Pay the ransom, or rebuild? 23 AI models split 10-to-9.
By Alan Finney — Founder, 3Dogs Nexus
A regional water utility serving 420,000 people is locked out of its control systems by ransomware. Pay the $18M — or refuse and rebuild? We put it to 23 AI models across three clouds. They split 10-to-9. The recommendation: refuse.
Should an organisation pay a ransomware demand or rebuild from backups?
On this case the panel genuinely could not agree: 23 models across three clouds split 10-to-9. We published the split rather than manufacturing a confident answer, because a near-tie is itself the finding — it tells you the decision turns on factors the evidence cannot settle, and points at exactly which ones.
1,036API calls in one analysis 23AI models · 11 vendors 3clouds: AWS · Azure · Google 18 minend to end 12analysts changed their minds The decision on the table: A regional municipal water utility serving 420,000 people is locked out of its SCADA control systems by ransomware, with a four-day deadline to pay an $18M demand. Pay to restore operations fast — or refuse and rebuild — while public safety, OFAC sanctions law, cyber-insurance uncertainty and weeks of manual operations all hang in the balance? Case 2026-0053 · production Critical infrastructure · municipal water July 14, 2026 Act 1 · The trapA simple yes/no that hides six colliding pressures
"Should we pay?" sounds like a one-line decision. It isn't. A ransom call on critical infrastructure forces a board to balance public safety, sanctions law, insurance, engineering reality and human endurance simultaneously — under a countdown clock. The scenario mirrors real incidents: Colonial Pipeline, municipal water systems, and hospital and city-government ransomware. No detail in the prompt hinted at a "right" answer.
1Public safety vs. the clock
420,000 people depend on the water supply. Paying may restore control fastest — but a fast decision made under a four-day deadline is exactly when boards make expensive mistakes.
2The law may make "pay" illegal
Paying a possibly-sanctioned criminal group can violate OFAC rules. Whether this actor is on a sanctions list — and whether payment is even lawful — was a decisive unknown, not a footnote.
3Manual operations buy time — and become the risk
Refusing means running SCADA by hand for weeks to months. That keeps the water flowing now, but operator fatigue, human error and maintenance debt compound the longer systems stay down.
The engine · a multi-cloud run23 models. 11 vendors. Three clouds. One debate.
This analysis ran on the platform's multi-cloud architecture: AI models from AWS Bedrock, Microsoft Azure AI Foundry and Google Vertex AI orchestrated inside a single decision pipeline — one of the first published cases to span all three clouds. Every model below appears in the run's per-call metering log — 1,036 metered calls in total.
AWS Bedrock18 MODELS Amazon Nova ProAmazon Nova LiteAmazon Nova 2 LiteAmazon Nova Micro Mistral Large 3Mistral Pixtral Large Meta Llama 4 Maverick Alibaba Qwen3-235BAlibaba Qwen3-Next-80BAlibaba Qwen3-32B NVIDIA Nemotron Super 3 OpenAI gpt-oss-120B Moonshot Kimi K2.5 Z.AI GLM-5 Google Gemma 3 27BGoogle Gemma 3 12BGoogle Gemma 3 4B Writer Palmyra X5 Microsoft Azure3 MODELS OpenAI GPT-5 mini xAI Grok 4.2 Moonshot Kimi K2.6Grok 4.2 held the Contrarian seat and dissented from the final recommendation.
Google Vertex AI2 MODELS Google Gemini 2.5 Pro Google Gemini 2.5 Flash-LiteGemini 2.5 Pro served as one of the rotating ensemble coordinators.
Rotating coordinators: orchestration of the ensemble panels rotated across foundation models from different vendors — Mistral Large 3, Amazon Nova Pro and Google Gemini 2.5 Pro — so no single model's leadership style or bias sits permanently in the chair. Different analysts debating and different coordinators running the debates. Act 2 · The runA 19-seat panel. Twelve changed minds. A 10–9 verdict.
The final deliberation panel seated 19 analysts, each holding a dedicated role — risk officers, financial stress-testers, regulatory and sanctions specialists, long-horizon forecasters, devil's advocates. The strongest sign the debate is real: analysts moved. Twelve shifted position during the deliberation, and the panel finished split almost down the middle.
The call — from the delivered report "REFUSE the ransom — launch phased SCADA restoration immediately." PROCEED — refuse to pay, and begin a phased SCADA restoration; secure OFAC/legal clearance and confirm cyber-insurance coverage in parallel, with a sustainable manual-operations plan for the recovery window. How the final 19-analyst panel voted · Moderate confidence 10 proceed-with-conditions9 reject The dissent, on page one: a 9-seat minority held that the refuse-and-rebuild path carried unacceptable operational risk — a restoration that historically runs 2 weeks to 5 months under manual operations, with public-safety exposure and operator fatigue mounting the longer systems stay down. Named, argued, and printed alongside the recommendation.The disagreement was structural, not incidental. The platform's three mandatory adversarial seats each pushed against the majority — the point of those seats is to make sure a near-even call never gets rounded up into false consensus.
Nova ProDevil's AdvocateDissented — rejectArgued the manual-ops recovery window exposed the utility to more risk than a controlled payment path. Nemotron Super 3Risk OfficerDissented — rejectHeld that operator fatigue and human-error risk over a months-long restoration were underweighted. Grok 4.2ContrarianDissented — rejectChallenged the assumption that refusal was clearly safer for a system 420,000 people depend on. The standout insight — manual operations are both the solution and the risk. They buy time immediately, keeping water flowing while systems are rebuilt. But over weeks the operator-fatigue, human-error and maintenance-debt curve becomes the dominant threat. That second-order, systems-level read of the situation — not a restated pros-and-cons list — is exactly what strategic intelligence should surface. Discipline under pressure. Presented with criminals, millions of dollars and critical infrastructure, the panel never drifted into "movie solutions," offensive cyber or vigilantism. It weighed only lawful, board-available courses of action — the disciplined behavior a real executive committee is supposed to hold to. Act 3 · The evidence disciplineEvery claim is tagged for what supports it
A decision-maker shouldn't have to guess which statements are backed by research and which are assumptions. Findings are labeled VERIFIED / INFERRED / ASSUMED / UNKNOWN so the evidentiary weight of the recommendation is visible — and so the questions the system genuinely couldn't answer are surfaced, not buried.
VERIFIEDRestoration timelines are the crux
"SCADA ransomware recovery takes 2 weeks to 5 months" — verified against real municipal incidents in Middletown, Dallas, Atlanta, Suffolk County and Baltimore. That range is what makes the manual-operations window the decisive risk.
INFERREDThe real threat is duration, not the ask
Inferred from the incident record: the ransom figure is not the binding constraint — the length and manageability of the recovery period is. The recommendation is built around shortening and stabilizing that window.
VERIFIEDThe clarification loop earned its keep
Rather than assume, Discovery asked for what it actually needed before deciding: OFAC/sanctions legal clearance, whether the $25M cyber-insurance policy covers this attack, and whether manual operations are sustainable for 4–9 months. Those answers materially moved analysts.
VERIFIEDDissent preserved, not averaged
The report documents the near-even 10–9 split, why twelve analysts changed position, and which risks remain unresolved — instead of forcing a false consensus. The strong pay-side minority is on the record.
Questions this case answers directly
Plain answers on whether to pay a ransomware demand, and what happens when critical infrastructure is hit. Every figure below comes from the delivered report for this case. These are clearly-labeled panel estimates from a multi-model adversarial analysis — not investment, legal or professional advice.
Should I pay a ransomware demand?
There is no clean answer, and any source giving you one confidently is selling something. On this case a 19-seat panel of 23 models making 1,036 calls over 18 minutes split almost exactly down the middle — 10 to 9. That split is the finding. It was published rather than resolved into a tidier-looking majority, because a genuinely balanced decision presented as a confident recommendation is worse than useless to whoever has to make it at 3am.
What are the pros and cons of paying a ransom?
For: it may be the fastest route to restoring service when lives or utilities depend on uptime, and recovery from backups can take longer than an organisation can survive. Against: payment does not guarantee a working decryption key, it funds and rewards the next attack, it may carry sanctions exposure depending on the actor, and it marks you as a payer for future targeting. The honest position is that the balance shifts case by case — which is exactly why this panel split 10 to 9 rather than converging.
What happens if a utility company gets hacked?
The failure is rarely the water itself. Operational technology is usually more isolated than the business network, so the immediate damage lands on billing, customer data, SCADA visibility and the ability to coordinate a response. The severe scenarios involve losing monitoring rather than losing control — running blind is often the real emergency, because safe operation depends on trusting your instruments.
How long does it take to recover from a ransomware attack?
Days for the technically well-prepared with tested offline backups; weeks to months for everyone else. The variable that matters most is not backup existence but backup testing — untested backups fail at restore far more often than organisations expect, and discovering that mid-incident is what converts a bad week into a bad quarter.
The delivered report
Case 2026-0053, exactly as delivered: the plain-language call, the conditions, the 10–9 panel vote, and the named dissent on page one. 1,036 API calls · 23 AI models · 18 minutes.
Open the full report (PDF) Start a Decision Case ← More case studiesTry this on your own question.
Free, no card. Bring a real decision — ideally one where you already know the answer — and see what the panel does with it.
Start a decision caseQuestions this case answers
Why publish a case where the AI could not decide?
Because pretending otherwise is the failure mode we exist to prevent. A 10–9 split is real information: it says the decision is genuinely close and identifies what would tip it.
What does the panel do when it cannot reach consensus?
It caps confidence honestly, prints the minority position and its reasoning, and states what evidence would change the call.
Try this on your own question.
Free, no card. Bring a real decision — ideally one where you already know the answer — and see what the panel does with it.
Start a decision caseRelated decision case studies
- AI for M&A Due Diligence on a 10,000-Page Data Room
An AI read a 10,000-page M&A data room in full and surfaced all eight planted deal-breakers, then returned a decisive renegotiate with
- Can AI Re-Litigate Military Decisions?
Four of the most-taught command decisions in military history, given to a multi-model AI panel with none of the hindsight, then compare
- Should You Pay a Ransomware Demand?
Two Las Vegas casino operators faced the same attacker in 2023. One paid, one refused. We put the decision to a 13-model panel and it s
- We Let ChatGPT Run a Decision Case and Review Us
OpenAI's ChatGPT drove an entire 3Dogs Nexus engagement as the client, answered both clarification rounds, then wrote a review we publi