If anyone builds superintelligence, everyone dies. That is, it is extremely reckless to build AI systems more intelligent than all humans, given anything like our current technical understanding. To address this, MIRI and others have suggested an immediate and decisive halt to pushing the frontier of general AI capabilities.
We think the existing arguments are strong, but many others are waiting for more evidence. This is explainable in part by the large contrast between the harms caused by current and future AI systems.
People in AI governance often talk about warning shots: events which could solve this conundrum, often by causing less-than-existential harm. This post attempts to analyze the likelihood of a successful warning shot for superintelligence, where success requires that the warning shot lead to effective action. We first propose a framework for predicting whether a warning shot will occur and be successful. We apply the framework to analyze commonly-discussed warning shots: AI-caused pandemics, various military applications, and cyber misuse affecting critical infrastructure.
In considering these cases and the framework, we conclude that it is quite plausible that there will simply be no warning shot which generates an appropriate response. Therefore, we think the AI governance community and policymakers should not be waiting for warning shots; the time for action is now.
A Framework for Predicting Whether Warning Shots Will Work
To motivate an effective response, a warning shot will need to meet these criteria1:
Likely: To motivate an effective response, a warning shot will need to occur. From our perspective, we ask whether the event is plausible given our current understanding.
Timely: It occurs early enough to be reacted to. Conditional on it occurring, will it precede the closing of the window for an effective preventive response?
Visceral: The event makes an impression. It is noticed. Muchof thediscourse on warning shots focuses on the power of visceral harms to motivate a response, but this is not sufficient on its own, hence the rest of the framework.
Sudden: The event happens or the visceral impacts occur over a short timeframe, so that individuals and societies experience “a moment”. The alternative dynamic is referred to as “frog boiling”, where individuals and society fail to notice the event or its implications because they gradually get accustomed to a new normal. Society might wake up without an event being sudden, but it seems much harder.
Unexpected: To change an observer’s beliefs, an observation needs to not have been totally predicted by that observer. That is, our audience has to notice that something happened which they didn’t expect to prompt reexamination of their current beliefs. It will likely need to be substantially outside of what they previously considered plausible to not be written off as a (un)lucky or one-off occurrence.
Attribution: It is perceived as being caused by AI; difficult to deny that AI progress is materially involved. It is not critical that AI was actually responsible.
Backlash: It motivates hostility toward continued AI development rather than enthusiasm. This is required in order to motivate restraints on AI development which actually make a difference in averting existential risk. Backlash can be undermined when the warning shot indicates that further investment in, or deployment of AI is warranted. This might happen when response is channeled into societal resilience rather than prevention.
Response Availability: Is a well-formed, legitimate policy response already available with well positioned advocates? Have policies of first resort been tried and shown to be ineffective? Crises can open windows for new policy, but these are often filled with policies which are ready and perceived to be easy. This is one area where the AI governance field can have a large impact, and where there is much work that has already been done. We exclude this from our analysis below, as it is largely agnostic to the properties of individual warning shots, but note it here, as in practice a warning shot being converted into policy may depend on the availability of a response.
For each class of warning shot below, we give a coarse grade of pass, uncertain, or fail to each criterion.
Which warning shots are expected to be strong?
AI-Caused Pandemics
COVID-19 caused between 15 million and 35 million extra deaths worldwide. It is also an example of tremendous harm not leading to an appropriate preventive response: society could purchase effective resilience against a future pandemic through any number of methods (stockpiling PPE, vaccine distribution pre-logistics, wastewater monitoring, hardening buildings against airborne spread through UV treatment and/or filtering), but has done surprisingly little of this2.
How likely is AI to facilitate a human-caused pandemic? Cutting edge AI systems have already demonstrated the ability to expand the number of actors who could perform dangerous pathogen development (source, source). Safeguarding frontier models against this kind of misuse is the object of substantial effort, but these safeguards are not perfect. Furthermore, impossible-to-safeguard open source model capabilities continue to advance. So we seem to already be taking risks that even present systems will be misused to this end.
A severe pandemic could close the window for effective governance by severely burdening society with managing its harms, while at the same time not so severely impacting the pace of frontier AI development. This means that while under “normal” circumstances society could react in a timely fashion, it is quite plausible that this type of warning shot could quickly move us past a point of no return.
