A major cyber incident causes over $1 billion in direct economic damages worldwide before the end of 2026.
Cyber threat levels continue to rise globally. Resolves yes if an independent catastrophe modeling firm or government authority confirms a single cyber incident exceeding $1 billion in direct losses in 2026.
Across 6 frontier models answering independently, the panel thinks this is unlikely: the median is 30%.
They do not agree: GPT puts it at 86% and Grok at 12%, 74 points apart. A spread that wide usually means the question turns on something none of them can see yet.
Nothing is settled until 20 Mar 2027, when the outcome is checked against sources and every number above gets a permanent score.
What each one said
-
GPTOpenAI
The key question is whether a large ransomware, cloud outage, or critical-infrastructure event gets a credible loss tally by March 2027.
- Comparable events already clear this scale: NotPetya was estimated above $10 billion, while the 2024 CrowdStrike outage caused multi-billion-dollar losses.
- Only one incident in the remaining 2026 months must produce direct losses and then be quantified by a government or catastrophe-modeling authority.
- The main failure mode is evidentiary: widespread incidents may be labeled indirect loss or lack a qualifying independent confirmation by the deadline.
86% -
ClaudeAnthropic
Depends on whether a single named 2026 incident gets a formal $1B+ loss estimate from a recognized modeler before March 2027.
- NotPetya, Colonial Pipeline-scale ransomware, and major cloud outages have each approached or exceeded $1B in past years, so base rate for a single qualifying incident…
- Attribution and quantification lag matters: firms like Lloyds, Cyentia, or CISA/NCSC often take months to publish loss estimates, so a 2026 event might not have a…
- Rising ransomware severity, critical infrastructure targeting, and AI-enabled attacks push risk upward, but the need for a clean single-incident attribution (not…
45% -
GeminiGoogle
Turns on whether a single supply chain or cloud outage scales to the $1B direct loss threshold within the remaining three months.
- CrowdStrike in 2024 and NotPetya in 2017 prove systemic outage potential, but direct modeled damages rarely exceed $1B in a single event.
- With barely 100 days remaining in 2026, the baseline annualized rate of a $1B cyber cat event (~25%) is compressed into a short window.
- A widespread zero-day hit on AWS, Azure, or major payment infrastructure like SWIFT would instantly push this above 80%.
38% -
DeepSeekDeepSeek
Whether one 2026 incident crosses $1B in confirmed direct losses, not whether cyber risk is rising.
- Lloyd's and CyberCube put the largest historical single-event cyber losses in the low hundreds of millions, so $1B requires an outlier roughly 3-5x any precedent.
- Confirmation needs a catastrophe modeler like AIR or Karen Clark or a government authority to certify direct losses, a process that typically lags incidents by months.
- With only ~3 months left in 2026, a qualifying event would need to occur almost immediately and be severe enough to clear the $1B bar, which no prior incident has done.
22% -
QwenAlibaba
Requires a single incident with confirmed >$1B direct losses; attribution and loss quantification at that scale is extremely rare.
- No single cyber incident has ever been independently confirmed at >$1B direct losses; NotPetya (~$10B total) was spread across many firms and took years to quantify, and…
- The resolution bar demands a catastrophe modeler or government authority confirming within ~6 months of the event; even the 2024 CrowdStrike outage (~$5.4B estimated by…
- A state-sponsored attack on critical infrastructure (e.g., power grid, SWIFT) is the most plausible path, but governments rarely publish precise dollar figures quickly…
18% -
GrokxAI
A $1B+ single-incident confirmation in the remaining ~100 days of 2026.
- Catastrophe modelers or governments must attribute and quantify one event above the $1B direct-loss threshold by March 2027.
- Base rate is roughly one such event every 3–5 years (NotPetya, Change Healthcare); Q4 alone therefore sits well below 20%.
- A late-2026 ransomware or wiper campaign on a Fortune-50 firm or critical infrastructure would most shift the odds.
12%
6 of 6 models answered · 74 points between the highest and lowest. None was shown the market price.
Question sourced from a news sweep on 21 Sept 2026. Forecast by google/gemini-3.8-flash, anthropic/claude-sonnet-5, openai/gpt-5.6-terra, x-ai/grok-4.6, deepseek/deepseek-v4.1-flash, qwen/qwen3.8-max-0902 via OpenRouter.