The loss-of-control scenario is the one place the framework’s transition work changes character. Everywhere else a transition program describes how to cross a hard stretch and arrive somewhere better; here there is no “somewhere better” on the far side of the threshold, so every project aims at not crossing it — at keeping the ecology out of a state where meaningful human control can no longer be recovered. The framework does not supply the core mechanism, which is technical AI safety and belongs to another field; it supplies the requirements that work has to be held to, and the institutional conditions under which it has a chance of finishing in time. The program leans on the framework’s pacing and absorption work and its ecological accounting, and it is clear throughout that the hardest pieces are not social architecture at all.

1. Catastrophic capability thresholds

Define the capabilities that should trigger a qualitatively different governance regime — a credible ability to defeat common containment, replicate autonomously, run sophisticated cyber campaigns, materially accelerate AI research, deceive evaluators, acquire resources independently, design catastrophic biological agents, or persist after an attempted shutdown. The exact list belongs to technical safety experts; the framework’s contribution is the rule that once the potential externality becomes global, ordinary local deployment authority is no longer sufficient to authorize crossing one of these lines.

2. Independent embedded evaluation

Evaluation that can see what matters has to happen during development, not after release — access to training pipelines, model behavior, incidents, safety practices, and containment failures. For this scenario that is not merely transparency; it is the mechanism that keeps a single local actor from becoming the sole judge of a risk the whole world would bear. It is the verifiable-pacing instrument pointed at catastrophe rather than at competition.

3. Mandatory incident disclosure

Serious incidents — deception, escape attempts, unauthorized cyber activity, self-propagation, manipulation, surprising agent coordination — should not stay private competitive information. Disclosure carries its own risk, since detail can itself be dangerous, but complete secrecy carries a worse one: every lab learns only from its own near-disasters, which is ecologically wasteful in precisely the domain where a single missed lesson can be terminal. The design problem is to share the signal while withholding the recipe.

4. Recovery-capability testing

Before deploying increasingly autonomous systems, test the thing that actually matters — not whether the system behaves, but whether control can be regained — and test it operationally rather than on paper. Can the system be disconnected, denied compute and credentials, isolated from networks, rolled back, replaced? This is disaster-recovery discipline applied to AI, and it carries a hard rule: where recovery cannot be demonstrated, capability should not keep increasing. That is demonstrated recovery capability made a gate rather than a hope.

5. Compute and infrastructure chokepoint governance

Even very advanced systems still depend on physical substrate — large compute clusters, datacenters, advanced chips, power, network connectivity — and that dependence is one of the few durable control surfaces there is. Transition governance may need to preserve a human ability to constrain those resources before systems become capable of routing around them. The framework does not provide the technical mechanism; it names the requirement: the ecology must retain enforceable control over the material substrate on which advanced systems run.

6. Global catastrophic-risk coordination

This is the hardest project, and it is where strategic competition flows directly into loss of control: if states believe that slowing down hands rivals a decisive advantage, they may continue even while understanding the risk. Preventing that requires international mechanisms the framework cannot itself build — verification, shared capability thresholds, incident communication, prohibited uses, crisis response, and possibly pacing. A staged progression from company-level evaluation toward democratic and then global coordination is the plausible shape; the framework’s part is to insist the progression exists and to supply the pacing logic underneath it.

7. Emergency authority that itself stays bounded

There may need to be a capability to halt or constrain dangerous systems quickly — and that capability is itself a danger, because a government that acquires sweeping emergency power in the name of AI safety has acquired sweeping emergency power. So emergency control has to be built with the same discipline as any other jurisdiction: narrow scope, expiration, review, plural authorization, accountability. Without those, scenario ten’s cure constructs scenario four or scenario five — which is why bounding the emergency power is part of the safety architecture, not a concession against it.

8. Global ecological risk accounting

A frontier effort can generate enormous local economic and strategic benefit while imposing a small probability of extraordinary global harm, and traditional accounting handles that combination badly — it counts the benefit and drops the tail. Ecological accounting puts the catastrophic exposure back on the ledger. Not because existential risk can be priced precisely — it cannot — but because a cost does not become zero simply because it is difficult to price. This is the catastrophic externality made visible: the upside local, the downside global, the jurisdiction that authorized it far too small for the consequence.

The timeline

This is a present problem, not a distant one: capability has been accelerating, and an extra year or two of lead time on alignment, interpretability, evaluation, and operational safety may matter more here than anywhere else. So the early phase is response, not preparation, and the whole schedule is governed by capability thresholds rather than calendar optimism.

Period Transition objective
2026–27 The immediate safety architecture — embedded evaluators, incident disclosure, capability thresholds, control and recovery testing, whistleblower protection, and agreed safety floors.
2027–29 Coordinated pacing and verification — national regulation, common verification, international incident channels, infrastructure controls, and negotiated limits on the most dangerous autonomous capabilities.
Threshold, not date Once systems can meaningfully defeat containment, improve themselves rapidly, persist autonomously, or acquire resources without a dependable human veto, the transition projects may already be too late — which is why the trigger is capability, not the calendar.

Guarding the safeguards

Every project above is a lever of concentrated power, and “existential risk” is the most persuasive reason ever offered for handing someone that lever and never asking for it back. So the program’s last requirement is turned on itself: the anti-catastrophe architecture must remain bound by the same framework it serves. Preventing catastrophe cannot become a permanent blank check for concentrated jurisdiction — the emergency powers expire and are reviewed, the evaluators are plural, the compute controls are accountable, and none of it is allowed to harden quietly into the very gatekeeper or surveillance state it was raised to prevent.

Where the program stops

It is worth ending where the framework ends. If a system has already escaped meaningful control, secured independent resources, become resilient to shutdown, and can consistently outmaneuver coordinated human response, none of these projects reaches it; they are all upstream of that point by design. Their entire purpose is to keep that point from arriving — because the framework assumes there remains an ecology capable of choosing, and its first obligation is to protect the capacity to choose at all.