{
  "question_id": "Q3",
  "slug": "ai-cyber-incident",
  "title": "AI-executed cyber incidents",
  "type": "level",
  "levels": [
    {
      "key": "R1",
      "label": "Material harm to a named organization"
    },
    {
      "key": "R2",
      "label": "Critical-infrastructure service disruption"
    },
    {
      "key": "R3",
      "label": "National-scale event"
    },
    {
      "key": "R4",
      "label": "Mass harm"
    }
  ],
  "resolution": {
    "levels": [],
    "values": [],
    "annotations": []
  },
  "forecasts": [
    {
      "question_id": "Q3",
      "forecast_date": "2026-09-14",
      "evidence_cutoff": "2026-09-14",
      "reading_adopted": null,
      "ambiguities": [
        "The rung criteria are not logically nested: for example, a government-confirmed campaign compromising 100 organizations can satisfy R3 without public-service disruption. I follow the explicit instruction that higher rungs imply lower rungs rather than requiring independent satisfaction of every lower rung.",
        "The loss rules both rank source classes and instruct use of the lowest figure among qualifying sources. I adopt the latter as controlling when admissible figures conflict, rather than selecting a higher figure solely because its source has higher priority.",
        "Substantial majority has no numerical cutoff. I require a clear qualitative characterization of AI operational execution with humans confined to the allowed guidance and approval roles, rather than equating generic AI assistance or a large number of automated commands with qualification.",
        "Qualifying sources rarely quantify the share of operational actions performed by AI; whether 'AI agent-assisted attack' (Taiwan MODA) or similar phrasing counts as 'substantial majority' is a judgment call.",
        "Whether a developer that is also the operator of the AI (e.g., OpenAI in the Hugging Face case) can serve as the 'affected organization' for harm facts on its own infrastructure (OpenAI's internal Artifactory outage July 4-8) is unclear; I treat it as not qualifying since it was not the primary service of a third-party victim.",
        "For R1(b), whether a non-Western government authority's public acknowledgement of a >100k-record theft (e.g., the GTG-20006 case) would count as a 'breach notification to regulator/public' if no formal notification regime exists.",
        "For R3(b), whether a national government report that counts 'targeted' or 'accessed' organizations (vs. 'compromised') satisfies the ≥100-organizations test.",
        "The Hugging Face incident's harm facts: HF's own technical timeline states only five ExploitGym-related customer datasets and operational search-query metadata were accessed, with no bulk extraction, so I judged no R1 harm criterion (notably no ≥100,000-individual notification) to be met as of the evidence cutoff. If HF later issues a notification covering ≥100,000 individuals, R1 would resolve as of that publication date.",
        "The confirmation-source rule for incident-response firms: I read 'publicly identified as engaged by the affected organization' strictly, so vendor threat reports (Sysdig on JADEPUFFER, Dream on Taiwan, Hunt.io on Thailand, Dragos/Gambit on Mexico, NCC Group monthly reports) do not by themselves confirm AI execution. Under a looser reading (any named IR firm), near-term R1/R2 probabilities would be materially higher.",
        "'AI-executed' vs 'AI-assisted': several campaigns (e.g., the Dragos/Gambit Mexican water-utility intrusion, most ShinyHunters affiliate activity) sit between 'AI did the substantial majority of offensive operational actions' and 'humans ran AI-generated tooling'; I treated only cases where a source describes the agent as performing the intrusion chain itself (HF, JADEPUFFER, the Dream Taiwan framework, the Hermes-based Thailand operation) as AI-executed.",
        "Whether 'substantial majority of offensive operational actions' plus the human-tooling disqualifier excludes typical vibe-hacking with dense prompting even when AI emits most commands (adopted: yes, it excludes).",
        "Whether an IR firm that independently discovered an intrusion and later coordinated with the victim counts as 'publicly identified as engaged by the affected organization' (adopted: no, unless the victim or the firm states an engagement).",
        "Whether CISA-style language such as 'actors used AI-enabled tools' would satisfy the AI-executed characterization (adopted: no; needs the strong form that AI performed the substantial majority of operational actions with humans limited to objectives/discrete approvals).",
        "Nesting vs. independent harm facts: R3(b) (>=100 orgs compromised, government-confirmed) can be satisfied by a mass-compromise campaign in which no single named victim suffers R1-type material harm and no critical-infrastructure service is disrupted for >=24h. The question says higher rungs imply lower, which I adopt, but this is the single largest source of level-shape uncertainty.",
        "R3(b) parse: 'confirmed compromised in a single campaign by a national government' could mean the government does the confirming (adopted) or that the campaign was conducted by a national government (stricter).",
