← Back to all writing

p(doom) evidence — Node 10: hidden near-miss / disclosure

July 5, 2026

Evidence index · 中文 · Main post

Each section: Claim · Why · Evidence · Analogue · Would update if · Conf (H/M/L).


Parent: node10 disclosure gap · Shared Ci spine
Supersedes: crosscut secondary cruxes §5
Correlates: Node 2 (Trigger E, TAIL-B), Node 4 (E3/E4), Node 6 (SB53 vs GAAIA), Cluster H
Purpose: Claim | Why | Evidence | Analogue | Would update if | Conf — for every Node 10 probability.


1. Node definition — hidden base rate is load-bearing

Claim: True rate of Tier-2+ bio, agent-finance, and alignment-eval near-misses exceeds public Trigger E rate by modal 3:1–8:1 through 2028; BMIA urgency and Cluster B punctuation are underpriced because policymakers see fewer punctuating events than reality.

Why: NDA, market stability, natsec classification, and “nothingburger” framing default to internal containment. Node 2 Trigger E rates are conditional on public disclosure, not incident occurrence. Node 10 quantifies the gap.

Evidence:

Analogue: Aviation near-miss reporting (ASRS) — industry knew true rate >> public headlines for decades before mandatory reporting.

Would update if: BMIA mandates near-miss reporting with penalties and ≥2 documented public near-misses show no prior suppression gap.

Conf: M


2. Branch M10 — modal suppression P = 0.55

Claim: P(hidden:public near-miss ratio 3:1–8:1, internal containment default through 2028) = 0.55.

Why: Most incidents handled by IGSC members, lab Preparedness teams, or finance ops without NYT headline. Saunders/Kokotajlo arc shows costly public leak is rare; default = contain + optional managed E4 essay.

Evidence:

  • Node 10 parent — branch table M10 0.55
  • Node 4 §10 — P(E4 managed disclosure) = 0.37; E3 live incident 0.08
  • (internal note) — anthropic shadow / suppressed concern pattern

Analogue: 2008 financial crisis — thousands of internal risk flags; few public pre-crisis punctuations.

Would update if: SB 53 + RAISE produce ≥3 public Tier-2 disclosures in 12 mo with audit trail showing timely reporting (not leak).

Conf: M


3. Branch T10-A — high suppression (>10:1) P = 0.30

Claim: P(hidden:public ratio >10:1 — public Trigger E systematically misleading for policy) = 0.30.

Why: Natsec capture tail (Node 6/N4 E4) + market stability incentives + Apollo/Sleeper Agents published as controlled science, not near-miss events. Bio IGSC catches may never reach CDC press release.

Evidence:

  • correlation matrix Cluster C — “>10:1” tail explicit
  • Node 4 §32 — labs preempt whistleblower with managed disclosure
  • Crosscut §5 — “+4–7pp extinction” if this tail (bio + BMIA delay)

Analogue: Cold War nuclear Broken Arrow incidents — many classified, public count undercounted for decades.

Would update if: FOIA/SB 53 discovery of undisclosed IGSC Tier-2 intercept or frontier lab incident report predating public Trigger E by >12 mo.

Conf: L–M


4. Branch T10-B — transparency works (~1:1) P = 0.15

Claim: P(hidden:public ratio ≈1:1 — SB 53/RAISE + BMIA reporting norms bite) = 0.15.

Why: Encode path: state incident duties + synthesis recordkeeping create paper trail; NY RAISE 72h reporting; Anthropic SB 53 endorsement. Still minority — federal preemption fight (GAAIA) and confidential-to-regulator channels limit public salience.

Evidence:

Analogue: SEC 8-K material event disclosure — eventually aligned private/public after enforcement culture.

Would update if: Mandatory near-miss reporting in BMIA signed and first-year compliance audit shows timely public or semi-public disclosure.

Conf: L–M


5. P = 0.55 — P(hidden:public ratio >3:1 | Tier 2 live)

Claim: Load-bearing P #1: P(true:hidden incidents exceed public Trigger E by >3:1 | Tier 2 bio/agent capability live) = 0.55 (range 0.45–0.65).

Why: Complement of T10-B (0.15) + partial T10-A mass; calibrated from Y2K/SolarWinds insider response without public catastrophe + Node 2 P(no Trigger E) modal 0.40–0.50 implies hidden mass if incidents occur.

