An exploit agent, a loitering munition and an influence campaign are one capability curve.
Anyone tracking only one of them is systematically surprised by the other two. That is the thesis, and it is the reason this brief covers three beats that nobody else covers together.
Two rankings, and why they disagree
Significance
newsworthiness × corroboration
Orders the weekly. Weights independent confirmation highest, which makes it a lagging indicator by construction.
Governs → the issue
Urgency
newsworthiness × window
Orders what gets amplified while the window is open. Median first-to-second-outlet gap: 30.5 hours (n=10, directional).
Governs → the feed
Built, curated and edited by
James Webb
Working CISO (verifiable on LinkedIn), educator and independent researcher. Argued this publication's thesis in 2022 — AI attacks “leverage unique inherent design characteristics of artificial intelligence systems” and differ enough from traditional threats to warrant independent policy attention. That was four years ahead of the consensus now forming.
The Harm Surface is an independent publication of Rational Mystic LLC, written in a personal capacity. It speaks for no employer, and no employer is named here for exactly that reason.
jamesthomaswebb.com · linkedin.com/in/jamestwebb · aisecuritypolicy.org
Advisory enquiries →
Corrections
Corrections are published in the next issue and annotated on the original item. Nothing is silently edited.
None issued yet — the record is young, and this line will update
honestly when that changes.
Corrections and tips: james.webb@harmsurface.com
Confidence language: confirmed · highly likely · likely · possible · unsubstantiated. The full scoring arithmetic is on the method page. Published by Rational Mystic LLC.