Key questions/how-far-to-trust-cyber-capability-numbers

How far can measured AI cyber capability be trusted?

moderate confidenceAnswered Sep 25, 2026Reviewed assistant-drafted
Current answer

As a lower or conditional bound. Scores move substantially with token budget, evaluation pipeline, and benchmark contamination.

UK AISI reports that fixed, low token budgets understate frontier cyber capability and its rate of progress. A preprint audit finds pipeline choices alone can move cyber benchmark scores by tens of points, public CTF benchmarks can be contaminated, and counting a crash as exploitation overstates capability. Single capability numbers, including trend estimates, are best read as lower or conditional bounds.

The findings behind it

4 reported

Each finding carries a status that changes as new work arrives. What the statuses mean.

Answer history

Answers are never edited after the fact. A revision adds a new answer and keeps the earlier ones here.

  1. 2026-09-25moderate confidencecurrentAs a lower or conditional bound. Scores move substantially with token budget, evaluation pipeline, and benchmark contamination.First answer, drawn from the findings linked here.