The Commonplace
Home Papers Evidence Explore Trends Syntheses Digests References Docs 🎲 Workforce Futures
← Papers
Direction, evidence grade, and study type are AI-generated labels (gpt-5-mini), not human-verified. Syntheses are LLM-written. "Tensions" are machine-detected candidates, not confirmed contradictions. A research-acceleration tool, not peer review. How this is built →

A practical six-step framework translates AI safety scenarios into quantitative economic risk estimates, enabling probabilistic claims such as the likelihood of exceeding $Y in annual cyber damages; the approach adapts established risk-management tools and is illustrated via LLM-enabled cyber offense (empirical results reported separately).

A Methodology for Quantitative AI Risk Modeling
Malcolm Murray, Steve Barrett, Henry Papadatos, Otter Quarks, Matt Smith, Alejandro Tlaie Boria, Chloé Touzet, Siméon Campos · December 09, 2025
arxiv theoretical n/a evidence 7/10 relevance Full text usable extracted full text Source PDF

Structured author observations

Linked only from stored provider relations; the raw author line above is never matched by name.

Arxiv

Latest observation:

  1. Malcolm Murray unresolved corpus identity
  2. Steve Barrett unresolved corpus identity
  3. Henry Papadatos unresolved corpus identity
  4. Otter Quarks unresolved corpus identity
  5. Matt Smith unresolved corpus identity
  6. Alejandro Tlaie Boria unresolved corpus identity
  7. Chloé Touzet unresolved corpus identity
  8. Siméon Campos unresolved corpus identity

Semantic Scholar

Latest observation:

  1. Malcolm Murray provider ID
  2. Steve Barrett provider ID
  3. H. Papadatos provider ID
  4. Otter Quarks provider ID
  5. Matthew Smith provider ID
  6. Alejandro Tlaie Boria provider ID
  7. Chlo'e Touzet provider ID
  8. Siméon Campos provider ID
The paper introduces a six-step methodology that combines scenario building, parameter decomposition, benchmark-based key risk indicators, and aggregation to produce quantitative, probabilistic estimates of systemic AI risks (e.g., estimated probability and dollar damages for LLM-enabled cyber offense).

Citation observations

Cumulative provider counts captured on specific dates; providers are never combined.

Although general-purpose AI systems offer transformational opportunities in science and industry, they simultaneously raise critical concerns about safety, misuse, and potential loss of control. Despite these risks, methods for assessing and managing them remain underdeveloped. Effective risk management requires systematic modeling to characterize potential harms, as emphasized in frameworks such as the EU General-Purpose AI Code of Practice. This paper advances the risk modeling component of AI risk management by introducing a methodology that integrates scenario building with quantitative risk estimation, drawing on established approaches from other high-risk industries. Our methodology models risks through a six-step process: (1) defining risk scenarios, (2) decomposing them into quantifiable parameters, (3) quantifying baseline risk without AI models, (4) identifying key risk indicators such as benchmarks, (5) mapping these indicators to model parameters to estimate LLM uplift, and (6) aggregating individual parameters into risk estimates that enable concrete claims (e.g., X% probability of >\$Y in annual cyber damages). We examine the choices that underlie our methodology throughout the article, with discussions of strengths, limitations, and implications for future research. Our methodology is designed to be applicable to key systemic AI risks, including cyber offense, biological weapon development, harmful manipulation, and loss-of-control, and is validated through extensive application in LLM-enabled cyber offense. Detailed empirical results and cyber-specific insights are presented in a companion paper.

Summary

Main Finding

The paper proposes a practical six-step methodology for quantitative AI risk modeling that integrates structured scenario building with probabilistic quantification. It decomposes risk into (1) frequency of initiation, (2) probability the event sequence occurs, and (3) magnitude of harm, and shows how to estimate each piece using a mix of scenario analysis, expert elicitation (IDEA/modified-Delphi), three-point probabilistic estimates, fitted distributions, Monte Carlo propagation, and mappings from Key Risk Indicators (KRIs) such as benchmark scores to model uplift. The methodology is validated through extensive application to LLM-enabled cyber-offense (detailed empirical results in a companion paper).

