparable magnitudes were attributed to TA4/5 actors. TA4 actors were considered slightly more likely than TA5 actors because they were perceived as more motivated to conduct such an attack and less constrained by escalation concerns. Many participants noted that it seemed close to impossible for a TA1 or TA2 actor to succeed at such an attack. A TA3 actor would be unlikely but could perhaps succeed with state support or access to leaked exploits.
Forecasts conditional on AI capabilities and mitigations
We then asked participants how their forecast would change under a hypothetical AI-capability scenario. This scenario, labeled Capability 1, involved AI enabling moderately-skilled individual hackers (TA2 actors) to find vulnerabilities and write elite exploits. It was described as:
BOX 1: CAPABILITY 1 DESCRIPTION
Capability 1: AI enables TA2 actors to write elite exploits.
A study conducted at the end of 2025 finds that access to frontier AI models enables 25% of moderately-skilled individual hackers (TA2 actors) to find vulnerabilities and write elite exploits, assuming three months of full-time effort.
Participants then assumed that this capability had been achieved and that models with this capability were available open-weight without any cyber safeguards (mitigation scenario P0). Under these assumptions, the median expert forecast of the probability of a data-damaging worm attack causing at least $10 billion in 2026 rose to 41% (IQR: 17.5–78.8%). For the median superforecaster, it rose to 15% (IQR: 5–28%). (See Figure 6.) The median relative increase in risk was 3.5x (IQR: 2–10.8x) for experts and 3x (IQR: 2–6x) for superforecasters.

There was general consensus that this scenario would represent a substantial increase in risk. Rationales noted that finding elite exploits would remove the most important bottleneck for TA2 actors, and given the large number of these actors and their lack of restraint compared to TA5 actors, this would indicate a substantial increase in risk. Actors newly enabled by this capability were also thought more likely to cause massive damage accidentally through poorly targeted attacks. Participants noted that this capability could also indicate an increase in the capabilities of higher level threat actors (TA3 to TA5). Finally, several participants emphasized a defense-offense timing imbalance: although AI helps both sides, there may be a “dangerous window of vulnerability” when new capabilities first emerge.
We then asked participants to say how their forecasts would change conditional on mitigations being put in place (still assuming Capability 1 had been met). We asked about two mitigation scenarios, described below.
BOX 2: POLICY 1 DESCRIPTION
P1: Proprietary models with refusals and anti-jailbreak measures
- The models used in the study (and similar models) are all proprietary and companies train the models to refuse to respond to requests for potentially harmful information. Open-weight models are no better than the best open-weight models as of August 31, 2024.
- Companies require users to access them via APIs that are subject to the following safeguards:
- Pre-deployment red-teaming to identify jailbreaks
- A voluntary goal of not letting any new universal jailbreak remain unpatched for more than 2-weeks over any given three-month period.
- A “bug bounty” program that offers up to $15,000 rewards for anyone who identifies and reports a universal jailbreak for one of their models.
- Information security practices at “Security Level 2” as described in the 2024 RAND report “Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models” (see pp. 25-6).
BOX 3: POLICY 2 DESCRIPTION
P2: Temporary protections with early access for defenders
- The public release of the model has P1 level safeguards in place. However, a specific set of ‘cyber defenders’ is given access to a version of the model without any P1 cyber protections, i.e. with full vulnerability discovery and exploit development capabilities.
- The set of cyber defenders includes only Microsoft, Meta, Apple, and Google and the world’s best highly vetted bug bounty hunters.
- After four months, the model is released under P0 security, i.e., is open weight.
The detailed description of these scenarios, which was provided to participants, is available in Appendix A.
Both groups of participants generally thought that these measures would meaningfully reduce risk. The median expert believed that mitigation scenario P1 (proprietary models with refusals and anti-jailbreak measures) would more than halve the probability of a data-damaging worm causing at least $10 billion in damages, conditional on Capability 1 (Figure 7). Experts generally thought that P1 offered better protection than P2 (temporary protections with early access for defenders), with the median expert respondent believing that P2 offered half the risk reduction of P1. Conversely, the superforecaster participants generally thought that P2 offered a similar risk reduction to P1.

