← Back to all writing

p(doom) evidence — Node 3: weight theft & geopolitics

July 5, 2026

Evidence index · 中文 · Main post

Each section: Claim · Why · Evidence · Analogue · Would update if · Conf (H/M/L).


Parent timeline: Shared Ci spine
Compressed tables: timeline prediction nodes 1 3 expanded
Date: 2026-07-03
Settings: Hybrid time (C); modal + tail branches


1. Where this fits in the repo

FileWhat’s there
This fileFull Node 3 — timing, theft probabilities, actor table, modal/tails, p(doom), falsifiers
Shared Ci spine §Node 3 summary5-line executive summary
timeline prediction nodes 1 3 expandedMedium-length Node 3 (tables compressed)
RAND_2024_Securing_AI_Model_Weights_导读.mdOC/SL framework; SL5 currently infeasible
research_us_china_ai_dialogues.mdGeneva 2024; 2026 guardrails restart
research_international_ai_governance_platforms.mdMultilateral fragmentation (Paris 2025)
research_ai_pause_advocacy_playbook.mdWhy treaty/pause dead; export ctrl live
Anthropic_Fable_Mythos_export_ban_2026_深度解读.mdExport-control precedent on deployed models
ai_2027_中文总结.mdSecurity appendix; Feb 2027 heist narrative
my pdoomGeopolitical + coordination failure bucket

2. Node definition (falsifiable claim)

At capability C5+ (continuous-learning Agent-2 class; ~2×10²⁸ FLOP training; 3× R&D multiplier), a salient weight-theft or natsec crisis triggers hardening + export controls + guardrails talks, but not a durable US–China training-limit treaty or unilateral frontier pause.

Separate three layers (do not merge into AI 2027 prose):

LayerNode 3 object
Capability CFrontier weights worth stealing; theft materially closes compute gap
Trigger EAttempt, partial exfil, or public discovery of state-linked theft
ResponseExport controls, WSL spend, dialogue restart — race continues

3. Hybrid timing — C5+ ~2028, not Feb 2027

LayerAI 2027 (narrative)Our anchor (hybrid C)Rationale
Theft salience2027-02 Agent-2 heist~2028 H1 at C5+Tracker ~0.70× on governance/economy; C5 = Agent-2 / 3× multiplier (Shared Ci spine)
Security upgradeWSL3→WSL4 overnight post-theft12–18 mo lag after triggerAI 2027 Security Forecast: ~12 mo WSL3→WSL5 with top-priority gov effort; RAND: SL5 needs 5-yr lead time
Policy peak2027-05 natsec clearance wave2028 H1–H2COVID analogue: 2–3 mo institutional delay even on obvious tails

Hybrid rule: Capability dates follow AI 2027 / METR fast track; human-response calendar lags ~30% unless Trigger E compresses. Anchor nodes by Ci, not drama calendar — the Feb 2027 heist is scenario color, not our base forecast date.

CiPlain capabilityTracker (2026-06)Node 3 relevance
C4Agent-1-mini; junior dev shockEconomic BehindTheft low value; WSL2–3
C5Agent-2; continuous learning; 3× R&D multiplierEmerging / Not testableFirst weights worth OC4 exfil campaign
C6Superhuman coderEmergingPost-theft hardening target
C7+Internal “genius country”EmergingGov deep involvement; kinetic options discussed

Calendar mapping (if 0.70× holds): AI 2027 C5 ≈ 2027-01 → ~2028 Q1 ±6 mo for salient theft/policy crisis.


4. AI 2027 Feb heist — scenario device, not base forecast

AI 2027 main text (Feb 2027): China steals Agent-2 via insider + microarch side channel on NVLink/NVIDIA CC VM, ~2 hours, multi-TB weights — then US pushes WSL4, catches last spy, discusses kinetic strike on PRC datacenters.