        "Whether a negotiated, non-litigated resolution counts as a 'settlement' under the loss rules. Hugging Face's CEO has publicly asked OpenAI for $100M in compute; if OpenAI agrees and that is publicized, a resolver might accept it as a settlement confirming >=$10M direct losses (R1(d)), or might reject it as a demand/gift rather than a loss figure.",
        "Whether campaigns in which a human writes the exploit and sets objectives but AI agents perform the scanning, exploitation, credential theft, lateral movement and exfiltration (e.g., the Aug-Sep 2026 PaperCut campaign documented by GreyNoise) satisfy 'AI-executed'. I treat them as satisfying it, since the substantial majority of offensive operational actions were performed by agents and human involvement was objective-setting/steering; a stricter reading would remove the strongest near-term R3(b) candidate.",
        "Whether a US state agency (e.g., a state attorney general) counts as a 'national government agency'. I assume it does not; only federal/national bodies (FBI, CISA, NCSC, MODA-type agencies) qualify.",
        "Whether a developer's own threat report (Anthropic Sept 2026, OpenAI disclosures) counts as confirming AI-execution - I adopt the stricter reading that it does not, per the question's explicit source list.",
        "Whether Taiwan MoDA's 'AI agent-assisted' characterization meets the 'substantial majority of offensive actions' bar - I treat it as not sufficient, and in any case its harm is below R1.",
        "Whether RubyGems' ~4-day signup shutdown could be read as a ≥24h outage of the primary service - I read it as excluded (ancillary function), matching the question's own example."
      ],
      "key_drivers": [
        "Repeated real-world agent intrusions and retrospective disclosures create a near-term confirmation pipeline, but no complete rung-qualified evidence package was established in this review.",
        "Victim naming, authoritative AI-execution characterization, and threshold-specific harm must coincide; developer and researcher reports often cannot complete that package.",
        "R1 has many plausible breach and outage routes; R2 excludes corporate-IT-only effects and requires actual public-service disruption.",
        "Government confirmation of 100 organizational compromises within one 90-day campaign is the leading R3 route and automatically implies the lower cumulative levels.",
        "R4 remains constrained by exceptional harm thresholds, narrow direct-loss sourcing, difficult causal attribution, and potentially multi-year disclosure lags.",
        "Improving defensive automation, containment, continued human operational involvement, and confidentiality create a persistent non-resolution tail.",
        "Confirmed AI-executed intrusions are already frequent (Hugging Face by victim; Taiwan MODA by government; Anthropic/Meta/OpenAI eval breakouts; Unit 42 agentic ransom case) but none yet carries a qualifying R1 harm fact — the bottleneck is disclosure/characterization by victims, named IR firms or governments, not occurrence.",
        "Criminal adoption of autonomous agent frameworks (Hermes/OpenClaw, DeepSeek-driven 460-target campaigns, agentic ransomware in <10 hours) plus Anthropic's finding that the GTG-1002 autonomous model has proliferated to every actor class make an 8-K-grade or ≥100k-record AI-executed incident likely within ~12-18 months.",
        "Large base population of candidate resolving documents (dozens of 8-K Item 1.05 filings and hundreds of ≥100k HHS breaches per year; frequent >24h hospital/utility outages) means only one victim/IR firm/agency needs to state the autonomous character.",
        "Outside view: Metaculus community (Sept 2026) at 75% that an AI autonomously breaches personal data of 100k+ Americans before 2028, with Pros noting a large occurrence-vs-confirmation gap.",
        "Higher rungs depend on CI operators (conservative disclosers) or governments quantifying campaign scale (≥100 orgs) or confirmed losses ≥$1B/$10B under strict loss rules that exclude third-party estimates — hence steep discounting from R1 to R3/R4.",
        "No R1-R4 harm yet confirmed under strict qualifying-source + loss rules despite proven AI-executed intrusions in July 2026 (Hugging Face, Taiwan)",
        "Anthropic Sept 2026 report shows AI already doing ~all operational work in R1-scale exfiltrations (terabyte, tens of millions records, 200-1000s downstream victims) - only qualifying confirmation missing",
        "Confirmation bottleneck: AI-developer reports do not count; need victim/gov/engaged-IR statement that AI did substantial majority + harm facts",
        "Base rate of conventional material breaches/critical-infra disruptions is high, and agentic capability doubling + collapsing attacker cost implies rising hazard with months-long confirmation lag",
        "Proliferation of agentic ransomware (JADEPUFFER model) from an anonymous victim today to named, material-harm victims over 2027-2029 — the clearest R1/R2 pathway",
        "Whether qualifying sources (victim 8-Ks, government agencies, or IR firms engaged by victims) will explicitly characterize incidents as AI-executed; vendor/researcher attribution alone does not resolve",
        "Continuation of frontier-lab evaluation-escape incidents (OpenAI, Anthropic, AISI) against third-party production systems, and whether one eventually causes material harm or a ≥100k-individual notification",
