If anyone builds superintelligence, everyone dies. That is, it is extremely reckless to build AI systems more intelligent than all humans, given anything like our current technical understanding. To address this, MIRI and others have suggested an immediate and decisive halt to pushing the frontier of general AI capabilities. We think the existing arguments are strong, but many others are waiting for more evidence. This is explainable in part by the large contrast between the harms caused by current and future AI systems.
People in AI governance often talk about warning shots: events which could solve this conundrum, often by causing less-than-existential harm. This post attempts to analyze the likelihood of a successful warning shot for superintelligence, where success requires that the warning shot lead to effective action. We first propose a framework for predicting whether a warning shot will occur and be successful. We apply the framework to analyze commonly-discussed warning shots: AI-caused pandemics, various military applications, and cyber misuse affecting critical infrastructure.
In considering these cases and the framework, we conclude that it is quite plausible that there will simply be no warning shot which generates an appropriate response. Therefore, we think the AI governance community and policymakers should not be waiting for warning shots; the time for action is now.
To motivate an effective response, a warning shot will need to meet these criteria1:
For each class of warning shot below, we give a coarse grade of **pass, uncertain, or fail **to each criterion. COVID-19 caused between 15 million and 35 million extra deaths worldwide. It is also an example of tremendous harm not leading to an appropriate preventive response: society could purchase effective resilience against a future pandemic through any number of methods (stockpiling PPE, vaccine distribution pre-logistics, wastewater monitoring, hardening buildings against airborne spread through UV treatment and/or filtering), but has done surprisingly little of this2.
How likely is AI to facilitate a human-caused pandemic? Cutting edge AI systems have already demonstrated the ability to expand the number of actors who could perform dangerous pathogen development (source, source). Safeguarding frontier models against this kind of misuse is the object of substantial effort, but these safeguards are not perfect. Furthermore, impossible-to-safeguard open source model capabilities continue to advance. So we seem to already be taking risks that even present systems will be misused to this end.
A severe pandemic could close the window for effective governance by severely burdening society with managing its harms, while at the same time not so severely impacting the pace of frontier AI development. This means that while under “normal” circumstances society could react in a timely fashion, it is quite plausible that this type of warning shot could quickly move us past a point of no return.
A pandemic causing substantial harm is very often top-of-mind when considering warning shots because of its obvious viscerality, suddenness, and unexpectedness.
However, would an AI-caused pandemic be attributable to AI? This is the first major problem for a pandemic as a warning shot. The question of COVID-19’s origin remains unresolved, and this is not an uncommon occurrence for pandemics: the 1918 Spanish Flu’s geographic origin is still unresolved.
Even putting aside the baseline difficulty of determining the origin of a pandemic, we then have to turn to determining whether a pandemic was dependent on AI assistance in a meaningful and salient way. Standard epidemiological techniques are even less relevant to this question. It is not certain that an AI-caused pathogen would exhibit any indication that it was designed with the help of AI vs. occurring naturally.
One hope is that if it is a hosted model which is misused to create a pandemic, the model provider could examine its own records to find the queries that led to a novel pathogen. Some issues with this include:
A final problem with pandemics is a lack of backlash. The benefits of advanced AI in the biomedical domain have long been touted, and a new pandemic will likely feature AI assistance as part of its crisis response. This all leads to a pandemic being a clear excuse to accelerate the development and adoption of AI systems in pandemic preparedness.
Additionally, the response to a pandemic, especially in light of the expected difficulty of attribution, is to instead properly pursue pandemic preparedness. Methods for employing AI to this end, such as in AI-aided monitoring of genetic synthesis, further undermines the potential for backlash against AI capabilities advancement.
This wake-up call asks what happens when military leaders see firsthand what capable machine intelligence can do for their conduct of war. While it is a trope of science fiction to integrate advanced artificial intelligence systems into military command and control, we are in fact already living in a time where this is largely the case and the nature of the developments is at risk of being overlooked and misunderstood.
In the US military, the Maven Smart System began development in 2017, and has been in use for several years. It integrates data collection with modern machine learning techniques including vision and language models. Its use has grown to include an estimated 80,000 US personnel. Integration of LLMs produces a fivefold increase in targeting speed, beyond the tenfold increase that vision models already provided. (link) It also expands the quantity of sensors which can be continuously employed: previously there was simply too much incoming footage for humans to review.
Viscerality and Suddenness
We cannot know the full employment of AI in warfighting outside of a classified setting. This frustrates the viscerality of this warning shot and/or restricts the audience. Given the long history of the employment of AI (and computing generally) by the military, which includes many stages of development and an incremental increase and refinement in capabilities, along with a gradual rollout to wider usage, we should expect that the full impact of this warning shot has likely been diluted by frog-boiling.
