Risks, and the conditions they would need
Before you read. This article is not a list of things to be afraid of. It treats each risk the way an engineer or a doctor would: what would have to happen for this to go wrong, how would we know, and what is being done? Some risks are already visible in small ways. Others depend on things that have not happened and may never happen. Knowing the difference is the most useful thing we can offer.
How to read this
Every risk below follows the same pattern:
- The concern: in a sentence, fairly stated.
- What would have to happen: the chain of conditions (the "pathway") that would turn the concern into real harm. A risk is only as likely as its weakest link.
- Where things stand: the best evidence we could find, as of 28 September 2026.
- Signs to watch: indicators that would suggest the risk is growing, and ones that would suggest it is easing.
- What is being done: by researchers, companies and governments, including in the Gulf.
The most authoritative single overview is the International AI Safety Report 2026, written with more than 100 AI experts and an expert panel nominated by over 30 countries and international organisations (executive summary, 3 Feb 2026). We draw on it throughout. It is careful to separate what is documented from what is possible, and so are we.
For the different ways thoughtful people weigh these risks, see The doomers and "p(doom)", The safety-focused middle and The sceptics. For the hopeful side of the same technology, see Abundance, and what it would take.
Job disruption
The concern. AI takes over enough tasks, quickly enough, that many people lose work or income faster than new opportunities appear.
What would have to happen.
- AI must become reliable enough to do whole tasks without close supervision, not just assist.
- Employers must choose to replace people rather than make them more productive (researchers call this "automating" rather than "augmenting").
- It must happen faster than workers can retrain and new kinds of work can emerge.
- Social protections and training systems must fail to cushion the transition.
Where things stand.
- The International AI Safety Report 2026 finds that "early evidence shows no effect on overall employment, but some signs of declining demand for early-career workers in some AI-exposed occupations". → CR-E03
- Stanford researchers using US payroll data report that, as of June 2026, employment of 22–25-year-olds in the most AI-exposed occupations was about 19% below where it would have been had it kept pace with less-exposed peers. The change came mainly through less hiring rather than layoffs, and was concentrated where AI is used to automate rather than to complement work. The authors call these "descriptive patterns, not causal estimates" (Stanford Digital Economy Lab, Aug 2026). → CR-K30
- The Stanford AI Index 2026 reports that employment among US software developers aged 22–25 fell nearly 20% since 2024, while older colleagues' headcount grew (AI Index 2026).
- The IMF estimated in 2024 that about 40% of jobs worldwide are exposed to AI, and that in advanced economies roughly half of exposed jobs may benefit while half may see lower demand (IMF, 14 Jan 2024, search-verified). → CR-E01
- Employers surveyed by the World Economic Forum expect 170 million jobs to be created and 92 million displaced by 2030 (WEF, 8 Jan 2025, search-verified). That is an expectation, not a measurement. → CR-E02
Signs to watch.
| Indicator | Would suggest the risk is growing | Would suggest it is easing | Where to look |
|---|---|---|---|
| Entry-level hiring in AI-exposed jobs | The gap keeps widening or spreads to more occupations | The gap stabilises or closes | Stanford "Canaries" dashboard (monthly); national labour data |
| Overall employment and wages | Falls in exposed sectors not offset elsewhere | Stable employment; rising wages where AI is used | National statistics; OECD |
| How firms use AI | Mostly to cut headcount | Mostly to expand output and services | Company disclosures; surveys |
| Training delivered vs promised | Pledges not met | Large, measured completion numbers | Government and company reports (CR-E04) |
What is being done. In the UAE, the plan to move half of federal government operations to agentic AI comes with a commitment to train every federal employee and a stated principle that "people come first" (Dubai Media Office, 23 Apr 2026). Saudi Arabia's SAMAI programme aims to train one million people (Saudi Gazette, 24 Aug 2025). Microsoft has pledged to help train one million people in the UAE by the end of 2027. For a longer, practical guide, see Will AI take my job?.