Our treatment:

ElementAI 2027Our P / stance
TimingFeb 2027Low as literal calendar; moderate conditional on C5+
2-hour full heistCanonical plotLow (~0.05–0.12) as operational template — see §5
Partial / secrets theft firstUnderweighted in main textHigher base rate — SSL harder than WSL (Security Forecast)
Discovery within ~1 monthYesModerate (~0.45–0.60) if full weights move
Kinetic strike discussedWhite House optionsTail T1 — P <0.02 executed

Narrative utility: makes strategic value of weights and WSL failure legible. Do not treat microarch side-channel + 2 hr + 2 TB as the reference class for P(attempt).


5. P(2-hour full heist) — LOW

Claim: P(successful full frontier weight exfil in ~2 hours via AI 2027-style op | C5+ attempt) ≈ 0.05–0.12.

FactorDirectionEvidence
Exfil bandwidthAgainst 2 hrAgent-2 class ~2 TB+ (Security Forecast); datacenter egress controls at WSL3+
Side-channel on CC VMPlausible onceAI 2027 specifies NVLink side channel — one path; not base-rate for all thefts
OC4 campaign lengthAgainst 2 hrRAND OC4: ~100 people, ~1 year, ≤$10M — WSL definition is under 2 months, not 2 hours
Insider + cyber comboFor fast opManhattan/OC5 ops can compress timeline — but full weights still need staging
Expert prior on theftFor some theft78% agree state actor steals frontier US weights before 2030not 2-hour full heist

Interpretation: Low P(2 hr heist) is compatible with moderate P(any state theft attempt) — attempts may be partial, distillation, secrets-first, or months-long exfil.


6. P(attempt) and P(discovered) — MODERATE

6.1 P(attempt | C5+ live, through 2030)

Working range: 0.55–0.75 (central ~0.65).

EvidenceWeight
AI 2027 Security workshop poll (n=27): 78% agree “state actor will most likely steal frontier AI model weights from a US company before 2030”Strong prior on attempt/success
RAND 2024: US frontier ~WSL2 (2024–25); SL3 first serious insider defense; SL5 currently impossibleVulnerability persists
CFR Cyber Ops Tracker: state cyber dominated by espionage since 2005; AI weights = high-value espionage targetReference class
AI 2027 Tracker (2026-03): no public confirm; espionage inherently hiddenAttempt may never surface
Open weights (Llama, DeepSeek, GLM)Downward on marginal value of full theft — not zero at C5+

6.2 P(discovered | successful full-weight theft)

Working range: 0.45–0.60 (central ~0.52).

For discoveryAgainst discovery
USG counterintel post-2024 chip war; lab instrumentation ↑Successful espionage often never public (Stuxnet attribution took years)
AI 2027 assumes US learns within ~1 monthAttacker may exfil to air-gapped CN CDZ with no public leak
RAISE/SB-53 72h incident reporting for weight theft (NY, 2027+)Classification may bury public salience
Fable/Mythos episode: gov already treats frontier models as munitionsDiscovery ≠ mainstream media cycle

Distinction: P(attempt) moderate–high; P(this exact op discovered and becomes DC crisis) = attempt × discovery × salience — we model salience at C5+ when gap-closure threatens natsec narrative.


7. Security levels — RAND / AI 2027 Security Forecast

Levelvs nation-state (OC4/5)2024–26 observed
WSL2VulnerableUS frontier default (RAND; Security Forecast)
WSL3Still beatable by OC42026 target; bandwidth limits, insider programs
WSL4Robust vs standard state op (95% / 2 mo)Post-crisis sprint; confidential computing
WSL5vs top-priority stateNot achievable without gov + years (RAND; 63% poll: no voluntary SL5)

Poll anchors (Security Forecast):

QuestionAgree
State steals frontier US weights before 203078%
No voluntary SL5 without law + gov assist63%
Gov #1 priority + >$100B → SL5 in <6 mo22% agree; 56% disagree

Implication for Node 3: Theft crisis is overdetermined in expert priors; defense sprint is slow — modal path = reactive hardening, not preemption.


