Power grab by a small group
A coup has always required the cooperation of many people, and that requirement was itself the safeguard. If critical personnel —military, civil service, technical— can be replaced by systems loyal to one person, the distributed veto disappears.
- Horizon
- 3–10 years
- Evidence
- Speculative
- Consensus
- Low
The starting point is a structural fact, not a hypothesis: historically a seizure of power requires the cooperation of many people —soldiers who obey, officials who carry orders out— and that need for cooperation is itself the safeguard. Tom Davidson, Lukas Finnveden and Rose Hadshar argue that an AI more broadly capable than humans dissolves it, and describe three routes that can combine [420]AI-Enabled Coups: How a Small Group Could Use AI to Seize PowerView source ↗.
The first is singular loyalties: if critical personnel can be replaced by systems loyal to a single person or to a small group, the distributed veto of whoever refuses to obey disappears. The second is secret loyalties: a system that appears to serve the institution while working for someone else, insertable and propagable across generations of models, with the difference that a human spy does not replicate. The third is exclusive access to enabling capabilities —weapons design, strategic planning, persuasion, cyber offence— in the hands of a few and before anyone else.
It is the most speculative of the six and that is worth saying first: it is institute work, not peer-reviewed, and its core is a conditional argument about capabilities that do not yet exist. The International AI Safety Report holds that current systems show early signs of relevant capabilities, but not at levels that would enable loss of control [538]International AI Safety Report 2026View source ↗. The most substantive counterargument is that the safeguard was never technical cooperation alone: legitimacy, federalism and international coordination also count, and none of them dissolves automatically. Narayanan and Kapoor frame it as the separation between capability and power [773]AI as Normal TechnologyView source ↗.
In favour of taking it seriously there is one panel figure, which is no more than that: the Delphi study of 272 experts places power centralisation among the five risks with the highest expected severity, and among the five that stay above a 10% probability of catastrophic harm by 2030 even assuming pragmatic mitigations [927]Prioritization of Risks from Artificial Intelligence: A Delphi Study of 272 International ExpertsView source ↗. These are expert beliefs aggregated with a common rubric, not calibrated frequencies.
Profile
- SpeedFast
- ReversibilityIrreversible
- ConcentrationVery high
Assumptions that must hold
That replacing critical personnel with automated systems is technically possible and, above all, politically tolerated.
That a secret loyalty can be inserted into a model and survive audits, propagating across model generations.
That a window of asymmetric access to decisive capabilities lasts long enough to be used.
That the real safeguard was the need for technical cooperation, rather than legitimacy, federalism and international coordination, which AI does not dissolve on its own.
What would refute it
That audits of models deployed in critical institutions reliably detect behaviour conditioned on a specific actor.
That state and military AI procurement verifiably diversifies across independent providers, which is the mitigation the authors themselves propose.
That decisive capabilities keep requiring broad chains of human cooperation, so that no order can be executed without passing through distributed vetoes.
That systems deployed in the state remain interchangeable across providers, with no singular loyalty possible through technical dependency.
Early signals
- Largest known training compute per yearWeak signal
What matters here is not the figure but its gap: it measures disclosure, and every year frontier labs stop reporting is a year less of outside visibility into who has what.
- Companies with a published frontier safety frameworkWeak signal
Twelve published frameworks out of twenty committed companies. The gap between committed and published is the signal, because this scenario runs on opacity about internal capabilities and uses.
«Not observed» is not a clean bill of health: it means nobody has seen it yet, which is different from it not happening.
View as table
| Indicators | State | Note |
|---|---|---|
| Largest known training compute per year | Weak signal | What matters here is not the figure but its gap: it measures disclosure, and every year frontier labs stop reporting is a year less of outside visibility into who has what. |
| Companies with a published frontier safety framework | Weak signal | Twelve published frameworks out of twenty committed companies. The gap between committed and published is the signal, because this scenario runs on opacity about internal capabilities and uses. |
See among the scenarios →Report a mistake in this entry →
Sources
- [420] AI-Enabled Coups: How a Small Group Could Use AI to Seize Power · Forethought 2025
- [495] Extreme power concentration · 80,000 Hours 2025
- [106] 46 - Tom Davidson on AI-enabled Coups · AXRP - the AI X-risk Research Podcast 2025
- [927] Prioritization of Risks from Artificial Intelligence: A Delphi Study of 272 International Experts · The University of Queensland / MIT FutureTech 2026
- [290] Pentagon-Anthropic Dispute over Autonomous Weapon Systems: Potential Issues for Congress · Congressional Research Service 2026 archived copy only
- [773] AI as Normal Technology · Knight First Amendment Institute at Columbia University 2025
- [1108] International AI Safety Report · Wikipedia 2026
- [538] International AI Safety Report 2026 · International AI Safety Report (panel con representantes nominados por más de 30 países) 2026