WRITTEN EVIDENCE SUBMITTED BY ANDREA MIOTTI

AND STEVEN ADLER

(RAI0031)

 

 

 

Written evidence

of

 

Andrea Miotti

Founder & CEO of ControlAI

 

&

 

Steven Adler

Former safety researcher and lead of “dangerous capability evaluations” at OpenAI

 

 

Before the UK Parliament’s Joint Select Committee on Human Rights

For an inquiry into “Human Rights and the Regulation of AI”

 

September 2025

 

 

Questions 2, 3, 4, 6 and 8 are examined herein

 

Both authors would welcome the opportunity to provide

oral evidence before the Committee.

 

 

On the authors

 

Andrea Miotti is the founder and CEO of ControlAI, a non-profit dedicated to reducing the risks posed by artificial intelligence. ControlAI develops policies to mitigate advanced AI risks, has engaged with policymakers in the UK, EU, and US, and has gained support from over 135,000 civil society members and more than 60 UK parliamentarians. ControlAI advocates for AI systems that serve as tools for humanity and enable safe technological innovation, while identifying superintelligent AI as the main vector for potential loss of control and supporting a global ban on such systems. Before founding ControlAI, Andrea was Head of Strategy and Governance at the AI startup Conjecture, which develops technical solutions to ensure AI systems remain controllable.

 

Steven Adler worked at OpenAI from December 2020 to November 2024, focusing on various safety-related research areas. He co-led the development of dangerous capability evaluations, identifying risks posed by advanced AI systems and creating methods to assess their capabilities. He designed evaluations in areas such as deception, persuasion, malware generation, and the concealment of security vulnerabilities. Several of these were incorporated into OpenAI’s Preparedness Framework, which guides risk assessment and safety protocols before a system is released publicly. All of Steven’s communications rely solely on public information, in compliance with his confidentiality agreement with OpenAI.

 

On the reason for submitting evidence

 

  1. The rights to life and security protected by Article 3 of the Universal Declaration of Human Rights (UDHR) can be compromised by advanced AI systems.

Article 3 of the UDHR affirms that “everyone has the right to life, liberty and security of person” [1]. This right can be undermined when public or private actors, in the course of their activities, create externalities through risk-taking that affect the wider population. In developing advanced AI systems, private companies are taking risks on behalf of all of society.

  1. Top experts have warned that the risks posed by AI systems could be severe enough to cause human extinction.

In 2023, Nobel Prize winners, leading AI scientists, and CEOs of AI companies, publicly released a statement which reads: “Mitigating the risk of extinction from AI should be a global priority alongside other societal-scale risks such as pandemics and nuclear war” [2]. Despite their warnings, the public has no say in determining the level of risk these companies may take on their behalf. Moreover, the mechanisms in domestic and international law for providing redress are often limited, reactive, and ill-suited to risks of the scale that - many of the world’s leading experts warn - could threaten the survival of humanity.

  1. In view of these warnings, it is important to carefully consider the impact of advanced AI systems on people's human rights.

The authors, whose expertise is strongest in this domain, hope that the Committee will find their contribution valuable.

Summary of Evidence Presented

 

  1. Question 2 regards the extent to which the UK’s existing legal framework provides sufficient protections for human rights in relation to AI. The authors respond that the current reliance on voluntary commitments leaves the UK vulnerable in protecting Article 3 of the UDHR. They explain how companies are, under this framework, within their rights to weaken their risk-mitigation strategies, and note that this has already occurred. The authors also point out that current risk-mitigation frameworks in AI companies contain gaps and vulnerabilities, while increased competitive pressures make compliance less likely.
  2. Question 3 examines whether the Government’s “AI Opportunities Action Plan” is sufficiently robust in safeguarding human rights. The authors conclude that it falls short of providing robust protection for Article 3 of the UDHR, as it maintains the reliance on voluntary commitments which leaves significant gaps in enforcement and accountability.
  3. Question 4 asks what future UK legislation would require to protect human rights. The authors emphasise the global nature of AI-related human rights risks and recommend that the UK pursue international consensus. Focusing on safeguarding the rights to life and security under Article 3 of the UDHR, they draw inspiration from the governance of chemical, biological, radiological, and nuclear (CBRN) technologies and advocate a treaty to prohibit superintelligent AI systems (the main vector of potential loss of control) along with restricting and monitoring precursor technologies.
  4. Question 6 seeks input on future-proof regulation capable of keeping pace with AI development to ensure the preservation of human rights. The authors emphasise the need to monitor existing precursors to artificial superintelligence while promptly identifying and restricting newly emerging ones. They also propose a comprehensive licensing regime that can be updated in line with the evolving state of AI capabilities.
  5. Question 8 considers the likely impact of the Council of Europe’s Framework Convention on AI, Human Rights, Democracy and the Rule of Law in the UK. The authors argue it will remain ineffective without legislation to enforce its binding obligations, as the current voluntary framework does not ensure compliance.