8. Trigger E (optional accelerators)

TriggerP(fire | C5+)Effect on response
E1 — Public/credible leak of full-weight theft0.15–0.25 by 2028Export ctrl 0.85+; security spend 0.90+; media cycle 6–10 wk
E2 — Classified discovery, selective leak (WSJ/FT)0.20–0.30Same as E1; kinetic discussed not executed
E3 — Failed attempt caught pre-exfil0.25–0.35Hardening without race-acceleration tail; treaty still <0.10
E4 — Export-control crisis (Fable-class, no theft)Already live (Jun 2026)Export ctrl regime precedes theft; lowers surprise
No Trigger E (theft hidden or only secrets)~0.25–0.35Incremental BIS rules; guardrails 0.40

Fable/Mythos (Jun 2026): first live commercial frontier model export recall — theft trigger partly front-run by deployment controls.


9. Modal path overview (~55–65% | C5+ crisis)

One sentence: Tighten chip + model export controls, 2–3× lab security spend, restart US–China guardrails talks; no training-limit treaty, no unilateral pause, no kinetic strike.

                    C5+ weights strategically salient (~2028)

           ┌──────────────────┼──────────────────┐
           ▼                  ▼                  ▼
      MODAL (58%)        TAIL-T3 (20%)      TAIL-T1 (3%)
   export ctrl +        race accelerates    kinetic /
   WSL spend +           DPA + IC surge      allied fracture
   guardrails talk       no treaty           (T4 14%)
           │                  │                  │
           └──────────────────┴──────────────────┘
                         TAIL-T2 (6%)
                    real bilateral treaty
                    (training limits)

10. Modal — export control expansion P ≈ 0.70

MechanismP(by 2028-12)Evidence
BIS AI model / weights rules tightened0.70Fable EAR §744.22(b) “is informed” on API (Jun 2026); 8/1 EO covered-model framework
Cloud KYC / foreign training reporting0.55Biden-era proposed rule; Trump EO 2026 acceleration frame still natsec-hawk
Chip export further tiering (HBM, equipment)0.65Pre-existing small-yard-high-fence; Geneva 2024 CN agenda
Deemed export on frontier API access0.60Fable foreign-national ban precedent; ID/biometric gating (Anthropic Jul 2026 policy)

Why not higher: Industry pushback (Lawfare, Dean Ball “cartoonish”); partial reversals (Mythos whitelist Jun 26; full lift Jul 1 2026 per BBC/BankInfoSecurity); controls ≠ pause.

Why not lower: Bipartisan chip-hawk baseline; Banks letter (Jun 2026) explicitly 防中国窃取; theft crisis adds momentum beyond Fable.

Conf: M


11. Modal — lab security spend ≥2× P ≈ 0.75

ActionPEvidence
Frontier labs double+ security budget0.75RAND 8 urgent recs largely unimplemented at SL2; crisis = finally funded
Third-party red team (OC4 simulation)0.65RAND rec #7; SL5 Task Force / standard.sl5.org
Confidential computing production deploy0.55RAND rec #8; hardest, strongest consensus
Insider program + privileged access ↓0.70SL3 watershed; AI 2027 → ~100 privileged by late 2027
NY RAISE weight-theft protocols (2027-01)0.70 prepMandatory protocol + 72h theft reporting

63% poll: SL5 won’t happen voluntarily — spend rises before SL5 achieved.

Conf: M


12. Modal — US–China guardrails talks P ≈ 0.50

OutcomePEvidence
Track I meeting within 12 mo of crisis0.502026-05 Beijing: restart agreed; Bessent 4–8 wk window
Track II → Track I text on red-team / non-state-actor access0.35Brookings–CISS terminology manual; 2026 guardrails scope narrow
Second Geneva-style session0.45Aug 2024 promised round 2 never held publicly — restart ≠ success

Geneva 2024-05-14 (verified): candid exchange; no joint statement; US raised misuse; CN raised export controls (NSC Watson statement; Reuters).

Guardrails ≠ treaty: Scope = best practices, non-state actors, foreign national access — not mutual training freeze (research_us_china_ai_dialogues.md §2.3; research_ai_pause_advocacy_playbook.md §1.2D).

