Have AI Risks Increased in the Past Two Years? The Evidence Says Yes

 

Have AI Risks Increased in the Past Two Years? The Evidence Says Yes

Overall Key Points
  • AI risks have increased because model capabilities, autonomy, and deployment have all expanded rapidly.
  • Cyber misuse, fraud, surveillance, manipulation, and privacy risks are becoming more practical rather than merely theoretical.
  • AI agents create a new category of risk because systems can increasingly take actions rather than simply generate information.
  • Frontier AI companies themselves have strengthened safety frameworks as capabilities have advanced.
  • Catastrophic loss-of-control risks remain uncertain, but near-term risks are already observable.

Have AI Risks Increased in the Past Two Years? The Evidence Says Yes

Two years ago, most public discussions about artificial intelligence focused on chatbots generating essays, images, and occasionally absurd factual mistakes.

That world already feels dated.

Modern AI systems increasingly write software, operate external tools, perform multi-step research, interact with websites, analyze scientific information, and function as semi-autonomous agents. At the same time, businesses and governments are integrating them into systems where mistakes can produce financial, security, or operational consequences.

That combination changes the risk calculation.

The question is no longer simply whether AI sometimes gives a bad answer. It is whether increasingly capable systems can produce harmful outputs, take unintended actions, lower the barrier to sophisticated abuse, or become difficult to supervise as their autonomy increases.

By that standard, AI-related risks have clearly increased.

1. AI Models Can Now Do Things That Were Difficult Two Years Ago

Key Point: Risk has grown largely because capability has grown.

The most fundamental change is capability.

Earlier generative AI systems were primarily conversational. Users asked questions, and the model produced text. That architecture could still create misinformation or harmful advice, but the model itself generally did not take many actions outside the conversation.

Today's systems are increasingly connected to tools.

They can write and execute code, search information, manipulate files, interact with software, call APIs, and perform multi-step tasks with limited supervision. AI agents can be assigned goals rather than individual prompts.

That is enormously useful.

It also creates a new class of failure.

An incorrect paragraph is inconvenient. An autonomous system taking an incorrect action in a production environment can be considerably more serious.

This is why leading AI developers have expanded their safety frameworks beyond traditional content moderation. OpenAI's Preparedness Framework focuses on severe risks associated with advanced capabilities, while its Frontier Governance Framework addresses cyber offense, chemical and biological threats, harmful manipulation, and potential loss of control.

Anthropic has similarly revised its Responsible Scaling Policy repeatedly as frontier models have become more capable.

The industry's own safety architecture therefore provides indirect evidence of the change: companies would not need increasingly elaborate frontier-risk frameworks if the technical risk profile had remained static.

2. Cybersecurity Risk Has Become Much More Concrete

Key Point: AI can reduce the expertise and time required to perform sophisticated cyber tasks.

Cybersecurity may be the clearest example of how AI risk has evolved.

Language models were once useful mainly for explaining programming concepts or generating basic scripts. Frontier systems can now perform increasingly complex coding and cybersecurity tasks.

This does not mean an AI model can automatically defeat every sophisticated security system. Human expertise, access, persistence, and operational knowledge still matter enormously.

But AI can reduce friction throughout the attack process.

It can assist with reconnaissance, automate repetitive technical work, analyze vulnerabilities, generate or modify code, craft convincing social-engineering messages, and help attackers troubleshoot failed attempts.

The concern becomes larger as agents gain the ability to interact directly with computers and networks.

By 2026, cybersecurity researchers were increasingly discussing AI agents not only as defensive tools but also as potential attackers and attack targets themselves.

This creates an unusual security environment. Organizations may eventually need to defend against automated systems operating at machine speed while simultaneously protecting their own AI agents from manipulation.

3. AI Misuse Is Expanding Beyond Scams and Deepfakes

Key Point: The danger is increasingly about lowering barriers to activities that previously required specialized expertise.

AI-generated fraud and misinformation were among the earliest widely recognized risks of generative AI.

Those problems have not disappeared. Voice cloning, fake images, synthetic video, automated phishing, impersonation, and mass-produced propaganda continue to improve as generative systems become cheaper and easier to use.

But the range of misuse has expanded.

Anthropic has publicly documented cases involving attempts to use advanced AI systems for cyber operations, surveillance, military-related technical assistance, propaganda, and sensitive biological research.

The important issue is not that AI independently created entirely new categories of criminal or military activity.

The deeper concern is democratization of capability.

A person who previously needed significant technical knowledge may now be able to ask an AI system to explain complex procedures, generate software, translate technical material, or troubleshoot a project interactively.

That does not instantly turn an inexperienced person into an expert. But reducing the expertise threshold even modestly can increase the number of people capable of attempting harmful activities.

This scaling effect may ultimately matter as much as the raw capability of the models themselves.

4. AI Agents Introduce Risks That Chatbots Did Not

Key Point: Giving AI permission to act creates different risks from giving AI permission to answer.

The rise of AI agents may be the most important structural change in the risk landscape.

A chatbot usually waits for the next instruction.

An agent can receive a goal and then decide which intermediate steps to take. It may browse websites, run software, use credentials, communicate with other systems, or perform actions without requesting approval for every individual step.

