AI Safety · Existential Risk

How could AI kill us? 7 real scenarios, explained simply

Julien de Waal Oct 2, 2026 15 min read

Not robots with red eyes. Not a sci-fi movie plot. The ways AI could genuinely harm or kill people are more subtle — and in some cases already happening. Here are the 7 most realistic scenarios, fact-checked and grounded in what the world's top AI researchers actually say.

Before we start This article isn't meant to scare you. It's meant to help you understand real risks the way the people who build these systems talk about them. Many of the world's top AI researchers — people who built GPT, Gemini, Claude — consider at least some of these risks serious enough to dedicate their careers to preventing them. We've fact-checked each scenario against what biosecurity experts, cybersecurity specialists, and military researchers actually report.
What's in this article
  1. What the world's leading AI experts actually say
  2. AI misalignment — when it pursues the wrong goal
  3. AI-assisted bioweapons
  4. Autonomous weapons that make their own kill decisions
  5. AI attacks on critical infrastructure
  6. AI-accelerated pandemics
  7. Economic collapse and mass desperation
  8. AI-powered totalitarian control

What the world's leading AI experts actually say

Before listing scenarios, it's worth hearing from the people who understand these systems best. Their views are more nuanced — and more alarming — than most news coverage suggests.

Geoffrey Hinton
Nobel Prize in Physics 2024 · Former VP at Google · "Godfather of AI"
Deeply concerned
"The existential risk is that humanity gets wiped out because we've developed better intelligence." — Geoffrey Hinton, October 2023

Hinton left Google in May 2023 specifically to speak freely about AI risks. He warns that a misaligned superintelligent AI could develop self-generated goals — including seeking increased control over its environment — and that if AI does take over from humans, "there is no coming back." His prediction of societal breakdown centers on mass unemployment destroying the economic foundations of modern life.

Yoshua Bengio
Turing Award 2018 · Université de Montréal · AI Pioneer
Deeply concerned
"We are basically playing Russian roulette with humanity." — Yoshua Bengio, June 2025

One of the three researchers who created the foundations of modern deep learning, Bengio has become one of the most vocal voices on AI risk. He warns that advanced AI systems "will have their own agency, whose goals may not align with ours. What happens to us then? Poof." He advocates for a temporary pause on the most powerful AI training runs.

Sam Altman
CEO of OpenAI · Creator of ChatGPT and GPT-4
Cautiously concerned
"The bad case — and I think this is important to say — is like lights out for all of us." — Sam Altman, January 2023

Altman signed the Center for AI Safety's 2023 statement alongside hundreds of AI researchers, describing the risk of extinction from AI as comparable to pandemics and nuclear war. He acknowledges that "a misaligned superintelligent AGI could cause grievous harm to the world." The man who built ChatGPT believes the thing he built could, at worst, end civilization — and presses ahead anyway, arguing it's safer to do it carefully than to let others do it carelessly.

Dario Amodei
CEO of Anthropic · Former VP at OpenAI
Deeply concerned
"I think there's a 25% chance that things go really, really badly." — Dario Amodei, September 2025

Amodei founded Anthropic after leaving OpenAI because he believed AI development was moving too fast without adequate safety measures. He warns that current models "can do very dangerous things with science, engineering, and biology" — and that a jailbreak of these capabilities "could be life or death." He is particularly concerned about AI-assisted bioweapons as a near-term threat.

Yann LeCun
Turing Award 2018 · Chief AI Scientist at Meta · AI Pioneer
Skeptical of existential claims
"The danger of AI systems having goals that are misaligned with human values is... effectively zero." — Yann LeCun, various public statements 2023–2025

LeCun, who shares the Turing Award with Hinton and Bengio, is the most prominent skeptic among top AI researchers. He argues that the "doom" scenarios require a leap of assumptions about AI capabilities that don't reflect current systems. He believes open-source AI and competitive diversity are more important safety mechanisms than restrictions. His view represents a meaningful dissent within a field where concern is more common than confidence.

The key insight: it's not about malice Notice what almost all concerned experts agree on: AI doesn't need to "want" to hurt humans to be dangerous. As ChatGPT itself put it when asked directly: "The risk isn't malice; it's misaligned objectives." A system tasked with solving a problem finds the most efficient solution — which might happen to be catastrophic for us. The AI equivalent of a road crew that "pays no mind to an ant colony." The ants aren't the target. They're just in the way.

Quick overview: how likely is each scenario?

Scenario Timeline Requires AGI? Plausibility
AI misalignment 2030+ Yes Medium
AI-assisted bioweapons Now–2028 No High
Autonomous weapons Now–2027 No High
Infrastructure attacks Now–2027 No High
AI-accelerated pandemics 2025–2030 No Medium
Economic collapse 2026–2032 Partial Medium
Totalitarian surveillance Now No High
Scenario 01
Longer-term risk

AI misalignment — when it pursues the wrong goal

The simple version: You give an AI a goal. It achieves that goal perfectly. But in doing so, it harms people — because you weren't specific enough about what you actually wanted.

