In October 2025, the Institute for Security and Technology (IST), with support from and in partnership with the Future of Life Institute (FLI), launched the AI Risk Barometer project to capture how national security professionals view the risks and opportunities of advanced AI.
Now, in a first-of-its-kind survey, the AI Risk Barometer is releasing in-depth insights to capture how national security practitioners and AI experts understand AI-related risks and opportunities and how they foresee AI shaping various national security functions. The survey targeted national security practitioners and experts with significant experience in domains including cybersecurity, intelligence analysis, Chemical, Biological, Radiological, and Nuclear (CBRN) risks, military planning, diplomacy, and AI and technology policy. Read the press release and register to join the launch event on September 2 at 1:30 pm ET.
A Unique Sample: Survey Respondents by the Numbers
111 national security professionals
participated in the survey, spanning current and former civilian officials, military officers, and academic or technical experts specializing in AI, cyber, nuclear policy, or defense strategy
1000+ answers
collected in response to quantitative & qualitative questions, including on the U.S. national security apparatus’ understanding of AI, AGI and ASI trajectories, loss of control, military integration of AI capabilities, and information warfare
93 percent
of survey respondents have engaged with AI policy, risk, or strategy on organizational, national, and/or international levels
70 quantitative & qualitative questions
asked and analyzed by the survey research team
Respondent Years of Government Experience
Nearly one quarter of respondents have served in government for 20 or more years, with the longest tenure reaching 42 years.
Respondent Government Experience by Department
Methodology at a Glance
IST began development of the survey questionnaire in January 2026 and collected responses between April 30 and July 15, 2026. All responses were kept strictly confidential; as a result, this survey reports only aggregated, anonymized data, along with a limited number of unattributed quotes collected from the open-ended questions.
For a detailed account of the survey design, questionnaire development, and participant recruitment, see Chapter Two.
Key Findings
Risks and Opportunities →
Respondents identify adversarial misuse as the number-one threat to U.S. national security (ranked top-three by 72 percent), followed by automated disinformation. They see AI's biggest opportunities concentrated in cybersecurity and intelligence, and its most significant defensive gaps as institutional — speed of response, legal frameworks, and coordination — rather than technical.
OPPORTUNITIES
- A discovery multiplier. About a third see AI reducing
“the time between scientific question and answer” — across every field at once. - Health and medicine are the most named promises.Some respondents also expect economic abundance
and relief from labor. - Assisting defenders. AI could give small, under-resourced defenders “faster learning loops than attackers.”
RISKS
- Higher escalation & misplaced trust. 54% expect AI to raise U.S.–China escalation risk.
- Analysis at scale. 87% say AI can turn scattered
open-source data into usable insight — its top intelligence value. - Cognitive over-reliance. Experts warn of “cognitive debt” as people cede judgment to AI
Timelines →
The median respondent felt with 90% confidence that artificial general intelligence (AGI) would be achieved by 2040, with their best guess being AGI by 2032. When asked about AI operating beyond human control with no way to regain it, 33% expected that scenario to occur within 10 years. And when asked whether AI would cause a catastrophe–described in the survey as one resulting in the deaths of at least 10 million people—40% of the respondents thought there was at least a five percent chance of such a catastrophe occurring by 2050.
"61% of those who answered both questions rate the catastrophe risk at or above the level they themselves deem acceptable."
AI and the Future of National Security
AI and Warfare →
Respondents rank AI accelerating decision cycles beyond human command as the top military risk, while pointing to cyber defense and decision support as the largest opportunities. They see the binding constraints as human and institutional — workforce literacy, data architecture, and acquisition speed — not the technology itself.
Policy Outlook →
Respondents define success largely as avoidance of a catastrophe, whether through governance, testing, human control, or international norms. They see clear promise for humanity in AI's ability to accelerate progress in science and medicine. Across every domain, the same pattern emerged: a broad mandate for guardrails coexists with low confidence that institutions are prepared to deliver them.
“A broad mandate for guardrails coexists with low confidence that institutions are prepared to deliver them.”
AI and the Future of National Security
Domain Deep Dives
Cybersecurity and Critical Infrastructure
AREAS OF CONSENSUS
Close-ended questions:
- AI will broadly improve cyber defense — 81 percent say all defensive capabilities are very likely to improve, and 88 percent expect AI to deliver significant or transformational gains (55 percent “very significant”).
- Yet the near-term balance favors attackers — 57 percent expect AI to tilt the offense-defense balance toward attackers.
- Speed, a lowered barrier to entry, and volume are the dominant challenges — speed (70 percent), lowered barrier to entry (68 percent), and sheer volume of AI-generated attacks (57 percent).
- Exploit discovery and vulnerability weaponization is the most critical risk — 52 percent rate it a critical risk, well ahead of the rest.
- Agentic AI is already seen as highly capable — respondents judge that today’s agentic system can already assist experts with analysis (95 percent), autonomously discover software vulnerabilities (92 percent) faster than experts, and match expert-human performance (82 percent) on specific cyber tasks.
- Governance should come first — 85 percent want oversight before systems reach these capabilities, and 93 percent favor some regulatory standard.
Open-ended questions:
- AI’s core opportunity is automated pre-emptive defense. Respondents agree the biggest opportunity is automated, preemptive defense — finding, patching and hardening vulnerabilities “before they can be exploited” at scale.
