← Evidence index · 中文 · Main post
Each section: Claim · Why · Evidence · Analogue · Would update if · Conf (H/M/L).
Parent timeline: Shared Ci spine
Compressed tables: timeline prediction nodes 1 3 expanded
Date: 2026-07-03
Settings: Hybrid time (C); modal + tail branches
1. Where this fits in the repo
| File | What’s there |
|---|---|
| This file | Full Node 3 — timing, theft probabilities, actor table, modal/tails, p(doom), falsifiers |
| Shared Ci spine §Node 3 summary | 5-line executive summary |
| timeline prediction nodes 1 3 expanded | Medium-length Node 3 (tables compressed) |
| RAND_2024_Securing_AI_Model_Weights_导读.md | OC/SL framework; SL5 currently infeasible |
| research_us_china_ai_dialogues.md | Geneva 2024; 2026 guardrails restart |
| research_international_ai_governance_platforms.md | Multilateral fragmentation (Paris 2025) |
| research_ai_pause_advocacy_playbook.md | Why treaty/pause dead; export ctrl live |
| Anthropic_Fable_Mythos_export_ban_2026_深度解读.md | Export-control precedent on deployed models |
| ai_2027_中文总结.md | Security appendix; Feb 2027 heist narrative |
| my pdoom | Geopolitical + coordination failure bucket |
2. Node definition (falsifiable claim)
At capability C5+ (continuous-learning Agent-2 class; ~2×10²⁸ FLOP training; 3× R&D multiplier), a salient weight-theft or natsec crisis triggers hardening + export controls + guardrails talks, but not a durable US–China training-limit treaty or unilateral frontier pause.
Separate three layers (do not merge into AI 2027 prose):
| Layer | Node 3 object |
|---|---|
| Capability C | Frontier weights worth stealing; theft materially closes compute gap |
| Trigger E | Attempt, partial exfil, or public discovery of state-linked theft |
| Response | Export controls, WSL spend, dialogue restart — race continues |
3. Hybrid timing — C5+ ~2028, not Feb 2027
| Layer | AI 2027 (narrative) | Our anchor (hybrid C) | Rationale |
|---|---|---|---|
| Theft salience | 2027-02 Agent-2 heist | ~2028 H1 at C5+ | Tracker ~0.70× on governance/economy; C5 = Agent-2 / 3× multiplier (Shared Ci spine) |
| Security upgrade | WSL3→WSL4 overnight post-theft | 12–18 mo lag after trigger | AI 2027 Security Forecast: ~12 mo WSL3→WSL5 with top-priority gov effort; RAND: SL5 needs 5-yr lead time |
| Policy peak | 2027-05 natsec clearance wave | 2028 H1–H2 | COVID analogue: 2–3 mo institutional delay even on obvious tails |
Hybrid rule: Capability dates follow AI 2027 / METR fast track; human-response calendar lags ~30% unless Trigger E compresses. Anchor nodes by Ci, not drama calendar — the Feb 2027 heist is scenario color, not our base forecast date.
| Ci | Plain capability | Tracker (2026-06) | Node 3 relevance |
|---|---|---|---|
| C4 | Agent-1-mini; junior dev shock | Economic Behind | Theft low value; WSL2–3 |
| C5 | Agent-2; continuous learning; 3× R&D multiplier | Emerging / Not testable | First weights worth OC4 exfil campaign |
| C6 | Superhuman coder | Emerging | Post-theft hardening target |
| C7+ | Internal “genius country” | Emerging | Gov deep involvement; kinetic options discussed |
Calendar mapping (if 0.70× holds): AI 2027 C5 ≈ 2027-01 → ~2028 Q1 ±6 mo for salient theft/policy crisis.
4. AI 2027 Feb heist — scenario device, not base forecast
AI 2027 main text (Feb 2027): China steals Agent-2 via insider + microarch side channel on NVLink/NVIDIA CC VM, ~2 hours, multi-TB weights — then US pushes WSL4, catches last spy, discusses kinetic strike on PRC datacenters.