A pandemic causing substantial harm is very often top-of-mind when considering warning shots because of its obvious viscerality, suddenness, and unexpectedness.
However, would an AI-caused pandemic be attributable to AI? This is the first major problem for a pandemic as a warning shot. The question of COVID-19’s origin remains unresolved, and this is not an uncommon occurrence for pandemics: the 1918 Spanish Flu’s geographic origin is still unresolved.
Even putting aside the baseline difficulty of determining the origin of a pandemic, we then have to turn to determining whether a pandemic was dependent on AI assistance in a meaningful and salient way. Standard epidemiological techniques are even less relevant to this question. It is not certain that an AI-caused pathogen would exhibit any indication that it was designed with the help of AI vs. occurring naturally.
One hope is that if it is a hosted model which is misused to create a pandemic, the model provider could examine its own records to find the queries that led to a novel pathogen. Some issues with this include:
Not all providers will retain this data. Even looking at the current data retention policies of Anthropic and OpenAI, such retention would likely require the conversation being classified as dangerous. But if these safeguards are insufficient to prevent misuse they may also be insufficient to classify a conversation as problematic in the first place.
The provider would have to cooperate with the authorities, but they may prefer to conceal the misuse.
The conversation would have to be associated with the pandemic in question. This could be frustrated by using multiple accounts and models to this end, fragmenting the work across multiple conversation streams.
A competent malicious actor will prefer to avoid hosted models which it expects are sufficiently monitored for misuse.
A final problem with pandemics is a lack of backlash. The benefits of advanced AI in the biomedical domain have long been touted, and a new pandemic will likely feature AI assistance as part of its crisis response. This all leads to a pandemic being a clear excuse to accelerate the development and adoption of AI systems in pandemic preparedness.
Additionally, the response to a pandemic, especially in light of the expected difficulty of attribution, is to instead properly pursue pandemic preparedness. Methods for employing AI to this end, such as in AI-aided monitoring of genetic synthesis, further undermines the potential for backlash against AI capabilities advancement.
Military Application: Command and Control
This wake-up call asks what happens when military leaders see firsthand what capable machine intelligence can do for their conduct of war. While it is a trope of science fiction to integrate advanced artificial intelligence systems into military command and control, we are in fact already living in a time where this is largely the case and the nature of the developments is at risk of being overlooked and misunderstood.
In the US military, the Maven Smart System began development in 2017, and has been in use for several years. It integrates data collection with modern machine learning techniques including vision and language models. Its use has grown to include an estimated 80,000 US personnel. Integration of LLMs produces a fivefold increase in targeting speed, beyond the tenfold increase that vision models already provided. (link) It also expands the quantity of sensors which can be continuously employed: previously there was simply too much incoming footage for humans to review.
Viscerality and Suddenness
We cannot know the full employment of AI in warfighting outside of a classified setting. This frustrates the viscerality of this warning shot and/or restricts the audience. Given the long history of the employment of AI (and computing generally) by the military, which includes many stages of development and an incremental increase and refinement in capabilities, along with a gradual rollout to wider usage, we should expect that the full impact of this warning shot has likely been diluted by frog-boiling.
Backlash
Backlash against AI capabilities progress seems to be quite a stretch for this warning shot. Our own military is experiencing a tremendous increase in utility without a clear downside. Even if a rival were to match US capabilities, it would increase the desire to lead in this area, rather than to constrain development.
Furthermore, initial skepticism or even hostility by some operators toward AI employment reportedly erodes with exposure and the speed and throughput demands of modern operations.
Military/Police Application: Robotics
What would happen if we witness a realization of some of the darkest Hollywood fears related to AI: armed machines visibly policing, fighting, or hunting human beings? Consider this progression:
Aerial quadcopter drones hunt humans, as in Ukraine in from 2024
Unmanned ground vehicles (UGVs) in the form of ground drones or quadruped (“dog”) platforms support or lead infantry operations
Ukraine has conducted robot-only assaults in which Russian soldiers surrendered to machines, and in April 2026 captured a position using unmanned platforms alone
Drones are used in police applications to do jobs which require the threat or implementation of violence, like security or riot control, going beyond surveillance or tracking
weaponized robots employed at scale in police or riot control work, in the United States or another wealthy democracy?
a highly publicized military campaign against a civilian population to which we’ve not already acclimated, like a Russian incursion against Poland or a Chinese invasion of Taiwan?