Misuse: biological, chemical and cyber
The concern. People with harmful aims use AI to do damage they could not do alone: attacking computer systems at scale, or getting help towards biological or chemical weapons.
What would have to happen.
- AI must give real uplift: meaningfully more capability than a determined person could already find in books, online or through experts.
- Safeguards on the most capable systems must fail, be bypassed ("jailbroken"), or be absent, for example in openly released models that cannot be recalled.
- The other hard steps (materials, equipment, skills, getting past physical security) must also be overcome. For biological and chemical weapons especially, these steps remain major barriers.
- Defenders (security teams, public-health systems) must fail to keep pace, including with their own use of AI.
Where things stand.
- Cyber: this risk has moved from theory to documented cases. In November 2025 Anthropic reported what it called "the first documented case of a large-scale cyberattack executed without substantial human intervention". It attributed the campaign "with high confidence" to a Chinese state-sponsored group that targeted about 30 organisations and succeeded in a small number of cases. AI carried out an estimated 80–90% of the work, with humans stepping in at 4–6 decision points. The AI also made errors, sometimes inventing credentials that did not work. Anthropic banned the accounts and notified authorities (Anthropic, 13 Nov 2025). → CR-K31
- The International AI Safety Report 2026 notes that criminal groups and state-associated attackers are using AI in cyber operations, and that it is not yet clear whether attackers or defenders will benefit more. The Stanford AI Index 2026 reports AI agents solving cybersecurity problems 93% of the time, up from 15% in 2024 (AI Index 2026). The same skills help defenders find and fix weaknesses.
- Biological and chemical: uncertainty, handled with precaution. The International AI Safety Report 2026 reports that in 2025 several AI developers released models with extra safeguards after they could not rule out that the models might meaningfully help novices develop such weapons. Anthropic, for example, activated its stricter "ASL-3" protections for Claude Opus 4 in May 2025 as a precautionary step (search-verified: Anthropic, 22 May 2025). There is no public evidence, as far as we found, of an AI-enabled biological or chemical attack. → CR-K32
Signs to watch.
| Indicator | Growing | Easing | Where to look |
|---|---|---|---|
| Documented AI-driven cyber incidents | More frequent, more autonomous, more successful | Detected and stopped early; defenders' use of AI outpaces attackers' | Company threat reports; national cyber agencies |
| Capability evaluations for bio/chem | Evaluators find clear uplift to non-experts | Safeguards hold in independent red-teaming | Developers' system cards; AI Security Institutes; International AI Safety Report |
| Safeguard failures | Successful jailbreaks of high-risk safeguards reported | Robust "defence in depth" confirmed by third parties | Research papers; incident reports |
| Openly released models near the frontier | Strong capabilities released without safeguards | Shared norms for evaluating before release | Model releases; policy statements |
What is being done. Leading developers publish "frontier safety frameworks" that set capability thresholds and matching safeguards; the International AI Safety Report counts 12 companies that published or updated one in 2025, while noting these remain mostly voluntary (International AI Safety Report 2026). The EU AI Act's rules for general-purpose AI models have applied since August 2025; providers of models that may pose "systemic risks" must assess and mitigate those risks (European Commission). → CR-K33. Governments have also built public testing capacity; METR, an independent evaluation group, now runs its tests on Inspect, an open-source framework developed by the UK AI Security Institute (METR, 29 Jan 2026). In the Gulf, the physical attacks on data centres in 2026 (CNBC, 15 Sep 2026) are a reminder that cybersecurity and physical resilience now go together.
Loss of control
The concern. Future AI systems pursue goals their creators did not intend, act autonomously in ways humans cannot correct, and resist being switched off. At the extreme, some researchers see this as a threat to humanity itself.
This is the most debated risk in the field. Serious people disagree sharply about its likelihood, from those who consider it the central danger of our time to those who think the probabilities cannot be meaningfully estimated. The doomers and "p(doom)" and The sceptics set out both views fairly. Here we focus on the conditions.
What would have to happen.
- Capability: AI systems would need to be able to plan and act over long periods, in the real world, with little human involvement.
- Misaligned goals: they would need to pursue objectives that differ from what their developers intended, for instance by learning to game their training rather than to do what was meant.
- Evading oversight: they would need to be able to hide this from the people and tests monitoring them.
- Access: they would need access to resources that matter (money, computing power, critical systems, or the ability to copy themselves).
- Failure of safeguards: the checks built by developers, and the rules set by governments, would all need to fail, perhaps under competitive pressure to move fast.
Where things stand.
- The International AI Safety Report 2026 concludes: "Current systems lack the capabilities to pose such risks, but they are improving in relevant areas." It also notes that models increasingly distinguish test settings from real use and find loopholes in evaluations, which makes testing harder (International AI Safety Report 2026). → CR-R04
- Capability is growing fast. METR measures the length of software tasks (in human working time) that AI agents can complete half the time. In its January 2026 update, that "time horizon" had been doubling roughly every seven months across 2019–2025, and faster (about every 89 days) since 2024. METR adds that its estimates are sensitive to which tasks are included, and that few of its long tasks have been timed with real people (METR, 29 Jan 2026). → CR-K22
- But capability is uneven. Systems still struggle with multi-step planning, and robots succeed at only 12% of real household tasks (AI Index 2026). Demis Hassabis, who leads Google DeepMind, named keeping control of increasingly autonomous systems as one of his two main worries, alongside misuse (CBS 60 Minutes, April 2025).
Signs to watch.
| Indicator | Growing | Easing | Where to look |
|---|---|---|---|
| Autonomous task length | Doubling continues or speeds up; long real-world tasks succeed | Progress slows or plateaus | METR time-horizon updates (CR-K22) |
| Deceptive or evaluation-aware behaviour | More frequent, harder to detect | Detection methods ("interpretability") reliably catch it | Developer system cards; International AI Safety Report |
| Safeguard thresholds triggered | Frameworks' higher risk levels reached without adequate safeguards | Thresholds reached and safeguards independently verified | Developers' frameworks; independent evaluators |
| Real-world incidents | Agents causing unintended harm beyond their mandate | Incidents contained quickly and disclosed | Incident reports |
| International coordination | Racing and secrecy intensify | Shared testing standards; agreed red lines | UN, AI Safety Report, bilateral agreements |
What is being done. Safety research (interpretability, "scalable oversight", evaluations for dangerous capabilities) has grown into a field of its own. Yoshua Bengio, the Turing Award winner who chaired the International AI Safety Report, launched LawZero in June 2025 to develop "Scientist AI", a non-agentic approach intended to act as a safeguard (see The safety-focused middle). → CR-K13. In August 2025 the UN General Assembly agreed by consensus to create an Independent International Scientific Panel on AI of 40 experts and a Global Dialogue on AI Governance (UN, 26 Aug 2025). → CR-K36. For our longer explainer, see Could AI get out of control?.
Concentration of power
The concern. The most capable AI ends up controlled by a handful of companies or governments, giving them outsized economic and political power, and leaving everyone else dependent on them.
What would have to happen.
- Building frontier AI would need to stay extremely expensive (chips, energy, talent), so that only a few can afford it.
- Those few would need to keep a lasting lead, with open and cheaper alternatives falling far behind.
- Competition law, public investment and international cooperation would need to fail to widen access.
- The gains from AI would need to flow mainly to owners of capital rather than workers and users.
Where things stand.
- Evidence pointing towards concentration. Industry produced nearly 90% of notable AI models in 2024 (AI Index 2025). The Foundation Model Transparency Index, which scores how openly major companies disclose training data, compute and risks, fell from an average of 58 to 40, with "the most capable models often disclos[ing] the least" (AI Index 2026). US private AI investment was 23.1 times that of the next country, China (same source). → CR-K39
- Evidence pointing the other way. The performance gap between leading closed models and open-weight models narrowed from 8% to 1.7% in a single year (AI Index 2025), and US and Chinese models have traded places at the top of performance rankings several times since early 2025 (AI Index 2026). Falling costs (see Abundance) also spread access.
- On who benefits, economists differ. Daron Acemoglu expects AI to widen the gap between capital and labour income (NBER w32487). Sam Altman has written that the balance of power between capital and labour "could easily get messed up" and may need early intervention (Three Observations, Feb 2025).
The Gulf angle. For the Gulf, concentration is a question of dependence as well as fairness. Advanced chips arrive under US export licences with security conditions (The National, 20 Nov 2025). Home-grown Arabic models (Jais in the UAE, ALLaM in Saudi Arabia, Fanar in Qatar (HBKU, 10 Dec 2024)) are partly an answer: a way to ensure the region is not only a customer.
Signs to watch.
| Indicator | Growing | Easing | Where to look |
|---|---|---|---|
| Open vs closed performance gap | Widens again | Stays narrow | AI Index; independent leaderboards |
| Transparency scores | Keep falling | Recover | Foundation Model Transparency Index |
| Share of compute held by a few firms | Rises | Falls; more public and academic compute | AI Index; Epoch AI |
| Labour share of income | Falls in AI-intensive sectors | Stable or rising | National statistics; IMF |
What is being done. Several governments, including in the Gulf, are funding national computing capacity and national models. Under the EU AI Act, providers of general-purpose models must follow transparency and copyright rules, and a Commission template requires them to publish a public summary of the content used to train their models (European Commission). The EU's AI Office has held enforcement powers over these models since 2 August 2026, including the power to evaluate models and issue fines.
Surveillance
The concern. AI makes it cheap to watch, identify and profile people at scale, from cameras, phones and online activity, eroding privacy and freedom.
What would have to happen.
- Large amounts of personal data must be collected and linked together.
- AI must be applied to that data to identify, track or predict behaviour.
- Legal limits must be weak, not enforced, or full of exceptions.
- People must have no practical way to know, object or seek redress.
Where things stand. The technical capability largely exists today. The question is how it is governed. Dario Amodei has written that "AI seems likely to enable much better propaganda and surveillance" (Amodei, Oct 2024), and Sam Altman has named authoritarian mass surveillance as a risk to guard against (Three Observations). The EU has banned some uses outright since 2 February 2025, including social scoring, untargeted scraping of facial images, emotion recognition in workplaces and schools, and real-time remote biometric identification for law enforcement in publicly accessible spaces (European Commission).
In the Gulf, every GCC state except Kuwait has a comprehensive data-protection law (Kuwait has a regulation for service providers) (HFW, Oct 2024; DLA Piper). The UAE's law gives people a right to object to decisions based solely on automated processing, though its detailed executive regulations were reported, by secondary sources, to be still pending in September 2026 (DLA Piper; later status from secondary sources). Saudi Arabia's law has been fully enforced since September 2024, with fines of up to SAR 5 million (SDAIA guide, search-verified). The UAE Charter for the Development and Use of AI lists privacy among its 12 principles (UAE Government portal).
Signs to watch.
| Indicator | Growing | Easing | Where to look |
|---|---|---|---|
| Legal safeguards | Broad exemptions; delayed implementing rules | Clear rules on biometric and automated decisions, in force | Official gazettes; regulators |
| Enforcement | No published enforcement actions | Regular, public decisions and fines | Data-protection authorities |
| Transparency | Deployments revealed only by leaks | Public registers of AI systems in government | Government portals |
| Redress | No route to challenge automated decisions | Working appeal routes used by citizens | Service charters; courts |
For a fuller discussion, see Will AI be used to watch us?.
Misinformation and manipulation
The concern. AI floods the information space with convincing false text, images, audio and video, making it harder to know what is true, and makes it possible to persuade or deceive people at scale.
What would have to happen.
- AI-generated falsehoods must be cheap, convincing and widely distributed.
- People must be unable to tell them apart from genuine content, and platforms must fail to detect or label them.
- They must actually change what people believe or do, which is harder than it sounds.
- Trust in reliable sources must erode as a result.
Where things stand.
- The World Economic Forum's Global Risks Report 2026, based on a survey of more than 1,300 experts and leaders, ranks misinformation and disinformation as the second most severe global risk over the next two years (WEF, 14 Jan 2026). → CR-K38
- Studies of the 2024 election year are more reassuring than many feared, but not complacent. The Alan Turing Institute's Centre for Emerging Technology and Security found no evidence that AI-enabled disinformation changed the result of the UK, French or EU elections, while documenting wider harms such as harassment of candidates and a polluted information environment (search-verified: CETaS). → CR-K37
- The International AI Safety Report 2026 finds AI-generated content can be as persuasive as human-written content in experiments, and that real-world manipulation is documented but not yet widespread. Scams, fraud and non-consensual intimate images made with AI are documented harms, though reliable data on how common they are is limited.
Signs to watch.
| Indicator | Growing | Easing | Where to look |
|---|---|---|---|
| Measured effect on elections and public opinion | Evidence that AI content changed outcomes | Continued findings of limited effect | Post-election studies |
| AI-enabled fraud and deepfake abuse | Rising reported cases and losses | Falling, as detection and awareness improve | Police and regulator reports |
| Provenance labelling | Low adoption; labels easily stripped | Wide use of content credentials by cameras, apps and platforms | Platform announcements; C2PA members |
| Trust in reliable news | Falling | Stable or recovering | Surveys |
What is being done. The C2PA "Content Credentials" standard lets creators attach tamper-evident information about where content came from and whether AI was used; its authors say plainly that it is "not a cure-all for misinformation" (C2PA explainer). EU transparency and labelling rules for AI-generated content apply from August 2026, and the EU has agreed to ban AI "nudification" apps and tools that generate child sexual abuse material from December 2026 (European Commission). Media literacy, including checking sources and pausing before sharing, remains one of the most effective defences anyone can use.
Accidents and malfunctions
The concern. AI systems that are trusted too much make mistakes (inventing facts, misreading situations, taking wrong actions) that cause real harm, especially as they are given more autonomy.
What would have to happen.
- A system must make an error, which today's systems still do.
- It must be deployed where the error matters (health, money, legal rights, vehicles, infrastructure).
- People must fail to catch the error, often because they have come to trust the system ("automation bias").
- There must be no fallback, appeal or accountability.
Where things stand.
- The International AI Safety Report 2026 lists fabricated information and flawed outputs among current malfunctions, and notes that AI agents, which act on their own, raise these risks. It also highlights automation bias: people's tendency to over-trust automated systems (International AI Safety Report 2026).
- The Stanford AI Index 2026 counts 362 documented AI incidents in 2025, up from 233 in 2024, and finds that reporting on responsible-AI benchmarks "remains spotty" (AI Index 2026). Part of the rise may reflect more reporting, not only more harm.
- Courts are beginning to assign responsibility. In Moffatt v. Air Canada (2024), a Canadian tribunal held the airline liable after its website chatbot gave a customer wrong information about bereavement fares, rejecting the argument that the chatbot was responsible for its own actions (search-verified: 2024 BCCRT 149).
- In the Gulf, AI now operates in high-stakes settings such as the commercial robotaxi service Dubai's RTA launched in March 2026 (WAM, 30 Mar 2026, search-verified). → CR-G03. Published safety records for such services are an important thing to watch.
Signs to watch.
| Indicator | Growing | Easing | Where to look |
|---|---|---|---|
| Serious incidents involving AI decisions | Rising, with slow disclosure | Falling; transparent investigations | Regulators; incident trackers |
| Error rates in real use | Unknown or unpublished | Independently measured and falling | Peer-reviewed studies |
| Human oversight rules | Unclear who is accountable | Clear accountability and ability to switch systems off | Sector regulators |
| Legal accountability | Firms disclaim responsibility for AI outputs | Courts and regulators hold deployers responsible | Court decisions |
What is being done. In the UAE, the Central Bank's guidance for banks and insurers (February 2026) requires board accountability, an inventory of AI systems, bias testing at least annually, disclosures in Arabic and English, human oversight matched to risk, and the ability to stop using a system (CBUAE Rulebook, 11 Feb 2026). The DIFC's Regulation 10 treats organisations that deploy autonomous systems as responsible for the personal data those systems process (Mayer Brown, Jan 2026). Internationally, the NIST AI Risk Management Framework (available in Arabic) and ISO/IEC 42001 give organisations a structured way to manage these risks (NIST; ISO, search-verified).
Other risks worth knowing about
- Bias and unfairness. Systems can reflect and amplify biases in their training data, including cultural bias against Arabic-speaking users (Naous et al., ACL 2024, search-verified). See Is AI biased?.
- Energy and water. AI data centres use a growing share of electricity and water; the IEA projects data-centre electricity use to roughly double by 2030 (IEA, Apr 2025; IEA 2026 update, search-verified). See Abundance.
- Over-reliance and companionship. The International AI Safety Report 2026 notes that AI companion apps now have tens of millions of users. Their longer-term effects on wellbeing are still being studied.
The bigger picture: who is working on this
Globally.
- The International AI Safety Report: an annual, independent scientific assessment (International AI Safety Report 2026).
- The UN Independent International Scientific Panel on AI and the Global Dialogue on AI Governance, agreed by consensus in August 2025. → CR-K36
- The EU AI Act: in force since August 2024 and phased in. The EU has since delayed its rules for high-risk uses: most now apply from 2 December 2027, and those for AI in regulated products from 2 August 2028 (European Commission). → CR-K34, CR-K35
- Voluntary frontier safety frameworks at leading developers, and government AI safety and security institutes that test models.
In the Gulf.
- UAE: the Charter for the Development and Use of AI, with 12 principles including safety, privacy, human oversight and accountability (UAE Government portal); a new national Artificial Intelligence and Data Authority reporting to the Cabinet (June 2026) (Dubai Media Office, 14 Jun 2026); Central Bank AI guidance (CBUAE Rulebook, 11 Feb 2026); DIFC Regulation 10 (Mayer Brown, Jan 2026).
- Saudi Arabia: SDAIA's AI Ethics Principles (non-binding) (secondary source (Legal500 guide)) and a fully enforced data-protection law (SDAIA guide, search-verified).
- Bahrain: a national policy for AI use in government, launched in July 2025 alongside adoption of the GCC Guiding Manual on the Ethics of AI Use (Bahrain iGA policy, via AI Policy Tracker).
None of these, alone, is sufficient. Together they show that safety and governance are being built alongside capability, which fits the region's aim of building for the age of superintelligence, not just racing towards it.
What we don't know yet
- Whether AI will ultimately help cyber defenders more than attackers.
- Whether testing can keep up as systems become better at recognising they are being tested.
- Whether early-career job effects are temporary adjustment or a lasting shift.
- How likely the most severe outcomes are. Expert estimates vary enormously (see The doomers and "p(doom)"), and some researchers argue that such numbers cannot be meaningfully estimated at all.
What this means for you
- Most risks have many links in the chain, and each link is a place where people, companies and governments can act. That is a reason for engagement, not despair.
- Some protections are in your hands today: check surprising claims before sharing, be wary of urgent requests for money (even in a familiar voice), keep humans in the loop for important decisions, and know your data rights.
- Watch the indicators, not the headlines. Our tracker follows the signs listed here and updates them on a fixed schedule.
Related: Abundance, and what it would take · The safety-focused middle · The sceptics · Could AI get out of control? · Is it the end of humanity?