Bad Watch by 2028

Open Cyber Parity

Open models reach frontier offensive-cyber capability; a global surge in AI-driven intrusion follows.

Probability this branch occurs by 2028
55–75%
5575%
1 revision · 0/2 tripwires crossed

The scenario

Within a year of Astra and Mythos reaching Critical cyber thresholds, an open-weight model does the same. Automated vulnerability discovery and exploitation become commodity. Ransomware, infrastructure attacks and fraud scale with compute rather than with skilled labor. Defenders using gated tiers hold the line in well-resourced sectors; everyone else is exposed.

Preconditions

  • Open Proliferation continues
  • No breakthrough in automated defense that outpaces offense
  • Attackers have compute (they do)

Leading indicators

  • Open-model scores on CyberGym / ExploitBench-class benchmarks
  • CISA and insurer data on intrusion frequency and time-to-exploit
  • Zero-days attributed to AI discovery

Tripwires

Observable thresholds. When one crosses, the scenario's status changes and the weekly re-run is brought forward.

clearocp-t1
Open-weight model matches Critical-tier cyber benchmark
clearocp-t2
A critical-infrastructure outage in an OECD country is attributed to an AI-discovered exploit

Playbook

Prevent
  • Defender access to gated cyber tiers before open parity
  • Memory-safe rewrites of critical software; automated patching pipelines
  • Delay open release of cyber-specialized weights (limited effect, buys months)
Detect
  • Benchmark tracking; incident attribution by CERTs
Respond

individuals

  • Hardware keys, password manager, automatic updates, offline backups; treat every unexpected message as suspect
  • Keep some cash and paper copies of essential documents

organizations

  • Assume-breach architecture; segment networks; 72-hour patch SLAs enforced by automation
  • Use defensive AI agents continuously, not annual pen-tests

governments

  • National patching mandates for critical infrastructure
  • Fund defensive AI access for hospitals, utilities, local government
  • Treat AI-exploit attribution as a diplomatic issue with deterrence
Recover
  • Post-incident: mandatory disclosure, shared indicators, no-fault reporting to speed collective defense.

Probability history

Every change is logged with its reason and the signals that drove it. Moves are bounded per week; a jump beyond the bound is flagged as a shock.

Probability range over time
Your estimate

Disagree with our range? Set yours. Estimates feed a community view that appears once enough people weigh in, and the weekly run reads the gap between our number and yours.

65%
2026-09-16
55–75%
seed

Seed estimate anchored on Metaculus (95% open-weight matches Mythos cyber benchmark by Jul 2027) discounted for whether parity produces a measurable intrusion surge. GLM-5.3 already claims thousands of real vulnerabilities found.

Signals pushing on this branch

2026-09-09
forecast
●●●○○

Metaculus: 95% an open-weight model matches the Mythos cyber benchmark by July 2027; 50% another sandbox escape by January 2027

Forecaster consensus that gated cyber capability leaks into open weights within a year, and that agent containment failures will recur.

timelines ▲ faster concentration ▼ open safety ▼ riskier
2026-08-28
release
●●●○○

Z.ai releases GLM-5.3 open weights (744B) with strong cyber capability

Released after a two-week self-imposed cyber-safety hold. Vendor-reported 84.5% on CyberGym and thousands of real vulnerabilities found in open-source projects. Flash variant MIT-licensed.

timelines ▲ faster concentration ▼ open safety ▼ riskier

Built on

Every source reviewed for this scenario. The full ledger is public.

DateSourcePublisherType
2026-09-09Forecasts after the Hugging Face incident, OpenAI breach, and cyberattack questions
Open-weight matches Mythos cyber benchmark by Jul 2027: 95%. Another sandbox escape by Jan 2027: 50%. AI hacks third party: 41%. Weight exfiltration confirmed: 7%. Kill-switch bill passes both houses by Sept 2027: 24%.
Metaculusforecast
2026-08-28Z.ai GLM-5.3 open weights (744B) released after cyber-safety holdTechJacknews
2026-09-01GPT-6 'Astra'
First model at Critical cyber threshold under Preparedness Framework; opaque recurrence weakens chain-of-thought monitoring.
OpenAIprimary
2026-09-02Gemini 3.8 Flash and Flash Cyber launch9to5Googlenews