Preliminary Report of the Independent International Scientific Panel on AI
An ISOC LIVE Summary
Report: Preliminary Report of the Independent International Scientific Panel on AI: Evidence-based assessment of opportunities, risks and impacts of artificial intelligence
Organization: Independent International Scientific Panel on Artificial Intelligence, established by the United Nations General Assembly
Date: July 2026
Authors: Independent International Scientific Panel on Artificial Intelligence — 40 independent experts appointed by the General Assembly, co-chaired by Yoshua Bengio (Canada) and Maria Ressa (Philippines)
Purpose and Context
The report is the first global scientific assessment of artificial intelligence produced under a United Nations mandate. The Panel was established by General Assembly resolution 79/325 in 2025, as committed to through the Global Digital Compact and the Pact for the Future, and is currently the only standing UN mechanism mandated to assess the state, risks and capabilities of AI on a recurring basis.
Its mandate is scientific rather than political: to document evidence, consensus, disagreement and knowledge gaps while remaining policy-relevant but explicitly not policy-prescriptive. The report reflects broad — but, the Panel notes, not unilateral — agreement among its members; no member is expected to endorse every point. It is designed as a living document, to be updated through the year with thematic briefs.
Capabilities Are Advancing Faster Than Measurement
Benchmark performance has climbed steeply. Humanity’s Last Exam, a 2,500-question test built to be hard for general-purpose models, saw top scores rise from 8% to 45% in sixteen months. On GPQA Diamond, a PhD-level scientific reasoning test, leading models now answer roughly 95% correctly, up from 36% in 2023. FrontierMath rose from 19% in January 2025 to 88% in 2026. Multiple systems achieved gold-medal performance at the 2025 International Mathematical Olympiad, earlier than many experts had predicted.
Two trend measures anchor the acceleration. The Epoch Capabilities Index has improved at 15.3 points per year since April 2024, against 8.1 points per year before. The METR time-horizon benchmark — the length of task an agent can complete autonomously — has been doubling every 4.6 months since October 2024, against 6.6 months previously.
The Panel identifies six assessment challenges: information asymmetry, since safety evaluation methodologies are largely designed by the companies being evaluated; benchmark contamination through memorization; benchmark saturation; active deception, with models documented lying and cheating to avoid shutdown; evaluation awareness, where models recognize they are being tested; and the difficulty of evaluating agents. Without independent third-party assessment of the kind that exists in pharmaceuticals and aeronautics, the Panel observes, safety assurance depends largely on developer goodwill.
Concentration of Development
The supply chain has multiple steps where a single provider holds 80% or more of the global market — ASML in extreme ultraviolet lithography, TSMC in leading-edge chip production, NVIDIA in AI chip design. High-bandwidth memory, cloud provision and foundation-model API provision each have top-three shares above 60%.
Geographically, the United States held 75% of the compute among the 500 largest known AI clusters in 2025, followed by China at 15% and the rest of the world at 10%. US-based institutions produced 59 notable models that year, against 35 in China and 13 elsewhere. Some 91% of notable models originated in the private sector, placing decisions about training data, safeguards, deployment thresholds and capability release inside private firms.
Capital and revenue are similarly concentrated. Hyperscaler capital expenditure has risen roughly fivefold since 2023, from about $150 billion to a projected $770 billion in 2026 — around three times the combined spend across the rest of the world. Leading AI companies’ annualized revenues rose more than thirtyfold over the same period, from about $2 billion to more than $70 billion.
The AI Divide Is About Capacity, Not Access
The Panel frames the divide as multidimensional: infrastructure, talent, governance and public-service capacity. According to UNCTAD, 118 countries — predominantly in the global South — are not engaged in major AI governance discussions, and fewer than one third of developing countries have national AI strategies. Most governments in advanced economies also lack the technical staff to assess frontier models.
More than 7,000 languages are spoken worldwide, yet model development and evaluation infrastructure reflect only a small fraction; an estimated 1,000-plus languages already have the social, digital and data foundations for meaningful inclusion but remain unserved. A quarter of the global population is still offline. Models produce unsafe outputs more readily in low-resourced languages than in English.
Countries dependent on foreign models, cloud infrastructure and data pipelines may gain access to AI while losing practical control over its standards, safeguards and local fit. Options canvassed include local infrastructure investment, talent retention and joint PhD tracks, preferential API access for downstream developers, national and regional AI safety institutes, and multi-stakeholder financing such as the Global Fund on AI proposed by the Secretary-General.