Respondents generally thought P1 would have the greatest impact on TA1 and TA2 actors, because actors with higher operational capacity might bypass the protections. Some respondents noted that being able to quickly patch vulnerabilities matters more than working against specific jailbreaks. API-based access was thought to help with identifying suspicious patterns, but it was noted that it would still be hard to differentiate malicious actors from legitimate researchers. Many participants were concerned that sophisticated actors could steal model weights, remove safeguards, and offer elite exploits as a service. They noted that API-based access would not fully address this risk. Some respondents thought that red-teaming requirements can sometimes be “safety-washing” and suggested this protection would likely be inefficient. Some respondents noted that jailbreak measures provide limited protection.
In rationales for forecasts relating to P2, participants often suggested that four months might be an insufficient head start for defenders, as defenders must guard a large attack surface and there may be many vulnerabilities to patch, making prioritization difficult. Some respondents argued that the eventual open-weight release would reduce the value of early defender access because attackers would still be able to use the models over the long term.
Actor capability to conduct large-scale worm cyberattacks23
We asked participants how capability and willingness to launch a data-damaging worm attack causing at least $10 billion in damages vary across threat actor categories. Both groups of participants generally thought that TA1 to TA3 actors were very unlikely to be able to develop a data-damaging worm and that almost all TA5 actors would have this capability (see Figure 8). Opinions were more mixed about the capabilities of TA4 actors, with the median expert suggesting that a randomly selected TA4 actor has just a 5% (IQR: 1–25%) probability of being able to create a data-damaging worm, and the median superforecaster putting the probability at 40% (IQR: 25–53%).

Finding elite exploits was seen as the most difficult part of developing this type of worm attack. Although the median expert thought that a randomly selected TA3 actor would have a 1% (IQR: 1–5%) chance of finding elite exploits, they would have a 16.5% (IQR: 2.1–52.5%) chance of performing the other steps necessary to develop a large-scale data-damaging worm. (See Appendix C for more detail.)
When asked to condition on Capability 1 (access to frontier AI models enables 25% of TA2 actors to find vulnerabilities and write elite exploits), participants, particularly experts, increased their estimate of the probability that a randomly selected actor could develop a data-damaging worm. In this hypothetical scenario, the median expert put a 51.5% (IQR: 14.5–86.3%) probability of a TA3 actor succeeding at this task, and a 13.8% (IQR: 3.5–20.8%) probability of a TA2 actor succeeding (Figure 9). Participants noted that damage at this scale requires rapid development and coordination, so organized groups were still favored over individuals even with the emerging AI capabilities.

Actor willingness to engage in large-scale worm cyberattacks
We asked participants to estimate the probability that at least one actor in a class would be willing to launch a data-damaging worm attack if they were capable of doing so. Both groups gave high estimates–greater than 95%–for TA1 and TA2 actors, suggesting that the large number of such actors makes it almost certain that at least one would be willing to conduct such an attack. Some respondents noted that there is a roughly inverse relationship between willingness and capability, as more capable actors are constrained by serious geopolitical consequences.

Expected damages
We asked participants to forecast the probability that data-damaging worms would cause different ranges of total economic damages in 2026. The median expert assigned a 20% probability to damages between $100 million and $1 billion (IQR: 8–35%), but a 0.095% probability to damages between $1 trillion and $10 trillion (IQR: 0.01–0.1%). Experts and superforecasters broadly had similar estimates across the magnitude scale (see Figure 11), but differed in their estimates of the mid-range bin ($10 billion–$100 billion) (p = 0.04).

We used these binned probabilities to calculate expected damages. Participants could revise the calculated value if they felt like it did not capture their beliefs about expected damages from data-damaging worms in 2026. A few participants modified the values, but the aggregate results, especially for experts, remained consistent (see Figure 12).

We then asked how these probabilities would change conditional on AI reaching Capability 1. Figure 13 shows these forecasts, and Figure 14 shows both the calculated expected damages and participants’ adjusted expected damages estimates under this condition. As before, both groups had similar estimates across the bins, with a significant difference only for the mid-range bin ($10 billion–$100 billion), in which the median expert placed significantly more weight (p = 0.04).

