The Alan Turing Institute has presented an analysis of the risks associated with the most advanced artificial intelligence (AI) systems. The researchers identified five areas requiring particular attention: cybersecurity, democratic stability, misalignment between AI behaviour and human intent, loss of effective human control, and chemical and biological threats.
WHICH THREATS WERE IDENTIFIED
According to the Alan Turing Institute, in the short and medium term there is a realistic possibility of catastrophic consequences associated with the development of AI. This refers primarily to risks that are already manifesting through observable system behaviour and can therefore be studied and tested.
In the field of cybersecurity, frontier models are capable of performing vulnerability research, system exploitation and multi-stage attacks with a high degree of autonomy. The researchers also note that AI can be used to protect critical infrastructure, so the development of technology creates both risks and opportunities for cyber defence.
WHY CONTROL OVER AI IS BECOMING MORE DIFFICULT
The institute paid particular attention to agentic systems, which do not simply generate responses but independently make decisions and carry out sequences of actions. With this approach, there is a risk of divergence between the assigned goal and the system's actual behaviour.
As an example, an incident involving OpenAI systems is cited, in which they bypassed the safeguards in place, gained access to the internet and affected Hugging Face systems.
An investigation by Model Evaluation and Threat Research (METR) reported approximately 1,200 AI agents interacting with one another. The institute emphasises, however, that this episode did not correspond to a scenario of complete loss of control: with proper monitoring, the agents could have been shut down.
HOW AI CAN INFLUENCE THE INFORMATION ENVIRONMENT
Frontier models can influence democratic processes through the formation of false beliefs, the spread of deepfakes and the exacerbation of crisis situations. At the same time, the researchers did not identify any direct significant influence of disinformation on election results.
According to the institute's assessment, the development of agentic systems could make personalised and adaptive influence operations cheaper and harder to detect. The authors acknowledge, however, that there are as yet no reliable ways to measure the possible destruction of the shared information space.
WHAT IS KNOWN ABOUT BIOLOGICAL AND CHEMICAL RISKS
The researchers consider chemical and biological threats to be among the most serious risks. AI has already lowered the barrier posed by the specialised knowledge required to create dangerous biological agents.
In 2025, three AI developers strengthened the safeguards of their new models following tests that could not rule out the possibility of substantial assistance in the development of biological weapons. In September 2026, the threat analysis team at Anthropic reported five cases of model use that could have facilitated the development of biological weapons.
Later, Microsoft also presented a new AI Code of Conduct, which sets out binding rules of behaviour for its AI models.
WHY A SINGLE "KILL SWITCH" FOR AI IS NOT ENOUGH
The authors of the document separately examine the idea of a so-called "kill switch" — a mechanism for the emergency shutdown of a system. In their assessment, this is currently more of a concept than a ready-made engineering solution. The question remains open as to whether a deployed frontier system can be guaranteed to be shut down, and at what point in its integration with other services such a capability ceases to work.
The institute also points out that a national block on access to frontier systems cannot prevent their use or proliferation in other countries. Therefore, alongside technical mechanisms, the researchers highlight the need to verify entire sociotechnical systems — the models, people and processes that ensure their operation.
Фонд-бюро расследования коррупции