Today: the five AI headlines of the day → and the AI Wiki
What a signpost is How to read this page

A watched question with a line drawn in advance

The threshold was written before the observation existed. That is what stops a state from being argued into place after the fact.

Four states, no probabilities

Observed, emerging, contested, not observed. These are qualitative readings against the threshold. No number is invented here, because an invented number would be the most quotable and least true thing on the page.

It stays alive between revisions

The update condition names what would move the state. A signpost that has stayed quiet is information too, and is published rather than hidden.

New to this publication?

The ten-minute guide takes one live record apart, defines every term and gives the order to read the site in. Start here →

WLD-D24-002 · Observed 2026-06-03

emerging

AI-enabled Cyberattack on Energy or Logistics

Qualitative signpost review · no probability assigned

Bounded observation

Anthropic examined 832 banned accounts with sufficiently detailed malicious cyber activity from March 2025-March 2026: 67.3% used AI for malware writing and 6.5% for lateral movement; later-stage chaining and autonomy increased. The dataset does not document cross-sector propagation through energy or logistics.

Trigger threshold

Move to observed when a verified incident report attributes materially autonomous AI exploit chaining to operational disruption in energy or logistics and documents propagation beyond the initial target.

Counter-indicator

Vendor visibility covers its own banned accounts; most activity was preparatory, only 54/832 showed lateral movement, and sector-specific physical disruption is absent.

Update criterion

Review CISA/ENISA/sector-ISAC incident reports and vendor disclosures; upgrade only with affected assets, autonomy evidence and operational impact, not malware generation alone.

Primary routes

  1. https://www.anthropic.com/news/AI-enabled-cyber-threats-mitre-attack