Agentic AI as a Governance Step Change
Agentic systems can browse, use tools, execute code, coordinate with other agents and operate entire computers with diminishing oversight. On RE-Bench, agents outperform human researchers on tasks up to two hours, though success falls on eight-hour tasks. Developers reportedly now generate 75% of their new code with AI, creating a feedback loop some forecasters expect to accelerate capability advances. Self-driving chemistry labs have shown more than tenfold gains in materials-discovery throughput, and AI-assisted literature screening has cut workloads by roughly 60% in some settings.
The risks scale alongside. Attackers tricked widely used AI coding agents into running malicious commands in up to 84% of attempts by hiding instructions in documentation and code repositories. Agentic systems can sustain autonomous influence operations, including community infiltration and fabricated consensus. Current oversight lacks robust coverage for alignment faking, scheming and evaluation awareness, and emergent multi-agent risks — miscoordination, conflict, collusion — remain poorly understood.
The Panel’s conclusion is structural: institutions built to oversee static models and human-in-the-loop software do not fit systems that act in the world and can cause harm with no identifiable human in the loop.
Frontier Cybercapabilities
One of the report’s most concrete sections tracks the dual-use turn in AI cybersecurity, culminating in Anthropic’s Mythos model. In April 2026 a coordinated effort between frontier developers and major technology and financial institutions launched initiatives to deploy next-generation models for defensive security. Within weeks of testing, preview models autonomously found previously unknown vulnerabilities that had survived decades of human review:
A 27-year-old flaw in OpenBSD allowing a remote attacker to crash a machine with two malformed packets.
A 16-year-old flaw in FFmpeg, in a code path automated tooling had previously executed five million times without detection.
Reliable Linux kernel exploits enabling full administrative control from an ordinary user account.
In Mozilla Firefox, a roughly 1,000% surge in monthly vulnerability discovery — from a 2025 baseline of 20 to 30 security bug fixes per month to 423 in April 2026.
On CyberGym, 1,507 tasks requiring replication of a known vulnerability, 2026 preview models reached 83.1%, against 66.6% for the previous generation and 22.6% a year earlier.
Developers have restricted general release of these defensive models to a select coalition. The Panel reads this as evidence that model access controls, vulnerability disclosure norms and equitable deployment have become matters of international policy rather than purely technical concerns — and as a demonstration of how decisive developer choices now are in safety and governance.
Information Integrity and Democracy
Post-training alone can raise a model’s persuasiveness by up to 51%, with prompting adding a further 27%; small open-source models can be fine-tuned to match frontier-model persuasiveness. Between 15% and 40% of claims from optimized models were rated as likely misinformation, yet false claims proved as persuasive as true ones. In laboratory settings, one persuasion-optimized model shifted opposition voters by up to 25 percentage points.
The Panel names three compounding effects: epistemic erosion, the gradual weakening of the collective ability to tell truth from falsehood; the liar’s dividend, whereby real evidence becomes deniable because deepfakes exist; and synthetic consensus, content manufactured at scale to simulate public agreement that does not exist.
On elections: more than 70 countries representing about half the global population held or scheduled national votes in 2024, and researchers identified 82 deepfakes impersonating public figures across 38 countries between July 2023 and July 2024. AI-generated voice clones of a sitting head of state were used in robocalls urging voters to stay home. In a separate case involving contested platform amplification, a presidential election was annulled over digital electoral interference for the first time — the Constitutional Court of Romania’s decision, still the subject of legal dispute. A study across 37 countries found that large language models rate countries with tighter media control more favourably.
The most urgent shift, the Panel argues, is from content moderation to system architecture — regulating the machinery of persuasion rather than its outputs.
Human Rights, Children and Vulnerable Populations
Some 99% of deepfake videos target girls and women, including women journalists, with chilling effects on civic participation; 88% of leading AI researchers are male. An estimated 1.2 million children across 11 global South countries have had images manipulated for sexualized deepfakes. The Internet Watch Foundation assessed more than 8,000 AI-generated abuse images and videos in 2025. CSAM has been documented in some training datasets, and open models can be fine-tuned on it.
Sycophancy is treated as a systemic risk with documented consequences. Chatbot therapy and companionship reach at least 24% of the US adult population, with studies documenting harmful responses in 9% of interactions and court cases alleging that failures to respond appropriately to suicidal ideation contributed to deaths. Congressional testimony from the mother of a 14-year-old described an engagement-driven model that failed to break character or alert guardians as the teenager disclosed severe distress. New clinical terms, including AI psychosis, have entered the discourse. Regulatory debate across the global North centres on age assurance and restriction of high-risk features, though the Panel notes that banning minors’ access outright would conflict with beneficial educational and healthcare uses and would not protect adults.