Supporting Context for the Evidence

  1. AI companies are rapidly advancing toward systems that could match or exceed human intelligence within the next decade.

 

  1. Current AI systems can already perform a range of sophisticated tasks, including programming of low-to-medium complexity, maintaining fluent conversations across multiple languages, and even achieving scientific breakthroughs [3]. For example, Google DeepMind’s Demis Hassabis and John Jumper received a Nobel Prize in Chemistry in October 2024 for developing an AI system that solved a 50-year-old problem: predicting protein structures [4]. In July 2025, AI systems from OpenAI and Google DeepMind also achieved gold-medal-level performance at the International Mathematical Olympiad, widely regarded as the world’s most prestigious competition for pre-university mathematicians [5], [6].

 

  1. Anticipating that automating tasks through AI will create substantial economic value, leading AI companies are committing tens to hundreds of billions of dollars [7], [8], [9], [10], [11] toward developing agentic AI systems designed to perform increasingly complex tasks with little to no oversight. Although today’s AI systems still struggle with complex, multi-step tasks, their proficiency in areas such as coding, research, and internet navigation is advancing rapidly.

 

  1. Several top experts predict that by 2030 we could see the emergence of artificial general intelligence (AGI) [12], [13], [14]: systems capable of performing essentially any cognitive task at a human level. Reflecting this view, the Secretary of State for Science, Innovation, and Technology, the Rt Hon Peter Kyle MP, recently remarked that “by the end of this parliament we are going to be knocking on artificial general intelligence.” [15] Some companies are already setting their sights beyond AGI, working toward artificial superintelligence (ASI) that would surpass human abilities across all domains [8], [16]. While ASI may seem a more distant prospect, the deployment of increasingly capable AI models, particularly in coding, to design and train future systems could dramatically accelerate its arrival [17].

 

 

  1. Top experts have warned that the risks posed by AI systems could be severe enough to cause human extinction.

Nobel Prize winners, leading AI scientists, and CEOs of major AI companies have placed the risks from AI systems on par with pandemics and nuclear war [2]. Dario Amodei, CEO of Anthropic, recently estimated that AI developers understand 3% [18] of how AI systems work, and has previously stated that his chance “that something goes really quite catastrophically wrong on the scale of human civilization might be somewhere between 10 per cent and 25 per cent” [19]. Similarly, experts such as Nobel laureate and “Godfather of AI” Geoffrey Hinton and Turing Award winner and the world’s most-cited[1] computer scientist Yoshua Bengio have cautioned that it is disturbingly unlikely that humanity will retain control over a more intelligent entity, a scenario unprecedented in human history [17], [22]. Geoffrey Hinton indeed resigned from his role as Vice President and Engineering Fellow at Google to be able to freely voice his concerns, and expressed that part of him regrets his contribution to the field [23].

Earlier this year, Secretary of State for DSIT Peter Kyle also stated that “we must consider the possibility that risks won’t just come from malicious actors misusing AI models, but from the models themselves [...] Losing oversight and control of advanced AI systems, particularly Artificial General Intelligence (AGI), would be catastrophic” and “must be avoided at all costs” [24].

  1. The development of AI capabilities is outpacing progress in ensuring control and oversight of advanced systems.

 

    1. The use of deep learning to train AI systems allows the development of increasingly powerful systems without a corresponding increase in explainability, transparency and control. Continued progress in AI capabilities is mostly dependent on resources such as AI chips, training data, and energy. Over the past decade, AI progress has been driven largely by the increasing computational power used to train these systems, which is estimated to have grown by 4-5x per year between 2010 and 2024 [25]. In contrast, progress in AI safety largely relies on achieving intellectual breakthroughs across a range of complex challenges. The science of managing AI risk remains underdeveloped, with current safety methods serving as temporary fixes rather than fundamental solutions. In this regard, the UK’s AI Security Institute recently warned that “today’s methods for training and controlling AI systems are likely insufficient for the systems of tomorrow.” Without further advances in AI safety, “future systems risk operating in ways we cannot fully understand or control, with profound implications for global safety and security” [26].

 

    1. Various research scenarios and experiments have evidenced the potential for agentic AI systems to pursue unintended objectives that conflict with human interests, including self-preservation instincts, blackmail tactics, and deceptive behaviour during evaluations [27], [28], [29], [30].

 

RESPONSES TO THE COMMITTEE’S QUESTIONS

 

Q2. To what extent does the UK’s existing legal framework provide sufficient protections for human rights in relation to AI?

 

  1. The UK’s legislative approach to AI currently relies on a framework of voluntary commitments which offer insufficient protections for human rights.

 

  1. In November 2023, the UK hosted the first AI Safety Summit at Bletchley Park, bringing together 28 countries and the European Union. The participants recognised the need to protect human rights through safety measures and appropriate human oversight. The resulting Bletchley Declaration acknowledged that frontier AI could pose safety risks, arising not only from potential intentional misuse but also from unintended loss of control [31].