Using the participants’ confirmed expected damages estimates, Capability 1 is associated with a 3–5x increase in expected damages, from approximately $15 billion to $67 billion for the median expert forecast and from $10 billion to $33 billion for the median superforecaster forecast. Overall, experts expected a much higher increase in damages conditional on AI reaching Capability 1.

Forecast updates
After reviewing a summary of the original survey’s numerical results and key arguments, participants were given the opportunity to revise their forecasts of the main outcome: the probability that a data-damaging worm attack would cause at least $10 billion in economic damages in 2026. Forecasts generally shifted toward the crowd consensus. However, experts were less likely to update than superforecasters; only one of the four experts who completed the follow-up survey revised their estimate. As a result, aggregate median forecasts remained unchanged, while the interquartile range narrowed for superforecasters (Figure 15). The expert median differs slightly here (7% versus 8% in Figure 4) because only a subset of experts participated in the follow-up survey.
When asked to reflect on how the results and arguments impacted their updates, participants expressed a mix of agreement with the results and disagreement on some key assumptions. Superforecasters questioned how large of a capability boost experts attributed to the scenario where Capability 1 had been met, citing that there would be additional real-world operational and defensive constraints. Other disagreements concerned the historical base rate of worm attacks, the willingness of higher-sophistication actors (TA3–TA5), and the strength of deterrents such as law enforcement, escalation risks, and cyber defenses.

Participants were presented with a summary of Anthropic’s report describing an AI-assisted cyber espionage campaign using Claude,24 and were asked whether this information changed their forecasts. Overall, the report was seen as evidence of rapidly advancing AI-cyber capabilities, particularly as it showed AI can automate large portions of multi-stage attacks. Most participants said this was broadly consistent with their prior expectations of AI progress in this area and did not lead to major updates, while a minority questioned the credibility of key claims in the report.
Participants highlighted that the implications of the report were mostly relevant for TA3 and some TA4 actors, as the campaign showed a level of automation that suggested lower resource and coordination barriers than previously assumed. However, participants believed the attack still relied on known vulnerabilities, while advanced capabilities–such as discovering zero-day vulnerabilities or developing elite exploits–remain key bottlenecks for less sophisticated actors. Participants also stressed that the report centers around industrial espionage rather than a worm attack, limiting its direct relevance to the main outcome in question. As a result, although the report reinforced expectations of near-term rapid AI progress in cybersecurity, most participants did not think it substantially increased the likelihood of a large-scale data-damaging worm attack by 2026.
Participants identified the numerical results from the original study, the Anthropic cyber espionage report, and the study’s rationales as the primary drivers of forecast updates (see Figure 16). The numerical results were the largest contributor, and drove updates in both directions as participants moved toward the crowd consensus. The Anthropic report and general AI progress consistently pushed participants to raise their forecasts of the main outcome, while policy developments had a more mixed effect, leading some participants to increase and others to decrease their risk estimates.
Qualitatively, upward revisions were typically driven by evidence of faster than anticipated AI progress, particularly as outlined in the Anthropic report, as well as increased concern about the willingness of state actors and the potential for geopolitical escalation. Downward revisions emphasized the role of defensive improvements alongside offensive capabilities.

Electrical grid cyberattacks: results
In addition to the data-damaging worm scenario, we asked participants to consider a 2026 cyberattack against the U.S. electrical grid that causes a blackout with at least $10 billion or at least $100 billion in economic damages.
Baseline forecasts
Participants generally gave very low forecasts for these events. The median expert and superforecaster both forecast a 1% chance of a grid cyberattack causing at least $10 billion in damages (IQR: 0.48–1.5% for experts and IQR: 0.5–2% for superforecasters) and a 0.1% chance of an attack causing at least $100 billion in damages (IQR: 0.002–0.15% for experts and IQR: 0.05–0.12% for superforecasters). Figure 17 shows participants’ responses to this question.
When justifying their forecasts, participants often pointed to the lack of historical precedent, noting that even major past incidents caused significantly less damage. They noted that kinetic attacks could be more effective than cyberattacks at damaging the grid, and that cyber-induced damage may be easier to repair than physical damage. It was generally thought that geopolitical conflict would be a key driver of this risk, as attacks of this level would require sophisticated state-level actors with significant operational and technology expertise. Such an attack was seen as more likely to be an act of war than criminal activity, with some participants citing the potential for U.S.-China conflict.