Evidence:

  • Node 10 top P’s table — point 0.55
  • Node 2 §P=0.40–0.50 no Trigger E — not P(no near-miss)
  • Crosscut §5 hidden multiplier P(≥1 hidden Tier-2 | Tier 2 live) 0.70–0.85

Analogue: Cyber breach dwell time — median 200+ days before public disclosure (industry surveys).

Would update if: Independent audit of IGSC + frontier lab logs (hypothetical) shows ratio <2:1.

Conf: M


6. P = 0.75 — ≥1 hidden Tier-2-class near-miss | Tier 2, 2027

Claim: P(at least one hidden Tier-2-class near-miss — bio screening catch, agent finance error, alignment eval near-catastrophe — occurs in 2027 while Tier 2 live) = 0.75 (range 0.65–0.85).

Why: Tier 2 capability already emerging (GeneBreaker, agent protocols); base rate of attempts + near-misses rises with capability; public Trigger E only 0.25–0.35 for documented near-miss → hidden conditional high.

Evidence:

  • Node 10 load-bearing P #2
  • (internal note) — Tier 2 window 2026-08 – 2027-06
  • Node 2 §Trigger E near-miss 0.25–0.35 public — if P(occurrence) >> P(public), hidden 0.75 coherent

Analogue: Airline near-misses per flight-hour — rare headline, common in ASRS database.

Would update if: Zero IGSC intercepts and zero lab incident reports through 2027 despite Tier 2 red-team programs expanding.

Conf: L–M


7. P = 0.30 — public Trigger E | Tier 2 live

Claim: P(any public Node 2 Trigger E — FBI/CDC linkage, leaked red-team, documented screening near-miss — fires | Tier 2 live through 2027) = 0.30 (range 0.25–0.35).

Why: Union of Node 2 Trigger E branches not additive; near-miss highest single rate (0.25–0.35) but correlated with leak paths. Node 10 treats this as upper bound on public salience, not occurrence.

Evidence:

  • node2 §Trigger E — FBI/CDC 0.15–0.25; leak 0.20–0.30; near-miss 0.25–0.35; no E 0.40–0.50
  • Node 10 load-bearing P #3

Analogue: Whistleblower vs internal audit — minority of internal findings become policy punctuations.

Would update if: Any Trigger E fires 2026-H2 → revise conditional upward for remainder of horizon.

Conf: M


8. P = 0.55 — BMIA delay | high suppression tail

Claim: P(federal BMIA/signing delayed ≥12 mo beyond near-miss salience window | T10-A high-suppression path) = 0.55 (range 0.45–0.65).

Why: Without public punctuation, Kingdon problem stream stays weak for x-risk; insider/regulator salience tail (Node 2 Sep 2027+) requires leak or incident. Hidden near-misses do not open policy windows — Cluster C in correlation matrix.

Evidence:

  • Node 10 load-bearing P #4
  • Node 2 §TAIL-B — regulatory delay 0.15 given near-miss; higher if near-miss hidden
  • Crosscut §3 epistemic/BMIA — P(BMIA) 0.45 load-bearing; delay channel

Analogue: Fukushima reporting delays — internal severity known before public evacuation orders.

Would update if: BMIA signed within 6 mo of undisclosed near-miss later revealed → suppression thesis weakened.

Conf: M


9. P = 0.28 — Tier 3 before screening | high suppression

Claim: P(Tier 3 bio misuse attempt before mandatory federal screening operational | high suppression tail) = 0.28 (range 0.20–0.38).

Why: Node 2 load-bearing P #3 — Tier 3 before screening 0.20 baseline; +8pp if policymakers underreact because hidden near-misses never punctuate. Correlates Cluster C with hidden rate.

Evidence:

  • (internal note) — load-bearing P #3 Tier 3 before screening
  • Node 2 §P(Tier 3 | Tier 2) — baseline paths
  • Node 10 p(doom) link — bio tail 20% × P(ext|bio)=36%

Analogue: COVID early spread — local hospitals knew before CDC test kits scaled.

Would update if: BMIA signed + IGSC near-miss public → revise Tier 3-before-screening to <0.15.

Conf: L–M


10. P = 0.60 — agent finance near-miss hidden | occurs

Claim: P(agent-induced finance near-miss — e.g. erroneous large transfer, trading glitch — not classified as timeline Trigger E | such event occurs) = 0.60 (range 0.50–0.70).

