Early build · daily prints since launch · history before then is reconstructed
The Data Pressure Index
A single daily number for the pressure artificial intelligence is putting on enterprise data, measured against how fast security and governance are catching up. When AI gets more capable, cheaper, more widely deployed, and more exposed faster than the defences around data improve, the number rises. When governance closes the gap, it falls.
Why it matters, and why you should care
The same thing that makes AI valuable makes it dangerous: it can read, join, and reason over all of your data at once, instantly, at almost no cost. When that reach is not governed, the quiet assumption every organisation runs on breaks. If a person is not cleared to open a document, they cannot. An AI system wired in for convenience often can.
The two sides move at different speeds. AI capability compounds and gets cheaper every month; the controls around data are slow, manual, and mostly unchanged. So the gap between what AI can reach and what governance actually permits widens by default, quietly, whether or not anyone is watching it. No single figure has followed that gap: breach counts, model releases, token prices and vulnerability feeds each tell part of the story, never the whole condition. A breach is simply the moment the gap becomes visible, and by then the pressure had been building for months.
That is the point of one daily number. It makes the gap visible before the incident, not after. If you hold enterprise data you already carry this risk today, tracked or not; the index tells you, every morning, whether it is getting worse or better, in time to do something about it.
How to read it
The number is in standard deviations (σ), written with the Greek letter sigma. Each input series is standardised against its own 2024 normal; the composite is then placed on a scale relative to the index's range since 2024, so the headline shows how today compares to the index's own history. Zero is the middle of that range, a positive reading means pressure is toward the high end, and the current level sits near its record high. The band names describe that composite level only; they do not, by themselves, assert anything about any single organisation.
| Reading | Band | Plain English |
|---|---|---|
| below 0 | Below baseline | in the lower half of the index's range |
| 0 to 1σ | Building | above the middle of the range |
| 1σ to 2σ | Elevated | toward the high end |
| above 2σ | Severe | at or near record highs |
What it measures
Around twenty public series roll up into six categories. Five push the number up; the sixth, governance, pushes it down.
- Capability velocity — how fast frontier AI systems are gaining capability.
- Deployment breadth — how widely AI models and agents are being deployed.
- Economic pressure — the economic forces pushing AI into data-handling work.
- Attack surface — new vulnerabilities in the AI toolchain and flaws exploited in the wild.
- Realised harm — breaches and incidents actually occurring.
- Governance counterweight (counterweight) — the security-and-governance response, which pushes the number down.
How it is built
Every series is first turned into a stationary form (a rate, a share, or a growth figure, so a rising trend is not mistaken for a permanent shift). Each is then standardised against its own fixed 2024 baseline, so a value becomes "how many standard deviations from normal". Those standardised values are averaged within each category, the categories are combined using published weights, and the composite is re-standardised onto a scale relative to the index's range since 2024, so the headline shows how extreme today is against its own history. Governance enters with a negative sign, so a stronger response genuinely lowers the number. New series appear first as candidates at zero weight, and only earn weight once they have enough history to be meaningful. Weights are editorial, frozen between monthly reviews, and published; the underlying data is downloadable so you can re-weight it yourself.
The precedent is the sort of pressure index a central bank publishes: many public series, standardised against a baseline, combined into one figure that is widely quoted and freely described, yet not trivially copied. The moat here is the daily operation and the growing archive, not secrecy. Provisional: the fixed calendar-2024 baselines and composite re-standardisation are pending (Stage B). Readings are early; series marked candidate carry zero weight until they mature and prove durable.
What it does not claim
It is an argument, not a prediction. It quantifies a condition — the pressure on enterprise data right now — and never forecasts a specific breach or incident, never measures any attacker's intent, and never scores a named vendor or product. A high reading is a statement about the environment, not about any one company's security.
Why you can check it
Every input is a public, free source, and the full methodis published in detail. Anyone with the same public data can reproduce the number. It is a personal editorial product by Rob Linton, published under his own name, not a product of any employer; see about. Nothing here is investment, security, or legal advice.
What feeds it today
The first tranche of series. More join as each source clears a live soak. Series markedcandidate are shown but carry zero weight until they mature.Track each metric individually →
Browse the AI governance registry →
Capability velocity · +2.53
| Series | Latest | Source |
|---|---|---|
| Frontier capability index (Epoch AI) | 162 | Epoch AI capability benchmarks |
Deployment breadth · +2.06
| Series | Latest | Source |
|---|---|---|
| Max frontier model context window (tokens) | 2,097,152 | Published frontier model specifications |
| Open text-generation models created on Hugging Face (7-day) · candidate | 3,488 | Hugging Face Hub model index |
Economic pressure · +0.50
| Series | Latest | Source |
|---|---|---|
| Private fixed investment: software (growth) | 0.0212 | US Bureau of Economic Analysis (via FRED) |
| Cheapest capable input token price (per 1M) | 0.01 | Published frontier model pricing |
Attack surface · +1.41
| Series | Latest | Source |
|---|---|---|
| Agent-security research intensity (share of cs.CR) | 0.417 | arXiv cs.CR submissions |
| CISA KEV additions (30-day rate) | 18 | CISA Known Exploited Vulnerabilities catalogue |
| NVD CVE velocity, AI-toolchain slice (30-day) | 93 | NIST National Vulnerability Database |
Realised harm · -0.11
| Series | Latest | Source |
|---|---|---|
| Accounts newly disclosed in breaches (30-day) | 93,944,673 | Have I Been Pwned breach catalogue |
| Ransomware leak-site victims (30-day) · candidate | — | Ransomware leak-site postings |
Governance counterweight (counterweight) · +0.68
| Series | Latest | Source |
|---|---|---|
| AI governance publication velocity (US Federal Register) | 32 | US Federal Register |
| Governance-vs-AI market-cap ratio · candidate | 0.482 | official exchange closing prices |