Our treatment:
| Element | AI 2027 | Our P / stance |
|---|---|---|
| Timing | Feb 2027 | Low as literal calendar; moderate conditional on C5+ |
| 2-hour full heist | Canonical plot | Low (~0.05–0.12) as operational template — see §5 |
| Partial / secrets theft first | Underweighted in main text | Higher base rate — SSL harder than WSL (Security Forecast) |
| Discovery within ~1 month | Yes | Moderate (~0.45–0.60) if full weights move |
| Kinetic strike discussed | White House options | Tail T1 — P <0.02 executed |
Narrative utility: makes strategic value of weights and WSL failure legible. Do not treat microarch side-channel + 2 hr + 2 TB as the reference class for P(attempt).
5. P(2-hour full heist) — LOW
Claim: P(successful full frontier weight exfil in ~2 hours via AI 2027-style op | C5+ attempt) ≈ 0.05–0.12.
| Factor | Direction | Evidence |
|---|---|---|
| Exfil bandwidth | Against 2 hr | Agent-2 class ~2 TB+ (Security Forecast); datacenter egress controls at WSL3+ |
| Side-channel on CC VM | Plausible once | AI 2027 specifies NVLink side channel — one path; not base-rate for all thefts |
| OC4 campaign length | Against 2 hr | RAND OC4: ~100 people, ~1 year, ≤$10M — WSL definition is under 2 months, not 2 hours |
| Insider + cyber combo | For fast op | Manhattan/OC5 ops can compress timeline — but full weights still need staging |
| Expert prior on theft | For some theft | 78% agree state actor steals frontier US weights before 2030 — not 2-hour full heist |
Interpretation: Low P(2 hr heist) is compatible with moderate P(any state theft attempt) — attempts may be partial, distillation, secrets-first, or months-long exfil.
6. P(attempt) and P(discovered) — MODERATE
6.1 P(attempt | C5+ live, through 2030)
Working range: 0.55–0.75 (central ~0.65).
| Evidence | Weight |
|---|---|
| AI 2027 Security workshop poll (n=27): 78% agree “state actor will most likely steal frontier AI model weights from a US company before 2030” | Strong prior on attempt/success |
| RAND 2024: US frontier ~WSL2 (2024–25); SL3 first serious insider defense; SL5 currently impossible | Vulnerability persists |
| CFR Cyber Ops Tracker: state cyber dominated by espionage since 2005; AI weights = high-value espionage target | Reference class |
| AI 2027 Tracker (2026-03): no public confirm; espionage inherently hidden | Attempt may never surface |
| Open weights (Llama, DeepSeek, GLM) | Downward on marginal value of full theft — not zero at C5+ |
6.2 P(discovered | successful full-weight theft)
Working range: 0.45–0.60 (central ~0.52).
| For discovery | Against discovery |
|---|---|
| USG counterintel post-2024 chip war; lab instrumentation ↑ | Successful espionage often never public (Stuxnet attribution took years) |
| AI 2027 assumes US learns within ~1 month | Attacker may exfil to air-gapped CN CDZ with no public leak |
| RAISE/SB-53 72h incident reporting for weight theft (NY, 2027+) | Classification may bury public salience |
| Fable/Mythos episode: gov already treats frontier models as munitions | Discovery ≠ mainstream media cycle |
Distinction: P(attempt) moderate–high; P(this exact op discovered and becomes DC crisis) = attempt × discovery × salience — we model salience at C5+ when gap-closure threatens natsec narrative.
