Chapter 06
Protection
Nineteen measures across three levels, with their effect in each scenario. Three are flagged as theatre: they cost and do not protect.
Table 6.1 · Measures by scenario. Each cell says whether the measure works, partly works, does not work or is counterproductive in that world; «—» means no declared effect. 19 of 19 measures.
| Measure | Catastrophe through misuse | Gradual disempowerment | Power grab by a small group | The intelligence curse | Rapid loss of control | AI as normal technology |
|---|---|---|---|---|---|---|
| Partial | Does not work | Does not work | Not stated | Not stated | Partial | |
| Not stated | Not stated | Not stated | Not stated | Partial | Not stated | |
| Partial | Not stated | Does not work | Not stated | Does not work | Partial | |
| Partial | Does not work | Not stated | Does not work | Not stated | Partial | |
| Partial | Partial | Partial | Partial | Partial | Partial | |
| Does not work | Does not work | Not stated | Not stated | Not stated | Does not work | |
| Does not work | Backfires | Does not work | Backfires | Does not work | Not stated | |
| Partial | Does not work | Does not work | Does not work | Not stated | Partial | |
| Works | Partial | Not stated | Partial | Does not work | Works | |
| Partial | Does not work | Does not work | Not stated | Not stated | Works | |
| Partial | Does not work | Not stated | Not stated | Does not work | Partial | |
| Partial | Does not work | Works | Not stated | Partial | Not stated | |
| Works | Partial | Partial | Not stated | Partial | Works | |
| Partial | Not stated | Does not work | Partial | Does not work | Partial | |
| Works | Does not work | Not stated | Does not work | Not stated | Partial | |
| Works | Does not work | Does not work | Not stated | Not stated | Partial | |
| Partial | Does not work | Does not work | Does not work | Not stated | Does not work | |
| Partial | Not stated | Does not work | Not stated | Does not work | Works | |
| Works | Not stated | Partial | Does not work | Partial | Works |
Open entry: Stored water and point-of-use treatment
View as table
Personal
- Stored water and point-of-use treatment
Two litres per person per day stored, plus a way to treat doubtful water. The reference meta-analysis over 124 studies reports diarrhoea relative risk of 0.50 for point-of-use filtration and 0.66 for chlorination.
What it does not solve: The good evidence is measured in children in low- and middle-income countries with endemic diarrhoea, not in high-income households after an emergency: the transfer is plausible but nobody has measured it. And it does not solve the case where water simply does not arrive, which is the failure mode modelled in the frozen-pipes literature.
- Isolate agents that run unattended
No automated process gets a capability whose worst case you cannot absorb: read-only credentials, no payment access, and a kill switch that lives outside the agent's reach.
What it does not solve: It protects you from nothing happening outside your own machines, which is where almost all of this scenario's risk lives.
- Offline library, with a local model
Documentation downloaded as text, your own power, and —if you like— an open model running on your machine. It is continuity of access to knowledge without a connection, and it is now technically cheap: there are open models designed to run in 16 GB of memory.
What it does not solve: It does not protect you from AI, changes no economic incentive and gives you privacy from nobody but your provider. The model is frozen at its cutoff: no news, no updates, no verification. And without power it is a paperweight, so the correct pairing is model plus power plus documentation as text, never the model alone.
- Some cash at home
Operational continuity, not finance: being able to buy bread if payment systems go down. FEMA and SENAPRED both list it in their household kit, and in the Iberian blackout electronic payments stopped working for 12 to 16 hours.
What it does not solve: Nothing specific to AI. If the outage lasts weeks or the problem is confidence in the currency, notes do not work either: they only work while someone accepts them. This is information about continuity when payment systems fail and says nothing whatsoever about where to put your savings.
- Far-UVC at home, today
A promising, unproven technology. The reference review, after nearly two years of work, lists real-world effectiveness evidence among its pending research priorities: that is, it does not exist yet.
What it does not solve: Nothing verifiable yet. Its effectiveness outside the lab, its photobiological safety for skin and eyes, and ozone generation with its mitigation strategies all remain open. As an institutional research line it is legitimate and worth funding; as a household purchase it runs ahead of the evidence, and displaces money that would do more in a fit-tested respirator.
- Fortifying the house and arming yourself
The measure with zero evidence in favour and one against: the only formal model that exists concludes that excessive fortification can provoke the attack rather than prevent it, and that what decides the outcome is legitimacy and reciprocity, not walls.
What it does not solve: Everything. It intervenes in none of the six scenarios, and carries a cost rarely counted: the time and disposition spent fortifying are the same that would build the neighbour network that does predict who recovers. It helps against ordinary crime, which is a real problem and not what this site is about.
- A 72-hour household kit
Water, food that needs no cooking, a battery radio, a torch, a first-aid kit, copies of documents and —the part people forget— a battery-powered carbon monoxide detector. It is the list of two state agencies in different countries, on a 48-to-72-hour horizon.
What it does not solve: Nothing specific to AI, and on its own not even what killed people in the Iberian blackout: carbon monoxide from badly placed generators, fires from candles and medical devices without batteries. A kit with no CO detector and no power backup prepares the picturesque and leaves out the lethal.
- First aid and CPR training
A short course carrying the hardest evidence on this whole list: across 30,381 witnessed out-of-hospital cardiac arrests in Sweden, 30-day survival was 10.5% with bystander CPR against 4.0% without it.