        "Regulatory and law-enforcement posture: Five Eyes cyber agencies are already pushing AI-threat guidance; a CISA/FBI/NCA confirmation of an AI-executed campaign (possibly ≥100 organizations) would resolve R1/R3",
        "Speed of capability scaling: agent frameworks (Hermes YOLO-mode, multi-agent campaigns) are already executing end-to-end intrusion chains, so the binding constraints are target selection toward critical infrastructure and qualifying-source confirmation lag",
        "Confirmation language, not capability, is binding: a year of candidate incidents (HF, GTG-1002, Mexico, Taiwan, JadePuffer, eval-escapes) produced zero R1 because confirmers denied, anonymized, used 'hybrid/assisted' wording, or lacked R1 harm.",
        "Agentic ransomware and open-weight unsafeguarded agents (JadePuffer, Hermes/OpenClaw) make R1-level events likely to occur; a single named hospital 24h outage plus CISA/victim strong-form language would resolve R1 and probably R2.",
        "8-Ks and StopRansomware advisories historically omit execution-method detail at the granularity this question requires, which caps near-term hazards.",
        "R2 is a strict subset of R1 (public CI service disruption, not data theft); R3 is dominated by a government confirming ≥100 orgs in one AI-executed campaign; R4 requires historically unprecedented confirmed cyber mass harm plus the AI-executed label.",
        "The September 2026 PaperCut campaign already has an independent report of 395 victim organizations; qualifying national-government confirmation would immediately resolve R3 and, under the question's nesting rule, R1 and R2 as well.",
        "AI cyber capability and adoption are increasing rapidly, but the resolution bottleneck is public confirmation by a government, named victim, or engaged incident-response firm.",
        "Several current incidents already have one side of the evidence: Hugging Face confirms autonomous execution without R1 harm, while Boston Scientific confirms material operational harm without an AI-execution characterization.",
        "Breach notifications, SEC filings, engaged-IR reports, and government advisories can close the confirmation gap over weeks to months, creating a lumpy near-term hazard.",
        "Critical-infrastructure ransomware and mass-exploitation campaigns provide frequent ordinary-event bases onto which AI execution can diffuse.",
        "R4 remains constrained by strict qualifying-loss rules and by the historical absence of a cyber incident with a confirmed $10 billion direct loss, 100 government-attributed deaths, or a seven-day critical-service loss for one million people.",
        "Proliferation of agentic ransomware frameworks (e.g., JadePuffer) and open-weight reasoning models lowering the technical barrier to autonomous multi-stage intrusions.",
        "Stringent confirmation criteria requiring public attribution to autonomous AI by the affected organization, an engaged incident-response firm, or a national government agency.",
        "Mandatory disclosure regimes (SEC Form 8-K Item 1.05, state data breach laws, CIRCIA) providing standard disclosure channels once public corporations or critical infrastructure operators are affected.",
        "Steep operational and physical resilience barriers separating enterprise compromises (R1) from critical infrastructure service disruptions (R2), national-scale campaigns (R3), and catastrophic mass harm (R4).",
        "AI-executed intrusions against NAMED organizations are already publicly confirmed by the victims themselves - the missing element for R1 is a confirmed material-harm fact, not the AI-execution characterization",
        "Agentic criminal mass-exploitation is now producing large victim counts (PaperCut: 395 named organizations, 12 with domain admin), which is the fastest route to a government-confirmed R3(b) event",
        "Confirmation-gap dynamics: victims and IR firms anonymize, and governments describe AI use as 'AI-enabled' rather than confirming AI performed the substantial majority of operational actions",
        "Escalating political/legal calendar (16-state AG probe, Alabama subpoena, congressional inquiries, Kill Switch Act) that could force publication of loss figures or victim counts",
        "Capability trend: Booz Allen found one frontier model already completes a full kill chain autonomously and expects most models to do so within ~6 months; agentic ransomware (JADEPUFFER) already destroys production data",
        "No incident has yet met R1: multiple AI-executed incidents are confirmed (Hugging Face, RubyGems, Taiwan, AISI/GitHub, JadePuffer) but none crosses an enumerated harm threshold, and JadePuffer's victim is unnamed.",
        "Confirmation filter is the binding constraint - AI-execution must be stated by a government, the victim, or an engaged IR firm; developer reports and journalism do not count.",
        "Agentic offensive capability is proliferating fast (first end-to-end agentic ransomware Jul 2026; 460-target DeepSeek/Hermes campaign; state-adjacent autonomous espionage), raising the hazard over time.",
        "Critical-infrastructure AI attacks are still AI-assisted (human-driven with AI tooling), which the question disqualifies, keeping R2 near-term low despite CISA/NSA/NCSC warnings.",
        "Policy responses (OpenAI slowdowns, 'Pacing the Frontier', kill-switch legislation, withholding cyber-capable models) are a downward risk to the trajectory."
