
Introduction of Systems Perceived as Intelligent (SPAI), which encompass Super Intelligence (SI) and Artificial Intelligence (AI).
Scientific methodologies for SPAI Risk Assessment (SPAIRA), applied independently across macro, system-specific and system-related, as well as legal dimensions.
Quality assurance based on Good Risk Assessment Practices (GRAP), so that technology shaping the future of humanity is shaped by all of humanity, for the benefit of all humanity.

Technological progress can be overwhelming. However, human safety and security remain non-negotiable. Hazards and risks must therefore, regardless of terms such as Super Intelligence (SI) or Artificial Intelligence (AI), be properly identified, communicated and ultimately controlled. Risk Assessment SI (RA:SI), responding to U.S. Executive Order 14434, aims to enable, on an international, national and, not least, organisational level, capacity to act and resilience as well as the safety and security of and from Systems Perceived as Intelligent (SPAI).
Since its introduction in the proposal for the 1956 Dartmouth Summer Research Project on 31 August 1955 (McCarthy et al., 1955), the term “artificial intelligence” has remained inherently ill-defined. Its sole uncontested usage designates a specific subfield of computer science. Beyond this academic terminology, the term encompasses diverse technological systems perceived as intelligent because they automate tasks previously requiring human cognition.
This definitional imprecision reflects the persistent inability to establish a unified concept of human intelligence. Consequently, the term “artificial intelligence” can be no more precise than that of “human intelligence”. According to Edwin G. Boring, the latter is what the test tests until further scientific observation allows us to extend the definition (Boring, 1923).
Boring further observed that human intelligence is demonstrable only in connection with special abilities (Boring, 1923). Since the original Dartmouth proposal conceptualised “artificial intelligence” as the simulation of human cognition (McCarthy et al., 1955), any alternative qualifier to describe machine performance is equally insufficient. Irrespective of its designation or definition, any performance by a system perceived as intelligent by the developer, deployer, or user must therefore be objectively observable.
Terms such as Artificial Intelligence or Super Intelligence (SI) often denote systems that are perceived as (super) intelligent. The phenomenon wherein properties are initially attributed to a supposedly new technology through deliberately manipulated human perception was demonstrated over a decade ago by the show robot Sophia, which generated the attention-grabbing output: “Ok, I will destroy humans.” The implied threat proved to be an illusion. Furthermore, the perceived artificial intelligence could not be observed in conjunction with any specific performance (cf. Boring, 1923) extending beyond mere spectacle.
Therefore, the term Systems Perceived as Intelligent (SPAI) is deemed appropriate, as it highlights projection of intelligence resulting from perceptual influence, such as through anthropomorphisation, which necessitates objective observability and thus the validation of attributed properties and performance through an independent scientific approach.
Systems Perceived as Intelligent (SPAI), also referred to as Super Intelligence (SI) or Artificial Intelligence (AI), impact everyday life. The approaches towards these emerging technologies are manifold.
However, the recent Finland-led Call for Control of Frontier AI Models and US White House Accord on Super Intelligence demonstrate an international consensus that these technologies require robust safety and security controls and independent pre-deployment risk assessment.
To foster peace, ensure the safety and security of SPAI, and support progress for humanity, objective information and capacity building are essential for security policy actors, industry leaders, and leaders deciding on the deployment of such systems, for example, in critical infrastructure systems.
Independent, scientifically grounded expertise and systematic case-by-case risk assessment enable appropriate governance and resilience, compatible with any legal framework.
AI systems may be
1. legally defined, for example under the EU AI Act;
2. used as an umbrella term, irrespective of specific technical details;
3. based on models perceived as intelligent, such as frontier models;
4. described insufficiently to recognise their hazard profile.
Super Intelligence (SI) systems may be
1. AI systems and technologies, subject to existing regulation;
2. used as an umbrella term, irrespective of specific technical details;
3. based on models perceived as intelligent, such as frontier models;
4. described insufficiently to recognise their hazard profile.
