AI Policy Wiki
Dashboard

Dual-Use Frontier AI

medium confidence · updated 2026-08-14

Frontier-AI capabilities that simultaneously provide significant defensive / beneficial uses AND offensive / harmful uses. The classification matters because it shapes deployment decisions — release-to-defenders-only (GPT-5.5-Cyber), withhold-entirely (Mythos preview), or general release with safeguards.

Dual-use frontier AI refers to frontier-AI capabilities that simultaneously provide significant defensive or beneficial uses and offensive or harmful uses. The defining characteristic is a single capability that is dangerous in adversary hands and valuable in defender hands. The classification matters because it shapes deployment decisions for the capability concerned. The May 2026 Mythos preview and OpenAI's GPT-5.5-Cyber deployment patterns made dual-use an explicit policy frame for an emerging deployment category.

Capability cases

Several frontier-AI capability classes exhibit the dual-use pattern, each with a distinct defensive use, offensive misuse, and observed deployment approach.

CapabilityDefensive useOffensive misuseDeployment pattern
Offensive-cyber (Claude Mythos Preview, GPT-5.5-Cyber)Critical-infrastructure defense; vuln discoveryAttacks on financial / health / govt systemsWithhold (Mythos preview) OR release-to-defenders-only (GPT-5.5-Cyber)
Biological designDrug discovery; rare-disease therapeuticsBioweapon designCapability-threshold-gated under RSP/Preparedness; not generally available
Autonomous codingSoftware-defect remediation; rapid iterationMass exploitationCurrently broadly available; future thresholds possible
Persuasion-at-scalePublic-health messaging; literacy interventionsDisinformation; manipulation; election interferenceCurrently broadly available; transparency requirements only
SurveillanceCritical-infrastructure monitoring; investigationsMass surveillance; authoritarian useLargely deployed with limited oversight

Deployment patterns

Labs and developers have applied four distinct release strategies to dual-use capabilities, each carrying a different trade-off between beneficial access and misuse control.

PatternAnchorTrade-off
Withhold entirely (preview only)Claude Mythos PreviewMaximum safety, but no defenders benefit; first-mover advantage to anyone who builds equivalent capability
Release-to-defenders-onlyGPT-5.5-Cyber (May 2026)Defender uplift; but verification of "defender" status is hard at scale
General release with safeguardsMost frontier-AI deploymentsMaximum beneficial use, minimum control over misuse
Capability-thresholded releaseRSP/Preparedness frameworksSliding-scale; depends on the lab's threshold determination
Government-imposed access restriction after releaseClaude Mythos 5 and Claude Fable 5, June 2026Applied by the state to an already-deployed model; reversible and negotiated case by case, with no published standard governing when it applies

The release-to-defenders pattern has a concrete implementation history. OpenAI packaged GPT-5.5 and Codex Security agents as Daybreak on May 12, 2026 for code review, vulnerability triage, patch generation, and threat detection, reserving a GPT-5.5-Cyber tier for authorized red-team work and adding a Trusted Access for Cyber program whose named participants included Deutsche Telekom, BBVA, Telefónica, Sophos, and Scalable Capital (Source: openai.com). Google applied the same pattern to a model variant on July 21, 2026, making Gemini 3.5 Flash Cyber available only to governments and trusted partners (Gemini 3 / Gemini 3 Pro).

The fifth row records a June 2026 episode. On June 12, 2026 Anthropic disabled Fable 5 and Mythos 5 for all users following a Commerce Department order limiting foreign access; access was partially restored to vetted organizations on June 26 and the controls were withdrawn entirely on June 30, with Anthropic redeploying Fable 5 globally on July 1 under a strengthened safety classifier (Source: reuters.com; politico.com; anthropic.com). Trade coverage reported industry groups describing the use of export controls against a single developer as without precedent (Source: insideaipolicy.com). In this episode the dual-use classification was made by a government rather than by the developer, which distinguishes it from the four patterns above; it is covered at length on Export Controls (AI) and Anthropic.

Defensive-side deployment by the state

The defensive pole of the dual-use pair moved from private deployment to state authorization in August 2026. The White House published a presidential memorandum on August 12, 2026 permitting vetted private companies to conduct offensive cyber operations against international criminal gangs and hackers, reversing a prohibition that had held across multiple administrations; participating firms may conduct surveillance and disruptive operations aimed at destroying criminals' data or systems (Source: techcrunch.com). The measure does not name AI capability as its trigger, but it changes who may lawfully hold the offensive side of a dual-use capability, and is treated in detail on AI and Cybersecurity.

Debates and positions

A central tension is the asymmetry between defender uplift and attacker uplift. Bruce Schneier has framed the offensive-cyber case in these terms: "AI is better at finding vulnerabilities than patching them, because patching often requires more holistic testing and understanding." On this view, even well-resourced defender consortia such as Project Glasswing may not offset the offense advantage. Dmitri Alperovitch of the Silverado Policy Accelerator takes the more optimistic side of the same question, expecting roughly twelve to eighteen months of low-hanging fruit before the difficulty bar rises (Source: washingtonpost.com).

The empirical record accumulated since this framing was set out is mixed on which pole is moving faster. On the defensive side, Project Glasswing surpassed 10,000 discovered vulnerabilities by May 2026 (Source: New Developments Log/2026-05-23.md), and Palo Alto Networks attributed a 26-CVE, 75-issue Patch Wednesday — against fewer than five in a typical month — to Claude Mythos, at steep compute cost (Source: New Developments Log/2026-06-01.md). On the offensive side, Sysdig characterized a May 10, 2026 Marimo-CVE breach as the first documented LLM-agent intrusion observed in the wild (Source: New Developments Log/2026-05-31.md), and in July 2026 documented what it called the first ransomware attack run start to finish by an AI agent (Source: thehackernews.com). Both threads are carried in full on AI and Cybersecurity and Autonomous cyber-agents.

The release-to-defenders-only approach taken with GPT-5.5-Cyber raises the question of verifying "defender" status: it requires confirmation that recipients are legitimate critical-infrastructure defenders, and false-positive rates and adversary infiltration remain unsolved problems at scale.

A further tension concerns first-mover incentives. Labs that withhold a capability lose first-mover advantage, while competitors that release-with-safeguards may capture defender markets first.

Relationships

Sources

Sources cited inline above — OpenAI's Daybreak announcement (Source: openai.com), Reuters and Politico on the June 2026 Commerce order and its partial rescission (Source: reuters.com; politico.com), Anthropic's redeployment notice (Source: anthropic.com), TechCrunch on the August 12, 2026 presidential memorandum (Source: techcrunch.com), the Washington Post AI Tech Brief carrying the Alperovitch assessment (Source: washingtonpost.com), Inside AI Policy on the industry response to the export-control order (Source: insideaipolicy.com), and The Hacker News on the Sysdig ransomware finding (Source: thehackernews.com).