Conf: M


13. Modal — formal US–China AI treaty P ≈ 0.04–0.08

Treaty typeP(by 2030)Blockers
Training FLOP ceiling + verification0.04–0.06No HEM maturity; 22% believe SL5 in 6 mo even with $100B — verification gap
Weights non-proliferation treaty0.05–0.08Geneva dead end; Paris 2025 US unsigned; India 2026 development frame
Mutual training freeze<0.02Playbook: unilateral pause = strategic suicide narrative

Multilateral context: Bletchley 2023 both signed principles; Seoul 2024 CN did not sign ministerial; Paris 2025 CN signed, US did not — fragmentation (research_international_ai_governance_platforms.md).

Historical analogue: NPT took decades; no US–USSR treaty stopped computing race during Cold War — export controls + espionage, not pause.

Conf: L–M (low rate is high-confidence)


14. Modal — kinetic strike / datacenter attack P < 0.02

Claim: P(US executes kinetic strike on PRC AI datacenter | theft crisis) <0.02; P(serious internal discussion) ~0.15–0.25.

Reference classLesson
Stuxnet (2010)Rare kinetic-adjacent cyber op — US/Israel attribution; not repeated at scale (CFR Cyber Tracker; Forescout: OT malware still rare)
State cyber ops 2005–22Espionage dominates; CFR: 77% of suspected ops from CN/RU/IR/KP — mostly exfil, DDoS, not bombs
AI 2027Discusses strike; scenario not forecast
Taiwan / TSMCSeparate tail; not Node 3 modal

Why discuss but not do: Escalation ladder to hot war; PRC second-strike; TSMC supply chain mutual destruction; cyber retaliation preferred (AI 2027 Security Forecast: sabotage ramps 2027).

Conf: L–M on <0.02 executed; M on “discussed”


15. Modal — unilateral US training slowdown P ≈ 0.08

ActorP(halt >30d unilateral)Evidence
Frontier labs0.05–0.08Anthropic RSI essay: pause only with multilateral verification — doesn’t exist
US executive0.06–0.10Trump EO 2026: voluntary 30-day review, not cap
US Congress<0.05Cruz moratorium stripped 99–1; natsec hawks anti-pause

Theft crisis effect: Accelerates training (close gap fear) more often than slows — see Tail T3.

Conf: M–H


16. Actor decision table (full)

ActorDecision menuP(outcome | modal)Evidence / analogueConf
US executive(a) BIS model/chip rules; (b) DPA datacenter seizure; (c) voluntary review expand; (d) guardrails restartP(export ctrl expand)=0.70; P(DPA seizure)=0.08; P(guardrails meet)=0.50Fable; EO 2026-06; Beijing 2026-05M
US Congress(a) Banks/GAAIA audit + theft reporting; (b) explicit theft sanctions; (c) training capP(theft-reporting law)=0.40; P(training cap)=<0.05Banks letter Jun 2026; GAAIA draftM
US IC / cyber command(a) Counterintel surge; (b) offensive cyber on CN AI; (c) kinetic option paperP(offensive cyber)=0.55; P(kinetic)=<0.02Stuxnet rarity; AI 2027 sabotage rampL–M
Frontier labs(a) WSL spend 2×; (b) gov co-location; (c) continue training; (d) conditional pause rhetoricP(spend 2×)=0.75; P(training stop)=0.08RAND; Anthropic RSIM
China(a) Exfil / continue gap-closure; (b) CDZ centralization; (c) guardrails talk; (d) open-weights PRP(exfil attempt | C5+)=0.65; P(treaty)=0.04–0.08AI 2027; DeepSeek/Z.ai narrativeM
EU / allies(a) Sovereign AI; (b) align US export regime; (c) fracture on US unilateralismP(sovereign AI spend)=0.60; P(full align)=0.45Fable overnight cutoff EU reactionM
Multilateral forumsUN Global Dialogue Jul 2026; Geneva 2027 summitP(binding theft treaty)=<0.05GDC non-military; Paris splitL–M
Public / marketsNatsec frame; not x-risk pause movementP(>2mo mainstream)=0.35 given E1FLI 2023 fadeL–M