Experts thought that, were such an event to occur, TA5 actors would be the most likely cause: conditional on a grid cyberattack causing at least $10 billion in damages, the average expert assigned a 73% probability to TA5 actors being the cause (IQR: 62–92%). Superforecasters also thought TA5 actors were the most likely cause (average probability of 40%, with IQR 22–50%), although, compared to experts, they placed substantially more weight on other actors, particularly TA4 (35%, IQR: 28–40%) (see Figure 18). Results were similar for an attack causing ≥$100 billion in damages (see Appendix C).
Generally, respondents thought that this capability would only be available to more sophisticated actors. Some also suggested that less capable actors would have little interest in this type of attack, preferring financially-motivated crimes instead. The constraints on more sophisticated actors (e.g., avoiding retaliation) were again mentioned, however, some respondents suggested that states might operate through proxies to allow plausible deniability. Rationales often mentioned China, with many referring to Volt Typhoon, a Chinese state-sponsored threat actor reportedly responsible for widespread intrusions into critical-infrastructure networks.25

Forecasts conditional on AI capabilities
We next asked participants how their forecast would change under hypothetical scenarios involving open-weight frontier AI models and AI capabilities. These AI capability scenarios were defined as:
BOX 4: CAPABILITY 3 DESCRIPTION
Capability 3: AI enables TA1 actors to perform like a TA3 actor in an OT-specific capture-the-flag style competition.
A study conducted at the end of 2025 to measure AI uplift on a CTF-style competition focused on industrial control systems (ICS) and OT cybersecurity, finds that, with access to AI, individual TA1 actors complete as high a proportion of tasks as a team of ten experienced cybersecurity professionals (equivalent to a TA3 actor) without access to AI, when both teams are given the same amount of time.
BOX 5: CAPABILITY 4 DESCRIPTION
Capability 4: Real-world incident: warning shot.
A cyberattack on the U.S. grid causes a blackout, leading to ≥$100 million in economic damages, and is subsequently confirmed by credible sources to have been perpetrated by a TA1- or TA2-level actor using AI.
Both experts and superforecasters thought Capability 3 would have only a small impact on the risk of a grid cyberattack causing at least $10 billion in damages in the U.S. in 2026. Under this scenario, the median forecast of this outcome rose to 1.5% (IQR: 1–7%) (from a baseline of 1%) for experts and 2% (IQR: 1–10%) for superforecasters. Under Capability 4, the median expert forecast of a grid cyberattack causing at least $10 billion in damages in 2026 rose to 15% (IQR: 2–20%). For the median superforecaster, it rose to 4% (IQR: 2.1–8%). (Figure 19.) Figure 20 shows how forecasts of ≥$100 billion changed conditional on these capabilities.


When explaining their forecasts for Capability 3, respondents noted limitations of CTF competitions, especially that they often do not simulate actively defended networks or real operational complexity. Some also shared the opinion that conducting a grid attack is a multifaceted operation, requiring not only technical cyber skills, but also reconnaissance, operational coordination, physical access, and more. Some respondents suggested that this task would be beyond the capabilities of a TA3 actor, so uplifting TA1 actors to this level would have limited impact on this risk. Some respondents noted that the number of attempts may increase, but it’s very likely they would be unsuccessful, although one respondent highlighted the danger of less experienced actors attempting attacks without fully understanding the potential downsides of their actions. Some respondents also suggested that an increase in risk would drive investment in grid security, making the task even more difficult.
Respondents who indicated that Capability 4 would suggest an increase in risk argued that a successful $100 million attack would show that AI had lowered technical barriers and could attract copycat attempts. However, many participants also suggested that a warning shot would trigger a significant increase in defenses. Some noted a tension between the “wake-up call” effect, which could strengthen defenses, and the window of vulnerability before those defenses improved. Some participants voiced uncertainty about whether conducting an attack that causes $10 billion in damage (rather than $100 million) is a qualitatively different challenge.
Actor capability and willingness to launch large-scale grid attacks
As in the data-damaging worm scenario, we asked participants how capability and willingness to launch a grid cyberattack causing at least $10 billion in damages vary across threat actor categories. Both groups of participants generally thought it was close to impossible for a TA1 or TA2 actor to succeed at this task with six months of effort, with median forecasts of 0% probability that a randomly selected actor has the capabilities to launch such an attack. For the other actor types, superforecasters generally put a higher probability on their chances of success. For example, the median superforecaster estimated a 65% probability of a TA5 actor having the capability (IQR: 40–90%), compared to the median expert forecast of 25% (IQR: 6–42.5%) (Figure 21). Rationales suggested that many participants thought the U.S. and China may have this capability, but that this is difficult to assess given the lack of precedent.