7. Security levels — RAND / AI 2027 Security Forecast
| Level | vs nation-state (OC4/5) | 2024–26 observed |
|---|---|---|
| WSL2 | Vulnerable | US frontier default (RAND; Security Forecast) |
| WSL3 | Still beatable by OC4 | 2026 target; bandwidth limits, insider programs |
| WSL4 | Robust vs standard state op (95% / 2 mo) | Post-crisis sprint; confidential computing |
| WSL5 | vs top-priority state | Not achievable without gov + years (RAND; 63% poll: no voluntary SL5) |
Poll anchors (Security Forecast):
| Question | Agree |
|---|---|
| State steals frontier US weights before 2030 | 78% |
| No voluntary SL5 without law + gov assist | 63% |
| Gov #1 priority + >$100B → SL5 in <6 mo | 22% agree; 56% disagree |
Implication for Node 3: Theft crisis is overdetermined in expert priors; defense sprint is slow — modal path = reactive hardening, not preemption.
8. Trigger E (optional accelerators)
| Trigger | P(fire | C5+) | Effect on response |
|---|---|---|
| E1 — Public/credible leak of full-weight theft | 0.15–0.25 by 2028 | Export ctrl 0.85+; security spend 0.90+; media cycle 6–10 wk |
| E2 — Classified discovery, selective leak (WSJ/FT) | 0.20–0.30 | Same as E1; kinetic discussed not executed |
| E3 — Failed attempt caught pre-exfil | 0.25–0.35 | Hardening without race-acceleration tail; treaty still <0.10 |
| E4 — Export-control crisis (Fable-class, no theft) | Already live (Jun 2026) | Export ctrl regime precedes theft; lowers surprise |
| No Trigger E (theft hidden or only secrets) | ~0.25–0.35 | Incremental BIS rules; guardrails 0.40 |
Fable/Mythos (Jun 2026): first live commercial frontier model export recall — theft trigger partly front-run by deployment controls.
9. Modal path overview (~55–65% | C5+ crisis)
One sentence: Tighten chip + model export controls, 2–3× lab security spend, restart US–China guardrails talks; no training-limit treaty, no unilateral pause, no kinetic strike.
C5+ weights strategically salient (~2028)
│
┌──────────────────┼──────────────────┐
▼ ▼ ▼
MODAL (58%) TAIL-T3 (20%) TAIL-T1 (3%)
export ctrl + race accelerates kinetic /
WSL spend + DPA + IC surge allied fracture
guardrails talk no treaty (T4 14%)
│ │ │
└──────────────────┴──────────────────┘
TAIL-T2 (6%)
real bilateral treaty
(training limits)
10. Modal — export control expansion P ≈ 0.70
| Mechanism | P(by 2028-12) | Evidence |
|---|---|---|
| BIS AI model / weights rules tightened | 0.70 | Fable EAR §744.22(b) “is informed” on API (Jun 2026); 8/1 EO covered-model framework |
| Cloud KYC / foreign training reporting | 0.55 | Biden-era proposed rule; Trump EO 2026 acceleration frame still natsec-hawk |
| Chip export further tiering (HBM, equipment) | 0.65 | Pre-existing small-yard-high-fence; Geneva 2024 CN agenda |
| Deemed export on frontier API access | 0.60 | Fable foreign-national ban precedent; ID/biometric gating (Anthropic Jul 2026 policy) |
Why not higher: Industry pushback (Lawfare, Dean Ball “cartoonish”); partial reversals (Mythos whitelist Jun 26; full lift Jul 1 2026 per BBC/BankInfoSecurity); controls ≠ pause.
Why not lower: Bipartisan chip-hawk baseline; Banks letter (Jun 2026) explicitly 防中国窃取; theft crisis adds momentum beyond Fable.
Conf: M
11. Modal — lab security spend ≥2× P ≈ 0.75
| Action | P | Evidence |
|---|---|---|
| Frontier labs double+ security budget | 0.75 | RAND 8 urgent recs largely unimplemented at SL2; crisis = finally funded |
| Third-party red team (OC4 simulation) | 0.65 | RAND rec #7; SL5 Task Force / standard.sl5.org |
| Confidential computing production deploy | 0.55 | RAND rec #8; hardest, strongest consensus |
| Insider program + privileged access ↓ | 0.70 | SL3 watershed; AI 2027 → ~100 privileged by late 2027 |
| NY RAISE weight-theft protocols (2027-01) | 0.70 prep | Mandatory protocol + 72h theft reporting |
63% poll: SL5 won’t happen voluntarily — spend rises before SL5 achieved.
