Epoch's work is free to use, distribute, and reproduce provided the source and authors are credited under the Creative Commons BY license.
Learn more about this graph
In this analysis, we examine the change between two poll waves in the share of US adults who report having experienced at least one cyber incident in the previous 12 months. We find no change for incidents in aggregate, and no specific incident type rose in a way we can reliably statistically detect. The share reporting any incident changed from 46% (90% CI: 44% to 49%) in June to 45% (42% to 47%) in September.
We also find no detectable change among respondents who report frequent AI use. Among them, the share changed from 53% (90% CI: 48% to 59%) to 51% (45% to 57%).
Other indicators and publicized incidents suggest increasing AI cyber capabilities may be affecting measurable security outcomes. We previously documented a sharp increase in serious vulnerability disclosures in June, followed by a further increase in July. The incident involving OpenAI models hacking Hugging Face is one documented example of what frontier models can do offensively capabilities.
In addition to closed models, cyber capabilities among open-weight models have increased as well. Among these, the US Center for AI Standards and Innovation (CAISI) assessed the open-frontier model GLM-5.3 as having similar cyber capabilities to US frontier models around the time of the Fable 5 release.
Our polling examines a different outcome: whether a larger share of ordinary Americans report experiencing cyber incidents.
Data
Analysis
Assumptions and limitations
Download this data
Explore this data
Tracking how employed Americans use AI at work, across demographics.