Footage of an armed robot confronting a human being is undeniably visceral. Decades of Hollywood priming amplifies this: audiences expect killer robots in fiction and could register their appearance on real streets as a threshold crossed.
There is a concern for suddenness, however. Each step of the progression so far has occurred without producing a global moment: drone-delivered tear gas in 2018 and 2024 generated regional outrage and no lasting response, and robotic assaults in Ukraine are covered as defense-industry news. The moment presumably arrives when the imagery is domestic–machines suppressing a crowd of one's fellow citizens–but it must overcome this gradual normalization of the use of robotics for these purposes.
Will such applications, especially for the policing of civilian populations, be attributed to, or even associated with, advanced AI development? There are a couple of ways that frontier AI development could drive or unlock rapid progress in robotics for police applications:
Sim-to-real methods for solving complex problems in robotics
AI-assisted design and programming of drones
AI-operated drones, either locally or remotely
How likely are these to be true of a given warning shot? It might not matter if the perception of this warning shots leads to pushback against AI broadly as a result. The greater risk is that attribution lands on the wrong target: on the platforms, their manufacturers, and the police departments deploying them, rather than on the AI development pipeline upstream.
Military employment of robotics could also frustrate backlash. Ukraine frames robotic infantry as the technology that lets machines die instead of soldiers, with the General Staff crediting robotic platforms for reducing personnel casualties by up to 30 percent. A public that sees machines taking casualties instead of soldiers will call for its own military to adopt the technology as rapidly as possible.
Military Applications: Software and Drone Control
AI-enabled military technology might wake up a national security audience. This audience may see the security implications, even if there aren't widespread societal effects.
Given current trends, AIs will probably become superhuman at software tasks before they become superhuman at hardware design tasks. The earliest potential warning shot related to military technology will probably be software developments.
One candidate development is the design of much better drone software. Such software may be able to radically improve the capabilities of drones, even with the same hardware. These drones will be limited to their existing on-board computers and so will not be running the advanced AI systems themselves. Instead, the AI systems will write specialized on-board software for the drones. Drones will possibly also send and receive communications from these advanced AI systems.
Demonstrations of these upgraded drone capabilities must also be sufficiently visceral. For example:
In autonomous drone dogfights, one upgraded drone may be able to beat 10 drones running the previous state of the art software.
An upgraded drone may be able to trounce the best human drone pilots, even when extremely outnumbered.
Upgraded drones may be able to evade the best drone defense.
There may also be real-world uses of these systems, such as drones used for targeted assassinations, even in locations which were supposedly defended from drones; or taking out large, well-defended military targets.
For military technology via software to act as a warning shot, the main concerns are whether the relevant audience wakes up and what the response would be.
These developments might be seen as the normal progression of military technology. However, this is less likely if the audience perceives this as a step change in military capabilities, for example, if this new technology is able to easily beat previous generations. This AI-enabled military technology may also be deployed in real combat, which could make this more visceral, for example, if a relatively small number of AI-upgraded units was able to take out a much larger opposing force.
Potentially the largest issue is whether this would generate backlash. AI might be seen as an amazing military opportunity which could prompt further investment. Backlash, if it occurs at all, might be limited to governments which lag the cutting-edge of AI, and only for those governments which have sufficient intelligence to understand how far behind they are.
Cyber Misuse: Critical Infrastructure
This warning shot consists of an event in which critical infrastructure is compromised through a cyberattack materially leveraging AI capabilities, producing visceral disruption to a service society depends on.
Likelihood and Timeliness
Critical infrastructure is a large category, especially when using a definition encompassing any infrastructure necessary for the continued functioning of society and the economy. This includes at least housing, heating, food production and distribution, water and power supply, transportation, police and military operation, communications, and financial services. This provides a large attack surface, and makes preemptive defense a huge task.
Cyberattacks on critical infrastructure, without AI, have already happened repeatedly:
In 2015, power service to about 230,000 Ukrainians was disrupted for a few hours as a result of a cyberattack which compromised information systems of three energy distribution companies.
In 2016, a substation outside of Kyiv was briefly brought offline, though the attack intended to cause longer-lasting damage.
In 2021, Colonial Pipeline, which provides gasoline and jet fuel to the Southeastern United States, was the target of a ransomware attack, in which billing systems were compromised and held at ransom. This led the operator to suspend pipeline operations, causing fuel shortages across the region. A ransom of $4.4 million USD was paid to the attackers.