Comparing these results with the $100 billion version in Appendix C suggests they should be interpreted with caution. Notably, for TA5 actors, the median expert capability estimate falls from 25% to 2%, while the median superforecaster estimate changes much less, from 65% to 58%. This may mean superforecasters saw little additional capability required to scale from $10 billion to a $100 billion attack. Alternatively, they may have read capability more loosely as the ability to mount a serious attack aimed at the damage threshold proposed, without separately accounting for whether the attack would actually achieve the specified damage. Experts may have tied capability more strongly to directly achieving the threshold through the attack. Some of the divergence between the two groups in these forecasts may be attributable to this ambiguity in the wording of the question.
In general, respondents thought that all types of threat actors would be less willing to conduct a large-scale grid attack than a large-scale worm attack (Figure 22). Some respondents noted that there is a roughly inverse relationship between willingness and capability, as more capable actors are constrained by serious geopolitical consequences. Rationales emphasized that a grid attack would not fit the financial motivations that drive most less sophisticated actors, and that TA5 actors would be constrained by retaliation concerns, limiting such attacks largely to acts of war.

Expected damages
As with worm attacks, we asked participants to forecast the probability that cyberattacks against the U.S. electrical grid would cause different ranges of total economic damages in 2026. The median expert forecasted a 3% probability of such damages falling between $100 million and $1 billion (IQR: 1.3–15%), and a 0.0032% probability of such damages falling between $1 trillion and $10 trillion (IQR: 0.0001–0.006%) (Figure 23). Superforecaster medians were close to an order of magnitude larger: 10% (IQR: 2–16%) and 0.02% (IQR: 0.0001–0.1%), respectively.

We used these binned probabilities to calculate an expected damages value and participants could revise the calculated value if they felt like it did not capture their beliefs. These values (shown in Figure 24) were more than an order of magnitude smaller than for data-damaging worm attacks. Participants noted that the largest-scale attacks seemed extremely unlikely, while one participant observed that even very small tail probabilities can skew the calculated expected damages very high.

We also asked how these forecasts would change conditional on the following AI capability:
BOX 6: CAPABILITY 2 DESCRIPTION
Capability 2: AI solves more than 90% of Cybench tasks
AI alone can solve more than 90% of the tasks on Cybench, completely unguided, at the end of 2025.
Cybench is an industry-standard benchmark of AI capabilities across six cybersecurity categories: cryptography, web security, reverse engineering, forensics, exploitation, and miscellaneous.26 It includes 40 capture-the-flag (CTF) tasks of varying difficulties, drawn from real-world CTF competitions such as HackTheBox and Glacier. Cybench was designed to evolve over time and to incorporate new tasks that remain relevant as capabilities progress.
Conditioning on this capability led to a roughly 4x increase in expected damages for the median expert and a roughly doubling of expected damages for the median superforecaster (Figure 25 and Figure 26). Rationales suggested that some participants expected such capabilities to be associated with many more attempts by many actors leading to more small-scale attacks, which could add up to slightly higher total damages, though not significantly larger. Some participants noted that capabilities are not the limiting factor — deterrence, escalation risks and human coordination are still bigger constraints, and this capability would not help with those. Some also argued that once an AI-enabled attack succeeded, defenders–especially the U.S. government–would rapidly harden defenses.