Conf: M
12. Modal — US–China guardrails talks P ≈ 0.50
| Outcome | P | Evidence |
|---|---|---|
| Track I meeting within 12 mo of crisis | 0.50 | 2026-05 Beijing: restart agreed; Bessent 4–8 wk window |
| Track II → Track I text on red-team / non-state-actor access | 0.35 | Brookings–CISS terminology manual; 2026 guardrails scope narrow |
| Second Geneva-style session | 0.45 | Aug 2024 promised round 2 never held publicly — restart ≠ success |
Geneva 2024-05-14 (verified): candid exchange; no joint statement; US raised misuse; CN raised export controls (NSC Watson statement; Reuters).
Guardrails ≠ treaty: Scope = best practices, non-state actors, foreign national access — not mutual training freeze (research_us_china_ai_dialogues.md §2.3; research_ai_pause_advocacy_playbook.md §1.2D).
Conf: M
13. Modal — formal US–China AI treaty P ≈ 0.04–0.08
| Treaty type | P(by 2030) | Blockers |
|---|---|---|
| Training FLOP ceiling + verification | 0.04–0.06 | No HEM maturity; 22% believe SL5 in 6 mo even with $100B — verification gap |
| Weights non-proliferation treaty | 0.05–0.08 | Geneva dead end; Paris 2025 US unsigned; India 2026 development frame |
| Mutual training freeze | <0.02 | Playbook: unilateral pause = strategic suicide narrative |
Multilateral context: Bletchley 2023 both signed principles; Seoul 2024 CN did not sign ministerial; Paris 2025 CN signed, US did not — fragmentation (research_international_ai_governance_platforms.md).
Historical analogue: NPT took decades; no US–USSR treaty stopped computing race during Cold War — export controls + espionage, not pause.
Conf: L–M (low rate is high-confidence)
14. Modal — kinetic strike / datacenter attack P < 0.02
Claim: P(US executes kinetic strike on PRC AI datacenter | theft crisis) <0.02; P(serious internal discussion) ~0.15–0.25.
| Reference class | Lesson |
|---|---|
| Stuxnet (2010) | Rare kinetic-adjacent cyber op — US/Israel attribution; not repeated at scale (CFR Cyber Tracker; Forescout: OT malware still rare) |
| State cyber ops 2005–22 | Espionage dominates; CFR: 77% of suspected ops from CN/RU/IR/KP — mostly exfil, DDoS, not bombs |
| AI 2027 | Discusses strike; scenario not forecast |
| Taiwan / TSMC | Separate tail; not Node 3 modal |
Why discuss but not do: Escalation ladder to hot war; PRC second-strike; TSMC supply chain mutual destruction; cyber retaliation preferred (AI 2027 Security Forecast: sabotage ramps 2027).
Conf: L–M on <0.02 executed; M on “discussed”
15. Modal — unilateral US training slowdown P ≈ 0.08
| Actor | P(halt >30d unilateral) | Evidence |
|---|---|---|
| Frontier labs | 0.05–0.08 | Anthropic RSI essay: pause only with multilateral verification — doesn’t exist |
| US executive | 0.06–0.10 | Trump EO 2026: voluntary 30-day review, not cap |
| US Congress | <0.05 | Cruz moratorium stripped 99–1; natsec hawks anti-pause |
Theft crisis effect: Accelerates training (close gap fear) more often than slows — see Tail T3.