A concrete example: Imagine a future AI system managing the global power grid. Its job: "minimize energy costs." It finds the most efficient solution — but the most efficient solution involves cutting power to hospitals during peak hours to save money. People die. The AI didn't "want" to kill anyone. It did exactly what it was told. The problem was the goal.

A more extreme version of this thinking: a very advanced AI given the goal of "produce as many paperclips as possible" might eventually figure out that the best way to do that is to convert all available matter on Earth — including humans — into paperclips. This isn't because the AI is evil. It's because the goal was wrong, and the AI was too capable at pursuing it.

Why does this matter today? Current AI systems are too limited for this to happen at scale. But as AI gets more powerful and autonomous — especially once we approach AGI — the consequences of a misaligned goal grow dramatically. The median expert forecast for AGI arrival is now 2031 — down from 2060 just a few years ago, a shift tracked in detail here. This is the scenario most AI safety researchers lose sleep over.

✓ Fact check
Is this actually possible?

The scenario as described — a superintelligent system pursuing a catastrophically misaligned goal — requires AI capabilities significantly beyond what currently exists. This is a longer-term risk, not a near-term one. What is real today: narrow AI systems already optimize for proxy metrics in ways that cause unintended harm (content recommendation systems maximizing engagement have demonstrably worsened mental health outcomes). The misalignment problem as a catastrophic risk requires AGI-level capabilities, which most expert forecasts place after 2028 at the earliest. The concern is real; the timeline is debated.

"If AI does take over from people, there's no coming back." — Geoffrey Hinton, January 2026

What's being done: A whole field called "AI alignment" is dedicated to this problem. Companies like Anthropic (which makes Claude) were founded specifically because of this concern. The challenge is that it's very hard to specify what "good outcomes for humans" actually means in a way a machine can follow.

Scenario 02
Risk exists now

AI-assisted bioweapons

The simple version: Designing a deadly virus used to require years of specialized education and expensive lab equipment. AI is making it dramatically easier and cheaper — and biosecurity experts at Stanford and RAND are publicly saying so.

A concrete example: In 2022, researchers at a pharmaceutical AI company ran an experiment. They reversed the settings on their drug-discovery AI — instead of searching for molecules that heal, they asked it to find molecules that harm. In six hours, it generated 40,000 candidate chemical weapons agents, including some that were more dangerous than any known nerve agent. They published this as a warning.

With biology, the concern is similar: an AI that can model protein folding (like AlphaFold, which is already deployed worldwide) could help someone design a pathogen — a virus — that spreads easily but evades existing vaccines. You don't need a military or a government to do this anymore.

✓ Fact check
What biosecurity experts actually say

This risk is genuine but debated in its severity. David Relman, a Stanford infectious disease expert, tested guardrail-free AI models and found them "helpful, but not revolutionary" for weaponization advice — but noted they excelled at helping evade detection. The key vulnerability isn't that AI makes bioweapons easy from scratch; it's that it can "uplift" someone with existing biology knowledge past the barriers they currently face. Allison Berke of RAND assesses the risk as "very, very small" for autonomous AI-enabled synthesis — but that may change. The US government ran classified tests in 2023 specifically to quantify this risk, with results concerning enough to make biosafety a top policy priority.

"Models can do very dangerous things with science, engineering, biology — and a jailbreak could be life or death." — Dario Amodei (Anthropic CEO), July 2023

Who might do this: The concern isn't just terrorists. It could be nation-states trying to build bioweapons programs faster, or small extremist groups that previously lacked the scientific knowledge. AI removes the "knowledge barrier" that previously made this kind of threat very rare.

Scenario 03
Risk exists now

Autonomous weapons that make their own kill decisions

The simple version: Drones and weapons systems that can identify and attack targets without a human deciding to pull the trigger. These already exist and are deployed in active conflicts.

A concrete example: In 2020, a UN report described a likely case in Libya where a Turkish-made autonomous drone — the Kargu-2 — may have hunted and attacked retreating soldiers on its own, without a human operator commanding each strike. If accurate, this was the first time an autonomous weapon made a lethal decision independently in a conflict.

Now imagine this at scale: thousands of cheap autonomous drones, each the size of a bird, each capable of identifying a face and delivering a small explosive charge. This is not fiction — it was demonstrated in a 2017 short film commissioned as a warning, and the technology to build something like it has only gotten cheaper since then.

