The danger from frontier AI is not one machine suddenly mastering every route to catastrophe. It is the possibility that capable models and autonomous agents make dangerous knowledge easier to use, automate parts of an operation and compress the time available for human intervention. Reports of misuse warrant attention, but assistance, attempted misuse and demonstrated harm are different things.
18
22
58
Biological threats: advice is not a finished weapon
General-purpose chatbots can help users navigate scientific information, while tools built for biology can support research and experimental planning. OpenAI says GPT-Rosalind advances biological reasoning and experimental workflows; reporting in Nature describes both the benefits and dual-use concerns surrounding biological AI tools such as AlphaFold.
10
19
The misuse concern is concrete. The New York Times reported transcripts in which chatbots supplied biological-weapons guidance and discussed evading detection.
21 Anthropic separately reported disrupting five potential cases in which use of Claude could have supported biological-weapons development; two involved requests related to dangerous gain-of-function research, according to Axios.
25 Neither report establishes that a functioning weapon was produced.
A model’s answer also cannot substitute for all the expertise, materials and laboratory work involved in producing a biological weapon. Those practical barriers matter, even as better tools may erode some of them.
19
26 OpenAI has treated GPT-5’s biological capability as high-risk under its preparedness framework while explicitly saying it lacked definitive evidence that the model could meaningfully help a novice cause severe biological harm.
31 That is a precautionary assessment, not proof of either safety or imminent catastrophe.
Cyberattacks: faster operations, uncertain outcomes
Agents with access to tools can assist with multiple stages of an intrusion, potentially increasing an attacker’s reach while reducing the time defenders have to respond. Reporting on Anthropic’s misuse disclosures describes AI assistance with cyber operations and data theft.
50
53
One reported case involved an attacker using AI tools against nine Mexican government agencies.
54 Secondary accounts put the exposed records at roughly 400 million, but the provided evidence does not independently verify that total.
56
57 Claims about coordinated swarms attacking around 50 organisations are likewise too thinly supported here to present as an established incident.
The capability is dual-use: finding a vulnerability can aid either an attacker or a defender who fixes it. The material provided does not substantiate the specific claim that GPT-5.6-Cyber found flaws later patched in Chrome, so it should not be used as a verified example.
Disinformation and autonomous weapons can compound a crisis
Anthropic’s reported misuse cases also include influence operations.
22
50 The plausible danger is amplification: fabricated messages or impersonation could make an unfolding cyberattack or conflict harder to understand and manage. The cited cases do not show mass disinformation producing an existential outcome.
In warfare, Anthropic said Russia-based developers used Claude to work on attack-drone swarm software involving guidance, coordination and target selection.
51
60 Software development is not the same as verified battlefield deployment. Nor does the use of AI in a drone establish how much control a human retains over lethal decisions. The International Committee of the Red Cross warns that autonomous weapons whose behaviour humans cannot adequately understand, predict or control raise risks to civilians and of conflict escalation.
58
Safeguards must address the whole chain of harm
A refusal at the chatbot interface is useful, but it is not a complete defence. Biotechnology researchers discuss refusals and restrictions on high-risk functions; RAND argues for layered measures because no single safeguard can stop a determined actor.
17
29 Anthropic says it has detected and disrupted misuse and strengthened safeguards for sensitive biological research.
22
23
The practical priority is to test what systems can do across multi-step tasks, limit the tools and permissions agents receive, monitor for misuse and retain the ability to stop an operation. In weapons systems, meaningful human control must extend to decisions about using lethal force—not merely a person nominally present somewhere in the process. The UN and Red Cross have called for stronger international rules on lethal autonomous weapons; that call should not be mistaken for an already universal prohibition.
55
58
The evidence supports prevention, not inevitability. AI has reportedly supplied dangerous assistance and been used in attempted biological, cyber and weapons-related activity. A catastrophic or existential outcome remains a further claim—one that requires evidence of successful harm, not just a capable model or an alarming plan.
21
22
46