Open models reach frontier offensive-cyber capability; a global surge in AI-driven intrusion follows.
Probability this branch occurs by 2028
55–75%
55–75%
1 revision · 0/2 tripwires crossed
The scenario
Within a year of Astra and Mythos reaching Critical cyber thresholds, an open-weight model does the same. Automated vulnerability discovery and exploitation become commodity. Ransomware, infrastructure attacks and fraud scale with compute rather than with skilled labor. Defenders using gated tiers hold the line in well-resourced sectors; everyone else is exposed.
Preconditions
Open Proliferation continues
No breakthrough in automated defense that outpaces offense
Attackers have compute (they do)
Leading indicators
Open-model scores on CyberGym / ExploitBench-class benchmarks
CISA and insurer data on intrusion frequency and time-to-exploit
Zero-days attributed to AI discovery
Tripwires
Observable thresholds. When one crosses, the scenario's status changes and the weekly re-run is brought forward.
clearocp-t1
Open-weight model matches Critical-tier cyber benchmark
clearocp-t2
A critical-infrastructure outage in an OECD country is attributed to an AI-discovered exploit
Playbook
Prevent
Defender access to gated cyber tiers before open parity
Memory-safe rewrites of critical software; automated patching pipelines
Delay open release of cyber-specialized weights (limited effect, buys months)
Detect
Benchmark tracking; incident attribution by CERTs
Respond
individuals
Hardware keys, password manager, automatic updates, offline backups; treat every unexpected message as suspect
Keep some cash and paper copies of essential documents
organizations
Assume-breach architecture; segment networks; 72-hour patch SLAs enforced by automation
Use defensive AI agents continuously, not annual pen-tests
governments
National patching mandates for critical infrastructure
Fund defensive AI access for hospitals, utilities, local government
Treat AI-exploit attribution as a diplomatic issue with deterrence
Every change is logged with its reason and the signals that drove it. Moves are bounded per week; a jump beyond the bound is flagged as a shock.
Probability range over time
Your estimate
Disagree with our range? Set yours. Estimates feed a community view that appears once enough people weigh in, and the weekly run reads the gap between our number and yours.
65%
2026-09-16
55–75%
seed
Seed estimate anchored on Metaculus (95% open-weight matches Mythos cyber benchmark by Jul 2027) discounted for whether parity produces a measurable intrusion surge. GLM-5.3 already claims thousands of real vulnerabilities found.
Z.ai releases GLM-5.3 open weights (744B) with strong cyber capability
Released after a two-week self-imposed cyber-safety hold. Vendor-reported 84.5% on CyberGym and thousands of real vulnerabilities found in open-source projects. Flash variant MIT-licensed.
Open-weight matches Mythos cyber benchmark by Jul 2027: 95%. Another sandbox escape by Jan 2027: 50%. AI hacks third party: 41%. Weight exfiltration confirmed: 7%. Kill-switch bill passes both houses by Sept 2027: 24%.