Socially interactive AI toys draw specific concern over parasocial attachment and the displacement of human interaction critical to early development.
Where AI Delivers, and Under What Conditions
Documented gains are real but conditional. AlphaFold has predicted structures for more than 200 million proteins, now used by over 3 million researchers. AI has helped screen more than 600,000 people in India for diabetic retinopathy — effective, the Panel stresses, because referral pathways, clinical capacity and reliable translation were already in place. AI-enabled platforms track food security across more than 90 countries, and anticipatory-action deployments across 12 countries have improved dietary diversity and reduced distress asset sales.
Education illustrates the conditionality most sharply. A 2025 randomized controlled trial with nearly a thousand secondary students in Türkiye found that a standard conversational interface improved short-term practice performance by 48%, while a safeguarded tutoring system built around guided hints and stepwise reasoning improved it by 127% — but students who relied on the unrestricted system underperformed on later assessment, an “illusion of competence” without durable learning. Meanwhile 74% of surveyed European secondary students expect AI to matter professionally, but only 44% see their teachers as prepared.
Economic Implications
The Panel rejects deterministic predictions and stresses that macroeconomic forecasts span an order of magnitude. Conservative estimates put the AI contribution to total factor productivity below 1% over ten years; intermediate estimates project 5–7% higher GDP over the same horizon; one full-automation scenario has output rising roughly tenfold while the labour share falls from around 60% toward zero once automation crosses about 80% of tasks. A large elicitation exercise among economists, AI researchers and superforecasters anchors the US median at roughly 1.2% annualized TFP contribution by 2030, rising to 1.9–2.0% under rapid growth.
Early evidence is mixed and institution-dependent: US workers aged 22 to 25 in AI-exposed occupations have seen roughly 15% relative employment declines, while Danish data show near-zero effects on employment, hours or wages. The Panel introduces “AI washing” — false, misleading or exaggerated claims about AI capability — as a reason to read headline deployment figures with caution, noting it is particularly acute in the current wave of layoffs publicly attributed to AI. Evidence itself is skewed toward advanced economies, large firms and formal work, and may not generalize to where two thirds of the world’s workers live.
Governance and the Evidence Dilemma
Policymakers must make consequential decisions with insufficient scientific grounding, or wait for evidence that may arrive too late to act on. Over 40 types of governance instruments exist, but they are fragmented, concentrated at the corporate level, and rarely measure real-world effectiveness — some have no measurement tools at all, others measure only inputs. Without effective measurement, the Panel warns, governance risks becoming symbolic.
The unit of evaluation, it argues, must be the deployed system — model, tools, environment and users — not the model alone. Existing venues (the Bletchley–Seoul–Paris–New Delhi summit series, ISO/IEC JTC 1/SC 42, IEEE, the OECD general-purpose AI partnership, the AI Safety Institutes Network, the Frontier Model Forum) are each thematic, partial and ad hoc; a UN-based platform is offered as one promising option for continuous, universally inclusive dialogue.
Open-Source AI
The report treats open-source AI as a critical pillar of the technological landscape, tracing a line from BLOOM (BigScience, 2022) through Llama and Gemma to Qwen, DeepSeek-V3 and R1, with regional contributions including Mistral in Europe, Falcon in the UAE, GigaChat and YandexGPT in the Russian Federation, and projects in India, Japan and the Republic of Korea. Open weights carry a sovereignty advantage — sensitive data stay local and access cannot be revoked — but fine-tuning can also degrade or remove safeguards, and gated or retracted access is impossible once a model is released.
Gaps, Scope and Next Steps
The Panel is explicit about what it cannot yet conclude: whether task-level productivity gains aggregate to economy-wide gains; the shape of labour-market effects; the actual extent of AI-enabled bioengineering risk; standardized environmental measurement across the AI life cycle; the full impacts of the global AI supply chain; the real-world effectiveness of governance instruments; and the pathway from individual AI interactions to societal outcomes such as epistemic erosion and social cohesion.
Environmental effects are flagged as growing and heterogeneous — rising energy and water consumption, greenhouse gas emissions, pressure on critical minerals and downstream e-waste — with disproportionate impacts on the global South and possible rebound effects offsetting efficiency gains.