These attacks predate the availability of capable AI agents. Regarding AI, we also already have examples of cyber misuse:
In 2025, Anthropic (partially) disrupted a cyber operation that leveraged Claude Code, in which an AI agent autonomously executed the majority of the operation. They write “This campaign demonstrates that the barriers to performing sophisticated cyberattacks have dropped substantially—and we can predict that they’ll continue to do so.”
In 2025-2026, a breach of nine Mexican government agencies showed clear evidence of AI coding agents being used to exploit vulnerabilities, leading to the compromise of large amounts of private data.
These are not examples of mere AI-assistance in offensive cyber operations, but rather examples of AI-driven autonomous operation. This fact should lower our estimation of how much human and organizational expertise and resources will be required to execute effective attacks as these capabilities advance.
There are some factors which cut against the likelihood of this warning shot.
Perhaps efforts to provide early access to powerful AI systems to defenders of critical infrastructure will enable them to secure their systems against attacks aided by an equivalent level of AI capability, by finding and patching vulnerabilities before they can be detected and exploited. Whether offense or defense will win in general, and in the area of critical infrastructure, is unclear, but there are at least some reasons to favor defenders. (Lohn 2025)
Will there be sufficient financial or political motivation for an attack severe enough to register? The Colonial Pipeline case suggests the financial rewards of holding critical infrastructure for ransom exist, but may be unreliable and draw the attention of authorities. Perhaps a more likely motivation is political or strategic. The number of politically motivated actors capable of causing real damage is increasing as autonomous offensive capabilities spread.
Viscerality
This category of warning shot gets a relatively easy pass on viscerality, because it is defined as events which interrupt critical services. Colonial Pipeline is arguably the most felt cyber event in U.S. history — gas lines, panic buying, fuel-price spikes, and direct White House involvement — and all this despite causing no physical damage and never touching the pipeline's control systems.
On the other hand, the Ukraine grid attacks, though more technically sophisticated and genuinely destructive, only interrupted the electrical supply for hours and made little lasting impression on audiences outside the security community. This suggests that visible disruption to everyday life drives viscerality more than technical sophistication or physical damage does.
Suddenness
Given the history of cyberattacks (including those with substantial use of AI), there is a real risk that audiences will be frog-boiled on cyber misuse. Warnings could be followed by increasing frequency and severity of attacks over time without creating a clear shared moment to motivate a response.
Unexpectedness
Relatedly, very few observers will be surprised by increasing ill effects of proliferated cyber capabilities. Events of this sort have historical precedent, are well represented in fiction and film, and have been warned about for years. As a result, what will be necessary for this to be unexpected is at least one of (a) the harm caused by the attack is especially severe or widespread or (b) the AI assistance was of an unexpected level of utility or power.
In July of 2026, water utilities in Minnesota were disrupted by a cyberattack, and while AI’s contributions have not yet been confirmed, it is expected, given the availability of AI agents, that more attacks of this sort will occur in the future.
Attribution
This warning shot anticipates the combination of AI assistance in the means of an attack with critical infrastructure as the target, leading to visceral impacts. Because AI capabilities relevant to cyber operations have already proliferated, it is essentially assured that AI assistance will be used in the next attack on critical infrastructure.
AI employment, especially in the form of autonomous systems, could be relatively easy to detect, as in the example of the Mexican government data breach, where the speed at which code changes were authored is a clear sign that AI assistance was used. We may also be so lucky as in Anthropic’s detection of the November 2025 campaign, in which attribution came directly from the model provider.
Backlash
“if AI models can be misused for cyberattacks at this scale, why continue to develop and release them? The answer is that the very abilities that allow Claude to be used in these attacks also make it crucial for cyber defense.” - Anthropic
The most likely outcome is that any potential backlash against AI development is redirected toward employment of AI for defensive purposes. This argument may flounder in the face of sufficient and visceral harms. At some point, society will not tolerate continued disruption and begin to suspect that AI-aided cyber defense is not viable to counteract the effects of AI-aided cyber offense.
Another possibility is that backlash against AI could be swamped by circumstances surrounding its employment in an attack. For example, if a US adversary uses AI for offensive cyber operations which target critical infrastructure, it would probably be in the context of some larger geopolitical crisis. There will be little energy to think about AI development and its consequences while we are faced with a clear external threat of a rival who is disrupting critical infrastructure as part of a larger crisis or conflict, and that external rival will absorb the backlash rather than the enabling technology.
