Insights from table-top exercises in Europe on AI safety and cyber misuse

Afek Shamir, Henri van Soest, Stephen Clare, Sana Zakaria

ResearchPublished Jul 1, 2026

This report presents findings from three table-top exercises (TTXs) run with senior government policymakers in Germany, the Netherlands, and France. Developed through a collaborative programme between RAND Europe, the UK AI Security Institute, and Mila – Quebec AI Institute, and grounded in the 2026 International AI Safety Report, the exercises were designed to help senior officials engage practically with challenges posed by emerging artificial intelligence (AI) risks.

Using RAND's ‘Day After’ methodology, each session placed fifteen to twenty senior officials in the role of Cabinet members confronting a simulated AI-enabled cybersecurity crisis across two turns. The scenario centred on FlowGPT, a fictional government-backed frontier AI model exploited at scale by criminal actors for cyberattacks. A second turn introduced an open-weight competitor with equivalent capabilities and little safety constraints, eliminating the governance leverage available in the first.

Across all three sessions, six issues dominated participant discussion:

  • Defining the crisis threshold. When does the pace and scale of AI-enabled cyberattacks amount to a national crisis rather than a more routine operational problem?
  • Engaging a national AI champion. In the exercise, the state had publicly backed and funded the problematic model’s developer. Acting against its interests meant admitting a governance failure and absorbing the political and economic cost of turning on a strategic asset.
  • Calibrating risk management when capabilities cannot be reliably evaluated. With no trustworthy way to assess the model’s risks independently, government was left relying on the developer’s voluntary — and potentially biased — risk assessments.
  • Preventing open-weight misuse. The diffusion of a highly capable open-weight model in turn 2 raised new challenges, as it is harder to monitor and implement safeguards on open-weight models.
  • Hardening critical infrastructure. Proposals for protecting vulnerable systems ranged from restricting access to the AI model to simulating attacks against critical systems.
  • Utilising this crisis as a catalyst for positive institutional change. The crisis brought attention, resources, and political will that could be used to invest in durable preparedness measures.
  • Cooperating with allies. Whether to restrict threat intelligence to trusted minilateral networks or share information broadly, including with potential adversaries.

Key Takeaways

Participants identified several priorities for crisis preparation. These centred on proactively generating evidence about AI capabilities and crisis response plans and creating communication channels and institutions to coordinate government response. Discussions surfaced the following priorities:

  • Pre-agreed escalation thresholds. Without clear triggers for when an AI incident becomes a national crisis, participants spent time debating what they were facing rather than responding to it.
  • Systematic cyberdefence reviews. National agencies lacked a baseline assessment of how exposed critical infrastructure and government systems were to AI-enabled attacks, and so could not triage during the crisis.
  • Independent technical capacity to evaluate AI risks. Relying on the developer's own account of its model's risks left government unable to confidently assess the risk level.
  • Targeted crisis communications strategies. Specific, practical information for the most-exposed actors was found more useful than broad warnings or silence.
  • Multilateral governance frameworks that can activate quickly. International cooperation was needed to manage risks and models that cross borders, but negotiations were too slow during the crisis.
  • Structured information flows between developers and government. In the crisis, governments were reliant on what information the developer chose to share. Public funding and procurement measures would provide leverage to obtain more information.

Topics

Document Details

Citation

Chicago Manual of Style

Shamir, Afek, Henri van Soest, Stephen Clare, and Sana Zakaria, Insights from table-top exercises in Europe on AI safety and cyber misuse. Santa Monica, CA: RAND Corporation, 2026. https://www.rand.org/pubs/research_reports/RRA5082-1.html.
BibTeX RIS

Research conducted by

This publication is part of the RAND research report series. Research reports present research findings and objective analysis that address the challenges facing the public and private sectors. All RAND research reports undergo rigorous peer review to ensure high standards for research quality and objectivity.

This document and trademark(s) contained herein are protected by law. This representation of RAND intellectual property is provided for noncommercial use only. Unauthorized posting of this publication online is prohibited; linking directly to this product page is encouraged. Permission is required from RAND to reproduce, or reuse in another form, any of its research documents for commercial purposes. For information on reprint and reuse permissions, please visit www.rand.org/pubs/permissions.

RAND is a nonprofit institution that helps improve policy and decisionmaking through research and analysis. RAND's publications do not necessarily reflect the opinions of its research clients and sponsors.