The three readings cannot be untangled at the level of “AI incidents in general.” The category is too broad — different harms have different exposure denominators, different reporting infrastructures, and different deployment curves.
The paper proposes a framework that works at a narrower level: pick one specific harm, estimate its harm and exposure separately, take the ratio, and classify the resulting trajectory of the risk.
Three moves: define a precise monitoring question using the SORT framework; estimate harm and exposure independently across two periods; then take their ratio and classify the trajectory. Harm and exposure are two parallel estimates, not a sequence — neither depends on the other.