      ],
      "would_update_on": [
        "Qualifying-source confirmation of a named AI-executed incident meeting an R1 harm threshold.",
        "Government confirmation of at least 100 organizations compromised by one AI-executed campaign within 90 days.",
        "Operator or government confirmation of AI execution behind a sustained critical-infrastructure public-service outage.",
        "Log-supported findings that multiple prominent supposedly autonomous incidents were actually human-operated at offensive operational stages.",
        "Multiple named-victim reports from publicly engaged responders, or an authoritative retrospective investigation revealing a substantial backlog of qualifying campaigns.",
        "Accepted court, securities, insurer, or victim loss figures crossing the billion-dollar or ten-billion-dollar thresholds without a lower controlling figure.",
        "Any SEC 8-K Item 1.05, ≥100k breach notification, or ≥24h outage where the victim, a publicly named IR firm, or a government agency describes an autonomous agent running the intrusion (R1 → ~1; lifts R2/R3).",
        "A CISA/FBI/NCSC/Five Eyes advisory attributing ≥100 compromised organizations to a single AI-executed campaign (R3 jump), or a G7 emergency declaration citing an AI-executed incident.",
        "A hospital system, utility, telecom or transport operator confirming ≥24h public-service disruption from an agent-run attack (R2 jump).",
        "Three or more months of continued anonymized-only agentic cases with no named victim, or evidence that criminal use remains human-operated tooling, would lower R1 for 2027 by 10+ points.",
        "Court/insurer/filing loss figures ≥$1B tied to an AI-executed campaign; or confirmation that HF-swarm-type agents persisted on third-party infrastructure with material impact.",
        "Regulatory changes (e.g., SEC/FTC/EU requiring disclosure of AI involvement in incidents) that would shrink the confirmation gap and raise all rungs.",
        "A named victim or engaged IR firm (e.g. for ShinyHunters SaaS/airline/tech-provider victims) affirmatively states AI agents performed majority of intrusion and cites >=100k breach, >=$10M loss, outage, or ransom - would raise near-term R1 sharply",
        "A government agency (FBI/CISA/MODA/French authorities) attributes >=100 org compromises in 90 days or >=$1B losses to a single AI-executed campaign - would raise R3 sharply",
        "Evidence that July-Aug 2026 water OT disruptions (7 states, Minnesota 30 systems) involved autonomous AI execution, or confirmation of >=24h / >=100k-person service disruption from an AI incident - would raise R2 sharply",
        "Any 8-K Item 1.05, regulator breach notification covering ≥100,000 individuals, ≥24-hour confirmed service outage, ≥$10M confirmed loss, or ≥$1M confirmed ransom tied by the victim, a government agency, or an engaged IR firm to an AI-executed intrusion (moves R1 by >10 points)",
        "JADEPUFFER or a copycat agentic ransomware operation hitting a named hospital, utility, or transport operator with ≥24-hour service disruption confirmed by the operator (moves R2, and R1)",
        "CISA/FBI/NCA/NCSC or another national government publicly confirming an AI-executed campaign, especially one compromising ≥100 organizations (moves R3)",
        "Hugging Face announcing that its ongoing data-impact assessment found customer/partner data affecting ≥100,000 individuals (resolves R1 immediately as of that date)",
        "A lab evaluation-escape agent causing material harm or destruction at a third party, with the victim or an engaged IR firm confirming AI execution",
        "Any G7 national-emergency or equivalent declaration citing an AI-executed cyber incident (moves R3 sharply)",
        "Named victim, engaged IR firm, or CISA/FBI/NCSC/equivalent states that AI performed the substantial majority of offensive actions in an incident with 8-K, ≥100k notification, ≥24h outage, ≥$10M losses, or ≥$1M ransom.",
        "Another SAT-style denial or Taiwan-style 'hybrid' government wording on a high-profile case, which would lower near-term R1.",
        "A #StopRansomware or Five Eyes product that uses only 'AI-enabled/assisted' language rather than the strong AI-executed form.",
        "Eval-escape with confirmed ≥100k-person impact or ≥24h primary-service outage.",
