How to read the claims
This project separates four kinds of statement:
- Observed facts report evaluation results, current federal directives and guidance, historical incidents, cloud-responsibility documents, operational incentive design, and existing RVA Cyber proposals.
- Supported inferences connect those facts: AI reduces some attacker labor constraints; legacy scorecards bias teams toward stability; correlated dependencies can amplify harm; and machine-speed defense can reduce closure time.
- Stress-test assumptions ask what follows if a capable actor attempts a coordinated destructive campaign using known flaws, chains, identities, suppliers, and wipers.
- Policy proposals describe institutions that do not yet exist as proposed here: the Continuity SLO, federal duty, open stack, free model service, deadlines, penalties, registry, and public compliance utility.
The site does not convert an inference into a fact by repeating it more confidently.
Important limits
p(hack)=100%is a preparedness rule, not an actuarial estimate.p(fab) + p(doom) = 1is a decision model, not a measured probability identity.- The fictional attacker is a stress test, not intelligence about a known operation.
- Current models have demonstrated material cyber capability, but they still struggle with some long, realistic sequences.
- The paper does not claim that patching alone stops phishing, malicious insiders, compromised vendors, poisoned updates, or unknown zero-days.
- “100-percent clean” means zero known, reachable, unmitigated paths under continuous measurement—not proof that no unknown flaw exists.
- The legal and technical program requires legislation, appropriations, pilots, privacy design, evaluation, and judicial review.
Publication record
This public working draft is intentionally versioned for iteration. The source manuscript passed 39 builder checks and 29 independent adversarial checks before the minisite build. The publication build adds route, link, fragment, download-hash, accessibility-structure, responsive-layout, visual, and production-integrity checks.
The current paper contains 25 source notes and 29 HTTPS source links. Direct server checks can receive automated-access denials from some government sites; the research corpus preserves the captured source material used for review.
Source ledger
The notes below are the paper's complete public source list. Each note retains the scope or limitation stated in the manuscript.
UK AI Security Institute, Frontier AI Trends Report, 2025.
Anthropic, Detecting and countering misuse of AI: September 2026, Sept. 10, 2026. Anthropic reports observations from its own services and investigations; the evidence should not be treated as an independent prevalence estimate.
White House Archives, “Statement from the Press Secretary”, Feb. 15, 2018.
Cybersecurity and Infrastructure Security Agency, Cyber Hygiene Services.
National Institute of Standards and Technology, SP 800-40 Rev. 4, Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology, 2022.
National Institute of Standards and Technology, IR 7946, CVSS Implementation Guidance, §2.2, 2014. This document addresses CVSS v2 and is cited for its explicit discussion of contextual risk and chaining limitations, not as the current CVSS specification.
National Institute of Standards and Technology, IR 7788, Security Risk Analysis of Enterprise Networks Using Probabilistic Attack Graphs, 2011.
Defense Advanced Research Projects Agency, “AI Cyber Challenge Results”, Aug. 8, 2025. DARPA corrected the synthetic-vulnerability denominator from 70 to 63.
Cybersecurity and Infrastructure Security Agency, #StopRansomware Guide.
U.S. Department of the Treasury, The Financial Services Sector's Adoption of Cloud Services, 2023, pp. 56–58.
U.S. Government Accountability Office, GAO-25-106369, Cloud Computing: Private Sector Leading Practices in Acquisition, Cybersecurity, and Workforce Development, 2025. GAO's company sample was nongeneralizable.
AWS Shared Responsibility Model; Microsoft, Shared responsibility in the cloud; Google Cloud, Shared responsibilities and shared fate.
Cybersecurity and Infrastructure Security Agency, BOD 26-04, Prioritizing Security Updates Based on Risk, June 10, 2026. The directive applies to covered Federal Civilian Executive Branch systems, not the private economy proposed here.
18 U.S.C. §3553(a); U.S. Department of Justice, Justice Manual §9-27.000, Principles of Federal Prosecution.
Federal Trade Commission, “FTC Finalizes Order with GoDaddy over Data Security Failures”, May 21, 2025.
Cybersecurity and Infrastructure Security Agency, “Applying Secure by Design Thinking to Events in the News”, Nov. 1, 2023.
National Institute of Standards and Technology, Cybersecurity Framework 2.0, 2024.
National Institute of Standards and Technology, SP 800-193, Platform Firmware Resiliency Guidelines, 2018.
RVA Cyber, The National Cyber Steward Corps, Discussion Draft 4.0, Aug. 17, 2026.
RVA Cyber, Can ii.inc Build an Intelligence Utility?, Sept. 5, 2026.
RVA Cyber, The Last Copilot.
RVA Cyber, No One Is Expendable.
Dario Amodei, The Adolescence of Technology, Jan. 2026, §2 (“Ability and motive may even be negatively correlated” and “this will break the correlation between ability and motive”). The paper applies Amodei's general destructive-misuse mechanism to cyber; it does not attribute Jimmy Staley's paraphrase to Amodei as a quotation.
Google, Site Reliability Engineering: Embracing Risk and Example Error Budget Policy. Google describes the incentive tension created when product teams are evaluated on velocity and SRE teams on reliability, and uses shared error budgets to align decisions.
U.S. Securities and Exchange Commission, Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure, Release No. 33-11216, July 26, 2023. The rule requires covered registrants to describe board oversight and management's role; it does not establish the Continuity SLO or outcome duty proposed here.