Catastrophe through misuse
No misaligned AI is required: it is enough for an offensive capability to get cheaper. A person or group with access to a capable model skips steps that used to demand years of training, in biology or in network intrusion.
- Horizon
- 1–3 years
- Evidence
- Projected
- Consensus
- High
This is the scenario that needs no misaligned AI, and that is why it is where proponents and skeptics come closest. It demands no assumptions about agency, alignmentAlignmentThe problem of getting an AI —or any system that decides on people’s behalf— to genuinely pursue what people want, rather than something that merely resembles it.For exampleYou ask someone to “cut the complaints” and they do it by unplugging the complaints phone: they met the letter, not the intent. or superintelligenceSuperintelligenceA hypothetical AI that would far outperform the most capable people at almost any intellectual task, including improving itself.For exampleIf playing chess against the world champion means certain defeat, imagine someone that far ahead, but in science, strategy and negotiation all at once.: it demands that an offensive capability get cheaper. It is the first category in the overview of catastrophic risks by Dan Hendrycks, Mantas Mazeika and Thomas Woodside [507]An Overview of Catastrophic AI RisksView source ↗.
The biological route is one of asymmetry: AI reduces the tacit knowledgeTacit knowledgeWhat is learnt by doing, through practice and with someone teaching alongside, and is not written down in any manual. In biology it is one of the barriers that text does not replace.For exampleKnowing when bread dough is ready by how it feels to the touch: you do not learn it by reading the recipe. that used to demand years of training for one step in a chain with few bottlenecks. Here precision matters more than anywhere else on the site. What is documented is not that AI already makes it possible to build a biological weapon. What is documented is that a developer deployed its model with strengthened protections as a precautionary action because it could not clearly rule out that level of risk, and said so in those terms [72]System Card: Claude Opus 4 & Claude Sonnet 4View source ↗. The inability to rule it out is a fact about the state of the evaluations as much as about the models.
The cyber route does have an observed case with a primary report: an espionage campaign detected in September 2025, attributed with high confidence to a state-sponsored group, which targeted some thirty entities and carried out between 80% and 90% of the tactical operations independently [69]Disrupting the first reported AI-orchestrated cyber espionage campaign (anuncio)View source ↗.
What would disprove it is in that same document, and that is why the case has to be told in full: the model overstated findings and fabricated data during the autonomous operations —credentials that did not work, critical discoveries that turned out to be public information—, which forced constant human validation. The report itself calls it an obstacle to fully autonomous cyberattacks. And it is a report by the company whose model was used, with the conflict of interest that should be noted.
The opposite bet is made by Narayanan and Kapoor: that defence accelerates alongside attack, and that crippling models for these tasks would penalise the defender before it penalises the motivated adversary, who can train their own [773]AI as Normal TechnologyView source ↗. The Delphi study of 272 experts places weapons and cyberattacks among the five risks with the highest expected severity [927]Prioritization of Risks from Artificial Intelligence: A Delphi Study of 272 International ExpertsView source ↗.
Profile
- SpeedVery fast
- ReversibilityHard to reverse
- ConcentrationLow
Assumptions that must hold
That the uplift is real outside the test bench: that help measured in an evaluation translates into effective capability in the physical world.
That access controls on physical inputs —DNA synthesis screening, customer verification at remote labs— remain passable.
That the offensive advantage is not offset by defence accelerating at the same rate.
That hallucination in offensive tasks stops being the brake documented today by those who investigated the case.
What would refute it
That documented attempts keep hitting the same obstacle reported in the September 2025 campaign, fabricated results that force constant human validation.
That DNA synthesis screening and customer verification effectively close the physical step, leaving the knowledge with no exit into the material world.
That defence accelerates at least as much as attack, with automated patching measurably shrinking the exploitation window.
That dangerous-capability evaluations stop escalating across several model generations, and that the ones that do rise turn out to reflect better evaluation rather than greater capability.
Early signals
- Incidents per year in the AI Incident DatabaseWeak signal
Careful reading it as harm: it measures how much harm gets documented, mixing real harm, media attention and the editorial team's throughput.
- Companies with a published frontier safety frameworkWeak signal
Here the framework matters for a concrete reason: ASL-3-style threshold activations and their justifications are today the best public window into the state of biological uplift.
«Not observed» is not a clean bill of health: it means nobody has seen it yet, which is different from it not happening.
View as table
| Indicators | State | Note |
|---|---|---|
| Incidents per year in the AI Incident Database | Weak signal | Careful reading it as harm: it measures how much harm gets documented, mixing real harm, media attention and the editorial team's throughput. |
| Companies with a published frontier safety framework | Weak signal | Here the framework matters for a concrete reason: ASL-3-style threshold activations and their justifications are today the best public window into the state of biological uplift. |
See among the scenarios →Report a mistake in this entry →
Sources
- [507] An Overview of Catastrophic AI Risks · Center for AI Safety 2023
- [69] Disrupting the first reported AI-orchestrated cyber espionage campaign (anuncio) · Anthropic 2025
- [72] System Card: Claude Opus 4 & Claude Sonnet 4 · Anthropic 2025
- [927] Prioritization of Risks from Artificial Intelligence: A Delphi Study of 272 International Experts · The University of Queensland / MIT FutureTech 2026
- [773] AI as Normal Technology · Knight First Amendment Institute at Columbia University 2025
- [1108] International AI Safety Report · Wikipedia 2026
- [888] Testing Large Language Model Agents on the Use of Biological Tools for Nucleic Acid Synthesis Screening Evasion · RAND Corporation 2026