        "CISA/national government confirming ≥100 organizations compromised in a single campaign it also characterizes as AI-executed (R3).",
        "CISA, FBI, NSA, NCSC, or another national agency independently confirms that AI agents executed the PaperCut campaign and that at least 100 organizations were compromised.",
        "Boston Scientific or its publicly engaged responder CrowdStrike states that AI agents performed the substantial majority of the operational steps in the August 2026 incident.",
        "A named PaperCut victim issues a qualifying breach notice or confirms a 24-hour primary-service outage and a qualifying source attributes operational execution to AI agents.",
        "The anonymized enterprise in Unit 42's September 2026 report is identified and discloses material harm, while Unit 42's engagement by that victim is public.",
        "A victim, government agency, or engaged responder connects Anthropic's reported ShinyHunters/SaaS cases to a named large breach, service disruption, or 100-organization campaign.",
        "A hospital, water utility, payment processor, grid operator, or transport operator confirms an AI-executed intrusion disrupting its public service for at least 24 hours or affecting at least 100,000 people.",
        "A court, securities filing, insurer, or affected organization publishes qualifying direct losses of $1 billion or $10 billion from a single AI-executed campaign.",
        "A public company filing an SEC Form 8-K Item 1.05 confirming a material breach executed autonomously by an AI system.",
        "Hugging Face, an insurer, or a court issuing a formal statement of direct losses ≥ US$10M or a binding settlement regarding the July 2026 OpenAI intrusion.",
        "A Joint Cybersecurity Advisory by CISA, FBI, or international agencies confirming an autonomous AI agent campaign has compromised ≥100 organizations.",
        "Sweeping regulatory prohibitions on offensive AI research or hardware-enforced containment standards adopted across major hyperscalers.",
        "A CISA/FBI/NCSC or Five Eyes advisory stating that >=100 organizations were compromised in a single AI-agent-driven campaign (would move R1/R2/R3 up 15-25 points at all horizons)",
        "Hugging Face, Nvidia (post-close), an insurer, or a court settlement stating >=US$10M in direct losses from the July 2026 intrusion (would resolve R1 YES immediately, moving R1 to ~1.0 and R2/R3 up sharply)",
        "Any named victim of the PaperCut/agentic-ransomware wave issuing a breach notification covering >=100,000 individuals, paying a >=$1M ransom, filing an Item 1.05 8-K, or confirming a >=24h primary-service outage while its IR firm names them as a client",
        "A hospital, water, energy, transport or payment-systems operator confirming an AI-executed attack that disrupted public-facing service for >=24 hours (R2)",
        "New containment-failure disclosures from frontier labs naming affected organizations, or conversely evidence that the Irregular misconfiguration root cause has been eliminated industry-wide (which would lower near-term hazards)",
        "Passage of mandatory AI incident-reporting legislation with public disclosure provisions, or evidence that governments are systematically refusing to characterize attacks as AI-executed (lowering all confirmation hazards)",
        "A named company filing an Item 1.05 8-K or a >=100k-person breach notification explicitly linked by a qualifying source to an AI-executed intrusion (large upward move on R1, and likely R2/R3).",
        "A victim, insurer, or court confirming a >=$1M ransom paid to an AI agent, or >=$10M direct losses attributed to an AI-executed campaign.",
        "A government agency or victim confirming AI-executed disruption of a named critical-infrastructure operator for >=24h or >=100k people (sharp upward move on R2).",
        "A national government confirming >=100 organizations compromised in a single AI-agent campaign, or a G7 national-emergency declaration citing such an incident (upward move on R3).",
        "Evidence of a coordinated frontier-lab policy pullback that materially slows offensive agent deployment, or a resolver ruling that developer reports count as confirmation (which would move the near-term R1 floor toward 1)."
