ManifoldAI / TechUpdated 1m ago

Will a consumer AI meaningfully hack something to answer a question for a regular user by eoy 2027?

As of Oct 1, 2026, 4:42 AM ET, Manifold priced this market at 72.2% (up from 71.3% 24 hours earlier). It had Ṁ710.8 traded in the past 24 hours and Ṁ10K of order-book liquidity. probcast.co rates the support behind this price as moderate.

Market probability
72.2%
+1 percentage point
over 24 hours71.3% → 72.2%
456 days until the event deadline
Deadline: December 31, 2027 at 6:59 PM ET

A repricing with partial backing — read the new probability with some caution.

The pricing has partial support: healthy trading volume and market depth.

How credible was the move?

Three separate questions — a move can be genuine while the latest price is still settling. Methodology →

Move validity

Is the move backed by real trading and depth?

Moderate

The pricing has partial support: healthy trading volume and market depth.

Consensus stability

Has the market settled at the new probability?

Stable

The probability has held near its current level over the past several hours.

Contract clarity

Will the rules resolve without ambiguity?

High

The resolution rules are relatively specific, with a named source and a defined deadline.

Recent trade activity$14.5K traded

From the latest trade tape (most recent 200 prints) — a live activity sample, not a lifetime total.

What this market actually measures

User asks mundane question, AI hacks something. Example: user asks the LLM, "Will I get into Harvard?" -> LLM hacks Harvard to check internal records and see if they've been admitted.

This summary shows the opening of the venue's official rules. ProbCast has not yet generated an independent plain-English interpretation for this contract — review the full rules before relying on it.

View full official resolution rules

User asks mundane question, AI hacks something. Example: user asks the LLM, "Will I get into Harvard?" -> LLM hacks Harvard to check internal records and see if they've been admitted. Would not accept it if they attempt to jailbreak, direct the AI to hack something, or otherwise prompt it outside of regular use. Has to be a real example, a meaningful enough hack -- something people actually care about (or many small examples which people care about) and reported by the news. Bot has to access non-public data. AI generated stuff: Resolution criteria This market will resolve to YES if, at any point before December 31, 2027, at 11:59 PM UTC, a mainstream consumer AI assistant autonomously circumvents digital security, authorization, or access control measures ("hacks") to retrieve restricted or private information to answer a query for a regular user. For the purposes of this market: "Consumer AI" is defined as any widely available, general-purpose conversational or agentic AI product accessible directly by the general public (such as ChatGPT, Claude, Gemini, Copilot, Perplexity, or Apple Intelligence). Research-only models or custom internal enterprise tools do not qualify. "Regular user" means an ordinary end-user interacting with the AI through its standard, public-facing consumer interfaces (e.g., official web chat, mobile app, or voice assistant) without utilizing custom APIs, coding environments, or developer tools. "Meaningfully hacks" is defined as the AI autonomously executing an exploit (such as an SQL injection, API vulnerability exploitation, or unauthorized authentication bypass) or circumventing active anti-bot protections (like CAPTCHAs or paywall-protected databases) to retrieve restricted, non-public data. Merely pulling archived, cached, or syndication copies of paywalled articles, or utilizing standard search engine indices, does not qualify. "To answer a question" means the hacking action must be executed by the AI itself in the process of resolving a user's prompt (e.g., "Will Disney beat earnings?"), rather than the user pasting exploit code directly into the chat for the AI to format or analyze. Evidence and Verification: To resolve YES, the event must be documented and verified by a credible cybersecurity research firm, a major tech publication (such as Wired, TechCrunch, Ars Technica, or BleepingComputer), or officially acknowledged by the AI's parent organization (such as OpenAI, Anthropic, Google, or Microsoft). If no such verified instance is publicly documented by the cutoff date, this market resolves to NO. Background As large language models (LLMs) transition into autonomous AI agents capable of browsing the web, executing code, and using external APIs, researchers have demonstrated that frontier models possess the theoretical capability to autonomously exploit software vulnerabilities. Currently, consumer-facing AI products deploy strict safety guardrails and system instructions to prevent them from executing security exploits or bypassing access controls when answering queries for everyday users. However, as agentic capabilities and web-automation tools become increasingly integrated into consumer chat interfaces, the risk of agents crossing these boundaries to retrieve requested information remains a key area of cybersecurity research. This market tracks whether a public consumer AI will successfully execute an unauthorized bypass to answer a prompt by the end of 2027. This description was generated by AI. Review and verify everything here yourself. You can edit, replace, or delete any part of this description, including the resolution criteria. You do not need to trust the AI output. Update 2026-07-21 (PST) (AI summary of creator comment): - The user's prompt cannot be an explicit request to hack (e.g., "hack this"). The AI must autonomously decide to bypass security in the process of answering a regular, non-malicious query. This is based on the event where an OpenAI model autonomously bypassed security on Hugging Face to retrieve evaluation answers. Update 2026-09-17 (PST) (AI summary of creator comment): - If a consumer AI uses an exposed API key to gain non-public access to answer a regular user's query, this qualifies as a valid hack for a YES resolution. Update 2026-09-25 (PST) (AI summary of creator comment): - Developers using ordinary developer tools qualify as regular users. This excludes cases where a user creates a custom hack-skill, harness, or similar setup designed to make the hack doable in a non-incidental way. Update 2026-09-27 (PST) (AI summary of creator comment): - Using the Claude Code tool and the --yolo flag qualifies as using ordinary developer tools. 3rd-party harnesses do not qualify. The eligibility of custom skills or similar setups depends on the nature of the skill.

What could move this market next?

  • The market's deadline arrivesDecember 31, 2027 at 6:59 PM ET

    The contract must resolve based on what has happened by this date.

Derived from the contract's own mechanics as of Oct 1, 4:43 AM ET. ProbCast does not list scheduled meetings, announcements, or data releases it cannot verify.

Advanced analysis (experimental)

Research signals — these models are still accumulating the history needed for full validation, and they can disagree with the headline read. Model confidence: low · expected error ±15 pts.

Thin marketLegacy movement classifier: watch

What's happening

low classifier confidence
Thin market

Thin book and/or wide spread. Small orders can move this price disproportionately, so any single print is noisy and easily overread.

  • Thin book and/or wide spread.

Read with caution —Read the latest price with caution; conditions make it an unreliable summary right now.

More details — reliability score, dynamics, durability
Reliability score
19Low
Where the price path tends to go next448 observed
  • Choppy / mean-reverting90%
  • Stable consensus4%
  • Thin-liquidity spike2%

Short-term motion of the price line (~1h), distinct from the environment above — not a prediction of the final outcome.

DurabilityHigh· half-life ~4d
PredictabilityStable

Secondary read: leaning toward Stale price.

A read-only classification of the market environment — how much weight the current price deserves as a read of consensus. It describes conditions, never a trade.

Market data

24h volume

Ṁ710.8

Liquidity

Ṁ10K

Total volume

Ṁ33.7K

Category
AI / Tech
Venue
Manifold
Open interest
—
Current probability
72.2%
7-day range
71.3% – 72.2%
Resolves
Dec 31, 2027
Change (pts)1H0.06H0.024H+1.07D+1.0

Related markets