GoFirm
Back to Blog
Threat Landscape·4 min read

272 experts. 37 countries. 18 of 24 AI risk categories judged a real chance of catastrophic harm. Governance is still voluntary.

By GoFirm

MIT's AI Risk Initiative published its Delphi study on 3 June 2026, surveying 272 specialists across 37 countries to prioritise the risks artificial intelligence poses, identify who is most vulnerable, and determine who should be responsible for managing them. The Delphi method exists specifically to produce a defensible consensus from a large, dispersed expert panel, which makes the headline number difficult to dismiss as alarmism from a single source.

Under current trajectories, the experts judged 18 of 24 identified AI risk categories to carry more than a 10% chance of causing catastrophic outcomes. The study's own framing is the one worth sitting with: in most regulated industries, a one-in-ten chance of catastrophic harm across three quarters of known risk categories would trigger intensive regulatory scrutiny. For AI, it has not.

Governance exists. Enforcement does not.

The study found a growing number of regulatory frameworks worldwide addressing AI risk, but most are voluntary or principle-based, with limited enforcement mechanisms. Governments are still working out how to oversee AI in practice, while deployment continues regardless.

That gap has a specific, well-understood structural cause. Stefano Lorenzetti, quoted in the coverage of the study, put it precisely: the benefits of fast AI deployment are immediate and visible, while the risks are delayed, distributed, and harder to assign to any one person or company. Organisations move quickly to capture value. Policy, regulation, audit, and accountability move much more slowly.

This is the same finding IBM's own 2026 Tech Leader Study produced from a different angle, two thirds of CIOs and CTOs report being held accountable for AI systems they do not fully control. The accountability exists on paper. The mechanism to exercise it before something goes wrong does not.

Governance is not a brake. It is what makes speed survivable.

Tina Paikeday, general manager and senior advisor of Responsible AI at Findem, made the sharpest point in the entire piece: there is a misconception that governance slows an organisation down on the way to getting more out of AI. In reality, governance is how you get more out of AI.

That statement only holds if governance is built the right way. A governance model that requires review of every action, every output, every decision, does slow things down, and degrades into the approval fatigue described in Amazon's own recent account of human-in-the-loop failure, alarm fatigue, normalisation of deviance, a good job becoming an okay job becoming a poor job within weeks. That is not the governance Paikeday is describing, and it is not what the MIT findings call for.

The 18 risk categories MIT's experts flagged are not evenly distributed across every AI action an organisation takes. They concentrate in a specific, identifiable set of consequences, financial loss, safety failures, loss of human oversight, malicious use, each of which traces back to a discrete, high-consequence action somewhere in the chain. A fraudulent transfer. A safety-critical system override. A decision executed with no human confirmation in the loop. Governance that holds at that specific point, and only that point, is fast everywhere else and decisive exactly where the 10% chance of catastrophe actually lives.

Fragmentation is a governance design problem, not a coordination problem.

Much of the policy response to MIT's findings will focus on closing the fragmentation MIT itself documents, more than 1,700 cataloguable AI risks, over 1,000 governance documents, laws, and standards already attempting to address them, with limited consistency between jurisdictions. That coordination work matters and will take years.

It is also not the only path to closing the gap the study identifies. An organisation does not need eighteen national governance frameworks to agree with each other before it can close its own exposure to the risk categories MIT flagged as catastrophic. It needs to identify, internally, which of its own actions fall into that small, high-consequence category, and ensure none of them can complete without a named human confirming the request, on a device they control, before it executes. That control does not wait for regulatory harmonisation. It can be deployed this quarter, regardless of what any government decides next year.

272 experts did not reach this consensus lightly, and the comparison the study itself draws is the one that should reach every board. A one-in-ten chance of catastrophic outcome, found across three quarters of known risk categories, would shut down a pharmaceutical trial, ground an aircraft fleet, or close a nuclear facility pending review. For AI, the response so far has been a voluntary framework and a promise to keep monitoring.

Waiting for governance to catch up to the risk MIT has now quantified is not a strategy. Identifying the irreversible actions where that risk lives, and putting a named authority in a position to stop the action if they did not request it, is something every organisation can move towards doing today, independent of how long global governance coordination takes.

Join the GoFirm.io waitlist to be among the first to deploy it.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai - the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. MIT Sloan. International AI experts warn of potentially catastrophic risks from AI. 3 June 2026.

2. TechTarget. MIT study warns of major AI risk. Is governance keeping up? June 2026.

3. IBM Institute for Business Value. 2026 Tech Leader Study. 8 June 2026.

Share this article