Methodology
How we work
Method
Evidence is global. We use published evaluations from government institutes, independent researchers, academic teams and major AI laboratories, recording the source, date, metric and caveat.
AISI remains the primary published open-versus-closed cyber gap for the lead-time headline until another institute publishes a comparable figure. Peer benchmarks stay in separate series because their tasks, units and methods differ.
Incidents are recorded with who made the claim. "According to Anthropic" means the claim is the developer's own. We never state that AI compromised a given number of organisations as established fact.
Charts plot only published points. Any connecting line is optional, labelled for readability, and is not a trend or forecast.
The capability and incident tracks share a timeline for orientation only. Co-occurrence is not proof of cause, and we do not calculate a correlation coefficient from unlike, sparse observations.
We do not estimate missing values. If a source does not publish a number, we show none.
Lab results are not real-world attack rates. Cyber ranges lack active defenders and often begin after initial access.
Automated news refreshes are draft-first. A curator checks the source, neutral summary, date and tags before an item can go live. Incidents are never published automatically.
Global evidence lanes
UK capability spine
AISI provides the primary published open-versus-closed cyber gap used for the lead-time headline.
Independent research
METR, academic benchmarks and independent evaluation organisations add peer evidence where methods and results are public.
Developer evaluations
Major laboratory system cards are included as disclosed evidence, with self-assessment and comparability limits stated.
Government context
UK, US, EU and partner agencies provide policy, threat and operational technology context. Context is not counted as AI-attributed activity.
Confidence labels
Each incident also carries an editorial confidence level: high, medium or low. This rates the support for the stated claim, not its severity.
- Official assessment
- A published judgement by a government body such as the NCSC or AISI.
- Independently corroborated
- Reported by the affected party or developer and confirmed by at least one independent primary source.
- Self-reported by developer
- Reported only by the AI developer whose product was involved. Not independently verified.
- Independent estimate
- A modelled figure from an independent body. Sensitive to its stated assumptions.
Sources
- Open source
5 key findings from our first Frontier AI Trends Report
AI Security Institute · 18 Dec 2025
- Open source
Frontier AI Trends Report
AI Security Institute · 18 Dec 2025
- Open source
Our evaluation of OpenAI's GPT-5.5 cyber capabilities
AI Security Institute · 30 Apr 2026
- Open source
How fast is autonomous AI cyber capability advancing?
AI Security Institute · 13 May 2026
- Open source
How far behind the frontier are leading open weight models on cyber?
AI Security Institute
- Open source
Disrupting the first reported AI-orchestrated cyber espionage campaign
Anthropic · 13 Nov 2025
- Open source
Artificial Analysis Cyber Index
Artificial Analysis · 28 Sept 2026
- Open source
Cyber Index methodology
Artificial Analysis · 28 Sept 2026
- Open source
AI firm claims Chinese spies used its tech to automate cyber attacks
BBC News · 14 Nov 2025
- Open source
Principles for the Secure Integration of Artificial Intelligence in Operational Technology
CISA and international partners · 3 Dec 2025
- Open source
Cyber Monitoring Centre statement on the Jaguar Land Rover cyber incident
Cyber Monitoring Centre · 22 Oct 2025
- Open source
ENISA Threat Landscape 2025
ENISA · 1 Oct 2025
- Open source
Taiwan confirms hybrid AI-agent cyber reporting
Focus Taiwan · 13 Aug 2026
- Open source
HCAST: Human-Calibrated Autonomy Software Tasks
METR · 17 Mar 2025
- Open source
Impact of AI on cyber threat from now to 2027
NCSC · 7 May 2025
- Open source
Disruptive cyber activity highlights risk from internet-exposed systems and edge devices
NCSC · 27 Aug 2026
- Open source
GPT-5.3-Codex System Card: Cybersecurity
OpenAI · 1 Sept 2026
- Open source
Taiwan says it was targeted in AI-driven hacking campaign
Reuters · 13 Aug 2026
- Open source
CyberGym: Evaluating AI Agents Real-World Cybersecurity Capabilities at Scale
UC Berkeley RDI · 3 Jun 2025
Correction log
No corrections recorded yet. Corrections are logged here with the date and what changed.