That creates obvious productivity benefits.

It also expands what security researchers call the attack surface.

An agent could misunderstand instructions. It could be manipulated by malicious information encountered online. It could expose confidential data. It could execute an inappropriate command. Another AI system could potentially exploit it.

The more authority an agent receives, the greater the consequences of an error become.

This creates a fundamental tradeoff.

An AI agent becomes more useful when humans give it broader access and autonomy. Yet those same permissions increase the damage it can cause if the model behaves incorrectly or is compromised.

Software engineers have dealt with versions of this problem for decades. The difference is that traditional software follows explicitly programmed logic, while modern AI systems behave probabilistically and may respond unpredictably to unfamiliar situations.

5. The Most Serious AI Risks Remain Uncertain, but They Cannot Be Ignored

Key Point: Immediate AI harms are observable, while catastrophic loss-of-control scenarios remain much harder to estimate.

Not all AI risks deserve the same level of certainty.

Some risks are already visible.

Fraud, impersonation, misinformation, privacy leaks, biased automated decisions, intellectual-property disputes, cyber misuse, and unreliable AI agents are measurable problems occurring today.

Other concerns are much more uncertain.

Researchers disagree strongly about whether future AI systems could become sufficiently autonomous and capable to evade human control, manipulate operators, improve their own capabilities, or pursue objectives that conflict with human interests.

These scenarios are sometimes described as alignment or loss-of-control risks.

No consensus exists about their probability or timeline.

That uncertainty creates a difficult policy problem. Waiting for definitive evidence of a catastrophic capability could be irresponsible if the technology develops rapidly. But treating every hypothetical scenario as inevitable would also distort policy and public understanding.

This is why frontier AI companies increasingly use capability thresholds, evaluations, security controls, risk reports, and deployment safeguards rather than relying solely on predictions.

The practical question is becoming less philosophical: what capabilities does the system possess today, what damage could those capabilities enable, and what safeguards should be required before deployment?

Key Takeaways at a Glance

  • Capability growth drives risk growth: Models can now perform coding, research, tool use, and multi-step autonomous tasks that were considerably weaker two years ago.
  • Cyber risk is becoming operational: AI can accelerate reconnaissance, coding, vulnerability analysis, and social engineering.
  • Misuse is becoming easier to scale: AI can reduce the expertise and time required for fraud, propaganda, surveillance, and other harmful activities.
  • Agents create a new security problem: Systems capable of taking actions can cause more consequential failures than systems limited to producing text.
  • Catastrophic risks remain uncertain: Near-term harms are observable, while long-term loss-of-control scenarios require careful evaluation rather than certainty in either direction.
AI Risk What Has Changed Current Risk Level
Cyber Misuse Models can perform increasingly advanced coding and security tasks Already significant and increasing
Fraud and Deepfakes Synthetic media has become cheaper, faster and more convincing Established real-world risk
Autonomous Agents AI systems increasingly interact with external tools and systems Rapidly emerging operational risk
Scientific Misuse Models provide stronger technical assistance in specialized domains Closely monitored frontier risk
Loss of Control Greater autonomy and reasoning have increased research attention High uncertainty, potentially severe

The Real Change Is That AI Can Increasingly Act, Not Just Talk

The strongest evidence that AI risk has increased over the past two years is not a dramatic prediction about superintelligence.

It is the simpler fact that AI systems have become considerably more capable and considerably more connected to the real world.

A model that produces incorrect text has limited reach. A model that can write software, control tools, access databases, communicate with other systems, or autonomously pursue a multi-step objective has a much larger potential impact.

That does not mean AI development is automatically dangerous or that every capability increase produces proportional harm. Many of the same capabilities creating new risks also generate enormous benefits in science, productivity, medicine, software engineering, and education.

But benefit and risk are not opposites.

A technology can become more useful precisely because it becomes more powerful, and greater power usually increases the consequences of misuse or failure.

That is where AI appears to be today.

The risk debate has moved beyond hypothetical chatbot mistakes. The central challenge is increasingly how to deploy systems powerful enough to perform meaningful work while keeping their permissions, autonomy, security, and behavior within boundaries humans can reliably control.

Sources

  • OpenAI, “Our Updated Preparedness Framework,” April 15, 2025
  • OpenAI, “Frontier Governance Framework,” May 28, 2026
  • Anthropic, “Responsible Scaling Policy,” updated August 14, 2026
  • Anthropic, “Responsible Scaling Policy Version 3.0,” February 24, 2026
  • Reuters, “AI Models' Capabilities Leap Comes With New Safety Warnings,” September 9, 2026
  • Associated Press, reporting on emerging AI safety and loss-of-control concerns, September 2026

Popular posts from this blog

임신 테스트기 희미한 두 줄, 시약선일까 임신일까? 5분 뒤 나타난 선의 진실

도대체 '밤티'가 무슨 뜻일까? (경상도 사투리의 숨은 매력 분석)

🩹 수술 후 3개월, 다 나은 줄 알았던 피지낭종 부위에서 냄새와 진물이? 원인과 대처법