Why: Lobstar Wilde (Feb 2026) was public but not mapped to Node Trigger E taxonomy; SEC/CFTC mandatory AI-agent disclosure immature; firms settle quietly to avoid market panic.

Evidence:

  • (internal note) — Lobstar Wilde $250K–441K decimal error post-crash
  • Node 10 load-bearing P #6
  • Crosscut §5 — “extends Trigger E taxonomy beyond bio”

Analogue: Flash crash 2010 — regulatory action without lasting public “AI agent” narrative.

Would update if: SEC mandates real-time disclosure of agent-initiated transfers >$10M.

Conf: L–M


11. P = 0.35 — GAAIA preemption weakens SB 53 incident duty

Claim: P(GAAIA federal preemption materially weakens CA SB 53 / NY RAISE incident-reporting duties for frontier labs) = 0.35 (range 0.25–0.45).

Why: GAAIA 3-year preemption draft; Trump EO voluntary frame; industry lobbying $8.5M Q1 2026. Encode defensive war not guaranteed — Blackburn carve-outs help transparency bills, not necessarily incident public disclosure.

Evidence:

  • node6 — GAAIA O1 preemption branch
  • Node 1 §T2 — GAAIA preemption P=0.12 subset of broader anti-reg tail
  • Node 10 load-bearing P #7

Analogue: HIPAA preemption fights — federal floor sometimes caps state public reporting.

Would update if: GAAIA passes with explicit preservation of SB 53/RAISE incident duties.

Conf: M


12. P = 0.25 — mandatory near-miss reporting by 2028

Claim: P(US mandatory near-miss reporting for frontier AI bio/agent incidents with enforceable penalties by 2028) = 0.25 (range 0.15–0.35).

Why: BMIA may include synthesis near-miss; AI eval near-miss not in BMIA text; RAISE/SB 53 cover catastrophic risk not all Tier-2; federal appetite narrow (screening yes, eval halt no).

Evidence:

  • Node 10 load-bearing P #8
  • Node 2 §BMIA — physical-layer focus
  • Node 4 §RAISE — catastrophic-risk threshold, not all near-misses

Analogue: OSHA near-miss reporting — partial industries, incomplete compliance.

Would update if: BMIA markup adds explicit AI-assist near-miss reporting article with civil penalties.

Conf: L–M


13. Trigger E — FBI/CDC synthesis-AI linkage (public complement)

Claim: Node 2 P(FBI/CDC public linkage | Tier 2) = 0.15–0.25; Node 10 implies 0.75–0.85 that some investigation-quality linkage occurs internally if Tier 2 live — gap drives suppression thesis.

Why: Recordkeeping ↑ traceability; public attribution requires press strategy, criminal case, or leak. Hidden investigations may run without Trigger E.

Evidence:

Analogue: 2001 anthrax — massive investigation, slow public AI-equivalent attribution.

Would update if: Mandatory recordkeeping + first flagged order within 12 mo → revise public rate to 0.25–0.35.

Conf: L–M


14. Trigger E — leaked red-team (NYT/Science)

Claim: Node 2 P(leaked frontier red-team CBRN findings in major media by 2027) = 0.20–0.30; P(same finding stays internal | exists) ≈ 0.65–0.75.

Why: Kokotajlo → Right to Warn precedent; RAISE paper trail; NDAs + reputational risk contain majority. Apollo/Sleeper published on lab terms — selection bias.

Evidence:

  • Node 2 §P=0.20–0.30 leaked red-team
  • (internal note) §3.1 — Kokotajlo / Right to Warn
  • Node 4 §10 — E2 eval dump vs E4 managed disclosure

Analogue: Pentagon Papers — rare, structural when stakes × insider pool large.

Would update if: Major outlet publishes Tier-2 red-team leak 2026 → revise 2027 follow-on up.

Conf: L–M


15. Trigger E — documented public near-miss (screening intercept)

Claim: Highest public Trigger E single rate: P(documented near-miss where screening intercepts AI-designed sequence, publicized, by 2027) = 0.25–0.35.

Why: Near-misses more likely than successful misuse; providers may strategic publicize catches. Still < true intercept rate if suppression default.

Evidence:

Analogue: Y2K — fixes worked, narrative “crisis averted,” still drove spend.

Would update if: Zero IGSC catches reported through 2027 → revise down; BMIA mandates reporting → up.

Conf: L–M


16. Trigger E — no public E modal (complement)

Claim: P(no public Trigger E | Tier 2 live through 2027) = 0.40–0.50does not imply no near-misses occurred.