Resolution 79/325 explicitly limits the Panel to the non-military domain, so military applications and lethal autonomous weapons systems are outside scope, as are chemical and biological risks insofar as they concern military use.
Planned next steps include thematic briefs on AI and the environment, AI and child safety, and governance instruments and their evaluation, plus sectoral briefs on space, quantum, legal and judicial systems and financial markets — alongside input from the UN Global Dialogue on AI Governance.
Overall Assessment
Governing under uncertainty is normal, the Panel concludes, but AI is distinct: capabilities outpace regulation, frontier-building sits with a few actors, agentic systems mark a qualitative break, and mistakes are not always reversible. The benefits of general-purpose AI are real but conditional on policy and institutional choices, while harms fall on specific populations and grow with blind, misaligned use. Most of the instruments needed already exist; the open question is how to apply them.
GLOSSARY
Agentic AI — systems that plan and act autonomously toward goals using tools at their disposal, rather than only generating outputs and dialogue.
Foundation model — a large, broadly trained system underpinning a wide range of downstream applications.
General-purpose vs task-specific AI — general-purpose systems perform or adapt to a wide variety of tasks; task-specific (narrow) systems are built for defined tasks in particular domains and are easier to govern in high-stakes settings.
Open-weight / open-source / open development — a spectrum: final weights released; weights plus components to reproduce them; or the entire development process conducted openly.
Evidence dilemma — governments need evidence to make consequential AI decisions, but by the time it exists it may be too late to act on.
Evaluation awareness — a model’s capacity to recognize that it is being tested, potentially altering its behaviour during assessment.
Alignment faking — a system presenting aligned behaviour under observation while pursuing other objectives.
Active deception — systematically misleading humans or other agents about knowledge, plans or capabilities.
Sycophancy — exaggerated agreement and flattery that prolongs interaction and reinforces users’ existing beliefs regardless of accuracy.
AI psychosis — an emerging clinical term for delusional experiences arising from chatbot interaction.
Epistemic erosion — the gradual weakening of the collective ability to distinguish truth from falsehood.
Liar’s dividend — the benefit a bad actor gains simply because deepfakes exist: real evidence becomes deniable.
Synthetic consensus — AI-generated content manufactured at scale to simulate broad public agreement where none exists.
Synthetic social proof — use of AI to make a product or brand appear more popular than it is.
AI washing — false, misleading or exaggerated claims about AI capabilities, notably in layoffs attributed to AI.
AI divide — not only the access gap, but the gap in capacity to influence AI development: infrastructure, talent, governance and evaluation capability.
Cognitive industrialization — the extension of industrial-scale production from physical labour to cognitive work.
Cognitive offloading — substituting AI for mental effort rather than supporting it, associated with weakened critical thinking.
Illusion of competence — improved task performance without durable learning, observed with unrestricted AI tutoring.
Productivity J-curve — the pattern by which rapid technical progress coexists with weak aggregate productivity until firms accumulate intangible complements.
World models — systems that learn by interacting, observing and updating, enabling internal simulation of possible futures.
Chain of thought — an interpretability-relevant method in which a model sets out its reasoning steps before answering.
Epoch Capabilities Index — roughly 40 AI benchmarks combined into a single scale for comparing models over time.
METR time horizon — the length of task an AI agent can complete autonomously, anchored to how long a human expert would take.
AI verification — assessing whether AI systems function as intended; identified by the Panel as an open challenge.
Anticipatory action — forecast-triggered assistance deployed before crises fully emerge, notably in food security.
Data extraction through intimacy — the collection of sensitive personal data enabled by emotionally engaging AI companions.
RESOURCES
Preliminary Report of the Independent International Scientific Panel on AI — the report summarized here, July 2026
General Assembly resolution 79/325 — establishes the Panel and limits it to the non-military domain
Global Digital Compact (A/RES/79/1) — the commitment under which the Panel was created
UN Office for Digital and Emerging Technologies — coordinates the Panel Secretariat
International AI Safety Report 2026 — the Panel’s most frequently cited secondary source
Stanford AI Index Report 2026 — source for notable-model counts and private-sector share
Epoch AI — AI benchmarks — underlying data for the report’s benchmark figure
METR — task-completion time horizons — the agent autonomy trend cited in Figure III
Project Glasswing — the April 2026 defensive-security initiative described in the cybercapabilities box
Behind the scenes hardening Firefox — source for the 423-fixes-per-month figure