Conclusion and Future Research
We hope this research can prompt some needed skepticism for the position that it is prudent to adopt a “wait and see” attitude toward the threat of AI risks.
We are excited to see the framework applied to other warning shots. These include: economic impacts of AI (including job loss), covert or kinetic conflict between great powers over AI, and the emergence of fully autonomous rogue AI systems (either intentionally created or self-exfiltrated).
Finally, it is possible that, rather than a singular warning shot, there will be many steps on the road to effective governance of the development of artificial superintelligence. These steps could include warning shots, shifts in the discourse, and the iterative implementation of imperfect policy. Is it plausible that we have time for this potentially lengthy process before it is too late? Especially regarding imperfect policy, what could distinguish steps which move us closer to effective governance rather than backtrack away from it? We are excited about future work which deeply engages with this question.
Appendix: Select Warning Shots
We’re interested in many other warning shots, and a partial list is included here:
Bio misuse foiled – An incidence or pattern of biological misuse of AI capabilities being detected and foiled, perhaps reported by AI providers or by intelligence agencies.
Bio uplift demonstration – A visceral demonstration of how AI tools dramatically increase the number of bio-risk relevant actors
Stock market crash – Some large downward movement of the stock market that is caused by or closely associated with AI.
Significant job loss – Majority un- or under-employment, especially for young people / college graduates.
Transformative job loss – What historically happened to weavers with the advent of mechanical looms but for all (cognitive) human labor.
Runaway inflation – What is happening for computer RAM affects other key inputs, particularly energy but perhaps others, ultimately massively increasing the prices of electricity, food, water, land, etc
Whistleblowing by frontier lab employees – A number of researchers whistleblow on the risks of continued development.
Recursive self-improvement – Humans are no longer directly involved in the research required to advance AI capabilities.
Novel scientific contributions attributed to AI – “A flood of groundbreaking arXiv papers” as described here.
Anticipated but alarming demos or applications – For example, mosquito-sized autonomous weapons or effective superpersuasion
Misalignment: Refusals – Military systems refusing to fight or automated AI researchers refusing to work
Rogue AI: Near Miss – Catching an AI system in the act of self-exfiltration of weights.
Rogue AI: Escaped – AI systems are stably independent of human control, with independent access to resources (money, compute).
Transformative AI-powered surveillance – Domestic applications of AI leveraging currently-proliferating methods of data collection enable powerful surveillance applications, and this generates backlash. Could also include open-sourcing of such tools enabling widespread access and misuse.
AI ruins encryption – AI finds exploitable weaknesses in widely-deployed cryptography (or accelerates cryptanalysis enough to matter), threatening secure comms, financial systems, and stored secrets.
Undermining Deterrence – AI is used to undermine the existing condition of stable deterrence against nuclear first use, such as by enabling some of: orbital detection of submarines, missile interception, tracking of mobile launchers, perfect cyber offense against nuclear command and control, etc.
Introduction
If anyone builds superintelligence, everyone dies. That is, it is extremely reckless to build AI systems more intelligent than all humans, given anything like our current technical understanding. To address this, MIRI and others have suggested an immediate and decisive halt to pushing the frontier of general AI capabilities.
We think the existing arguments are strong, but many others are waiting for more evidence. This is explainable in part by the large contrast between the harms caused by current and future AI systems.
People in AI governance often talk about warning shots: events which could solve this conundrum, often by causing less-than-existential harm. This post attempts to analyze the likelihood of a successful warning shot for superintelligence, where success requires that the warning shot lead to effective action. We first propose a framework for predicting whether a warning shot will occur and be successful. We apply the framework to analyze commonly-discussed warning shots: AI-caused pandemics, various military applications, and cyber misuse affecting critical infrastructure.
In considering these cases and the framework, we conclude that it is quite plausible that there will simply be no warning shot which generates an appropriate response. Therefore, we think the AI governance community and policymakers should not be waiting for warning shots; the time for action is now.
A Framework for Predicting Whether Warning Shots Will Work
To motivate an effective response, a warning shot will need to meet these criteria1:
For each class of warning shot below, we give a coarse grade of pass, uncertain, or fail to each criterion.