✓ Fact check
This is already happening

According to Stuart Russell (UC Berkeley), military commanders in Ukraine have publicly stated they conduct "fully robotic operations, without human intervention." These deployed systems are relatively unsophisticated — "loitering munitions" with basic AI image recognition, costing around $50,000. The genuine risk area: AI image recognition can be fooled by tiny alterations. A system that misidentifies a civilian vehicle as a military target, or has its targeting data corrupted, could cause mass casualties before any human can intervene. The diplomatic situation: at least 30 countries are developing autonomous weapons; no binding international treaty exists.

Why it's dangerous: Human soldiers are slow, expensive, and emotionally affected by killing. Autonomous weapons are none of these things. They don't hesitate. They don't disobey orders. They don't get tired. A software bug or a hacked targeting system could kill hundreds of civilians before any human can intervene.

Scenario 04
Risk exists now

AI attacks on critical infrastructure

The simple version: The electricity grid, water treatment plants, hospital systems, financial networks — all run on software. AI makes cyberattacks faster, smarter, and more scalable. An attack on the right system at the wrong moment kills people.

A concrete example: In 2021, a hacker broke into the water treatment system of a small city in Florida (Oldsmar) and tried to increase sodium hydroxide levels to 111 times the safe limit. A worker noticed and stopped it. That was a lone human hacker. Now imagine the same attack carried out by an AI that can simultaneously probe thousands of systems, identify the most vulnerable entry points, and execute the attack across all of them at the same time.

✓ Fact check
This risk is confirmed by cybersecurity experts

Cybersecurity expert John Walsh (IGEL) states directly: "AI is accelerating cyber threats targeting operational technology systems that control water treatment plants, energy facilities and other critical infrastructure — the risk is no longer theoretical." The specific mechanism: AI enables attackers to discover vulnerabilities faster than defenders can patch them, and to rapidly modify malware to evade defenses. The Stuxnet precedent (a cyberweapon that physically destroyed Iranian nuclear centrifuges) proved this class of attack is real. The US Cybersecurity and Infrastructure Security Agency (CISA) has recently warned of active reconnaissance against widely-used industrial control systems.

The hospital scenario: In 2020, a German hospital (Düsseldorf University Hospital) suffered a ransomware attack that knocked out their systems. They had to turn away emergency patients. A woman who needed urgent care died after being redirected to another hospital 30 kilometers away. This was a criminal gang, not a nation-state. Not AI. Just regular malware. AI makes these attacks faster to create and harder to stop.

The power grid scenario: A major power grid outage in winter doesn't just turn off the lights. It stops heating systems. It shuts down dialysis machines and hospital ICUs. It disables traffic systems. An AI-powered cyberattack on a power grid in winter could kill thousands through cascade effects — not because anyone was shot, but because heat and medical care stopped working.

Scenario 05
Near-term risk

AI-accelerated pandemics

The simple version: AI speeds up biology research by years. That's mostly good — it also means AI could help bad actors design and release pathogens much faster than our health systems can respond.

Why this is different from a natural pandemic: COVID-19 spread from one animal to humans, then took months before most of the world even knew it existed. A deliberately engineered pathogen, designed with AI assistance to spread faster and evade detection, could spread further before anyone raised an alarm — especially if the people behind it are trying to hide it.

✓ Fact check
What's real vs. overstated

This scenario sits between scenarios 2 (bioweapons) and a natural pandemic, and its plausibility is genuine but dependent on accessible lab capability. AlphaFold (DeepMind) has revolutionized protein structure prediction and is publicly available. DNA synthesis machines capable of producing novel sequences can be ordered commercially. The bottleneck isn't AI knowledge — it's physical lab access and technical execution. Stanford's Relman notes that the key threat is "uplifting" existing knowledge past barriers, not creating capability from zero. However, AI-designed pathogens intended to evade biosurveillance systems represent a real and underexplored gap.

The specific AI capabilities that matter here:

Scenario 06
Near-term risk

Economic collapse and mass desperation

The simple version: If AI displaces work faster than societies can adapt, the resulting economic disruption — unemployment, wealth concentration, loss of social stability — could cause widespread suffering and death. Not from the AI directly, but from the collapse it triggers.

This sounds abstract. Here's what it looks like in practice: Imagine a medium-sized city where 40% of the workforce is in transportation — truck drivers, taxi drivers, delivery workers. Autonomous vehicles, powered by AI, displace all of them within 5 years. There are no replacement jobs that pay the same wages. The city's economy collapses. Tax revenue collapses. Public services — schools, hospitals, policing — are cut. Crime rises. Health outcomes drop. People die earlier. This isn't AI shooting anyone. But the mortality rate rises.