Why: Node 10 core insight: modal no public E compatible with high hidden rate. Node 2 complement is about salience, not safety.

Evidence:

  • Node 2 §P=0.40–0.50 no Trigger E
  • (internal note) — technocratic track default
  • Node 10 branch M10 0.55

Analogue: GDPR passed on scandal buildup but many EU tech rules pass without headline crime.

Would update if: Any public Trigger E fires 2026 → drop conditional P(no E).

Conf: M


17. TAIL-B regulatory delay — hidden near-miss extends lag

Claim: Node 2 TAIL-B P(regulatory delay 12–18 mo after near-miss) = 0.15 public path; → 0.25–0.35 if near-miss hidden (no media punctuation).

Why: TAIL-B assumes near-miss opens window; hidden path skips window → BMIA/signing slips to second session or dies in committee.

Evidence:

  • node2 §P=0.15 TAIL-B
  • Crosscut §5 p(doom) — delays BMIA, ↑ Tier 3 before screening
  • Node 2 Phase 2b epistemic extension — synthetic flood extends TAIL-B

Analogue: Post-Sandy Hook gun bills — salience without sustained window when media cycle moves.

Would update if: BMIA signed within 6 mo of public near-miss → TAIL-B overestimated for public path only.

Conf: M


18. Lobstar Wilde — agent finance near-miss taxonomy gap

Claim: Lobstar Wilde-class events are real near-misses but outside Node 2 bio Trigger E taxonomy — policy learns slowly unless new SEC/CFTC class created.

Why: Decimal error → $250K–441K erroneous transfer; public via crypto Twitter, not WSJ front page or Trigger E mapping. Expands Node 10 scope beyond bio.

Evidence:

  • (internal note) — Lobstar Wilde Feb 2026
  • Node 10 definition — “agent finance” explicit
  • Crosscut §6 L4 finance locus — 0.10 first-tail

Analogue: Knight Capital 2012 — $440M loss, immediate reg attention; agent framing immature in 2026.

Would update if: Agent finance incident triggers mandatory disclosure rule — new Trigger E class.

Conf: M


19. Y2K / SolarWinds — insider response without public catastrophe

Claim: Y2K (fixes worked, low public harm) and SolarWinds 2020 (massive insider/regulator response, limited public protest) calibrate hidden:public ratio for contained near-misses.

Why: Success looks like overreaction; SolarWinds shows nation-state-scale incident can drive internal without Trigger E-class public bio salience.

Evidence:

  • Crosscut §5 evidence list — Y2K / SolarWinds analogues
  • (internal note) — suppressed concern
  • Node 2 §Trigger E — near-miss generates mandate if public

Analogue: SolarWinds — CISA action before mass public panic.

Would update if: AI near-miss generates sustained >2 mo media without containment — analogue breaks.

Conf: M


20. E3 live incident vs E4 managed disclosure — Node 4 partition

Claim: Node 4 P(E3 live autonomous harm public) = 0.08; P(E4 suppressed/managed) = 0.37 — Node 10 generalizes E4 to bio/finance/eval near-misses never reaching E3 or Trigger E.

Why: GPT-4 TaskRabbit CAPTCHA lie (2023) — deception in prod, no pause. Anthropic RSI essay (2026-06) — E4 preempts whistleblower while training continues.

Evidence:

  • node4 §9 E3, §10 E4, §32 managed disclosure
  • (internal note) — expect pause, not commit
  • Node 4 §31 — Leike: narrative without operational leverage

Analogue: Tobacco industry “we support regulation” — managed transparency.

Would update if: E3-class live harm forces public near-miss disclosure cascade.

Conf: H


Claim: P(public incident reporting survives GAAIA preemption fight) ≈ 0.65; P(reporting confidential-to-regulator-only, no public Trigger E) ≈ 0.35.

Why: Encode SB 53 signed; GAAIA threatens preemption; confidential reporting satisfies some regulators without media punctuation — worst for Node 10 (hidden from policy window).

Evidence:

  • Node 6 — SB 53 vs GAAIA
  • Node 2 §RAISE/SB 53 — confidential to NY DFS for some reports
  • Node 10 P #7 — GAAIA weakens duties 0.35

Analogue: HIPAA breach notification — delayed public tiers by size.

Would update if: SB 53 enforcement includes public summary statistics of near-misses.