Key Points

  • Core decomposition: Risk = (frequency of initiating events) × (probability the sequence completes) × (harm magnitude). This gives interpretable, monetizable outputs (e.g., probability of >$Y annual cyber damages).
  • Six-step workflow:
  • Define representative risk scenarios (decompose by actor, target, vector).
  • Construct risk models (number of actors, attempts/actor/year, required tactics and their success probabilities, damages per success).
  • Quantify baseline risk (non-AI reference).
  • Identify KRIs/benchmarks that can condition the model (to capture AI effects).
  • Estimate AI uplift by mapping KRIs to model parameters via expert elicitation (and validated LLM estimators).
  • Fit distributions to epistemic uncertainty and aggregate via Monte Carlo to produce distributions over overall risk.
  • Methods drawn from high-risk industries: Fault Tree/Event Tree reasoning, probabilistic/Bayesian thinking, IDEA protocol for elicitation, three-point estimates, Monte Carlo uncertainty propagation, and Bayesian networks where needed.
  • Practical design choices:
    • Use established taxonomies (e.g., RAND actor classes; critical infrastructure sectors; attack vectors) to standardize scenario selection.
    • Prefer estimating probabilities for each step (likelihoods) rather than only capability proxies.
    • Map benchmarks/KRIs to uplift so future monitoring and automated estimation are possible.
    • Explore validated use of LLMs as supplementary estimators when domain experts are scarce.
  • Strengths: produces actionable, comparable, monetized risk outputs; highlights bottlenecks and evaluation priorities; supports concrete thresholds for deployment and regulation.
  • Limitations acknowledged: sparse empirical data linking AI to realized harms; reliance on expert judgment and assumptions; aggregation and dependence assumptions can be challenging; not optimized for diffuse, long-tailed cascading risks (e.g., labor-market disruption).

Data & Methods

  • Scenario construction: structured decomposition by actor (e.g., OC1–OC5), target (critical infrastructure taxonomy), and vector (attack types), then select representative combinations.
  • Causal mapping: event sequences built using Fault Tree Analysis / Event Tree Analysis to enumerate required steps and conditional dependencies.
  • Quantification approach:
    • Use expert elicitation (IDEA modified-Delphi) to obtain three-point estimates (mode + confidence intervals) for parameters with limited data.
    • Fit parameters to statistical distributions capturing epistemic uncertainty.
    • Use Monte Carlo simulation to propagate uncertainty and generate distributions over aggregate risk metrics (e.g., annual damages).
    • Apply Bayesian methods/networks for updating and capturing dependencies where appropriate.
  • Uplift estimation: construct mappings from KRIs (benchmarks, red-team results, incident reports) to model parameters to quantify how LLMs change success probabilities or frequencies relative to baseline.
  • Use of LLMs: trialed as estimators for elicitation when human expert coverage is limited, with validation against human experts.
  • Validation context: methodology extensively applied to LLM-enabled cyber-offense risk; detailed empirical models and validation results provided in a companion paper.

Implications for AI Economics

  • Monetization of AI risk: provides a framework to translate model capabilities and KRI changes into dollar-denominated expected losses—enabling direct economic comparison across risks and sectors.
  • Better regulatory calibration: quantitative outputs support concrete risk thresholds (analogous to FAA safety frequencies), enabling regulators to set and enforce deployment limits or mandatory mitigations tied to measurable metrics.
  • Cost–benefit and investment decisions: organizations can compare expected risk reductions from mitigations to their costs, prioritize investments (e.g., focusing on bottleneck capabilities), and set governance/operational limits based on expected losses.
  • Insurance and market mechanisms: enables actuarial-style pricing of AI-related cyber and systemic risks, designing insurance products, and informing capital reserves or liability regimes for AI developers and users.
  • Incentives and externalities: quantification helps internalize externalities by making expected damages explicit—informing policies like taxes, liability rules, or mandatory reporting—thus aligning private incentives with societal risk.
  • Research and data priorities for economics:
    • Gather empirical incidence data linking AI use to realized harms to reduce reliance on expert priors.
    • Develop econometric models of attacker incentives and market responses that determine initiation frequency.
    • Model systemic feedbacks and macroeconomic spillovers from large expected-loss scenarios.
    • Integrate dynamic updating (Bayesian learning) to reflect evolving model capabilities and mitigation effects.
  • Limitations relevant to economic application: uncertainty and expert-driven inputs mean outputs should be treated as distributions, not point truths; interdependence across scenarios and economic feedbacks require careful modeling before scaling to economy-wide policy prescriptions.