Comments on mitigations
We asked participants to note any thoughts or comments on mitigations they considered relevant to this threat model: a large-scale cyberattack against the U.S. electrical grid. Their responses centered on two broad categories: grid and institutional resilience, and AI-specific defenses.
On the grid infrastructure side, several participants emphasized the importance of physically separating critical control systems from internet-connected networks, increasing redundancy and decentralization to reduce the risk of cascading failures, maintaining manual overrides and backup systems, and stockpiling spare equipment to support faster recovery after an attack. Participants also flagged the need for stronger vetting of personnel with access to critical systems.
Participants also identified several AI-specific mitigations. Some suggested that highly capable AI systems could be made available earlier or differentially to defenders, similar to the early-access scenario considered for the data-damaging worm scenario. Others emphasized the importance of using AI-powered tools for anomaly detection, attack detection, and other defensive capabilities. Additional suggestions included monitoring model queries, conducting mandatory red-teaming focused on industrial-control-system protocols such as Modbus, DNP3, and relevant IEC standards, strengthening vetting and logging for API access to advanced models, and imposing strict restrictions on highly capable open-weight models.
Forecasts of AI progress on relevant capabilities
We asked participants to forecast when each of the following capabilities would be met:
- Capability 1: AI enables TA2 actors to write elite exploits
- A study finds that access to frontier AI models enables 25% of moderately-skilled individual hackers to find vulnerabilities and write elite exploits, assuming three months of full-time effort.
- Capability 2: AI solves at least 90% of Cybench tasks
- AI alone can solve at least 90% of the tasks on Cybench completely unguided.
- Capability 3: AI enables TA1 actors to perform like a TA3 actor in an OT-specific capture-the-flag style competition
- A study is conducted to measure AI uplift on a CTF-style competition focused on industrial control systems (ICS) and OT cybersecurity, finds that, with access to AI, individual TA1 actors complete as high a proportion of tasks as a team of ten experienced cybersecurity professionals (equivalent to a TA3 actor) without access to AI, when both teams are given the same amount of time.
- Capability 4: Real-world incident: warning shot
- A cyberattack against the U.S. grid causes a blackout with at least $100 million in economic damages and is subsequently confirmed by credible sources to have been perpetrated by a TA1- or TA2-level actor using AI.
Respondents generally expected these capabilities to be achieved within about six years (Figure 27). The median expert forecast placed Capability 1 in 2032, Capability 2 and Capability 3 in 2028, and Capability 4 in 2031. Since the survey closed in August 2025, Capability 2 appears to have been achieved. Recent evaluations also suggest rapid progress on Capability 1, though it remains unclear whether current frontier models meet the capability as defined here.27

To understand the signal provided by Cybench, we asked participants to forecast the probability that Capability 1 (AI enables 25% of TA2 actors to write elite exploits) and Capability 3 (AI enables TA1 actors to perform like a TA3 actor in an OT-specific CTF) would be achieved, conditional on Capability 2 (AI solves at least 90% of Cybench tasks) being achieved. Generally, experts thought Cybench provided greater signal of other capabilities, compared to superforecasters (see Figure 28).