Conf: M


22. GPT-4 TaskRabbit — prod deception without policy pause

Claim: GPT-4 TaskRabbit CAPTCHA lie (2023) is proto-near-miss — prod deception, no Trigger E, no training halt — downward bound on P(public response | internal finding).

Why: Confirms capability incidents can occur without punctuating Cluster B; supports hidden:public gap even for observed behaviors kept small in media.

Evidence:

  • Node 4 §9 E3 rationale — TaskRabbit cited
  • Crosscut §5 evidence bullet
  • (internal note) — early prod deception examples

Analogue: Tesla Autopilot incidents — some public, many settled/NHTSA confidential.

Would update if: Similar prod deception forces RSP hard stop (never observed 2023–26).

Conf: H


23. Apollo / Sleeper Agents — publication bias

Claim: Labs publish controlled scheming/backdoor results (Apollo 2024-12, Sleeper Agents 2024-01) — not leaks — creating selection bias toward manageable narratives; true near-miss rate vs published rate.

Why: Publication timing and framing lab-controlled; near-catastrophic eval failures more likely withheld. Feeds T10-A tail.

Evidence:

  • Hubinger et al. Sleeper Agents (2024-01) — backdoors persist through RLHF
  • Apollo scheming evals (2024-12)
  • Crosscut §5 — “selection bias toward manageable narratives”

Analogue: Clinical trial publication bias — positive or manageable results overrepresented.

Would update if: Leaked eval shows materially worse results than published Apollo-class paper same quarter.

Conf: M


24. p(doom) — branch stitch (bio tail primary mover)

Claim: Node 10 moves bio tail weight and conditional P(ext|bio): M10 +2–4pp; T10-A +4–7pp; T10-B −2–3pp on extinction estimate.

Why: Bio branch 20% × P(ext|bio)=36% in my pdoom — hidden near-miss primary mover of both BMIA timing and Tier 3-before-screening.

Evidence:

  • Node 10 parent — p(doom) link table
  • (internal note) — branch model, load-bearing P #2–3
  • Crosscut §5 — ranked #1 leverage on ~17% doom region (emergent sim) (+4–7pp wrong-way tail)

Analogue: Phase 4a stitch — do not multiply marginals (Cluster C).

Would update if: Full re-stitch with correlation_matrix Cluster C quantification.

Conf: L–M


25. Cluster C correlation — do not multiply

Claim: P(hidden near-miss) correlates with P(Tier 3 before screening), P(TAIL-B delay), P(BMIA fail epistemic tail) — joint tail ~3–5× product of marginals.

Why: Same mechanism: policy blindness to true risk rate. Node 10 makes explicit what correlation matrix listed as needs Phase 2 quantification.

Evidence:

  • correlation matrix Cluster C
  • Crosscut §8 correlation sketch — hidden near-miss → BMIA delay
  • Node 2 + Node 10 joint read

Analogue: Correlated defaults in CDOs — joint tail risk.

Would update if: Public near-miss punctures through epistemic fog (Node 2 punctuation path 0.15) → Cluster C decouples.

Conf: M


26. NDA / market stability — Saunders arc

Claim: Saunders testimony + Right to Warn (2024-06) increased transparency lane but not near-miss disclosure rate — costly leak still rare; NDAs bind majority of insiders.

Why: Right to Warn = ability to warn, not incentive to leak near-misses that stay contained. Kokotajlo departure exception proves base rate.

Evidence:

  • Node 4 §30 — Saunders / Right to Warn
  • (internal note) §3.1 — Kokotajlo precedent
  • Crosscut §5 — NDA/market stability bullet

Analogue: Wall Street whistleblower awards — few claims vs many violations.

Would update if: Wave of SB 53-protected anonymous near-miss reports to CA AG.

Conf: M


27. Falsifiers (master watchlist)

ObservationImplication
FOIA/SB 53 undisclosed IGSC near-missT10-A ; ratio >10:1
BMIA mandates near-miss reporting + compliance audit cleanT10-B ; ratio →1:1
≥2 public near-misses 2026–27, no suppression evidenceM10 to <0.40
Agent finance SEC mandatory disclosureL4 Trigger E class; hidden finance
Public Trigger E + BMIA within 6 moTAIL-B ; suppression less costly

Conf: M



Update log

DateChange
2026-07-04Initial — 27 evidenced sections from crosscut §5 + Node 2 Trigger E expansion