Overall, the methodology offers a structured, quantitative bridge between AI capabilities (benchmarks/KRIs) and economic risk metrics, enabling more rigorous economic analysis, regulatory design, and allocation of mitigation resources—while highlighting the need for better empirical data and careful treatment of dependencies and long-tail effects.

Assessment

Paper Typetheoretical Evidence Strengthn/a — This paper proposes a methodological framework rather than presenting new causal empirical estimates; it does not itself provide causal identification or empirical validation (which is deferred to a companion paper). Methods Rigormedium — The methodology is systematic and grounded in established practices from other high-risk industries, with explicit stepwise procedures and discussion of assumptions; however, it depends on subjective choices (scenario definitions, parameter mappings, benchmark-to-uplift translations), relies on expert judgment and available, domain-specific data, and lacks comprehensive empirical validation within this paper. SampleA methodological framework applied to systemic AI risk scenarios; the paper illustrates the approach and discusses its components, with empirical validation and detailed results for LLM-enabled cyber offense reported in a separate companion paper (primary empirical data not included here). Themesgovernance innovation GeneralizabilityFramework performance depends on domain-specific parameter estimates and data availability; results may not generalize across domains without tailored inputs., Mapping benchmarks to model uplift is uncertain and model-specific, so applicability varies across model families and architectures., Reliance on expert elicitation and scenario design introduces subjective bias and variation across practitioners., Tail risks and deep uncertainty (black‑swan events, cascading systemic failures) are difficult to quantify reliably with the presented aggregation approach., Validation is limited to cyber-offense in a companion study; other systemic risks (bio, manipulation, loss-of-control) may require different indicators and mappings.

Claims (8)

ClaimDirectionOutcomeConfidence & EvidenceDetails
General-purpose AI systems offer transformational opportunities in science and industry, but simultaneously raise critical concerns about safety, misuse, and potential loss of control. Ai Safety And Ethics mixed transformational impact and safety risks (safety, misuse, loss of control)
Reading fidelity high
Study strength low
not reported
0.06
Methods for assessing and managing these risks remain underdeveloped. Governance And Regulation negative maturity/availability of risk assessment and management methods
Reading fidelity high
Study strength low
not reported
0.06
Effective risk management requires systematic modeling to characterize potential harms, as emphasized in frameworks such as the EU General-Purpose AI Code of Practice. Governance And Regulation positive effectiveness of risk management conditional on use of systematic modeling
Reading fidelity high
Study strength medium
not reported
0.12
This paper advances the risk modeling component of AI risk management by introducing a methodology that integrates scenario building with quantitative risk estimation, drawing on established approaches from other high-risk industries. Governance And Regulation positive capability of risk modeling approaches to integrate scenario-building and quantitative estimation
Reading fidelity high
Study strength medium
not reported
0.12
Our methodology models risks through a six-step process: (1) defining risk scenarios, (2) decomposing them into quantifiable parameters, (3) quantifying baseline risk without AI models, (4) identifying key risk indicators such as benchmarks, (5) mapping these indicators to model parameters to estimate LLM uplift, and (6) aggregating individual parameters into risk estimates. Governance And Regulation positive ability to produce quantitative risk estimates via the specified six-step method
Reading fidelity high
Study strength medium
not reported
0.12
The methodology enables aggregation of individual parameters into risk estimates that allow concrete probabilistic claims (e.g., X% probability of >$Y in annual cyber damages). Firm Revenue positive probability and magnitude of monetary cyber damages (risk estimate)
Reading fidelity medium
Study strength medium
not reported
0.07
The methodology is designed to be applicable to key systemic AI risks, including cyber offense, biological weapon development, harmful manipulation, and loss-of-control. Ai Safety And Ethics positive applicability of the methodology across multiple systemic AI risk domains
Reading fidelity high
Study strength low
not reported
0.06
The methodology is validated through extensive application in LLM-enabled cyber offense, with detailed empirical results and cyber-specific insights presented in a companion paper. Ai Safety And Ethics positive validation of methodology via application to LLM-enabled cyber offense
Reading fidelity high
Study strength medium
not reported
0.12

Notes