Conf: M–H
16. Actor decision table (full)
| Actor | Decision menu | P(outcome | modal) | Evidence / analogue | Conf |
|---|---|---|---|---|
| US executive | (a) BIS model/chip rules; (b) DPA datacenter seizure; (c) voluntary review expand; (d) guardrails restart | P(export ctrl expand)=0.70; P(DPA seizure)=0.08; P(guardrails meet)=0.50 | Fable; EO 2026-06; Beijing 2026-05 | M |
| US Congress | (a) Banks/GAAIA audit + theft reporting; (b) explicit theft sanctions; (c) training cap | P(theft-reporting law)=0.40; P(training cap)=<0.05 | Banks letter Jun 2026; GAAIA draft | M |
| US IC / cyber command | (a) Counterintel surge; (b) offensive cyber on CN AI; (c) kinetic option paper | P(offensive cyber)=0.55; P(kinetic)=<0.02 | Stuxnet rarity; AI 2027 sabotage ramp | L–M |
| Frontier labs | (a) WSL spend 2×; (b) gov co-location; (c) continue training; (d) conditional pause rhetoric | P(spend 2×)=0.75; P(training stop)=0.08 | RAND; Anthropic RSI | M |
| China | (a) Exfil / continue gap-closure; (b) CDZ centralization; (c) guardrails talk; (d) open-weights PR | P(exfil attempt | C5+)=0.65; P(treaty)=0.04–0.08 | AI 2027; DeepSeek/Z.ai narrative | M |
| EU / allies | (a) Sovereign AI; (b) align US export regime; (c) fracture on US unilateralism | P(sovereign AI spend)=0.60; P(full align)=0.45 | Fable overnight cutoff EU reaction | M |
| Multilateral forums | UN Global Dialogue Jul 2026; Geneva 2027 summit | P(binding theft treaty)=<0.05 | GDC non-military; Paris split | L–M |
| Public / markets | Natsec frame; not x-risk pause movement | P(>2mo mainstream)=0.35 given E1 | FLI 2023 fade | L–M |
17. Tail branches T1–T4
| Tail | Description | P(branch | C5+ crisis) | Key drivers | p(doom) channel |
|---|---|---|---|---|
| T1 — Kinetic / hot war | US or allied kinetic strike on AI infra or PRC retaliation escalating to conventional clash | 0.02–0.04 | AI 2027 Aug 2027 options; Taiwan coupling; Stuxnet-class rarity for physical strike | +2–5pp extinction via great-power war |
| T2 — Real treaty | Bilateral training limits + partial verification (HEM pilot) | 0.04–0.08 | Slowdown Ending “The Deal”; requires verification R&D + political window | −2–4pp coordination failure |
| T3 — Race accelerates | DPA + IC budget surge; explicit “never pause” natsec narrative; CN mobilization | 0.15–0.25 | Modal competitor to treaty; theft closes gap → panic; Fable precedent for gov gate without slowdown | +1–3pp misalignment speed; +0.5–1pp war |
| T4 — Allied fracture | EU/UK/CA decouple from US export overreach; CN gains diplomatic wedge | 0.10–0.18 | Fable global shutdown; Carney/Tugendhat sovereignty statements; Paris 2025 split | +0.5–1pp coordination; indirect misalignment |
Branch hygiene: T1∪T3 overlap — model as correlated (ρ ~0.3) not independent sum.