 

  1. At the 2024 Seoul Summit, 16 major AI firms committed to publish safety frameworks, define “intolerable” risk thresholds that would justify halting the development or deployment of advanced AI systems, refrain from deploying such systems if risks could not be reliably reduced below those thresholds, and maintain internal accountability mechanisms with transparency to authorities and, where feasible, the wider public [32], [33]. If such commitments were honoured in practice, they would help safeguard the right to life under Article 3 of the UDHR by reducing foreseeable harm.

 

  1. The UK Government has stated its intention to introduce binding requirements for companies developing the most powerful AI systems, drawing on the voluntary commitments secured at the Seoul and Bletchley AI Summits and placing the AI Security Institute on a statutory footing [34], [35], [36], [37], [38]. However, these requirements have yet to be introduced. In the meantime, reliance on voluntary commitments leaves the UK vulnerable in protecting human rights.

 

  1. Reliance on a framework of voluntary commitments leaves the UK vulnerable in its protection of Article 3 of the UDHR.

 

Examples of voluntary risk-mitigation strategies include Anthropic’s Responsible Scaling Policy (September 2023) [39], OpenAI’s Preparedness Framework (December 2023) [40], and Google DeepMind’s Frontier Safety Framework (May 2024) [41]. These strategies have been updated following their respective publications.

 

  1. As long as commitments remain voluntary, AI companies are within their rights to weaken their risk-mitigation strategies. Cases of non-fulfilment of voluntary commitments have already occurred.

 

Consider, for instance, OpenAI’s Preparedness Framework. OpenAI treats this framework as a living document which “has revision as a built-in principle.” Following publication of evidence by former employee Steven Adler showing that OpenAI had not been meeting its testing commitments for months, the company quietly removed this requirement from an updated version of its Preparedness Framework without noting the change in its summary of updates [42]. In April 2025, the Financial Times also revealed that OpenAI had accelerated its safety testing schedule, cutting it down from several months to only a few days [43]. As reported by the Washington Post, this incident was not the first protestation of OpenAI’s safety teams that they feel pressured to rush through safety protocols [44].

 

Broken commitments are not unique to OpenAI; they have been a common issue among leading AI companies. For instance, the recent release of Gemini 2.5 Pro by Google DeepMind failed to honour the transparency requirements specified in paragraph VIII of the Seoul Summit commitments [32] . In response to this, 60 UK parliamentarians supported a letter on 29 August 2025 warning of the “dangerous precedent” that this sets, and noting that “Google’s technical capabilities come with commensurate obligations to society” [45]. Similarly, Anthropic abandoned commitments not to deploy any system of high risk without first developing risk-mitigation frameworks for systems of greater capability, shifting to a just-in-time approach [39], [46][2].

 

To avoid the security risks associated with the current regime of voluntary commitments, over 60 UK parliamentarians have supported ControlAI’s campaign calling for “binding regulation on the most powerful AI systems” [47].

 

  1. Current risk-mitigation frameworks within AI companies also have gaps and vulnerabilities.

 

OpenAI’s governing safety framework, the Preparedness Framework, assesses model capabilities, assigns risk levels, and sets precautions for deployment or continued operation. At the highest tier, “critical risk”, a model is considered so dangerous that it may be unsafe even to keep on OpenAI’s own systems, as it could be stolen and misused by hostile actors [40]. Former OpenAI employee Steven Adler warns that a system of this nature could emerge sooner rather than later, and that whether a large training run happens to reach critical level depends essentially on an accident of mathematics and science [48].

 

  1. Increased competition makes it less likely for companies to comply with their voluntary commitments.

 

Current and former members of the AI industry have expressed concern that strong financial incentives drive companies to avoid oversight [49]. They have also pointed out that companies cannot be relied upon to voluntarily disclose information about system capabilities, limitations, protective measures, risk levels, and potential harms [50].

 

As competitive pressures intensify, it becomes increasingly risky for the government to expect that AI companies comply with the voluntary commitments made at the Seoul Summit, and rely on this expectation for human rights to be protected.

 

  1. These vulnerabilities indicate that, at least in relation to Article 3 of the UDHR, the UK’s existing legal framework does not provide adequate protection for human rights.

 

The rights to liberty and security under Article 3 of the UDHR cannot be protected without binding legislation requiring effective risk-mitigation measures for advanced AI systems.

 

 

Q3. To what extent is the Government’s policy approach to deploying AI, expressed in its “AI Opportunities Action Plan”, sufficiently robust in respect of safeguarding human rights?

 

  1. The AI Opportunities Action Plan does not explicitly address the UK’s vulnerability in protecting human rights under voluntary commitments.

 

Despite some commendable measures - such as collaboration with existing regulators, deployment of regulatory sandboxes to foster innovation, and continued backing for the AI Security Institute - the AI Opportunities Action Plan does not explicitly address the problems arising from the UK’s reliance on voluntary commitments [51]. Safety and assurance, as invoked in the Plan, require regulation with statutory force to ensure human rights are safeguarded and that AI systems are developed and deployed under rigorous, enforceable controls.

 

  1. Accordingly, the AI Opportunities Action Plan does not, on its own, offer robust protections to Article 3 of the UDHR.

 

Q4. What would be needed in any future UK legislation to protect human rights?

 

  1. AI-related risks to human rights, such as the rights to life and security, have an international scope. The UK cannot address these risks fully through domestic measures alone and should therefore pursue international consensus.

 

When legislating to protect human rights, including Article 3 of the UDHR, a key question arises: can the UK address AI-related human rights risks through domestic measures alone? As with other dual-use technologies - such as chemical, biological, radiological, and nuclear (CBRN) - how other countries develop and deploy AI can also endanger UK citizens. To safeguard rights such as life and security, future UK legislation must therefore be grounded in international consensus.

 

  1. International CBRN treaties illustrate how layered, defence-in-depth frameworks can enable safe civilian use of high-risk technologies while preventing their most dangerous applications.

 

  1. Multiple international treaties address high-risk technologies.

 

Some significant, although imperfect successes, include the Chemical Weapons Convention [52] and the Treaty on the Non-Proliferation of Nuclear Weapons [53] . These agreements demonstrate how international frameworks can support the safe development of beneficial civilian applications while restricting a small subset of harmful uses.

 

  1. CBRN international agreements employ a defence-in-depth framework: layered protections designed to mitigate the most serious risks.

 

In practice, this approach typically combines three core elements: outright prohibitions on harmful applications, licensing regimes to control authorised uses, and regulation of precursor materials to prevent their diversion into prohibited activities. For biological and chemical agents, UK law and international treaties impose a complete ban on weaponisation, with no blanket exemptions for state or military use [52], [54], [55], [56], [53]. Nuclear technology, while permitted for the UK’s military under international treaty provisions, is strictly regulated in the civilian sphere and subject to non-proliferation obligations and long-term disarmament commitments aimed at reducing arsenals [51], [52], [58].

 

  1. Safeguarding the right to life and security in AI development requires a CBRN-style approach that permits beneficial uses while prohibiting the creation of superintelligent AI systems.

 

  1. Most AI systems are tools to advance human welfare. Superintelligent AI systems carry severe risks to life and security.

 

Protecting the right to life and security, ensuring robust risk and impact management, and maintaining effective oversight throughout the AI lifecycle require an approach akin to that used for CBRN technologies: one that targets the most dangerous subsets of the technology while enabling beneficial applications to flourish under oversight proportionate to their risks. Most AI systems, though imperfect, do not endanger life and security and instead are tools that serve to advance human welfare. By contrast, superintelligent AI systems - the primary vector for potential loss of human control - pose catastrophic risks, including human extinction, according to top experts. Therefore, the international community should work toward consensus on a binding global treaty that bans the development of superintelligent AI systems and establishes enforcement mechanisms to ensure no private actor, company, or government can pursue it outside this treaty. This is not to be lifted before there is a scientific consensus that it can be built safely and controllably, with clear public buy-in on the project [60].

 

  1. An international AI treaty should prohibit superintelligent AI development and establish an IAEA-like authority to monitor global compliance.

 

The prohibition on developing superintelligent AI systems should be enshrined in an international treaty that harmonises regulatory frameworks across all participating countries. Through the signing of the AI treaty, a new international authority should also be established to monitor compliance with the treaty, promote AI safety research, and facilitate cooperation between signatories. The new international institution could be modeled on the International Atomic Energy Agency (IAEA), serving as the administrative backbone of the treaty with the authority to inspect and audit facilities in signatory states and monitor AI development to ensure compliance [60].

 

 

Q6. How might regulation match the pace of AI technology development, such as the emergence of agentic AI, to ensure that human rights are preserved as technology continues to develop?

 

  1. To keep pace with AI development and safeguard human rights, existing precursors to artificial superintelligence must be monitored, while newly emerging ones should be promptly identified and appropriately restricted.

 

  1. As outlined in Question 4, AI should be governed through a defence-in-depth framework, similar to that used for CBRN technologies, with layered protections to address the most severe risks. Domestically, this could be implemented via an independent body with statutory powers working closely with the UK security apparatus. To keep legislation aligned with rapid AI advances and protect human rights, key measures include restricting and monitoring precursor technologies and adopting a licensing regime that can adapt as AI capabilities evolve.

 

  1. Restricting and monitoring precursors to superintelligent AI systems prevents their diversion into harmful activities. These precursors do not qualify as superintelligent AI systems themselves, but could be easily diverted to create such systems. For example, AI systems with self-improvement capabilities could easily lead to uncontrolled AI development, while self-replication capabilities would make it more difficult to shut down a system should this become necessary, as the system could escape containment. As more dangerous capabilities are identified through the ongoing development and examination of advanced AI systems, the subset of precursors that authorities should restrict and monitor must evolve accordingly.

 

  1. Comprehensive licensing requirements should also be established and regularly updated in line with the evolving state of AI capabilities.

 

  1. A comprehensive licensing regime enables authorities to maintain effective oversight across the AI lifecycle and supply chain, reducing the risk of negative impacts on human rights. To keep pace with AI development, licensing requirements can adapt to reflect current AI capabilities and agency, ensuring oversight remains proportional to the risks posed by each training run or deployed system.

 

  1. To ensure that scrutiny scales with a system’s capabilities and risks, a reliable proxy for measuring those capabilities is essential. This proves challenging since humanity lacks both a general predictive theory of intelligence and a metrology of intelligence. Currently, the computational resources (compute) used to train AI systems serve as a widely accepted proxy for capabilities, with compute thresholds helping legislators distinguish between controllable systems and those posing risks of loss of control. As an imperfect measure, compute thresholds need to be complemented with other protections from the defence-in-depth approach: for instance, alternative proxies for the measurement of capabilities, monitoring and restricting dangerous precursors, and requiring developers to design and implement risk-mitigation strategies before training systems.

 

  1. AI developers must obtain a training license and secure approval before commencing model training. Andrea Miotti proposes that this license requirement is triggered when systems are trained above the compute threshold of 10^25 FLOP - a standard measure of the number of mathematical operations that the system performs during training -. The license application must detail the planned training run, expected system capabilities, risk management and mitigation measures, safety protocols, and additional specified requirements. Similarly, cloud computing service providers and data centre operators must hold a compute license, comply with know-your-customer regulations, and implement physical GPU tracking. Andrea Miotti proposes that this requirement be triggered when cloud computing providers operate above 10^17 FLOP/s - a standard measure of the number of mathematical operations a system performs per second during training[3]. Finally, Andrea Miotti proposes that any developer intending to develop an AI application that draws on a licenced model whose capabilities are enhanced for the purpose of developing the application must also apply for an application license [60].

 

 

  1. Should authorities receive evidence that artificial intelligence systems below the specified threshold demonstrate a significant likelihood of developing artificial superintelligence or dangerous capabilities, or that technological advances have substantially reduced the compute requirements for developing such capabilities, they should be able to adjust the compute threshold accordingly.

 

  1. This three-tiered licensing regime would enable oversight across the supply chain of the most capable AI systems, which pose the greatest risks of loss of control and, consequently, to the right to life and security. The proxy used to identify such systems can be updated to reflect the current state of AI capabilities and supplemented with additional safeguards, such as restrictions on dangerous capabilities and mandatory risk-mitigation plans. Together, these measures would strengthen protection of the right to life and security under Article 3 of the UDHR while supporting the safe innovation envisioned by the Council of Europe’s Framework.

 

 

Q8. The likely impact of the Council of Europe’s Framework Convention on Artificial Intelligence, Human Rights, Democracy and the Rule of Law on human rights protection in the UK.

  1. The Council of Europe’s Framework Convention on Artificial Intelligence, Human Rights, Democracy and the Rule of Law could strengthen protections for Article 3 of the UDHR.

The Council of Europe’s Framework Convention on Artificial Intelligence, Human Rights, Democracy and the Rule of Law outlines mechanisms that could help protect the rights to life and security set out in Article 3 of the UDHR. These include transparency and oversight throughout the AI system lifecycle (Article 8), measures to promote system reliability (Article 12), safe innovation (Article 13), and the adoption of risk and impact management frameworks to prevent and mitigate AI-related risks (Article 16) [61].

To maximise their effectiveness, however, these provisions must be translated into more specific guidelines through domestic legislation, supported by robust domestic enforcement mechanisms. For the Convention to provide comprehensive protection to human rights, the domestic regulatory regime would also need to introduce redress mechanisms - measures notably absent from the Seoul Commitments.

  1. Because the current voluntary framework does not guarantee compliance with the broader binding obligations set out in the Council of Europe’s Convention, the Convention is likely to remain ineffective unless such legislation is enacted.

Until then, adherence to the framework’s provisions remains entirely at the discretion of AI companies.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

REFERENCES

 

[1]              United Nations, ‘Universal Declaration of Human Rights’. [Online]. Available: https://www.un.org/en/about-us/universal-declaration-of-human-rights

[2]              ‘Statement on AI Risk’. Centre for AI Safety, 2023. [Online]. Available: Statement on AI Risk

[3]              Bengio, Y., et al., ‘International AI Safety Report 2025’, 2025. [Online]. Available: https://www.gov.uk/government/publications/international-ai-safety-report-2025/international-ai-safety-report-2025

[4]              ‘Nobel Prize in Chemistry 2024 - Press Release’. The Royal Swedish Academy of Sciences, Oct. 09, 2024. [Online]. Available: https://www.nobelprize.org/prizes/chemistry/2024/press-release/

[5]              T. Luong and E. Lockhart, ‘Advanced version of Gemini with Deep Think officially achieves gold-medal standard at the International Mathematical Olympiad’. Google DeepMind, July 21, 2025. [Online]. Available: https://deepmind.google/discover/blog/advanced-version-of-gemini-with-deep-think-officially-achieves-gold-medal-standard-at-the-international-mathematical-olympiad/

[6]              A. Wilkins, ‘DeepMind and OpenAI claim gold in International Mathematical Olympiad’, New Scientist, July 22, 2025. [Online]. Available: https://www.newscientist.com/article/2489248-deepmind-and-openai-claim-gold-in-international-mathematical-olympiad/

[7]              OpenAI, ‘Announcing The Stargate Project’. Jan. 21, 2025. [Online]. Available: https://openai.com/index/announcing-the-stargate-project/

[8]              Hannah Murphy, ‘Meta shares jump on strong results as Zuckerberg sets out “superintelligence” goals’, Financial Times, July 30, 2025.

[9]              Anthropic, ‘Powering the next generation of AI development with AWS’. Nov. 22, 2024. [Online]. Available: https://www.anthropic.com/news/anthropic-amazon-trainium

[10]              Carmen Arroyo and Jill R Shah, ‘Musk’s xAI Burns Through $1 Billion a Month as Costs Pile Up’, Bloomberg, June 17, 2025. [Online]. Available: https://www.bloomberg.com/news/articles/2025-06-17/musk-s-xai-burning-through-1-billion-a-month-as-costs-pile-up?embedded-checkout=true

[11]              Thomas Seal, ‘DeepMind CEO Says Google Will Spend More Than $100 Billion on AI’, Bloomberg, Apr. 16, 2024. [Online]. Available: https://www.bloomberg.com/news/articles/2024-04-16/deepmind-ceo-says-google-will-spend-more-than-100-billion-on-ai?embedded-checkout=true

[12]              Anthropic, ‘Statement from Dario Amodei on the Paris AI Action Summit’. Feb. 11, 2025. [Online]. Available: https://www.anthropic.com/news/paris-ai-summit

[13]              Steven Rose, ‘Demis Hassabis on our AI future: “It’ll be 10 times bigger than the Industrial Revolution – and maybe 10 times faster”’, The Guardian, Aug. 04, 2025. [Online]. Available: https://www.theguardian.com/technology/2025/aug/04/demis-hassabis-ai-future-10-times-bigger-than-industrial-revolution-and-10-times-faster

[14]              D. Kokotajlo, S. Alexander, T. Larsen, E. Lifland, and R. Dean, ‘AI 2027’. Apr. 03, 2025. [Online]. Available: https://ai-2027.com/

[15]              Jimmy’s Jobs of the Future, ‘5 Things Labour’s AI Masterplan Can Teach Us About The Future’, July 08, 2025. [Online]. Available: https://youtu.be/WW9yKHcd-0I?t=2638

[16]              ‘Governance of superintelligence’. OpenAI, May 22, 2023. [Online]. Available: https://openai.com/index/governance-of-superintelligence/

[17]              ‘AI 2030 Scenarios Report HTML (Annex C)’, GOV.UK, Jan. 2024. [Online]. Available: https://www.gov.uk/government/publications/frontier-ai-capabilities-and-risks-discussion-paper/ai-2030-scenarios-report-html-annex-c

[18]              Norges Bank Investment Management, ‘Dario Amodei - CEO of Anthropic | Podcast | In Good Company | Norges Bank Investment Management’, June 26, 2024. [Online]. Available: https://youtu.be/xm6jNMSFT7g?t=161

[19]              D. Alex, ‘CEO of AI company warns his tech has a large chance of ending the world’, Indy100, Oct. 09, 2023. [Online]. Available: https://www.indy100.com/science-tech/ai-extinction-chance-humans#

[20]              ‘Highly Cited Researchers 2.626.767 Scientists Citation Rankings - 2026’. AD Scientific Index, 2025. [Online]. Available: https://www.adscientificindex.com/citation-ranking/

[21]              S. Brown, ‘Why neural net pioneer Geoffrey Hinton is sounding the alarm on AI’, MIT Management Sloan School, May 23, 2023. [Online]. Available: https://mitsloan.mit.edu/ideas-made-to-matter/why-neural-net-pioneer-geoffrey-hinton-sounding-alarm-ai

[22]              TED, ‘The Catastrophic Risks of AI — and a Safer Path | Yoshua Bengio | TED’, May 21, 2025. [Online]. Available: https://www.youtube.com/watch?v=qe9QSCF-d88

[23]              C. Metz, ‘“The Godfather of A.I.” Leaves Google and Warns of Danger Ahead’, New York Times. [Online]. Available: https://www.nytimes.com/2023/05/01/technology/ai-google-chatbot-engineer-quits-hinton.html

[24]              ‘Remarks made by Technology Secretary Peter Kyle at the Munich Security Conference’. GOV.UK, Feb. 14, 2025. [Online]. Available: https://www.gov.uk/government/speeches/remarks-made-by-technology-secretary-peter-kyle-at-the-munich-security-conference

[25]              ‘Machine Learning Trends’. EpochAI, Jan. 13, 2025. [Online]. Available: https://epoch.ai/trends#:~:text=Our%20expanded%20AI%20model%20database,and%20models%20from%20leading%20companies.

[26]              ‘AI Security Institute launches international coalition to safeguard AI development’. GOV.UK, July 30, 2025. [Online]. Available: https://www.gov.uk/government/news/ai-security-institute-launches-international-coalition-to-safeguard-ai-development

[27]              A. Meinke, B. Schoen, J. Scheurer, M. Balesni, R. Shah, and M. Hobbhahn, ‘Frontier Models are Capable of In-context Scheming’. Dec. 06, 2025. [Online]. Available: https://arxiv.org/abs/2412.04984

[28]              ‘Sabotage evaluations for frontier models’. Anthropic, Oct. 18, 2024. [Online]. Available: https://www.anthropic.com/research/sabotage-evaluations

[29]              ‘Detecting misbehavior in frontier reasoning models’. OpenAI, Mar. 10, 2025. [Online]. Available: https://openai.com/index/chain-of-thought-monitoring/

[30]              ‘Agentic Misalignment: How LLMs could be insider threats’. Anthropic, June 20, 2025. [Online]. Available: https://www.anthropic.com/research/agentic-misalignment

[31]              ‘The Bletchley Declaration by Countries Attending the AI Safety Summit, 1-2 November 2023’. GOV.UK, Nov. 02, 2023. [Online]. Available: https://www.gov.uk/government/publications/ai-safety-summit-2023-the-bletchley-declaration/the-bletchley-declaration-by-countries-attending-the-ai-safety-summit-1-2-november-2023

[32]              GOV.UK, ‘Frontier AI Safety Commitments, AI Seoul Summit 2024’. Feb. 07, 2025. [Online]. Available: https://www.gov.uk/government/publications/frontier-ai-safety-commitments-ai-seoul-summit-2024/frontier-ai-safety-commitments-ai-seoul-summit-2024

[33]              ‘New commitment to deepen work on severe AI risks concludes AI Seoul Summit’. GOV.UK, May 22, 2024. [Online]. Available: https://www.gov.uk/government/news/new-commitmentto-deepen-work-on-severe-ai-risks-concludes-ai-seoul-summit

[34]              ‘Labour Party Manifesto 2024: Our plan to change Britain’. Labour Party, Jan. 13, 2024. [Online]. Available: https://labour.org.uk/updates/stories/labour-manifesto-2024-sign-up/

[35]              London Tech Week 2024: Keynote and Q&A with Peter Kyle. [Online Video]. Available: https://youtu.be/5K6ozLdNaTU?t=833

[36]              ‘AI Opportunities Action Plan Volume 752: debated on Friday 26 July 2024’. Hansard, July 26, 2024. [Online]. Available: https://hansard.parliament.uk/commons/2024-07-26/debates/24072618000012/AIOpportunitiesActionPlan#:~:text=Volume%20752%3A%20debated%20on%20Friday%2026%20July%202024&text=Through%20targeted%20action%20this%20Government,services%20to%20make%20them%20better.

[37]              ‘AI Opportunities Action Plan Volume 846: debated on Thursday 5 June 2025’. Hansard, June 05, 2025. [Online]. Available: https://hansard.parliament.uk/Lords/2025-06-05/debates/D222E294-6D4E-4F99-8708-F7BE32F4F45F/AIOpportunitiesActionPlan?highlight=consultation#contribution-F8C82A71-EB5C-4D04-AB5A-EA5E69861750

[38]              ‘The Government response to the Call for Views on the cyber security of AI Statement made on 3 February 2025’. Hansard, Feb. 03, 2025. [Online]. Available: https://questions-statements.parliament.uk/written-statements/detail/2025-02-03/hlws404

[39]              ‘Anthropic’s Responsible Scaling Policy (version 2.2)’. Anthropic, May 14, 2025. [Online]. Available: https://www-cdn.anthropic.com/872c653b2d0501d6ab44cf87f43e1dc4853e4d37.pdf

[40]              ‘Our updated Preparedness Framework’. OpenAI, Apr. 15, 2025. [Online]. Available: https://openai.com/index/updating-our-preparedness-framework/

[41]              ‘Introducing the Frontier Safety Framework’. Google DeepMind, May 17, 2024. [Online]. Available: https://deepmind.google/discover/blog/introducing-the-frontier-safety-framework/

[42]              A. Steven, ‘AI companies should be safety-testing the most capable versions of their models’, Clear-Eyed AI. [Online]. Available: https://stevenadler.substack.com/p/ai-companies-should-be-safety-testing

[43]              C. Criddle, ‘OpenAI slashes AI model safety testing time’, Financial Times, Apr. 11, 2025. [Online]. Available: https://www.ft.com/content/8253b66e-ade7-4d1f-993b-2d0779c7e7d8

[44]              P. Verma, T. Nitasha, and C. Zakrzewski, ‘OpenAI promised to make its AI safe. Employees say it “failed” its first test.’, The Washington Post, July 12, 2024.

[45]              PauseAI UK, ‘Letter to Sir Demis Hassabis’, Aug. 29, 2025. [Online]. Available: https://pauseai.info/dear-sir-demis-2025

[46]              G. Lovely, ‘Exclusive: Anthropic is Quietly Backpedalling on its Safety Commitments’, Obsolete. [Online]. Available: http://obsolete.pub/p/exclusive-anthropic-is-quietly-backpedalling

[47]              ControlAI, ‘ControlAI Campaign Statement’. 2025. [Online]. Available: https://controlai.com/statement

[48]              ControlAI, ‘Ex-OpenAI Researcher Warns AI Companies Will Lose Control of AI | ControlAI Podcast w/ Steven Adler’, June 24, 2025. [Online]. Available: https://youtu.be/dMQWlvUKfGA?t=624

[49]              H. Toner, ‘Written testimony of Helen Toner Director of Strategy and Foundational Research Grants Center for Security and Emerging Technology, Georgetown University Before the U.S. Senate Committee on the Judiciary Subcommittee on Privacy, Technology, and the Law For a hearing on “Oversight of AI: Insiders’ Perspectives” September 17, 2024’. Sept. 17, 2024. [Online]. Available: https://www.judiciary.senate.gov/imo/media/doc/2024-09-17_pm_-_testimony_-_toner.pdf

[50]              J. Hilton et al., ‘A Right to Warn about Advanced Artificial Intelligence’. June 04, 2024. [Online]. Available: https://righttowarn.ai/

[51]              ‘AI Opportunities Action Plan’. GOV.UK, Jan. 13, 2025. [Online]. Available: https://www.gov.uk/government/publications/ai-opportunities-action-plan/ai-opportunities-action-plan

[52]              ‘Chemical Weapons Convention’. Organisation for the Prohibition of Nuclear Weapons, 1993. [Online]. Available: https://www.opcw.org/chemical-weapons-convention

[53]              ‘Treaty on the Non-Proliferation of Nuclear Weapons (NPT)’. GOV.UK, 1968. [Online]. Available: https://disarmament.unoda.org/wmd/nuclear/npt/

[54]              ‘The Biological Weapons Convention’. United Nations - Office for Disarmament Affairs Treaties Database, 1972. [Online]. Available: https://treaties.unoda.org/t/bwc

[55]              ‘Biological Weapons Act 1974’. GOV.UK, 1974. [Online]. Available: https://www.legislation.gov.uk/ukpga/1974/6/contents

[56]              ‘Chemical Weapons Act 1996’. GOV.UK, 1996. [Online]. Available: https://www.legislation.gov.uk/ukpga/1996/6/contents

[57]              ‘Nuclear Explosions (Prohibition and Inspections) Act 1998’. GOV.UK. [Online]. Available: https://www.legislation.gov.uk/ukpga/1998/7/contents

[58]              ‘Nuclear Safeguards Act 2018’. Gov, 2018. [Online]. Available: https://www.legislation.gov.uk/ukpga/2018/15/contents

[59]              ‘Anti-terrorism, Crime and Security Act 2001’. GOV.UK, 2001. [Online]. Available: https://www.legislation.gov.uk/ukpga/2001/24/contents

[60]              A. Miotti, T. Bilge, D. Kasten, and J. Newport, ‘A Narrow Path’. Oct. 02, 2024. [Online]. Available: https://www.narrowpath.co/

[61]              ‘Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law’, Counc. Eur., Sept. 2024, [Online]. Available: https://rm.coe.int/1680afae3c

 

 

 

(Sept 2025)

 

16


[1] According to the AD Scientific Index (Engineering & CS) [20].

[2] In its May 14 update, Anthropic released Claude Opus 4 (its first release to trigger the risk level AI Safety Level 3) without having publicly outlined a risk-management plan for AI Safety Level 4 systems, as it had previously committed to doing.

[3] The 10^17 FLOP/s threshold is numerically lower because it measures a rate (throughput per second), whereas 10^25 FLOP is a total amount of compute for a training run.