17. Tail branches T1–T4

TailDescriptionP(branch | C5+ crisis)Key driversp(doom) channel
T1 — Kinetic / hot warUS or allied kinetic strike on AI infra or PRC retaliation escalating to conventional clash0.02–0.04AI 2027 Aug 2027 options; Taiwan coupling; Stuxnet-class rarity for physical strike+2–5pp extinction via great-power war
T2 — Real treatyBilateral training limits + partial verification (HEM pilot)0.04–0.08Slowdown Ending “The Deal”; requires verification R&D + political window−2–4pp coordination failure
T3 — Race acceleratesDPA + IC budget surge; explicit “never pause” natsec narrative; CN mobilization0.15–0.25Modal competitor to treaty; theft closes gap → panic; Fable precedent for gov gate without slowdown+1–3pp misalignment speed; +0.5–1pp war
T4 — Allied fractureEU/UK/CA decouple from US export overreach; CN gains diplomatic wedge0.10–0.18Fable global shutdown; Carney/Tugendhat sovereignty statements; Paris 2025 split+0.5–1pp coordination; indirect misalignment

Branch hygiene: T1∪T3 overlap — model as correlated (ρ ~0.3) not independent sum.


18. Historical analogues (human-response reference class)

EventDateWhat happenedPolicy outcomeLesson for Node 3
Manhattan espionage1940sKlaus Fuchs et al.Hardening; no US unilateral nuclear stopInsider + state actor beats lab opsec
Stuxnet2010US/IL cyber sabotage IR centrifugesNo treaty; escalation in cyber domainKinetic-adjacent cyber rare; preferred to bombs
SolarWinds2020RU SVR supply-chain espionageSanctions; no pause on US softwareEspionage → hardening, not industry halt
Chip export controls2022–26BIS tieringRace frame dominatesControls default; dialogue sidecar
Geneva AI dialogue2024-05-14Track I #1No joint statementTalks cheap; treaties dear
Fable/Mythos ban2026-06EAR on deployed APIPartial restore Jul 1Export ctrl on models now real — theft response partially pre-deployed

19. Fable/Mythos export ban — live modal precedent

Jun 2026 sequence (Anthropic_Fable_Mythos_export_ban_2026_深度解读.md):

  1. 6/9 Fable/Mythos release → 6/12 Commerce deemed-export directive (foreign nationals) → global takedown
  2. 6/26 Mythos partial whitelist (~100 US critical-infra orgs)
  3. ~7/1 Restrictions lifted after Anthropic security commitments (BBC; BankInfoSecurity)

Node 3 implications:

ImplicationEffect on priors
Gov can recall deployed frontier models without weight theftExport ctrl P before C5
Jailbreak trigger, not theftE4 trigger live — Node 3 may merge with export-control track
Government-gated tier release (whitelist)Modal deployment control, not training stop
Allies sovereignty shockT4 allied fracture
Dario FAA-style mandatory testing Jun 10 → ban Jun 12Labs’ conditional pause rhetoric operational halt

20. US–China dialogue evidence (Geneva + 2026 restart)

Track I inventory (research_us_china_ai_dialogues.md):

  • 2023-11 SF: establish mechanism
  • 2024-05-14 Geneva: only formal Track I session to date — no deliverables
  • 2024-08: agree “timely” round 2 — not publicly held
  • 2026-05 Beijing: Trump–Xi agree restart; Bessent: guardrails, non-state actors, 4–8 weeksunconfirmed schedule

Agenda mismatch: US — catastrophic risk + misuse; CN — lift chip controls + UN centrality. Theft crisis reinforces US hawk side; weakens CN incentive for limits unless bundled with semiconductor concessions.

P(guardrails talk | modal) = 0.50 reflects restart pressure, not treaty probability.


21. International governance — why treaty tail is thin

Platform2024–26 signalImplication
Paris 2025US unsigned ministerialUS won’t bind via summit
Seoul 2024CN skipped ministerialSafety coalition without CN
India 202688 signatories; sovereign AIGlobal South anti-freeze
UN GDC / DialogueNon-military; Jul 2026 GenevaNo weights verification mandate
REAIM military AICN didn’t sign BlueprintMil AI split from civilian

Weights verification (AI 2027 Appendix S): HEM / compute pause / AI polygraph — all immature in 2026. Treaty tail T2 needs hardware progress pause playbook puts at 3–5 yr medium horizon.


