MIT surveyed 272 experts on AI risk. For 18 risk domains out of 24, they see at least a 1-in-10 chance of catastrophic harm by 2030.

The study, published by MIT's AI Risk Initiative in June 2026, ran three rounds of expert ratings on 24 AI risks over the next five years. Catastrophic means more than 1 million deaths, more than USD 100B in losses, or damage at civilizational scale.

What it says

Finance and insurance is one of the three most exposed sectors, through fraud, AI security vulnerabilities, and system failures.

The people most exposed to AI harm are users and the public. The people judged most responsible for preventing it are model developers and regulators. The two groups barely overlap.

Why it matters

Experts say cost-effective action cuts the worst odds roughly in half, and getting the rest of the way requires governance instruments that mostly do not exist yet. Other industries built those instruments: standards, liability, insurance. Aviation did. Pharma did.

Until they exist for AI, the gap is yours. If your institution deploys AI, no regulator or model provider carries your customer harm, your audit findings, or your incident response. A model provider's safety page is not a control. Access rules, logging, evaluation gates, and the ability to shut a system down are controls, and they only count if you own them.

Key takeaways

  • Five risks stay at 1-in-10 or worse even with countermeasures in place: dangerous AI capabilities, AI-enabled weapons and cyberattacks, environmental harm, inequality and unemployment, and power centralization. Experts judge these persistent because they are structural: race dynamics, compute concentration, entrenched inequality. Countermeasures at the model level do not reach them.
  • Two of the five run straight through a financial institution's threat model. AI-enabled cyberattacks are an attack surface question. Power centralization is a vendor concentration question: the fewer providers everything depends on, the larger the blast radius of a single failure.
  • These are expert judgments, not calibrated forecasts. Treat the direction as signal and the named list as a prioritization input for your own risk register.

Source:
· MIT FutureTech — Prioritization of Risks from Artificial Intelligence: A Delphi Study of 272 International Experts — futuretech.mit.edu, June 2026

Before an AI system touches a regulated workflow, which control would you demand evidence of first: access, logging, evaluation, or kill switch?

Mathieu Flamant
Founder · Tech Leader · mathieuflamant.com