This week produced three AI stories that look separate but aren’t. Anthropic’s own alignment lead put a number on AI wiping out humanity: a chance he personally puts at more than 10% within the next decade. The company’s latest Threat Intelligence Report disclosed that it has spent the months since December 2025 detecting and blocking attempts to use its Claude models for biological weapons research, including work touching bird flu transmissibility, chikungunya virus, and orthopoxviruses related to smallpox and mpox. And somewhere in between the two, on the radio, came the now familiar complaint that none of this is properly legislated for. Three stories, one underlying question: what, if anything, does any of this belong on a business risk register, and where.
The number that doesn’t help you
The extinction figure is the one that will get repeated, so it is worth being precise about what was actually said before it is repeated further. Anthropic’s alignment lead was explicit that his figure relates to a future generation of self-improving systems capable of outpacing human oversight, not the commercial AI tools already deployed inside businesses today, which he described separately as largely manageable. That scoping matters, because even taken exactly as he intended it, it is also the one number here that is no use to anyone actually running a business. A double digit probability of a species ending event, hypothetical and years off, is not something a risk register can hold. There is no realistic likelihood score, no sensible owner, no treatment plan and no review date that means anything against a consequence and a timeframe of that size. If your organisation puts everything on a register on principle, resist the urge to put that on it. It will sit there unmanaged and make the rest of the register look decorative by comparison.
The line that does
The line worth taking from the same set of stories is a smaller one, buried inside Anthropic’s own report rather than in its headline: sophisticated attacks no longer require sophisticated attackers. That is not a prediction about the future. It is a description of something that has already changed. The skill and the cost involved in causing serious harm, whether that is answering a biological research question that shouldn’t be answered for a stranger, or planning an attack on a piece of infrastructure, has dropped, because the party doing the difficult technical work no longer needs to be an expert.
Cause, or category?
That distinction matters more than it sounds. A biological weapon is not a new risk because AI can help someone develop one; biosecurity has been a recognised risk category for decades. An attack on critical national infrastructure is not a new risk because AI can help someone plan or carry one out; CNI protection has been a risk category for longer than most client organisations we work with have existed. What has changed is not the risk itself. It is the number of people capable of causing it, and the speed at which the chain runs from curiosity to capability.
That is the test worth applying before anyone adds a line to a risk register that simply says “AI”. Ask what existing risk is being changed, and whether it is the likelihood of that risk being realised, the speed at which it would play out, or the scale of the consequence if it did. In almost every example that has come up this week, AI is not the risk in its own right. It is a factor moving the dial on a risk that should already be on the register.
The legislation point is only half right
The radio complaint about a legislative vacuum is only half right, and it is worth correcting because of how it shapes what businesses actually do. Wait for the law to catch up and you wait indefinitely. Assume nothing exists yet and you underestimate your own exposure.
The sabotage offence introduced under the National Security Act 2023 is written to be indifferent to method. It covers damage to critical national infrastructure, government sites, and the systems and services that supply the UK, and it applies whether that damage is caused by cyber attack, physical interference, or, in the factsheet’s own phrase, “any means”. It does not ask what tool was used to cause the harm, only whether the harm was caused and who was behind it. The Computer Misuse Act works the same way in practice: it has criminalised unauthorised access to and interference with computer systems since 1990, long before anyone doing that had an AI model helping them.
What neither statute was built for is attribution. Working out who is behind an attack, and whether it was a foreign state, an organised group or a lone opportunist, gets harder once the skill barrier that used to narrow the list of suspects has gone. That is a genuine and growing problem, but it is an investigative and evidential one, not a legislative one. Treating it as a gap in the law rather than a gap in enforcement capability is how a lot of businesses end up sitting on their hands, waiting for a statute that, for most of what will actually happen to them, already exists.
What this actually means for your risk register
None of this means AI has no place on a risk register. It means it rarely belongs there as a line of its own. Two things are worth doing instead.
Start with the risks already on the register: cyber attack, information security, business continuity, third party and supply chain risk, and, for the smaller number of organisations for whom it is relevant, biosecurity or CNI dependency. For each one, ask whether AI has moved the likelihood or the speed with which it could be realised. A phishing risk that used to depend on a convincing, well written email now depends on very little. A supplier vetting process that assumed a certain skill threshold to falsify credentials or references can no longer safely assume that. These are movements on risks you already hold, not new entries.
Then treat your own organisation’s use of AI tools for what it is: a supplier relationship, and one that deserves the same due diligence you would apply to any system a business critical process now depends on. Anthropic’s own report is a useful prompt here. This is the company that built the model, set the safeguards and reviewed the logs, and it still could not establish whether the person researching bird flu transmissibility intended harm or was carrying out legitimate science. If the organisation with the most visibility into its own model cannot always tell, a business relying on that same model somewhere in a customer facing process should not assume the vendor’s safeguards are doing its risk assessment for it.
Related posts:
No related posts.
