Previous estimates of global cybercrime damages: tens of billions to tens of trillions. The uncertainty spans three orders of magnitude. That's not measurement — it's guessing.
Systematic evaluation of 27 existing damage estimates (arXiv:2603.20570) reveals the problem: most come from law enforcement databases (which capture reported crimes, not actual damages) or complex economic models (which layer assumptions until the output reflects the model, not reality). The few that use large-sample victimization surveys — asking people what actually happened — converge more tightly.
The new estimate: approximately $500 billion USD annually, with a 90% confidence interval from $100 billion to $1 trillion. Derived from UK and US victimization surveys scaled globally, plus cybersecurity spending data. Focuses on quantifiable direct losses, response costs, and defense expenditure. Excludes harder-to-measure impacts like intellectual property theft — which means the true number is higher, but the measured number is reliable.
The AI risk application: a 20% increase in cybercrime damage from AI-enabled attacks could trigger industry mitigation thresholds. But current data limitations prevent detecting a 20% change with certainty when the baseline spans an order of magnitude. You can't measure a perturbation without a baseline.
The structural insight: risk assessment of novel threats (AI-enabled cybercrime) requires a reliable baseline of existing threats (conventional cybercrime). The previous estimates were too uncertain to detect change. Narrowing the baseline from “tens of billions to tens of trillions” to “$100B-$1T” doesn't just improve the estimate — it makes the perturbation measurable. The measurement precision determines what changes you can detect.