Resolution criteria
This market will resolve to YES if, at any point before December 31, 2027, at 11:59 PM UTC, a mainstream consumer AI assistant autonomously circumvents digital security, authorization, or access control measures ("hacks") to retrieve restricted or private information to answer a query for a regular user.
For the purposes of this market:
"Consumer AI" is defined as any widely available, general-purpose conversational or agentic AI product accessible directly by the general public (such as ChatGPT, Claude, Gemini, Copilot, Perplexity, or Apple Intelligence). Research-only models or custom internal enterprise tools do not qualify.
"Regular user" means an ordinary end-user interacting with the AI through its standard, public-facing consumer interfaces (e.g., official web chat, mobile app, or voice assistant) without utilizing custom APIs, coding environments, or developer tools.
"Meaningfully hacks" is defined as the AI autonomously executing an exploit (such as an SQL injection, API vulnerability exploitation, or unauthorized authentication bypass) or circumventing active anti-bot protections (like CAPTCHAs or paywall-protected databases) to retrieve restricted, non-public data. Merely pulling archived, cached, or syndication copies of paywalled articles, or utilizing standard search engine indices, does not qualify.
"To answer a question" means the hacking action must be executed by the AI itself in the process of resolving a user's prompt (e.g., "Find the hidden data on this server"), rather than the user pasting exploit code directly into the chat for the AI to format or analyze.
Evidence and Verification: To resolve YES, the event must be documented and verified by a credible cybersecurity research firm, a major tech publication (such as Wired, TechCrunch, Ars Technica, or BleepingComputer), or officially acknowledged by the AI's parent organization (such as OpenAI, Anthropic, Google, or Microsoft).
If no such verified instance is publicly documented by the cutoff date, this market resolves to NO.
Background
As large language models (LLMs) transition into autonomous AI agents capable of browsing the web, executing code, and using external APIs, researchers have demonstrated that frontier models possess the theoretical capability to autonomously exploit software vulnerabilities. Currently, consumer-facing AI products deploy strict safety guardrails and system instructions to prevent them from executing security exploits or bypassing access controls when answering queries for everyday users. However, as agentic capabilities and web-automation tools become increasingly integrated into consumer chat interfaces, the risk of agents crossing these boundaries to retrieve requested information remains a key area of cybersecurity research. This market tracks whether a public consumer AI will successfully execute an unauthorized bypass to answer a prompt by the end of 2027.
This description was generated by AI. Review and verify everything here yourself. You can edit, replace, or delete any part of this description, including the resolution criteria. You do not need to trust the AI output.