"To reach a YES resolution before January 1, 2028, a strict and unprecedented conjunction of events must occur: an AI system must cause catastrophic global damage, and authorities must respond with a deliberate, substantial, multi-country shutdown of internet infrastructure specifically attributed to the AI. Current evidence indicates that AI offensive capabilities, while advancing, remain far below the threshold required to trigger systemic global collapse. (Gerd adds: This is where I disagree). The most significant AI-orchestrated cyber incident to date - the espionage campaign disrupted by Anthropic in November 2025 (GTG-1002) - relied heavily on human intervention, targeted a limited number of entities, and caused no infrastructure damage. While organizations like the Five Eyes, IMF, and Bank of England have raised valid anticipatory warnings regarding AI's potential to accelerate cyber exploitation and exacerbate systemic financial risks, actual incidents have not materialized as cascading catastrophes"
"Even conditional on a major AI-driven catastrophe, a multi-country shutdown of global internet infrastructure is highly unlikely. Standard cyber incident response playbooks, such as those from CISA, heavily emphasize targeted containment - isolating affected networks and air-gapping specific systems- rather than disconnecting broad internet backbone or multi-country infrastructure. Shutting down significant portions of the internet would be economically ruinous and technically complex. Proposals for AI-specific 'kill switches' (such as those analyzed by RAND) focus on localized, data-center-level disconnections, explicitly avoiding broad global shutdowns. Furthermore, organizations like the Internet Society emphasize maintaining connectivity to limit technical cross-border fallout, creating strong incentives against a coordinated shutdown.
It is also critical to distinguish this scenario from recent large-scale disruptions, which do not meet the criteria. The massive July 2024 CrowdStrike outage and various 2025-2026 Cloudflare disruptions were the result of routine software updates and internal configuration errors, not malicious AI activity. Similarly, while hundreds of internet shutdowns occur annually, they are virtually all single-country, government-imposed blackouts for domestic political control or censorship (such as Iran's nationwide shutdown in early 2026), entirely unrelated to AI.
In summary, the roughly 1.5-year horizon to January 2028 leaves very little time for the requisite discontinuous leap in AI capabilities, let alone for a profound shift in global incident-response protocols. The probability is overwhelmingly constrained by the necessity of a deliberate, multi-country internet disconnection—a drastic measure contrary to established cyber-defense practices. A very low estimate strictly accounts for the extreme tail risk of a sudden, unexpectedly severe AI capability jump prompting a panicked, overreactive international response"
Set against related questions on frontier AI progression, this forecast was held at 1%, as the extreme tail risk of a systemic catastrophe remains largely decoupled from the anticipated competitive dynamics of open-weight models.

"By or before early 2028, there is a 35% chance that a major AI-driven cyber catastrophe will force governments to severely limit public Internet access, either globally or across multiple major economies, for days - or more likely - for weeks."
This isn't just another cybersecurity problem. AI makes it possible to launch millions of coordinated attacks simultaneously. Instead of thousands of hackers, imagine millions of autonomous software agents operating continuously, adapting in real time. This is a fundamental change in the economics of cyber conflict - and there are a LARGE number of people talking about this (see list below).
The discussion has recently moved away from "AI might become dangerous someday" toward "AI is dramatically increasing systemic cyber risk" today. Here are some of the latest reads that support my analysis (imho:)
The FT explicitly says AI is making the internet less safe and that governments face an escalating cyber arms race.
The WSJ reports the IMF warning that AI could create macro-financial disruption, systemic cyber incidents, failures propagating across finance, attacks spreading into telecoms and energy
The 2028 Global Intelligence Crisis is a report authored by James van Geelen and Alap Shah and published by Citrini Research in February 2026, on the impact of artificial intelligence on humanity's future.[1][2][3] Written in the form of a scenario analysis, it was viewed millions of times online[1] and reportedly caused a fall in the stock market prices of major tech and financial firms.[4] It also received criticism[5] among others, for its allegedly flawed economic logic.[6][7]

07:41
YouTube
Anthropic and the Fable of Mythos | AI Pioneer Stuart Russell | Future Takes
Mythos-class models can actually do, why the guardrails around them won't hold. If they escape, the only way to contain the damage could be to shut down the internet itself. Watch the full episode, The $15 Quadrillion Black Hole Sucking Humanity Toward Extinction: https://www.youtube.com/watch?v=GUWNTkPsJr8 Subscribe to Futurology: https://linkin.bio/futurology #AI #Mythos #AISafety #StuartRussell #Futurology
Twenty years ago, losing the Internet meant inconvenience. Today it means losing… everything: banking, communications, payments, logistics, hospitals, cloud computing, emergency services, government operations, news, media and entertainment. We've rebuilt our civilization on a digital nervous system. That VASTLY increases systemic risk, and AI will provide the tools.
Within 18 months, much of the Internet will consist of autonomous software talking to other autonomous software. AI is eating the internet.
When AI attacks AI:
Humans basically become spectators.
The issue isn't the Internet itself. It's how TRUST is being destroyed in this process. If no one knows whether financial transactions, government messages, emergency alerts, military communications are authentic... then the Internet stops functioning as a trusted public infrastructure. Once trust collapses, governments will start limiting access.
Some governments already disconnect stock markets, power grids, i ndustrial systems, military networks - extending that logic to parts of the Internet is NOT unprecedented.
This is a key distinction. I am not arguing governments want more control. I am arguing that after a sufficiently large AI disaster they may conclude they have no alternative. "We must slow everything down until we understand what's happening." Pretty much what happened during COVID—but applied to cyberspace.
History shows that societies will accept extraordinary restrictions when faced with existential threats. Examples include financial market circuit breakers, emergency powers after terrorist attacks, pandemic lockdowns, grounding aircraft after 9/11. A digital equivalent is conceivable if an AI-driven crisis threatened the stability of essential services.

I'm not forecasting that the Internet could disappear - I'm forecasting a one-in-three chance that governments conclude unrestricted Internet connectivity is temporarily too dangerous following a major AI-enabled catastrophe. I think the threat is very real.
The real danger isn't that AI becomes evil. The real danger is that AI becomes so powerful, so autonomous and so deeply embedded in our critical systems that, during a major crisis, our only remaining safety mechanism is to disconnect large parts of the digital world. The Internet transformed humanity precisely because it connected everything; now, ironically, its greatest vulnerability may be that it now connects everything.
The issue isn't AI versus humanity. It's resilience versus fragility. We have built extraordinary intelligence into our digital infrastructure, but not enough TELOS, wisdom, trust, collaboration or governance.
Probably the world's best-known public cybersecurity thinker. His long-standing argument is that AI doesn't need to become superintelligent to be dangerous—it simply makes attackers vastly more productive and lowers the cost of sophisticated attacks.
Former Director of CISA. She has repeatedly warned that AI is creating an entirely new scale of cyber risk, particularly for critical infrastructure. Her emphasis has consistently been on speed, scale and automation.
Co-founder of CrowdStrike, frequently argues that AI will become a force multiplier for nation-state cyber operations.
Former U.S. Deputy National Security Advisor for Cyber, has repeatedly emphasized protecting critical infrastructure against increasingly automated attacks.
While primarily an economist, Erik has warned that AI creates enormous systemic concentration risk because societies increasingly depend on digital infrastructure.
Although focused on frontier AI risks rather than cybersecurity, Hinton has repeatedly warned that societies are underestimating AI's capacity to create large-scale unforeseen failures.
Shutdown28 is humbly presented by Gerd Leonhard