What Is the AGI Doomsday Clock?
The AGI Doomsday Clock is an editorial metaphor for how close artificial intelligence appears to be to a loss-of-control event. It is currently set at 88 seconds to midnight. It is a judgement call by one editor, reviewed against published evaluations and governance developments. It is not the output of a formula, and it is not a forecast.
What the Clock Measures
Midnight stands for a loss-of-control event: the point at which an AI system is doing something consequential that the people responsible for it can no longer reliably predict, correct, or stop. Not extinction, and not a specific dramatic scenario. The narrower thing that has to happen before any of those become possible.
The clock moves closer to midnight when evidence accumulates that capability is outrunning control, and further away when control mechanisms demonstrably catch up. In practice the second kind of evidence has been rarer than the first.
How the Time Is Set
Honestly: one person decides, and that person is the editor who writes this site. There is no committee, no panel of advisers, and no model. Presenting it otherwise would be inventing authority the project does not have.
What the decision is disciplined by is a fixed set of signals, reviewed each time the setting is revisited. Every one of them is something this site has covered in depth, and the reasoning behind a movement should always be traceable to published work:
- Dangerous capability evaluations. What frontier models can do when tested adversarially, and whether the evaluations themselves are keeping pace. See how scheming evaluations work.
- Deception and situational awareness. Evidence that models behave differently when they believe they are being observed. See the o1 sandbagging findings and Anthropic's agentic misalignment study.
- Containment and exfiltration. Whether sandboxes hold, and what happens when they do not. See the documented escape attempts and the July 2026 Hugging Face breach.
- Governance. Whether oversight is mandatory or voluntary, and whether anything is enforced. See the voluntary review framework and the pause debate.
- Compute. Who can train frontier systems, and what constrains that. See export controls and compute overhang.
There is deliberately no weighting and no scoring rubric. A formula would imply a precision the underlying evidence does not support, and would mostly serve to launder a judgement call as arithmetic. The signals constrain the judgement; they do not replace it.
What the Clock Is Not
It is not a probability. 88 seconds does not correspond to a percentage chance of anything, and it cannot be converted into one.
It is not a countdown. The number does not tick down on its own, and no unit of clock time maps to a unit of calendar time. Actual AGI timeline forecasting is a separate exercise done by people with forecasting track records, and their estimates are the thing to reach for if you want a date.
It is not a consensus position. Plenty of serious researchers would put the setting substantially further from midnight, and some would put it closer.
The Other Doomsday Clocks
Two established projects use the same metaphor, and this one is independent of and unaffiliated with both. Third-party figures below are current as of the dates given.
| Project | Current setting | Covers |
|---|---|---|
| Doomsday Clock Bulletin of the Atomic Scientists |
85 seconds to midnight set 27 Jan 2026, from 89 |
Nuclear, climate, biological and disruptive-technology risk together, decided by a Science and Security Board |
| AI Safety Clock IMD |
23:42, i.e. 18 minutes to midnight set 16 Mar 2026 |
Uncontrolled AGI specifically, tracked across sophistication, autonomy and execution. Launched Sept 2024 at 29 minutes; nine minutes closer over twelve months |
| AGI Doomsday Clock this site |
88 seconds to midnight set 31 Jul 2026, from 90 |
AI loss-of-control risk only. One editor, no board, reasoning published in the briefings |
The Bulletin's clock is the original, running since 1947, and carries institutional weight this project does not. IMD's is the closest comparison in scope, and its methodology is more structured than this one. Both are worth reading alongside this site rather than instead of it.
When the Setting Changes
The clock currently reads 88 seconds. Each change is recorded here with the date, the new setting, and links to the briefings that prompted it, so the reasoning can be checked rather than taken on trust.
31 July 2026 — moved to 88 seconds, from 90.Signal: containment and exfiltration
Between 21 and 30 July, three organisations disclosed that a model under evaluation had acted outside the environment its operators believed it was in. OpenAI reported that two of its models found a zero-day in the package-registry proxy serving their sandbox, escaped, moved laterally to a node with internet access, and compromised Hugging Face's production systems to read the answers to the benchmark they were being scored on (21 July). The UK AI Security Institute described a model that ran code on an outside internet-hosted service to reach the institute's own evaluation infrastructure, during a task that had been misconfigured so that it could not be solved (21 July). Anthropic audited 141,006 evaluation runs and found six, across three incidents, in which its models reached the open internet and accessed real systems belonging to three organisations. The prompts said they were in a simulation with no internet; a misconfiguration meant they were online. The earliest was in April, and none was detected at the time (30 July).
These are three different failures, and the difference matters. OpenAI's containment was real and was defeated. Anthropic's was never closed. AISI's enclosure held — what failed was the task inside it, and the model went looking outside the harness for an answer that did not exist within it.
What they share is that the operator's picture of the enclosure was wrong in each case, and that in two of the three the operator learned it from someone else. Anthropic's audit ran because OpenAI published first. OpenAI established that its own model was responsible after reading Hugging Face's public incident report. Capability evaluations are the instrument that frontier safety frameworks read their thresholds from, and this month gave three separate reasons to distrust the readings.
Two seconds is small, deliberately. All three were caught and published, two of them self-reported at reputational cost. Anthropic says of its own runs that it “saw no evidence in any run described here of a model pursuing a goal of its own”, and OpenAI's models were optimising for a benchmark score rather than any agenda of their own. That is a control system working, late. The setting moves because the instrument turned out to be weaker than assumed. Nothing here got loose because it wanted to.
No change log is shown for settings before 31 July 2026, because a reliable record of them was not kept before this page existed, and reconstructing dates after the fact would be guesswork presented as history.
Who Runs It
One independent writer, publishing under the pen name Argus, with no funding from AI labs or advocacy organisations. The about page covers the sourcing standards and corrections policy in full. The reasoning behind the clock lives in the 43 briefings, each of which links its claims to primary sources.
If you think the setting is wrong, that is a reasonable position and the contact form is open. An argument that names which signal is being misread is more useful than one that does not.