22. Pause playbook — why modal ≠ pause

From research_ai_pause_advocacy_playbook.md:

LeverViable 2026?Node 3 role
Compute export controlsYes — containing CNModal core
Training FLOP capNo federallyNot modal
Multilateral verification treatyNo — 7–9 prerequisites missingT2 only
Voluntary frontier commitmentsNo enforcementSeoul 2024
Anthropic conditional pauseRhetoric onlyExpect, not commit

Coalition: Natsec hawks + Big Tech beat pause camp on theft response — race accelerates (T3) more likely than slowdown (0.08).


23. p(doom) — conditional lifts (geopolitical + coordination)

Definition slice: ΔP(human extinction by ~2050) from Node 3 branch, primarily via great-power war, coordination failure on pause, and speed → misalignmentnot double-counting Node 4 misalignment chain.

23.1 Hanson disjunction channel

P(extinction) ⊃ P(AI-enabled great-power war) + P(misalignment | race accelerated)

Node 3 feeds AI war bucket and raises P(no effective pause) for Node 4.

23.2 Conditional lifts (working — calibrate in my pdoom)

BranchΔP(extinction by 2050) vs baselineMechanismConf
Modal+0.5–1.5ppExport ctrl + spend without pause; guardrails theater; slight speedM
T3 race accelerates+1–3pp (incremental over modal)DPA; IC offensive cyber; explicit never-pauseM
T1 kinetic+2–5pp if firedHot war tail; low PL
T2 treaty−2–4ppRare; cuts coordination cruxL
T4 allied fracture+0.5–1ppWeakens US-led chokepointsL–M

Combined tail T3∪T1 (correlated): +3–8pp over baseline if both escalate — matches parent doc summary.

Node 3 outcomeEffect on Node 4
ModalP(coordinated pause) ; classified evals → whistleblower fuel
T3P(extinction | E, modal) ↑ 1–2pp via speed
T2P(mandatory halt | alignment scare) — rare

Rob Miles crux: Warning shots scarce — theft crisis consumes political bandwidth on CN, not alignment.

23.4 Double-counting guard

  • Do not add modal Node 3 and full Node 4 misalignment chain without conditioning
  • AI war bucket overlaps misalignment if same conflict — weight by scenario tree

24. Downstream effects (next-node priors)

If modalIf T3If T2
WSL4 spend institutionalized; training FLOPs OpenBrain–gov fusion narrativeVerification R&D ; 3–6 mo slower frontier
Node 4: more classified evals, same P(halt)Node 4: alignment scare raced pastNode 4: halt more credible
Node 2 CBRN: decoupled — natsec ≠ bio screeningChip smuggling Export ctrl paired with dialogue
EU sovereign AI accelerationCN open-weights diplomacyHEM pilot funded

25. Falsifiers

ObservationImplication
Ratified US–CN training-limit treaty with verification by 2030T2 modal wrong; revise treaty P
≥2 frontier labs public halt >90d after theft newsUnilateral slowdown P too low
C5+ reached, zero credible theft attempts through 2030Attempt P too high; open-weights reduced value more than modeled
Public 2-hour full exfil confirmedHeist P too low; revisit security model
Kinetic US strike on PRC AI DCT1 not tail — revise upward
Theft + no export ctrl expansion within 12 moModal export P too high
No guardrails meeting by 2029 despite 2026 restart promiseGuardrails P too high

26. Confidence summary

ClaimConf
Anchor at C5+ ~2028, not Feb 2027M–H
P(2 hr full heist) lowM
P(state attempt by 2030) moderate–high (~65%)M (78% expert poll)
Modal = export ctrl + spend, not pause/treatyM–H
Kinetic <0.02L–M
Treaty 0.04–0.08M
Exact branch probabilitiesL
Conditional p(doom) liftsL (needs main forecast mixture calibration)

27. External sources

28. Repo sources

  • (internal note)
  • (internal note)
  • (internal note)
  • (internal note)
  • (internal note)
  • (internal note)
  • (internal note)
  • (internal note) (Appendix 5 Security Forecast)
  • (internal note)
  • (internal note)