Which warning shots are expected to be strong?
AI-Caused Pandemics
COVID-19 caused between 15 million and 35 million extra deaths worldwide. It is also an example of tremendous harm not leading to an appropriate preventive response: society could purchase effective resilience against a future pandemic through any number of methods (stockpiling PPE, vaccine distribution pre-logistics, wastewater monitoring, hardening buildings against airborne spread through UV treatment and/or filtering), but has done surprisingly little of this2.
How likely is AI to facilitate a human-caused pandemic? Cutting edge AI systems have already demonstrated the ability to expand the number of actors who could perform dangerous pathogen development (source, source). Safeguarding frontier models against this kind of misuse is the object of substantial effort, but these safeguards are not perfect. Furthermore, impossible-to-safeguard open source model capabilities continue to advance. So we seem to already be taking risks that even present systems will be misused to this end.
A severe pandemic could close the window for effective governance by severely burdening society with managing its harms, while at the same time not so severely impacting the pace of frontier AI development. This means that while under “normal” circumstances society could react in a timely fashion, it is quite plausible that this type of warning shot could quickly move us past a point of no return.
A pandemic causing substantial harm is very often top-of-mind when considering warning shots because of its obvious viscerality, suddenness, and unexpectedness.
However, would an AI-caused pandemic be attributable to AI? This is the first major problem for a pandemic as a warning shot. The question of COVID-19’s origin remains unresolved, and this is not an uncommon occurrence for pandemics: the 1918 Spanish Flu’s geographic origin is still unresolved.
Even putting aside the baseline difficulty of determining the origin of a pandemic, we then have to turn to determining whether a pandemic was dependent on AI assistance in a meaningful and salient way. Standard epidemiological techniques are even less relevant to this question. It is not certain that an AI-caused pathogen would exhibit any indication that it was designed with the help of AI vs. occurring naturally.
One hope is that if it is a hosted model which is misused to create a pandemic, the model provider could examine its own records to find the queries that led to a novel pathogen. Some issues with this include:
A final problem with pandemics is a lack of backlash. The benefits of advanced AI in the biomedical domain have long been touted, and a new pandemic will likely feature AI assistance as part of its crisis response. This all leads to a pandemic being a clear excuse to accelerate the development and adoption of AI systems in pandemic preparedness.
Additionally, the response to a pandemic, especially in light of the expected difficulty of attribution, is to instead properly pursue pandemic preparedness. Methods for employing AI to this end, such as in AI-aided monitoring of genetic synthesis, further undermines the potential for backlash against AI capabilities advancement.
Military Application: Command and Control
This wake-up call asks what happens when military leaders see firsthand what capable machine intelligence can do for their conduct of war. While it is a trope of science fiction to integrate advanced artificial intelligence systems into military command and control, we are in fact already living in a time where this is largely the case and the nature of the developments is at risk of being overlooked and misunderstood.
In the US military, the Maven Smart System began development in 2017, and has been in use for several years. It integrates data collection with modern machine learning techniques including vision and language models. Its use has grown to include an estimated 80,000 US personnel. Integration of LLMs produces a fivefold increase in targeting speed, beyond the tenfold increase that vision models already provided. (link) It also expands the quantity of sensors which can be continuously employed: previously there was simply too much incoming footage for humans to review.
Viscerality and Suddenness
We cannot know the full employment of AI in warfighting outside of a classified setting. This frustrates the viscerality of this warning shot and/or restricts the audience. Given the long history of the employment of AI (and computing generally) by the military, which includes many stages of development and an incremental increase and refinement in capabilities, along with a gradual rollout to wider usage, we should expect that the full impact of this warning shot has likely been diluted by frog-boiling.
Backlash
Backlash against AI capabilities progress seems to be quite a stretch for this warning shot. Our own military is experiencing a tremendous increase in utility without a clear downside. Even if a rival were to match US capabilities, it would increase the desire to lead in this area, rather than to constrain development.
Furthermore, initial skepticism or even hostility by some operators toward AI employment reportedly erodes with exposure and the speed and throughput demands of modern operations.