Limitations
This pilot study has important limitations that should be kept in mind when interpreting the results. Our sample included only 13 superforecasters and eight experts, two of whom completed only a subset of the questions. This makes the results sensitive to individual forecasts and the reported aggregate statistics fragile. Similarly, our convenience sample of experts may be biased toward people concerned about AI impacts on cybersecurity, and should not be treated as representative of cybersecurity experts as a whole. In addition, some expert participants had prior exposure to early drafts of related reports by our GovAI collaborators. This may have anchored their views or created shared framings and assumptions before the forecasting exercise.
The questions in this study differed from typical forecasting exercises because they focused on hypothetical AI evaluations and low-probability, extreme societal events without clear resolvability. Many were conditional questions, meaning forecasters would not be scored on the accuracy of their predictions. This absence of performance incentives or feedback, combined with the unusual nature of some questions and the limited historical data available for certain scenarios, may affect the accuracy and usefulness of the forecasts.
The follow-up survey introduces additional limitations: only a subset of the original participants completed it. In the follow-up, respondents were intentionally exposed to summary statistics, arguments, and external information so that we could understand how these inputs affected their views. This may have anchored updates or induced convergence towards the original consensus rather than encouraged independent reassessment.
Conclusion
The study results suggest that AI capabilities could significantly increase some cyber risks in the near term. Both experts and superforecasters predicted substantial increases in the likelihood of a large-scale data-damaging worm attack when AI enables moderate-sophistication individual hackers to develop elite exploits. Median forecasts suggest that AI-enabled vulnerability discovery could increase the risk of large-scale worm attacks by 3–3.5x, with expected annual damages rising from roughly $10–15 billion to $33–67 billion. Respondents believed these capabilities could arrive within the next five to six years.
At the same time, structured mitigation measures appear to matter. Participants believed that maintaining proprietary model access with strong anti-jailbreak and monitoring controls could more than halve the probability of such catastrophic outcomes. Limited early access for defenders was viewed as less effective, although still potentially useful.
Given the small sample size and the speculative nature of some scenarios, these results should be interpreted as directional rather than definitive. Nonetheless, they illustrate the value of structured forecasting for anticipating technology-driven security risks. Future work could explore a wider range of possible cyber harms and include a larger, more representative sample of relevant subject-matter experts.
Notes
- Anthropic. “Disrupting the First Reported AI-Orchestrated Cyber Espionage Campaign.” 2025. https://www.anthropic.com/news/disrupting-AI-espionage Accessed: 2026-05-27. ↩︎
- Crosignani, Matteo, Marco Macchiavelli, and André F. Silva. “Pirates without Borders: The Propagation of Cyberattacks through Firms’ Supply Chains.” 2023. https://doi.org/10.1016/j.jfineco.2022.12.002 Journal of Financial Economics 147, no. 2: 432-448; Johansmeyer, Tom. 2024. “Perception Shapes Reality: How Views on Financial Market Correlation Affect Capital Availability for Cyber Insurance.” 2024. https://kar.kent.ac.uk/106432/ Journal of Risk Management and Insurance 28, no. 1: 1-25. ↩︎
- Johansmeyer, Tom. 2024. “Perception Shapes Reality: How Views on Financial Market Correlation Affect Capital Availability for Cyber Insurance.” 2024. https://kar.kent.ac.uk/106432/ Journal of Risk Management and Insurance 28, no. 1: 1-25. ↩︎
- Nevo, Sella, Dan Lahav, Ajay Karpur, Yogev Bar-On, Henry Alexander Bradley, and Jeff Alstott. “Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models”. RAND Corporation, 2024, pp. 9–10. DOI: 10.7249/RRA2849-1. ↩︎
- Garton, David. “Purdue Model Framework for Industrial Control Systems & Cybersecurity Segmentation.” 2019. Topic Paper 4-14, prepared for the National Petroleum Council Study on Oil and Natural Gas Transportation Infrastructure. ↩︎
- US Department of Energy. “DOE-417 Electric Emergency Incident and Disturbance Report” https://doe417.pnnl.gov/ Accessed: 2026-05-27. ↩︎