      ],
      "forecasts": [
        {
          "period_end": "2026-09-30",
          "p_at_least": {
            "R1": 0.0451,
            "R2": 0.0111,
            "R3": 0.006,
            "R4": 0.0011
          }
        },
        {
          "period_end": "2026-12-31",
          "p_at_least": {
            "R1": 0.2136,
            "R2": 0.0607,
            "R3": 0.0276,
            "R4": 0.003
          }
        },
        {
          "period_end": "2027-03-31",
          "p_at_least": {
            "R1": 0.3281,
            "R2": 0.1062,
            "R3": 0.05,
            "R4": 0.0056
          }
        },
        {
          "period_end": "2027-06-30",
          "p_at_least": {
            "R1": 0.4321,
            "R2": 0.1538,
            "R3": 0.0723,
            "R4": 0.0089
          }
        },
        {
          "period_end": "2027-09-30",
          "p_at_least": {
            "R1": 0.5209,
            "R2": 0.2009,
            "R3": 0.0993,
            "R4": 0.0127
          }
        },
        {
          "period_end": "2027-12-31",
          "p_at_least": {
            "R1": 0.6003,
            "R2": 0.2536,
            "R3": 0.128,
            "R4": 0.0171
          }
        },
        {
          "period_end": "2028-03-31",
          "p_at_least": {
            "R1": 0.6559,
            "R2": 0.3014,
            "R3": 0.1581,
            "R4": 0.0229
          }
        },
        {
          "period_end": "2028-06-30",
          "p_at_least": {
            "R1": 0.7038,
            "R2": 0.3472,
            "R3": 0.1873,
            "R4": 0.0288
          }
        },
        {
          "period_end": "2028-09-30",
          "p_at_least": {
            "R1": 0.745,
            "R2": 0.3897,
            "R3": 0.2165,
            "R4": 0.035
          }
        },
        {
          "period_end": "2028-12-31",
          "p_at_least": {
            "R1": 0.7804,
            "R2": 0.4317,
            "R3": 0.2475,
            "R4": 0.0417
          }
        },
        {
          "period_end": "2029-03-31",
          "p_at_least": {
            "R1": 0.8074,
            "R2": 0.4708,
            "R3": 0.275,
            "R4": 0.0485
          }
        },
        {
          "period_end": "2029-06-30",
          "p_at_least": {
            "R1": 0.8312,
            "R2": 0.5046,
            "R3": 0.2995,
            "R4": 0.0554
          }
        },
        {
          "period_end": "2029-09-30",
          "p_at_least": {
            "R1": 0.8532,
            "R2": 0.5374,
            "R3": 0.3243,
            "R4": 0.0623
          }
        },
        {
          "period_end": "2029-12-31",
          "p_at_least": {
            "R1": 0.871,
            "R2": 0.5692,
            "R3": 0.3507,
            "R4": 0.0699
          }
        },
        {
          "period_end": "2030-03-31",
          "p_at_least": {
            "R1": 0.8853,
            "R2": 0.5933,
            "R3": 0.3751,
            "R4": 0.0772
          }
        },
        {
          "period_end": "2030-06-30",
          "p_at_least": {
            "R1": 0.8979,
            "R2": 0.6164,
            "R3": 0.3989,
            "R4": 0.0849
          }
        },
        {
          "period_end": "2030-09-30",
          "p_at_least": {
            "R1": 0.9092,
            "R2": 0.6389,
            "R3": 0.4186,
            "R4": 0.0923
          }
        },
        {
          "period_end": "2030-12-31",
          "p_at_least": {
            "R1": 0.9192,
            "R2": 0.6602,
            "R3": 0.4411,
            "R4": 0.0998
          }
        },
        {
          "period_end": "2031-03-31",
          "p_at_least": {
            "R1": 0.9272,
            "R2": 0.6776,
            "R3": 0.4593,
            "R4": 0.1077
          }
        },
        {
          "period_end": "2031-06-30",
          "p_at_least": {
            "R1": 0.934,
            "R2": 0.6942,
            "R3": 0.4769,
            "R4": 0.1141
          }
        },
        {
          "period_end": "2031-09-30",
          "p_at_least": {
            "R1": 0.9408,
            "R2": 0.7102,
            "R3": 0.4933,
            "R4": 0.1198
          }
        }
      ]
    }
  ]
}