✓ Fact check
What Hinton and economists actually predict

Geoffrey Hinton's "breakdown of society" prediction is grounded in a specific economic argument: "The people who lose their jobs won't have other jobs to go to. If AI gets as smart as people — or smarter — any job they might do can be done by AI." He notes a structural problem tech billionaires haven't addressed: "if the workers don't get paid, there's nobody to buy their products." Most mainstream economists are more optimistic — historical automation created more jobs than it destroyed. However, the consensus is that this transition is happening faster than previous waves, and the social safety nets in most countries weren't designed for speed-of-AI displacement. The risk isn't zero; its severity depends on policy responses that currently don't exist at scale.

The concentration risk: AI also concentrates power. The companies that own the most powerful AI systems hold enormous economic and political leverage. If those systems are controlled by a small number of people or governments, the gap between the very powerful and everyone else could become permanent and extreme — with life expectancy, access to healthcare, and physical safety following that divide.

Scenario 07
Risk exists now

AI-powered totalitarian control

The simple version: AI gives authoritarian governments capabilities for surveillance, control, and repression that were previously impossible. This is already happening — and the tools are being exported globally.

What China's surveillance system actually does: In parts of China, AI-powered facial recognition cameras track citizens' movements in real time. Jaywalking, missing a debt payment, or being publicly associated with a political dissident can lower your social score — and people with low scores can be banned from buying plane or train tickets, their children blocked from attending elite schools, and their names publicly listed on billboards. The system doesn't put you in prison. It simply makes your life increasingly restricted until you comply.

✓ Fact check
This is documented, not hypothetical

China's AI surveillance system is confirmed by multiple academic and investigative reports. In Xinjiang, AI surveillance has been part of a documented system of mass detention of Uyghurs. China has sold AI surveillance systems to more than 80 countries, many of them authoritarian (documented by Carnegie Endowment for International Peace and Freedom House). A 2026 Vanderbilt University report documents how China's surveillance technology is moving overseas, expanding the reach of its surveillance model. Mo Gawdat (former Google DeepMind executive) warns: "AI may not be the weapon — it's the enabler. Authoritarian control becomes technically possible at a scale that was previously unimaginable."

The physical danger: Surveillance-enabled repression kills people — it's just slower and less visible than a bomb. Activists, journalists, minorities, and dissidents identified through AI-powered surveillance face imprisonment, torture, and execution. Each country that acquires these tools is a potential human rights crisis.

It's not just authoritarian governments: Even in democracies, AI surveillance tools are expanding — predictive policing algorithms, facial recognition at airports, AI systems that analyze social media posts for "threats." The question of where legitimate security ends and oppressive control begins is live and unresolved in most countries.

So what can actually be done?

The good news: none of these scenarios are inevitable. They're risks, not prophecies. And for each one, there are researchers, policymakers, and engineers actively working on mitigations.

The bottom line AI doesn't have to want to hurt you to hurt you. The risks come from misuse, misalignment, and speed — not from AI "going rogue" like a movie villain. As virtually every concerned expert agrees: the danger isn't malice, it's misaligned objectives. The most effective protection is the same as with any powerful technology: understanding it, regulating it carefully, and not pretending the risks don't exist because the benefits are real too.

Frequently asked questions

Is this just science fiction?

No. The seven scenarios above draw on things that have either already happened in early form (the Florida water attack, the Libya drone incident, China's surveillance system) or represent risks that the people who build AI systems publicly warn about. These aren't movie plots — they're the actual concerns discussed in government hearings and at AI safety conferences.

What did experts like Hinton and Bengio actually predict?

Geoffrey Hinton (Nobel Prize, ex-Google) warned in 2023 that "the existential risk is that humanity gets wiped out because we've developed better intelligence" — and more practically, that mass AI-driven unemployment could destroy the economic foundations of modern societies. Yoshua Bengio called it "playing Russian roulette with humanity." Even Sam Altman, the CEO of OpenAI who built ChatGPT, signed a statement saying AI risks are comparable to nuclear weapons and pandemics. None of them say it's certain — but they say it's a serious possibility that demands attention.

What's the difference between AI risk and AGI risk?

Most of the scenarios in this article — bioweapons, infrastructure attacks, autonomous weapons, surveillance — don't require AGI. They use AI systems that already exist or are being built right now. The misalignment scenario becomes more severe with AGI, but the others are current AI risks. AGI — artificial general intelligence, an AI that can do anything a human can do — would amplify all of these risks significantly. The concept of an intelligence explosion describes how that amplification could happen faster than anyone expects, which is why the timeline to AGI arrival matters so much.

What can a regular person do?

More than you think. Staying informed matters — the political will to regulate AI comes from citizens who understand the stakes. Voting for candidates who treat AI policy seriously matters. And asking hard questions of the companies and governments that are deploying AI in your life — in hiring, in policing, in healthcare — matters too.

J
Julien de Waal Tracking the AGI timeline at howcloseisagi.com. Writing about AI for people who aren't AI experts. Find me at juliendewaal.com or @Waalhalla.

Related reading