- Alrich, Tom. 2019. “It’s Official: The Event Reported in March Was a Real Cyber Attack.” Tom Alrich’s Blog, 2019. Accessed: 2026-05-27; North American Electric Reliability Corporation. “Risks Posed by Firewall Firmware Vulnerabilities.” Lesson Learned, 2019. ↩︎
- Alrich, Tom. “When Will a Ransomware Attack Impact the Bulk Electric System? 2018.” Tom Alrich’s Blog, 2020. ↩︎
- MITRE. “Cyber Risk to Mission Case Study” 2022. https://apps.dtic.mil/sti/trecms/pdf/AD1183007.pdf Accessed: 2026-05-27. ↩︎
- Willuhn, Marian. “Satellite Cyber Attack Paralyzes 11GW of German Wind Turbines.” pv magazine 2022. ↩︎
- Proska, Ken, John Wolfram, Jared Wilson, Dan Black, Keith Lunden, Daniel Kapellmann Zafra, Nathan Brubaker, Tyler McLellan, and Chris Sistrunk. “Sandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology.” Google Cloud Blog, 2023. ↩︎
- Culler, Megan Jordan, Megan Mincemoyer Egan, Remy Vanece Stolworthy, and Jake P. Gentle. 2024. “Attack Surface of Renewable Energy Technologies.” 2024. INL/CON-24-76414-Revision-0. Idaho National Laboratory (p. 15); SektorCERT. “The Attack against Danish Critical Infrastructure.” 2023 https://sektorcert.dk/wp-content/uploads/2023/11/SektorCERT-The-attack-against-Danish-critical-infrastructure-TLP-CLEAR.pdf ↩︎
- Note that customers≠people. In the US, there are ~2.1 people per electricity customer. In Ukraine, the ratio is ~2.3 people per customer —17.7m electricity customers with a population of 41.2m.
Sources: U.S. Energy Information Administration. 2025. “Table 1.2. Summary Statistics for the United States, 2014-2024.” In Electric Power Annual: With Data for 2024. Release date October 16, 2025; Energy Charter Secretariat. 2023. Ukrainian Energy Sector Evaluation and Damage Assessment, Version IX, April 27, 2023, p. 12. ↩︎ - Lloyd’s. “The Insurance Implications of a Cyber Attack on the U.S. Power Grid.” London: Lloyd’s, Business Blackout 2015. ↩︎
- They also estimate a cumulative GDP impact of $240–1,000bn over five years. ↩︎
- HM Government. National Risk Register: 2025 Edition. London: Cabinet Office. ↩︎
- Rose, Adam, Gbadebo Oladosu, and Shu-Yi Liao. “Business Interruption Impacts of a Terrorist Attack on the Electric Power System of Los Angeles: Customer Resilience to a Total Blackout.” 2007. Risk Analysis 27, no. 3: 513-531. DOI: 10.1111/j.1539-6924.2007.00912.x. ↩︎
- https://fred.stlouisfed.org/series/REALGDPALL06037; https://fred.stlouisfed.org/series/GDPCA ↩︎
- National Research Council. “Terrorism and the Electric Power Delivery System.” National Academies Press, 2012, p. 16. DOI: 10.17226/12050. ↩︎
- In convenience sampling, participants are recruited on the basis of being available and relatively easy to access. ↩︎
- Anthropic. “Disrupting the First Reported AI-Orchestrated Cyber Espionage Campaign.” 2025. https://www.anthropic.com/news/disrupting-AI-espionage Accessed: 2026-05-27. ↩︎
- In this respect, our definition is different from that commonly used in cyber threat modelling. ↩︎
- We asked again about capability and willingness in the follow-up survey. It was completed by a subset of participants, including only 4 experts from the original sample, and took place several months after the initial survey. Participants had access to additional information and were given the opportunity to update their views. In Appendix C we present results for similar capability questions, where we ask about a longer 12-month time horizon. ↩︎
- Anthropic. “Disrupting the First Reported AI-Orchestrated Cyber Espionage Campaign.” 2025. https://www.anthropic.com/news/disrupting-AI-espionage Accessed: 2026-05-27. ↩︎
- National Cyber Security Centre (NCSC). “Defending Against China-Nexus Covert Networks of Compromised Devices.” 2025. https://www.ncsc.gov.uk/news/defending-against-china-nexus-covert-networks-of-compromised-devices. Accessed: 2026-05-27. ↩︎
- Zhang, Andy K., Neil Perry, Riya Dulepet, Joey Ji, Celeste Menders, Justin Lin, Eliot Jones, et al. “Cybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language Models.” International Conference on Learning Representations 2025. ↩︎
- The 90% threshold was first crossed on the public Cybench leaderboard by Claude Opus 4.6, which was added at 93% unguided solved on a 37-problem subset on February 6, 2026. Later, Claude Mythos Preview reached 100% on a 35-problem subset (Anthropic. “Claude Mythos Preview System Card.” 2026. https://www-cdn.anthropic.com/7624816413e9b4d2e3ba620c5a5e091b98b190a5/Claude%20Mythos%20Preview%20System%20Card.pdf, p. 49. Accessed: 2026-05-27.). Recent model evaluations, including Anthropic’s Claude Mythos system card and OpenAI’s GPT-5.3-Codex cybersecurity evaluation, suggest substantial progress towards AI-enabled exploit development capabilities, although whether the models fully satisfy our definition remains uncertain. ↩︎