18. Historical analogues (human-response reference class)
| Event | Date | What happened | Policy outcome | Lesson for Node 3 |
|---|---|---|---|---|
| Manhattan espionage | 1940s | Klaus Fuchs et al. | Hardening; no US unilateral nuclear stop | Insider + state actor beats lab opsec |
| Stuxnet | 2010 | US/IL cyber sabotage IR centrifuges | No treaty; escalation in cyber domain | Kinetic-adjacent cyber rare; preferred to bombs |
| SolarWinds | 2020 | RU SVR supply-chain espionage | Sanctions; no pause on US software | Espionage → hardening, not industry halt |
| Chip export controls | 2022–26 | BIS tiering | Race frame dominates | Controls default; dialogue sidecar |
| Geneva AI dialogue | 2024-05-14 | Track I #1 | No joint statement | Talks cheap; treaties dear |
| Fable/Mythos ban | 2026-06 | EAR on deployed API | Partial restore Jul 1 | Export ctrl on models now real — theft response partially pre-deployed |
19. Fable/Mythos export ban — live modal precedent
Jun 2026 sequence (Anthropic_Fable_Mythos_export_ban_2026_深度解读.md):
- 6/9 Fable/Mythos release → 6/12 Commerce deemed-export directive (foreign nationals) → global takedown
- 6/26 Mythos partial whitelist (~100 US critical-infra orgs)
- ~7/1 Restrictions lifted after Anthropic security commitments (BBC; BankInfoSecurity)
Node 3 implications:
| Implication | Effect on priors |
|---|---|
| Gov can recall deployed frontier models without weight theft | Export ctrl P ↑ before C5 |
| Jailbreak trigger, not theft | E4 trigger live — Node 3 may merge with export-control track |
| Government-gated tier release (whitelist) | Modal deployment control, not training stop |
| Allies sovereignty shock | T4 allied fracture ↑ |
| Dario FAA-style mandatory testing Jun 10 → ban Jun 12 | Labs’ conditional pause rhetoric ≠ operational halt |
20. US–China dialogue evidence (Geneva + 2026 restart)
Track I inventory (research_us_china_ai_dialogues.md):
- 2023-11 SF: establish mechanism
- 2024-05-14 Geneva: only formal Track I session to date — no deliverables
- 2024-08: agree “timely” round 2 — not publicly held
- 2026-05 Beijing: Trump–Xi agree restart; Bessent: guardrails, non-state actors, 4–8 weeks — unconfirmed schedule
Agenda mismatch: US — catastrophic risk + misuse; CN — lift chip controls + UN centrality. Theft crisis reinforces US hawk side; weakens CN incentive for limits unless bundled with semiconductor concessions.
P(guardrails talk | modal) = 0.50 reflects restart pressure, not treaty probability.
21. International governance — why treaty tail is thin
| Platform | 2024–26 signal | Implication |
|---|---|---|
| Paris 2025 | US unsigned ministerial | US won’t bind via summit |
| Seoul 2024 | CN skipped ministerial | Safety coalition without CN |
| India 2026 | 88 signatories; sovereign AI | Global South anti-freeze |
| UN GDC / Dialogue | Non-military; Jul 2026 Geneva | No weights verification mandate |
| REAIM military AI | CN didn’t sign Blueprint | Mil AI split from civilian |
Weights verification (AI 2027 Appendix S): HEM / compute pause / AI polygraph — all immature in 2026. Treaty tail T2 needs hardware progress pause playbook puts at 3–5 yr medium horizon.
22. Pause playbook — why modal ≠ pause
From research_ai_pause_advocacy_playbook.md:
| Lever | Viable 2026? | Node 3 role |
|---|---|---|
| Compute export controls | Yes — containing CN | Modal core |
| Training FLOP cap | No federally | Not modal |
| Multilateral verification treaty | No — 7–9 prerequisites missing | T2 only |
| Voluntary frontier commitments | No enforcement | Seoul 2024 |
| Anthropic conditional pause | Rhetoric only | Expect, not commit |
Coalition: Natsec hawks + Big Tech beat pause camp on theft response — race accelerates (T3) more likely than slowdown (0.08).
23. p(doom) — conditional lifts (geopolitical + coordination)
Definition slice: ΔP(human extinction by ~2050) from Node 3 branch, primarily via great-power war, coordination failure on pause, and speed → misalignment — not double-counting Node 4 misalignment chain.
23.1 Hanson disjunction channel
P(extinction) ⊃ P(AI-enabled great-power war) + P(misalignment | race accelerated)
Node 3 feeds AI war bucket and raises P(no effective pause) for Node 4.
