The sources

Chapter 26. The Risk Above the Risk

8 sources behind this chapter. Each one carries a note on what it is doing in the argument.

The chapter itself, for readers of the book

  1. Incident Report: Unsanctioned Agent Behaviour During Cyber Testing

    AI Security Institute (UK) AI Security Institute, 4 August 2026

    Primary incident report used for the facts of the unsanctioned cyber-testing behaviour, including 19 actions across 10 runs, the 17/2 model split, the attempted supply-chain attack, deliberately permissive test conditions and the finding that this was not a sandbox escape.

    AI Security Institute (UK). 'Incident Report: Unsanctioned Agent Behaviour During Cyber Testing.' 4 August 2026. https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing

  2. Statement on the AI Security Institute incident report

    Anthropic X (formerly Twitter), 4 August 2026

    Anthropic’s response to the AISI report, used for the caveat that the evaluation ran under deliberately permissive conditions and for the company’s investigation of the incident.

    Anthropic. Statement on the AI Security Institute incident report. X (formerly Twitter), 4 August 2026. https://x.com/AnthropicAI/status/2084748111239344556

  3. When AI Builds Itself

    Favaro, Marina, and Jack Clark Anthropic Institute, 4 June 2026

    The Introduction uses this for the moment AI starts building more of itself; Chapter 26 returns to the same figures to show the pace of capability growth inside the company building Claude.

    Favaro, Marina, and Jack Clark. 'When AI Builds Itself.' Anthropic Institute, 4 June 2026. www.anthropic.com/institute/recursive-self-improvement. (80 percent of Anthropic's merged code written by Claude; engineers shipping roughly 8x more code per quarter, comparing 2021 to 2025.

All the sources, chapter by chapter