Military/Police Application: Robotics
What would happen if we witness a realization of some of the darkest Hollywood fears related to AI: armed machines visibly policing, fighting, or hunting human beings? Consider this progression:
Could this be followed by…
That the first three steps of this progression have already occurred might give us some confidence that these next steps are likely and timely. Both Ukraine and Russia are mass-producing ground combat robots; Ukraine's defense ministry reported nearly 24,500 UGV missions in the first quarter of 2026, and China is exporting armed quadrupeds and the operational concepts for using them.
Footage of an armed robot confronting a human being is undeniably visceral. Decades of Hollywood priming amplifies this: audiences expect killer robots in fiction and could register their appearance on real streets as a threshold crossed.
There is a concern for suddenness, however. Each step of the progression so far has occurred without producing a global moment: drone-delivered tear gas in 2018 and 2024 generated regional outrage and no lasting response, and robotic assaults in Ukraine are covered as defense-industry news. The moment presumably arrives when the imagery is domestic–machines suppressing a crowd of one's fellow citizens–but it must overcome this gradual normalization of the use of robotics for these purposes.
Will such applications, especially for the policing of civilian populations, be attributed to, or even associated with, advanced AI development? There are a couple of ways that frontier AI development could drive or unlock rapid progress in robotics for police applications:
How likely are these to be true of a given warning shot? It might not matter if the perception of this warning shots leads to pushback against AI broadly as a result. The greater risk is that attribution lands on the wrong target: on the platforms, their manufacturers, and the police departments deploying them, rather than on the AI development pipeline upstream.
Military employment of robotics could also frustrate backlash. Ukraine frames robotic infantry as the technology that lets machines die instead of soldiers, with the General Staff crediting robotic platforms for reducing personnel casualties by up to 30 percent. A public that sees machines taking casualties instead of soldiers will call for its own military to adopt the technology as rapidly as possible.
Military Applications: Software and Drone Control
AI-enabled military technology might wake up a national security audience. This audience may see the security implications, even if there aren't widespread societal effects.
Given current trends, AIs will probably become superhuman at software tasks before they become superhuman at hardware design tasks. The earliest potential warning shot related to military technology will probably be software developments.
One candidate development is the design of much better drone software. Such software may be able to radically improve the capabilities of drones, even with the same hardware. These drones will be limited to their existing on-board computers and so will not be running the advanced AI systems themselves. Instead, the AI systems will write specialized on-board software for the drones. Drones will possibly also send and receive communications from these advanced AI systems.
Demonstrations of these upgraded drone capabilities must also be sufficiently visceral. For example:
There may also be real-world uses of these systems, such as drones used for targeted assassinations, even in locations which were supposedly defended from drones; or taking out large, well-defended military targets.
For military technology via software to act as a warning shot, the main concerns are whether the relevant audience wakes up and what the response would be.
These developments might be seen as the normal progression of military technology. However, this is less likely if the audience perceives this as a step change in military capabilities, for example, if this new technology is able to easily beat previous generations. This AI-enabled military technology may also be deployed in real combat, which could make this more visceral, for example, if a relatively small number of AI-upgraded units was able to take out a much larger opposing force.
Potentially the largest issue is whether this would generate backlash. AI might be seen as an amazing military opportunity which could prompt further investment. Backlash, if it occurs at all, might be limited to governments which lag the cutting-edge of AI, and only for those governments which have sufficient intelligence to understand how far behind they are.
Cyber Misuse: Critical Infrastructure
This warning shot consists of an event in which critical infrastructure is compromised through a cyberattack materially leveraging AI capabilities, producing visceral disruption to a service society depends on.
Likelihood and Timeliness
Critical infrastructure is a large category, especially when using a definition encompassing any infrastructure necessary for the continued functioning of society and the economy. This includes at least housing, heating, food production and distribution, water and power supply, transportation, police and military operation, communications, and financial services. This provides a large attack surface, and makes preemptive defense a huge task.
Cyberattacks on critical infrastructure, without AI, have already happened repeatedly:
These attacks predate the availability of capable AI agents. Regarding AI, we also already have examples of cyber misuse:
These are not examples of mere AI-assistance in offensive cyber operations, but rather examples of AI-driven autonomous operation. This fact should lower our estimation of how much human and organizational expertise and resources will be required to execute effective attacks as these capabilities advance.
There are some factors which cut against the likelihood of this warning shot.
Perhaps efforts to provide early access to powerful AI systems to defenders of critical infrastructure will enable them to secure their systems against attacks aided by an equivalent level of AI capability, by finding and patching vulnerabilities before they can be detected and exploited. Whether offense or defense will win in general, and in the area of critical infrastructure, is unclear, but there are at least some reasons to favor defenders. (Lohn 2025)
Will there be sufficient financial or political motivation for an attack severe enough to register? The Colonial Pipeline case suggests the financial rewards of holding critical infrastructure for ransom exist, but may be unreliable and draw the attention of authorities. Perhaps a more likely motivation is political or strategic. The number of politically motivated actors capable of causing real damage is increasing as autonomous offensive capabilities spread.
Viscerality
This category of warning shot gets a relatively easy pass on viscerality, because it is defined as events which interrupt critical services. Colonial Pipeline is arguably the most felt cyber event in U.S. history — gas lines, panic buying, fuel-price spikes, and direct White House involvement — and all this despite causing no physical damage and never touching the pipeline's control systems.
On the other hand, the Ukraine grid attacks, though more technically sophisticated and genuinely destructive, only interrupted the electrical supply for hours and made little lasting impression on audiences outside the security community. This suggests that visible disruption to everyday life drives viscerality more than technical sophistication or physical damage does.
Suddenness
Given the history of cyberattacks (including those with substantial use of AI), there is a real risk that audiences will be frog-boiled on cyber misuse. Warnings could be followed by increasing frequency and severity of attacks over time without creating a clear shared moment to motivate a response.
Unexpectedness
Relatedly, very few observers will be surprised by increasing ill effects of proliferated cyber capabilities. Events of this sort have historical precedent, are well represented in fiction and film, and have been warned about for years. As a result, what will be necessary for this to be unexpected is at least one of (a) the harm caused by the attack is especially severe or widespread or (b) the AI assistance was of an unexpected level of utility or power.
In July of 2026, water utilities in Minnesota were disrupted by a cyberattack, and while AI’s contributions have not yet been confirmed, it is expected, given the availability of AI agents, that more attacks of this sort will occur in the future.
Attribution
This warning shot anticipates the combination of AI assistance in the means of an attack with critical infrastructure as the target, leading to visceral impacts. Because AI capabilities relevant to cyber operations have already proliferated, it is essentially assured that AI assistance will be used in the next attack on critical infrastructure.
AI employment, especially in the form of autonomous systems, could be relatively easy to detect, as in the example of the Mexican government data breach, where the speed at which code changes were authored is a clear sign that AI assistance was used. We may also be so lucky as in Anthropic’s detection of the November 2025 campaign, in which attribution came directly from the model provider.
Backlash
“if AI models can be misused for cyberattacks at this scale, why continue to develop and release them? The answer is that the very abilities that allow Claude to be used in these attacks also make it crucial for cyber defense.” - Anthropic
The most likely outcome is that any potential backlash against AI development is redirected toward employment of AI for defensive purposes. This argument may flounder in the face of sufficient and visceral harms. At some point, society will not tolerate continued disruption and begin to suspect that AI-aided cyber defense is not viable to counteract the effects of AI-aided cyber offense.
Another possibility is that backlash against AI could be swamped by circumstances surrounding its employment in an attack. For example, if a US adversary uses AI for offensive cyber operations which target critical infrastructure, it would probably be in the context of some larger geopolitical crisis. There will be little energy to think about AI development and its consequences while we are faced with a clear external threat of a rival who is disrupting critical infrastructure as part of a larger crisis or conflict, and that external rival will absorb the backlash rather than the enabling technology.
Conclusion and Future Research
We hope this research can prompt some needed skepticism for the position that it is prudent to adopt a “wait and see” attitude toward the threat of AI risks.
We are excited to see the framework applied to other warning shots. These include: economic impacts of AI (including job loss), covert or kinetic conflict between great powers over AI, and the emergence of fully autonomous rogue AI systems (either intentionally created or self-exfiltrated).
Finally, it is possible that, rather than a singular warning shot, there will be many steps on the road to effective governance of the development of artificial superintelligence. These steps could include warning shots, shifts in the discourse, and the iterative implementation of imperfect policy. Is it plausible that we have time for this potentially lengthy process before it is too late? Especially regarding imperfect policy, what could distinguish steps which move us closer to effective governance rather than backtrack away from it? We are excited about future work which deeply engages with this question.
Appendix: Select Warning Shots
We’re interested in many other warning shots, and a partial list is included here: