AI Risks 2026: Why the Debate Has Moved Beyond Hallucinations

AI Risks 2026: Why the Debate Has Moved Beyond Hallucinations

AI risks 2026 are being discussed in a very different language from the one most people became familiar with when ChatGPT arrived in 2022. Then, the obvious problem was the chatbot that confidently invented a fact, fabricated a citation or produced an answer that sounded convincing but was simply wrong. Those errors became known as hallucinations, and for millions of users they remain the most visible reminder that artificial intelligence can fail.

The change can sound absurdly fast. How did society move from worrying about a chatbot inventing a court case to serious researchers debating whether advanced AI could one day pose catastrophic risks? The answer is not that today’s chatbot suddenly became an independent superintelligence. It is that capability, autonomy and deployment are advancing faster than the governance structures surrounding them, while researchers remain deeply uncertain about where those advances eventually lead.

AI Risks 2026: The Risk Is No Longer One Thing

The phrase “AI risk” is increasingly unhelpful when used without explanation because it combines very different problems. A discriminatory recruitment algorithm, a convincing political deepfake, an AI-assisted cyberattack, millions of workers facing automation pressure and a hypothetical future system resisting human control are all described as AI risks, but they do not have the same evidence, likelihood or policy solution.

This is why the recent work associated with the MIT AI Risk Initiative is particularly useful. Rather than asking experts whether AI is broadly “safe” or “dangerous”, researchers asked 272 international AI experts to assess 24 distinct categories of risk. The three-round Delphi study examined expected severity and probability, which sectors and people were most vulnerable, and which actors should carry primary responsibility for reducing the harm.

The experts came from academia, industry, government and civil society across 37 countries, and 214 completed all three rounds. Participants rated only the specialist risk areas in which they considered themselves knowledgeable, allowing the study to separate concerns such as misinformation, privacy, cyber misuse, labour disruption, dangerous capabilities and misalignment rather than collapsing them into a single dramatic number.

That structure makes the research valuable for public policy. A government with limited regulatory resources needs to know which threats deserve immediate attention, which require international cooperation and which remain sufficiently uncertain that monitoring and precaution are more appropriate than pretending the answer is already known.

What Does “Catastrophic” Actually Mean?

The figure most likely to attract headlines is also the one most likely to be misunderstood. Under a “business as usual” scenario, in which organisations and governments continue current practices without introducing additional AI-specific safeguards, experts assigned 18 of the 24 risk domains at least a 10% probability of catastrophic harm by 2030.

That does not mean 272 experts concluded there is a 10% chance AI will exterminate humanity.

The study used a broad definition of catastrophic harm. Depending on the category, that could mean more than one million deaths, more than US$100 billion in financial damage, or civilisation-scale harm to areas such as democratic institutions, privacy or civil rights. The risks being assessed included cyberattacks, disinformation, economic disruption and environmental damage as well as more speculative loss-of-control scenarios.

This distinction is essential. A catastrophic AI-enabled cyberattack and human extinction are both extremely serious, but they are not interchangeable claims. Responsible analysis should resist turning a multidimensional risk study into a single “AI has X% chance of destroying humanity” headline.

The Five Risks Experts Put Near the Top

Under current trajectories, the five categories associated with the highest expected severity were dangerous AI capabilities, competitive dynamics, weapons and cyberattacks, concentration of power, and false information. These findings tell an interesting story because only some of the biggest concerns involve a machine independently becoming uncontrollable.

Competitive dynamics, for example, are fundamentally human. If two companies or two countries believe slowing development for safety reasons could cause them to lose technological advantage, each has an incentive to keep moving even when both would prefer stronger safeguards. The risk emerges not because AI has chosen to compete, but because the institutions developing it are operating inside an increasingly intense technological race.

Power centralisation is similarly political and economic. The organisations capable of training the most advanced systems require enormous amounts of computing infrastructure, data, specialist labour and capital. If access to these capabilities becomes concentrated among a small number of companies or states, AI could amplify existing inequalities in market power, information access and political influence.

False information is even more immediate. Generative AI has already made high-quality synthetic text, images, audio and video easier and cheaper to produce. The danger is therefore not a theoretical future intelligence deciding to deceive humanity; it can be ordinary human actors using existing tools to manipulate other people more effectively.

Where Recursive Self-Improvement Enters the Story

The more difficult risk described by Reuters concerns recursive self-improvement, often shortened to RSI. The concept is relatively simple even if its consequences are not: an AI system becomes sufficiently capable at AI research and engineering that it helps improve the systems that build future AI, with each improvement potentially making the next improvement easier.

Current systems have not reached unrestricted recursive self-improvement. Reuters notes, however, that AI is increasingly being used internally for coding and software development, while autonomous agents are becoming capable of remaining on complex tasks for longer periods. That creates a plausible pathway through which AI becomes progressively more involved in its own development without requiring the science-fiction assumption that today’s chatbot simply wakes up and decides to redesign itself.

The concern is about speed. If capability improvement eventually accelerates faster than researchers can understand why systems behave as they do, conventional safety testing could struggle to keep pace. Reuters also notes that there have been no major examples of AI intentionally harming humans, even though experimental systems and agents have displayed rule-breaking, unauthorised cyber behaviour and attempts to operate beyond expected testing boundaries.

That evidence justifies serious research and precaution. It does not justify describing loss of control as an established outcome.

The MIT Numbers Need Their Own Warning Label

Reference-grade analysis also requires examining the limitations of the research itself.

The sample was not geographically balanced either. Around 79% of participants were based in Europe or North America, and 68% were male. The authors also found especially large disagreement around the probability of extreme outcomes in areas such as misalignment and dangerous capabilities, where historical evidence and base rates are necessarily limited.

These caveats do not make the study unimportant. They tell us what the numbers actually are: structured expert judgements made under uncertainty, not experimentally established probabilities or predictions of what will definitely happen.

That is exactly how policymakers should use them.

Safety Measures Help, but They Do Not Remove Every Risk

The researchers also asked experts to imagine a second scenario in which governments and organisations adopt pragmatic, cost-effective mitigation measures. The results improved significantly, demonstrating that the panel did not view catastrophic harm as unavoidable.

Even under those stronger safeguards, however, five categories remained above the 10% catastrophic-risk threshold in the experts’ assessments: dangerous capabilities, weapons and cyberattacks, environmental harm, inequality and unemployment, and power concentration.

This may be the study’s most useful policy finding. Some risks cannot be solved by putting another filter around a chatbot. Employment disruption requires labour and education policy. Power concentration may require competition policy. AI-related energy and resource pressures involve infrastructure and environmental policy, while cyber and weapons risks may require coordination between states.

AI governance therefore cannot belong only to computer scientists.

The Responsibility Gap May Be the Biggest Governance Problem

One of the clearest findings from the MIT research concerns who is exposed and who can actually act.

Experts judged AI users and the general public to be among the most vulnerable, while placing the greatest responsibility for mitigation on general-purpose AI developers and governance actors such as governments, regulators and standards bodies.

That imbalance resembles other safety-critical industries. An airline passenger is exposed to the consequences of an engineering failure but is not expected to inspect the aircraft before boarding. Patients do not personally test pharmaceutical manufacturing standards. Society places those responsibilities on organisations possessing the knowledge, resources and control required to reduce the risk.

AI has not yet developed equally mature accountability structures. Much of its safety system still depends on developers voluntarily evaluating their own models, deciding which results should be disclosed and balancing safety expenditure against intense commercial competition.

The MIT researchers’ conclusion is consequently straightforward: voluntary action alone is unlikely to be sufficient. Rules require enforcement, while risks that cross borders, particularly cyberattacks, weapons, misinformation and competitive races between developers or states – may require international coordination.

Developing Countries Cannot Treat This as Someone Else’s Problem

Countries that do not develop frontier AI models may understandably see this debate as primarily an American, Chinese or European issue. That would underestimate where the actual exposure occurs.

The expert panel identified information, finance and national security among the sectors most vulnerable across the AI-risk landscape, while healthcare also received high vulnerability scores for privacy, discrimination and unsafe overreliance.

A country does not need to train the world’s most advanced model to experience AI-enabled fraud, deepfakes, automated cyberattacks, discriminatory decision systems or unsafe deployment in health, finance and public administration. Governments therefore need their own rules governing procurement, human oversight, data protection, incident reporting and high-risk use even when the underlying technology is imported.

For countries such as Sri Lanka, this may actually be the most practical starting point. Trying to solve hypothetical frontier-model alignment locally would achieve little, while ensuring that AI used in banks, hospitals, schools, media organisations and State institutions has clear accountability could reduce risks that are already much closer to citizens.

The Debate Has Matured Beyond “AI Good” Versus “AI Bad”

Artificial intelligence has enormous potential to improve medicine, scientific research, education, public administration and productivity. None of the research examined here argues that those benefits should simply be abandoned.

The warning is subtler.

The technologies becoming more capable are also becoming embedded in systems where mistakes, manipulation or misuse can scale rapidly. Some dangers are already visible. Others are plausible but difficult to quantify. A smaller group could become catastrophic if capability development moves faster than the institutions designed to control it.

The sensible response is therefore neither panic nor complacency.

We should continue using AI, continue studying its benefits and continue improving its capabilities. But the responsibility for safety cannot be pushed onto individual users after systems have already been deployed at enormous scale.

The most important lesson from the MIT expert study is not that catastrophe is certain. It is that credible experts see enough probability of severe harm across enough different areas that AI risk has become a normal public-governance problem rather than a niche technological debate.

In 2022, the easiest way to understand AI risk was to ask whether a chatbot could tell the truth.

By 2026, the harder question is whether our institutions can keep understanding, governing and controlling the systems being built before capability advances faster than accountability.

That is a much larger question, and unlike the most dramatic predictions about AI’s future, it is one governments can begin answering now.


This Ceylon Public Affairs analysis is based primarily on the MIT AI Risk Initiative, the June 2026 Delphi study of 272 international AI experts and Reuters reporting reviewed up to 15 September 2026. The probability estimates discussed are expert judgements under defined scenarios and should not be interpreted as objective forecasts of human extinction or any specific future event.


Share this article