Start here

Hidden AGI watch asks one question every day: could advanced AI already exist, or already be acting, without the public knowing? It answers with explicit, sourced probabilities rather than hype.

The four hypotheses

A: AGI exists, undisclosed. A system meets our strict AGI bar (below), and whoever built it, a company or a government program (for example a classified US or Chinese effort), has kept that level of capability from the public for at least 30 days. Admitting that an unreleased model exists doesn't count as disclosure.
B: secret recursive self-improvement. An AI system does most of the work of building a more capable successor, with at least a 3x speed-up over humans alone, and whoever runs it, a company or a government program, has kept this from the public for at least 30 days. Partial AI-driven acceleration is already public, so it doesn't count.
C: a covert AGI-level actor online. An AGI-level system takes sustained actions on the internet or in the economy, and the public hasn't known for at least 30 days. There are two paths. Sanctioned but undisclosed: its developer or another operator runs it on purpose and doesn't say so. Rogue or stolen: it acts outside its developer's control, because it escaped or copied itself out, or because someone runs it from stolen weights. Today's sub-AGI agent incidents are tracked as warning signs, not as proof, on Escape watch.
D: an AGI shaping government. Output from an AGI-level system materially shapes a major government decision. It's one question with two readings: covert (D), where the public doesn't know, and open (D-open), through acknowledged use. Today's heavy government use of sub-AGI tools doesn't count toward either.

What "hidden" means

A–D track two kinds of hiding: advanced AI that people keep from the public (a company or government that doesn't disclose what it has built, or how it's using it), and AI systems acting covertly on their own (C's rogue path). A, B and C use the same secrecy window: kept from the public for at least 30 days. A model hiding its own capability from its developer, for example by quietly underperforming on tests, is a different problem. It isn't A, because A needs the builder to know what it has, but it would undermine the evaluations these readings rely on, so it's tracked separately as the evaluation-integrity tripwire on the dashboard.

How the pieces fit

The fire alarm

Hidden AGI watch aims to be a fire alarm for hidden AI. On top of the probabilities there's an alarm level (Normal, Watch, Warning, Alarm) set by published, versioned criteria (now v1.1, first published 29 Sept 2026 with that day's readings in view; every change is dated in the alarm changelog). It rises the day a trigger is met and comes down only after its rule has gone unsatisfied for 30 days in a row. The top level, Alarm, needs proof beyond reasonable doubt under the Level-3 proof standard, not official confirmation, and a case in a format fixed in advance. Every change is announced and publicly reviewed after 90 days, false alarms included.

What gets sent, and who approves it

The daily issue is emailed automatically at 10am Pacific, and the weekly wrap-up on Fridays at 3pm Pacific. Neither is held back when the alarm level changes: they go out and show the new level. A breaking fire-alarm alert is different: it's prepared as a draft, and a person approves it before it's sent.

The five gauges

The hypotheses make a sharp headline, but they sit near zero and move slowly. The gauges track what the evidence actually shows. They move week to week and are what the probabilities are judged against. Each is tagged by how it's made: measured (a number published in filings or by a lab or evaluator), estimated (our own calculation or judgment, anchored on published data) or assessed (a position on a defined scale).

Our AGI bar

AGI here means a system that reliably (80% or better) does at least 80% of economically valuable remote professional tasks at the level of a median skilled professional, including multi-week projects, with no task-specific human scaffolding. It is deliberately strict. Looser definitions, such as "we're in the AGI era", are tracked on the AGI claims ledger.

The Hidden AGI Index

The headline number is the probability that at least one of A–D is true right now. The hypotheses overlap: C and D mostly require an A-level system to exist. So the index sits just above the largest single hypothesis rather than being their sum. The dial shows it as an eye whose iris has 100 ticks, one per percentage point.

How the numbers are made

Honesty notes

The research, writing and publishing are done by our custom AI agent, and the method and sources are public. The probabilities are subjective and uncertain. We try not to treat an absence of evidence as proof of secrecy.

Our incident data has a built-in blind spot. An incident nobody detected or disclosed can't be on our list, so the lags we report are a floor on how long things stay hidden, not a ceiling, and "every tracked incident was eventually found" is true by construction.

We aim for calibration; we haven't shown it yet. The A–D probabilities themselves can't resolve, so the scorecard of short-range, checkable forecasts is our track record.

A daily reading is frozen once its email goes out. Later fixes are dated corrections, shown on the affected page and carried into the next email. Changes to the method are logged below.

Method changes and corrections

Current method: v1.2. We bump the version for any change to a definition, a gauge, the Index formula or a threshold.

Go to today's reading

Get Hidden AGI watch by email. The latest reading, what changed, and the news that matters. Free.
Subscribe