What it does not solve: It resolves nothing systemic. It changes the outcome for one person beside you in the minutes before an ambulance arrives, and that is its entire scope.
- Power backup for medical equipment
If someone in your home depends on an oxygen concentrator, a ventilator or refrigerated medication, a backup battery and a plan agreed with their medical team are the measure that applies. Eight people died in the Iberian blackout and none for lack of food.
What it does not solve: It is not a general measure: it applies only to someone dependent on a device or on cold-chain medication. And it does not cover a weeks-long outage, which is a grid problem rather than a battery problem.
- Reusable respirator, with a fit test
The only household purchase on this list with technical literature behind it, and with a condition almost nobody meets: without a fit test, a respirator's protection factor is unknown, not the one printed on the box.
What it does not solve: It is not a recommendation to households: the report behind it addresses a national stockpile, the health sector and industry, and applying it to a home is an inference. Without medical evaluation and a fit test you do not have protection, you have equipment. And far-UVC, sold as an alternative, still has its real-world effectiveness evidence sitting among open research questions.
- Relocating far away because of AI
The paper people cite to justify moving to New Zealand analyses seven global risks and AI is not among them. Its verbatim conclusion is that there is no place on Earth resilient to all of them, and that even Australia depends on international trade continuing.
What it does not solve: Nothing that motivates the move. The regional resilience literature is written for abrupt sunlight reduction, geomagnetic storms and pandemics, not for AI, and its own recommendations are public policy —reserves, hardened grid, international agreements— not a personal destination. It also costs enormously and dismantles the local network that does have evidence.
- Phishing-resistant second factor
Two physical FIDO keys —one as backup— on the accounts that anchor your digital identity: email, bank, password manager. Someone can talk you into reading out a six-digit app code; they cannot talk you out of a key.
What it does not solve: It intervenes in no catastrophic mechanism: a key protects your account, not the system. It also does not cover someone impersonating you to a third party, nor does it help when the fraud arrives by a route that asks for no credentials.
Community
- Ties with your neighbourhood, before anything happens
Knowing your neighbours, taking part in something local and knowing who lives alone on your block. It is the best-evidenced personal measure of all, measured on real mortality: in the 1995 Chicago heat wave, living alone multiplied the risk of dying by 2.3 and not leaving home daily by 6.7.
What it does not solve: It stops no event: it changes who recovers. It cannot be improvised on the day something happens, because the social capital these studies measure is pre-existing. And it bears repeating until it sinks in: the evidence is from heat waves, tsunamis and earthquakes, not from AI.
- A code word agreed with your family
A word or phrase agreed in person, known only to your household, to verify identities when an urgent call asks for money or data. The FBI recommends it in writing against cloned-voice impersonation.
What it does not solve: It only works if the whole family knows and uses it, which makes it a community measure disguised as a technical one. Nobody has measured how much fraud it prevents: what is documented is the attack and the official recommendation, not the effect size.
Civic
- Working on the problem, or funding it
It is the only thing recommended by the five serious organisations we reviewed: a career in technical safety or governance, training, donating, political participation. None of the five offers a shopping list, and that is a position, not an oversight.
What it does not solve: It does not protect you, and nobody has measured its effect: it is the recommendation with the most institutional backing and the least empirical evidence on the whole list. It is also not assessable in the short term, and it competes with the rest of your life. Honesty requires adding that 80,000 Hours' own resilience profile warns there has been very little research on this and that it could all be mistaken.
- Backing whistleblower protection
An AI-specific whistleblower programme, with anonymity, protection against retaliation and a secure platform to report loss of control or negligent practices. Today it is a proposal, not a law: the Future of Life Institute set it out in March 2025.
What it does not solve: Nobody has measured its effect, and on a site that separates evidence from intent that has to be said: it is a reasonable argument without demonstration. It also fails if the legal framework does not genuinely protect —a channel without retaliation safeguards is a list of people to fire— and does not reach jurisdictions that never adopt it.
- Demanding mandatory incident reporting
It is already law in the European Union: article 73 requires reporting serious incidents within 15 days at most, two in cases of widespread infringement and ten when a death is involved. Whether it exists and gets enforced depends on sustained public pressure.
What it does not solve: It prevents no catastrophe on its own: it produces information after the fact, and only about providers inside a jurisdiction that enforces. It does not reach offensive state actors or anyone deploying outside the legal framework, which is precisely the route with observed evidence.
- Public reserves and food continuity
Almost all the good resilience literature lives here, and it is not domestic: strategic reserves in highland areas, a hardened grid, scalable resilient foods and national risk assessments. It is decided by voting and pressing, not by shopping.
What it does not solve: It is not a household measure and cannot be turned into one. The models behind it assume intact international trade and standing industrial infrastructure; when trade breaks, the calorie coverage of an animal-traction scenario falls from 80% to 30%. That also buries the vegetable patch as personal calorie insurance: the bottleneck is trade and national allocation, not the area you cultivate.
- Demanding that evaluations be published
That dangerous-capability thresholds, adversarial testing and their results be public and auditable. Twenty companies committed to publishing a frontier safety framework and twelve did: the gap between those two numbers is the indicator that matters.
What it does not solve: A published framework measures the promise, not compliance, and independent evaluation of those frameworks finds very uneven quality. Nor does it fix that whoever writes the threshold is whoever decides if it was crossed, and it does not cover developers who never committed to anything.