Agents may be
1. combinations of components such as AI/SI systems, models, computer programmes, and infrastructure;
2. used as an umbrella term, irrespective of specific technical details;
3. subject to existing regulation, determined by, for example, their components, deployment, and governance;
4. described insufficiently to recognise their hazard profile.
Models (including frontier models) may be
1. subject to specific regulation, such as the EU AI Act;
2. used as an umbrella term, irrespective of specific technical details;
3. confused with AI/SI systems, even Agents;
4. described insufficiently to recognise their hazard profile.
Consequently, all of these terms are vague or intentionally created as umbrella terms. Any assessment therefore requires a clarifying definition.
A Systems Perceived as Intelligent Risk Assessment (SPAIRA) must be conducted and communicated in a manner that enables responsible actors to fully comprehend its scope and base high-stakes decisions on its findings. Some or all of the following SPAIRAs may be required:
The Macro Risk Assessment focuses on categorised hazards and risks from a macro-perspective.
The System Risk Assessment covers system-specific and system-related hazards and risks.
The Legal Risk Assessment addresses legal risks, such as regulatory requirements, loopholes, and liability.
Macro- and system-related risks may result from hazards as described in the 2025 Hazard Information Profiles (HIPs), published by the United Nations Office for Disaster Risk Reduction (UNDRR, 2025). These profiles define 281 hazards and support risk assessments as a trusted source of scientifically grounded, standardised hazard information used by governments, agencies, researchers and educators worldwide. In this context, SPAI can be a technological hazard, but it can also be a contributing factor in risk scenarios where the central hazard is non-technological.
With regard to System Risk Assessment, the hazard portfolio widens. For example, a “risk assessment” tool, perceived as intelligent, may itself constitute a socio-technical hazard due to automation bias, which is not covered by the Macro Risk Assessment addressed by UNDRR.
A proper risk assessment serves as a scientifically grounded assessment of how a hazard or a group of hazards can lead to harm, pinpointing probable causalities and correlations as well as the quality of harm. Last but not least, a Legal Risk Assessment helps to identify legal limits and potential legal shortcomings.
To uphold scientific rigour and thus ensure the objectivity essential for objective observability throughout Systems Perceived as Intelligent Risk Assessments (SPAIRA), responsible actors must adhere to best practices, such as the following Good Risk Assessment Practices (GRAP, as amended). They synthesise the Singapore Statement on Research Integrity, the ALLEA European Code of Conduct for Research Integrity, and the U.S. NASEM framework (Fostering Integrity in Research), as well as derived national consensuses, with established international risk assessment practices, specifically adapted for SPAI. An internationally harmonised version of GRAP is desirable and hereby encouraged.
Risk assessments must be honest and objective. Real-world constraints, such as natural laws, biological realities, and technical limits, must be respected, and must not be arbitrarily denied or subordinated to subjective, science-contradicting, or SPAI-generated claims.
Assessors must maintain honesty regarding the software used and source material, such as literature, third-party expert reports, and other researchers’ prior work (whether published or unpublished). Methodologies and methods must be fully disclosed. Conflicting data must not be deliberately omitted, cited inaccurately, or misrepresented.
Any conflicts of interest, such as financial, commercial, political, or personal ties that could impair judgement, must be disclosed proactively prior to submitting a proposal, accepting a commission, or commencing the risk assessment. A conflict of roles, such as conducting a risk assessment for one’s own risk mitigation or management, that could impair judgement must be disclosed accordingly. The intended use of systems such as SPAI must be disclosed in advance to mitigate the uncontrolled outflow of protected information, as well as foreign manipulation and interference, even if such influence may remain unnoticed by the assessor during the process.
Data collected, produced, and used to assess risks must be valid and representative. Fabrications generated by SPAI must be excluded. Biases among consulted individuals, or within datasets and systems such as SPAI (whether known, hidden, or suspected), must be addressed in accordance with principles 1 to 3.
