1) A capability/model with dual-use potential (beneficial and harmful) is identified. 2) Its risk is assessed: capability evaluations (evals), red teaming, analysis of misuse scenarios and thresholds. 3) Measures proportionate to the risk are chosen: guardrails, filtering, access controls, tiered access, an open-vs-closed weights decision. 4) Governance is applied: responsible disclosure, usage policies, monitoring and regulatory compliance.
It helps reason about AI technologies that cannot be simply classified as 'good' or 'bad'. Instead of a ban, the dual-use framing steers toward risk management (evals, guardrails, access controls, governance).
The same function with beneficial and harmful value (e.g. vulnerability discovery, bio/chem knowledge).
Measuring dangerous capabilities and misuse scenarios (evals, red teaming, thresholds).
Official
Guardrails, filtering, access control, tiered access, open-vs-closed weights decision.
Official
Responsible disclosure, usage policies, monitoring, regulatory compliance.
Official
Too-strict measures destroy beneficial uses; too-weak ones fail to prevent misuse.
Once weights are released, access cannot be revoked and server-side guardrails cannot be added.
Publishing effective tools/attacks can facilitate misuse (info-hazard).
The report 'The Malicious Use of Artificial Intelligence' (2018) formalizes concern about the dual-use of AI.
With LLMs/GenAI, dual-use becomes central to releases, red teaming and regulation (e.g. the US AI executive order, capability evaluations).
Formalization of dangerous-capability thresholds and deployment policies (responsible scaling, tiered access) in labs and regulation.
Time complexity: Nie dotyczy (koncept polityki/bezpieczenstwa, nie algorytm). Space complexity: Nie dotyczy.
The challenge is not compute but credibly measuring dangerous capabilities and choosing proportionate measures - without blocking useful applications (the safety/usefulness balance).
Cyber, bio/chem, disinformation, fraud, autonomy, etc.
Open vs closed weights, tiered access, API vs download.
Proportionality of guardrails/controls to the assessed risk.
Risk and measures depend on capability and context; dual-use itself is a concept, not a compute paradigm.
Capability evaluations can be parallelized; governance decisions are a human process.
A policy/safety concept - hardware-independent; it concerns assessment and governance, not execution on an accelerator.