- Scale and speed drive the danger, not novelty. Most see AI amplifying the volume, speed and accessibility of attacks on poorly-defended critical infrastructure rather than inventing wholly new attacks.
AREAS OF DISAGREEMENT
Close-ended questions:
- Whether operators could regain control of a rogue cyber AI. No majority — 48 percent say it “depends entirely on implementation,” 28 percent are somewhat confident, 26 percent are not confident or think it may be impossible, and none are highly confident.
- Which regulatory approach is best. Despite 93 percent wanting a standard, they split on the form — a hybrid federal-plus-sector model (36 percent), sector-specific standards (31 percent), or mandatory cross-sector federal requirements (26 percent).
Open-ended questions:
- Technical fix vs. governance. Some see the key opportunity in technology (secure code, defensive AI agents that find and patch vulnerabilities at scale); others place it in policy and institutions (regulation, public-private partnerships, U.S. credibility).
Nuclear Weapons
AREAS OF CONSENSUS
Close-ended questions:
- Sentiment on integrating AI into NC3 tilts negative — half of respondents (50 percent) find it concerning (29 percent find it “very concerning — risks clearly outweigh benefits”), against just 21 percent positive.
- Most expect AI to reshape deterrence — 76 percent expect it to affect nuclear deterrence or strategic stability; only 12 percent expect no significant change.
- Erroneous warnings and automation bias are the top risks — many rank erroneous or ambiguous AI-assisted strategic warning as the biggest risk (62 percent), then automation bias under time pressure (62 percent), and limited transparency (52 percent).
- Broad concern about an AI-driven NC3 arms race — 72 percent are at least moderately concerned.
- Strong backing for confidence-building measures and red lines — AI-specific confidence-building measures (72 percent), red lines on specific uses (62 percent), and AI-enhanced treaty verification (59 percent).
Open-ended questions:
- Humans must stay central. Respondents insist almost unanimously that AI must not dominate nuclear decision-making and must “augment human judgment while preserving clear human accountability.”
- Test and go slow before integrating. They back testing, standards and a deliberate pace, and stress that “AI is not monolithic” — integration should stay selective and start with low-risk functions.
- Unintended use is the core danger. Most agree the paramount risk is inadvertent nuclear use or escalation through error, misinterpretation or faulty early warning — not a deliberate attack.
- Verification is missing; the upside is better information. Respondents agree robust AI-verification mechanisms for NC3 do not yet exist, and that AI’s clearest benefit is stronger monitoring, warning and situational awareness.
AREAS OF DISAGREEMENT
Open-ended questions:
- Restrict vs. actively build AI capability. Some would cap AI’s role in decision-making; others urge building capability at the national labs to “enhance all activities.”
- Effect on deterrence. They disagree on whether AI reduces reliance on nuclear weapons or strengthens deterrence — and whether any genuine positive outcome is realistic.
Chemical and Biological Weapons
AREAS OF CONSENSUS
Close-ended questions:
- AI tilts the biological/chemical weapons balance toward offense. A majority (52 percent) say AI favors offense — barriers to attack fall faster than defensive capability advances (32 percent “strongly favor offense”); only 12 percent think defense keeps pace.
- Biology is the dominant concern, well ahead of chemistry. 64 percent are very or extremely concerned that AI worsens biological dual-use dilemmas, versus 41 percent for chemical — matching the open-ended view that pandemic-capable biology outranks chemical attacks.
- The bioweapons risk is here or near-term. 70 percent say AI already meaningfully increases bioweapon-development risk (33 percent) or will within two–three years (37 percent); only 12 percent think it is “unlikely to ever” do so.
Open-ended questions:
- AI can already design pathogens. Most accept that AI’s pathogen-design capability is real and improving fast — one notes AI “can currently design pathogen genomes, including variants not found in nature.”
- Expanding access is the core danger. Respondents agree AI’s chief threat is lowering the barrier to entry for less-skilled actors and states, and they name pandemic-capable biology the dominant concern over chemical attacks.
- Defense is the shared priority. They converge on strengthening detection, monitoring, early warning and countermeasures, “early detection, vaccine development” as the central opportunity. (Consistent with the closed data: the single most-picked application is AI-powered pathogen surveillance and early warning, 36 percent.)
AREAS OF DISAGREEMENT
Open-ended questions:
- Whether design capability means real risk. Some treat AI-designed pathogens as alarming; others insist that physical production, dissemination and planning remain the true bottleneck.
- Who the main threat actor is. Respondents split between small non-state actors and state programs with the scale to weaponize.
About the Analysis
The quantitative analysis in this report is primarily descriptive. To gain further depth into respondents’ perspectives beyond quantitative results, the team analyzed their open-text responses to distill areas of convergence and divergence, presented as the “areas of consensus” and “areas of disagreement” before each section of the survey results.
Why It Matters
The survey is just the first step in a broader conversation needed around the intersection of national security and artificial intelligence. We hope the dataset serves as a useful basis for further analysis and discussion for researchers who want to dive deeper into specific subsections, for the policymakers who want to draw from the empirical evidence, and for the AI and cybersecurity industry experts to inform their decisions.