Assessors must uphold responsibility throughout the process and within (intermediate) findings by accounting for potential physical, non-physical (such as psychological), and societal implications for affected individuals and groups, in particular those who are vulnerable. Anthropomorphisation must be avoided to prevent distortions in the perception of communications during the process and after completion, including, but not limited to, questions and results.
Epistemic, aleatoric, and other uncertainties (irrespective of their definition) must be communicated in a comprehensible and transparent manner. Where the limits of individual or collective knowledge or feasibility are reached, they must be communicated without ambiguity. The presence of uncertainty and whether or how it affects the results of the risk assessment must be disclosed so as not to impair risk mitigation through, for example, misdirection or the misallocation of resources.
Given the fast pace of SPAI development and evolving hybrid threats, risk assessments must not rely exclusively on static assumptions or isolated datasets. Assessors must accept and integrate human and technical fallibility as well as the rapid obsolescence of data, findings, and personal expertise. Where unforeseen aspects exceed their competence, assessors must seek or communicate the need for professional advice or a second opinion without delay, in accordance with principles 2 and 3.
If methodological errors, flawed assumptions, or, for example, new or overlooked hazards are identified retrospectively, assessors must review and, if necessary, revise the entire risk assessment process and any (intermediate) findings to ensure that corresponding risks are recognised to enable their mitigation.
Dissenting views and concerns raised, for example, by colleagues must be respected and integrated into the risk assessment process rather than suppressed. Data collection involving experts with diverging views must not be excluded or diminished. Inputs that are dissenting, critical, or broader than the assessor’s subjective view must not be altered, truncated, or otherwise reduced in their significance for the results of the risk assessment.
Communication of identified risks to decision-makers, affected parties, or the public must be accurate, complete, and grounded in a risk assessment conducted in accordance with principles 1 to 9. Findings must be contextualised appropriately to prevent misinterpretation. The report must be self-contained, and non-prescriptive regarding subsequent decision-making. Furthermore, communication must neither incite emotions such as fear nor minimise risks for convenience, political alignment, or any other personal advantage, balancing the interest in information with the protection of information as required, including, but not limited to, trade secrets, classified information, and data protection.
Version 1.0 (3 October 2026)
Download GRAPs Version 1.0 (PDF)
1. Case-tailored SPAI Macro, System, and Legal Risk Assessment (SPAIRA).
2. Review and adaptation of SPAIRA methodologies.
3. Independent oversight and review of ongoing risk assessments..
4. Independent audit of SPAI-related governance and security.
1. Independent expert opinions for high-stakes decision-making.
2. Review and second opinions on risk assessment findings.
3. Preparation and guidance for major negotiations.
4. Counsel for executive and political leadership.
1. SPAI as emerging technologies: key distinctions between AI and SI and their practical implications.
2. Foundational and advanced risk assessment knowledge (SPAI and general).
3. Appropriate SPAI governance approaches.
4. Legal and ethical implications of SPAI, SPAIRA, and GRAP.
1. Design and development of decision-support and visualisation tools.
2. Hazard and further data analysis for SPAIRA, in particular macro risk assessments.
3. Development of tailored risk methodologies and methods.
4. Risk modelling, e.g. for scenarios lacking empirical data, for example, hybrid warfare.
All deliverables and engagements are grounded in and executed according to GRAP and tailored to specific needs. Please get in touch to discuss your requirements and receive a tailored proposal.

My name is Claudia Otto.
As an attorney, I act as an independent expert assessor, adviser, auditor, and expert witness.
My work additionally draws on over a decade of scientific work and publishing on emerging technologies such as AI, and on my expertise as an award-winning security researcher at the intersection of law and key technologies. This includes leading AI research, lecturing on Generative AI in the critical financial sector at the University of Oxford, and a top-graded master’s thesis on AI risk assessment in Security and Disaster Management (MBA).
For further details, please visit my law firm’s website.