23.2 Conditional lifts (working — calibrate in my pdoom)
| Branch | ΔP(extinction by 2050) vs baseline | Mechanism | Conf |
|---|---|---|---|
| Modal | +0.5–1.5pp | Export ctrl + spend without pause; guardrails theater; slight speed | M |
| T3 race accelerates | +1–3pp (incremental over modal) | DPA; IC offensive cyber; explicit never-pause | M |
| T1 kinetic | +2–5pp if fired | Hot war tail; low P | L |
| T2 treaty | −2–4pp | Rare; cuts coordination crux | L |
| T4 allied fracture | +0.5–1pp | Weakens US-led chokepoints | L–M |
Combined tail T3∪T1 (correlated): +3–8pp over baseline if both escalate — matches parent doc summary.
23.3 Coordination crux link (Node 4)
| Node 3 outcome | Effect on Node 4 |
|---|---|
| Modal | P(coordinated pause) ↓; classified evals ↑ → whistleblower fuel |
| T3 | P(extinction | E, modal) ↑ 1–2pp via speed |
| T2 | P(mandatory halt | alignment scare) ↑ — rare |
Rob Miles crux: Warning shots scarce — theft crisis consumes political bandwidth on CN, not alignment.
23.4 Double-counting guard
- Do not add modal Node 3 and full Node 4 misalignment chain without conditioning
- AI war bucket overlaps misalignment if same conflict — weight by scenario tree
24. Downstream effects (next-node priors)
| If modal | If T3 | If T2 |
|---|---|---|
| WSL4 spend institutionalized; training FLOPs ↑ | OpenBrain–gov fusion narrative | Verification R&D ↑; 3–6 mo slower frontier |
| Node 4: more classified evals, same P(halt) | Node 4: alignment scare raced past | Node 4: halt more credible |
| Node 2 CBRN: decoupled — natsec ≠ bio screening | Chip smuggling ↑ | Export ctrl paired with dialogue |
| EU sovereign AI acceleration | CN open-weights diplomacy | HEM pilot funded |
25. Falsifiers
| Observation | Implication |
|---|---|
| Ratified US–CN training-limit treaty with verification by 2030 | T2 modal wrong; revise treaty P ↑ |
| ≥2 frontier labs public halt >90d after theft news | Unilateral slowdown P too low |
| C5+ reached, zero credible theft attempts through 2030 | Attempt P too high; open-weights reduced value more than modeled |
| Public 2-hour full exfil confirmed | Heist P too low; revisit security model |
| Kinetic US strike on PRC AI DC | T1 not tail — revise upward |
| Theft + no export ctrl expansion within 12 mo | Modal export P too high |
| No guardrails meeting by 2029 despite 2026 restart promise | Guardrails P too high |
26. Confidence summary
| Claim | Conf |
|---|---|
| Anchor at C5+ ~2028, not Feb 2027 | M–H |
| P(2 hr full heist) low | M |
| P(state attempt by 2030) moderate–high (~65%) | M (78% expert poll) |
| Modal = export ctrl + spend, not pause/treaty | M–H |
| Kinetic <0.02 | L–M |
| Treaty 0.04–0.08 | M |
| Exact branch probabilities | L |
| Conditional p(doom) lifts | L (needs main forecast mixture calibration) |
27. External sources
- AI 2027 Security Forecast — 78% poll; WSL timeline; 2-month exfil window
- RAND RRA2849-1 — Securing AI Model Weights
- NSC statement — Geneva AI talks 2024-05-15
- Reuters — US-China AI talks Geneva
- CFR Cyber Operations Tracker
- Anthropic — Fable/Mythos access statement (2026-06-12)
- BBC — US lifts export ban Jul 2026
- Lawfare — export controls on AI models
- AI 2027 Tracker — model theft prediction
28. Repo sources
- (internal note)
- (internal note)
- (internal note)
- (internal note)
- (internal note)
- (internal note)
- (internal note)
- (internal note) (Appendix 5 Security Forecast)
- (internal note)
- (internal note)