Backlash
Backlash against AI capabilities progress seems to be quite a stretch for this warning shot. Our own military is experiencing a tremendous increase in utility without a clear downside. Even if a rival were to match US capabilities, it would increase the desire to lead in this area, rather than to constrain development.
Furthermore, initial skepticism or even hostility by some operators toward AI employment reportedly erodes with exposure and the speed and throughput demands of modern operations.
What would happen if we witness a realization of some of the darkest Hollywood fears related to AI: armed machines visibly policing, fighting, or hunting human beings? Consider this progression:
Could this be followed by…
That the first three steps of this progression have already occurred might give us some confidence that these next steps are likely and timely. Both Ukraine and Russia are mass-producing ground combat robots; Ukraine's defense ministry reported nearly 24,500 UGV missions in the first quarter of 2026, and China is exporting armed quadrupeds and the operational concepts for using them.
Footage of an armed robot confronting a human being is undeniably visceral. Decades of Hollywood priming amplifies this: audiences expect killer robots in fiction and could register their appearance on real streets as a threshold crossed.
There is a concern for suddenness, however. Each step of the progression so far has occurred without producing a global moment: drone-delivered tear gas in 2018 and 2024 generated regional outrage and no lasting response, and robotic assaults in Ukraine are covered as defense-industry news. The moment presumably arrives when the imagery is domestic–machines suppressing a crowd of one's fellow citizens–but it must overcome this gradual normalization of the use of robotics for these purposes.
Will such applications, especially for the policing of civilian populations, be attributed to, or even associated with, advanced AI development? There are a couple of ways that frontier AI development could drive or unlock rapid progress in robotics for police applications:
How likely are these to be true of a given warning shot? It might not matter if the perception of this warning shots leads to pushback against AI broadly as a result. The greater risk is that attribution lands on the wrong target: on the platforms, their manufacturers, and the police departments deploying them, rather than on the AI development pipeline upstream.
Military employment of robotics could also frustrate backlash. Ukraine frames robotic infantry as the technology that lets machines die instead of soldiers, with the General Staff crediting robotic platforms for reducing personnel casualties by up to 30 percent. A public that sees machines taking casualties instead of soldiers will call for its own military to adopt the technology as rapidly as possible.
AI-enabled military technology might wake up a national security audience. This audience may see the security implications, even if there aren't widespread societal effects.
Given current trends, AIs will probably become superhuman at software tasks before they become superhuman at hardware design tasks. The earliest potential warning shot related to military technology will probably be software developments.
One candidate development is the design of much better drone software. Such software may be able to radically improve the capabilities of drones, even with the same hardware. These drones will be limited to their existing on-board computers and so will not be running the advanced AI systems themselves. Instead, the AI systems will write specialized on-board software for the drones. Drones will possibly also send and receive communications from these advanced AI systems.
Demonstrations of these upgraded drone capabilities must also be sufficiently visceral. For example:
There may also be real-world uses of these systems, such as drones used for targeted assassinations, even in locations which were supposedly defended from drones; or taking out large, well-defended military targets.
For military technology via software to act as a warning shot, the main concerns are whether the relevant audience wakes up and what the response would be. These developments might be seen as the normal progression of military technology. However, this is less likely if the audience perceives this as a step change in military capabilities, for example, if this new technology is able to easily beat previous generations. This AI-enabled military technology may also be deployed in real combat, which could make this more visceral, for example, if a relatively small number of AI-upgraded units was able to take out a much larger opposing force.
Potentially the largest issue is whether this would generate backlash. AI might be seen as an amazing military opportunity which could prompt further investment. Backlash, if it occurs at all, might be limited to governments which lag the cutting-edge of AI, and only for those governments which have sufficient intelligence to understand how far behind they are.
This warning shot consists of an event in which critical infrastructure is compromised through a cyberattack materially leveraging AI capabilities, producing visceral disruption to a service society depends on.
Likelihood and Timeliness
Critical infrastructure is a large category, especially when using a definition encompassing any infrastructure necessary for the continued functioning of society and the economy. This includes at least housing, heating, food production and distribution, water and power supply, transportation, police and military operation, communications, and financial services. This provides a large attack surface, and makes preemptive defense a huge task.
Cyberattacks on critical infrastructure, without AI, have already happened repeatedly:
These attacks predate the availability of capable AI agents. Regarding AI, we also already have examples of cyber misuse:
These are not examples of mere AI-assistance in offensive cyber operations, but rather examples of AI-driven autonomous operation. This fact should lower our estimation of how much human and organizational expertise and resources will be required to execute effective attacks as these capabilities advance.
