The Alan Turing Institute has published a report on the risks associated with the development of the most powerful artificial intelligence systems. The researchers believe that uncertainty around long-term and potentially catastrophic scenarios should not delay work on threats that can already be observed, studied, and mitigated.
The authors of the report Frontier AI Risks: A practical way forward identified five areas requiring practical measures right now: cybersecurity, democratic stability, AI behavior misaligned with human intentions, loss of effective human control, as well as chemical and biological threats.
It is not enough to test models in isolation
One of the report’s main ideas is that testing the AI model itself before release does not guarantee the safety of the system in real-world operation.
After deployment, the model interacts with people, other software, and infrastructure, and its operating conditions change over time. The more autonomous systems become, the harder it is to predict in advance all the possible ways they may behave.
That is why the researchers propose paying more attention to testing full AI systems in real-world conditions, not just individual models. Such testing should take into account not only technical characteristics, but also the people, processes, and organizations surrounding the system.
In this approach, the institute assigns a special role to verification and assurance technologies — methods that make it possible to check whether a system actually complies with established safety requirements and continues to comply with them after deployment.
Five risks they propose studying right now
Cyberattacks
According to the report’s authors, advanced AI systems already make it possible to carry out cyberattacks faster and at greater scale. This increases pressure on critical infrastructure and organizations.
At the same time, AI is also being used to defend against attacks. Therefore, the researchers propose developing AI cybersecurity tools and assessing whether defensive capabilities can keep pace with offensive ones.
Particular attention should be paid to the security of critical infrastructure.
Democratic instability
AI-generated disinformation and deepfakes can intensify crises and reduce public trust in information and institutions. As technologies develop, systems may also be used for more personalized and adaptive influence campaigns.
The institute considers it necessary to strengthen society’s resilience to such operations while also studying how advanced AI systems may affect democratic processes and public trust.
Misalignment with human intentions
Another problem is misalignment — that is, a situation in which a system acts differently from what its developers and users intended or wanted.
The risk grows as AI systems become more autonomous and capable of coordinating actions among themselves. An error in a single component of such a system could potentially have a larger impact, and detecting and stopping it becomes more difficult.
The report proposes developing behavioral evaluation methods that would allow organizations to understand, monitor, and control the behavior of autonomous systems, especially when operating in critical domains.
Loss of effective human control
The faster and more complex AI systems become, the harder it may be for humans to assess their decisions, challenge them, or intervene in their operation.
This is especially important for systems embedded in significant public and commercial services.
The researchers propose paying more attention to the ability to observe AI behavior, verify its operation, and safely switch the system into a fallback mode. A key requirement remains the human ability to understand what is happening and, if necessary, override an AI system’s decision.
Chemical and biological threats
AI has already lowered the barrier to accessing specialized knowledge related to chemical and biological threats. At the same time, it remains unclear how strongly access to such tools increases the real practical capabilities of malicious actors.
Therefore, the institute primarily calls for expanding the evidence base and distinguishing confirmed risks from assumptions. This will make it possible to direct protective measures where they are truly needed.
There is no simple “kill switch” for AI
The authors also examined several proposals discussed in the context of frontier AI safety, including emergency shutdown of systems and slowing the development of the most powerful models.
The researchers believe that none of these approaches solves the problem on its own. A shutdown mechanism must be complemented by governance procedures, safe fallback scenarios, and clear rules for action in an emergency.
Significantly slowing the development of frontier AI, in turn, would require large-scale cooperation between governments, the technology industry, and regulators. The report’s authors believe that under current conditions it will be difficult to achieve that level of coordination.
Turing launches a £2 million program
The publication of the report coincided with the launch of a new research program by the Alan Turing Institute dedicated to the safety of transformative AI. It has received a £2 million grant from Coefficient Giving.
The program will study how the most powerful AI systems may change the security landscape, what measures governments need to prepare for these changes, and how to improve the resilience of society and critical infrastructure.
At the same time, the institute’s Centre for Emerging Technology and Security published a separate report on the behavioral reliability of autonomous AI agents. It examines eight ways in which agents may act contrary to the intentions of organizations, as well as the conditions under which such errors become especially serious. The researchers formulated seven principles intended to help organizations monitor and manage agent behavior.
“We know enough about many serious AI risks to act,” said Alan Turing Institute CEO Jean Innes. According to her, discussing the long-term future of humanity is important, but work on frontier AI risks cannot be reduced only to the most extreme scenarios or left solely to technology companies.
The institute’s approach comes down to the idea that many threats do not require waiting for the emergence of a hypothetical super-powerful AI. Some of their manifestations can already be observed — and that means they can be tested, measured, and used to build practical protective mechanisms.