There are some factors which cut against the likelihood of this warning shot.
Perhaps efforts to provide early access to powerful AI systems to defenders of critical infrastructure will enable them to secure their systems against attacks aided by an equivalent level of AI capability, by finding and patching vulnerabilities before they can be detected and exploited. Whether offense or defense will win in general, and in the area of critical infrastructure, is unclear, but there are at least some reasons to favor defenders. (Lohn 2025)
Will there be sufficient financial or political motivation for an attack severe enough to register? The Colonial Pipeline case suggests the financial rewards of holding critical infrastructure for ransom exist, but may be unreliable and draw the attention of authorities. Perhaps a more likely motivation is political or strategic. The number of politically motivated actors capable of causing real damage is increasing as autonomous offensive capabilities spread.
Viscerality
This category of warning shot gets a relatively easy pass on viscerality, because it is defined as events which interrupt critical services. Colonial Pipeline is arguably the most felt cyber event in U.S. history — gas lines, panic buying, fuel-price spikes, and direct White House involvement — and all this despite causing no physical damage and never touching the pipeline's control systems.
On the other hand, the Ukraine grid attacks, though more technically sophisticated and genuinely destructive, only interrupted the electrical supply for hours and made little lasting impression on audiences outside the security community. This suggests that visible disruption to everyday life drives viscerality more than technical sophistication or physical damage does.
**Suddenness **
Given the history of cyberattacks (including those with substantial use of AI), there is a real risk that audiences will be frog-boiled on cyber misuse. Warnings could be followed by increasing frequency and severity of attacks over time without creating a clear shared moment to motivate a response.
Unexpectedness
Relatedly, very few observers will be surprised by increasing ill effects of proliferated cyber capabilities. Events of this sort have historical precedent, are well represented in fiction and film, and have been warned about for years. As a result, what will be necessary for this to be unexpected is at least one of (a) the harm caused by the attack is especially severe or widespread or (b) the AI assistance was of an unexpected level of utility or power.
In July of 2026, water utilities in Minnesota were disrupted by a cyberattack, and while AI’s contributions have not yet been confirmed, it is expected, given the availability of AI agents, that more attacks of this sort will occur in the future.
Attribution
This warning shot anticipates the combination of AI assistance in the means of an attack with critical infrastructure as the target, leading to visceral impacts. Because AI capabilities relevant to cyber operations have already proliferated, it is essentially assured that AI assistance will be used in the next attack on critical infrastructure.
AI employment, especially in the form of autonomous systems, could be relatively easy to detect, as in the example of the Mexican government data breach, where the speed at which code changes were authored is a clear sign that AI assistance was used. We may also be so lucky as in Anthropic’s detection of the November 2025 campaign, in which attribution came directly from the model provider.
Backlash
“if AI models can be misused for cyberattacks at this scale, why continue to develop and release them? The answer is that the very abilities that allow Claude to be used in these attacks also make it crucial for cyber defense.” - Anthropic
The most likely outcome is that any potential backlash against AI development is redirected toward employment of AI for defensive purposes. This argument may flounder in the face of sufficient and visceral harms. At some point, society will not tolerate continued disruption and begin to suspect that AI-aided cyber defense is not viable to counteract the effects of AI-aided cyber offense.
Another possibility is that backlash against AI could be swamped by circumstances surrounding its employment in an attack. For example, if a US adversary uses AI for offensive cyber operations which target critical infrastructure, it would probably be in the context of some larger geopolitical crisis. There will be little energy to think about AI development and its consequences while we are faced with a clear external threat of a rival who is disrupting critical infrastructure as part of a larger crisis or conflict, and that external rival will absorb the backlash rather than the enabling technology.
We hope this research can prompt some needed skepticism for the position that it is prudent to adopt a “wait and see” attitude toward the threat of AI risks.
We are excited to see the framework applied to other warning shots. These include: economic impacts of AI (including job loss), covert or kinetic conflict between great powers over AI, and the emergence of fully autonomous rogue AI systems (either intentionally created or self-exfiltrated).
Finally, it is possible that, rather than a singular warning shot, there will be many steps on the road to effective governance of the development of artificial superintelligence. These steps could include warning shots, shifts in the discourse, and the iterative implementation of imperfect policy. Is it plausible that we have time for this potentially lengthy process before it is too late? Especially regarding imperfect policy, what could distinguish steps which move us closer to effective governance rather than backtrack away from it? We are excited about future work which deeply engages with this question.
We’re interested in many other warning shots, and a partial list is included here: