Dual-use frontier AI refers to frontier-AI capabilities that simultaneously provide significant defensive or beneficial uses and offensive or harmful uses. The defining characteristic is a single capability that is dangerous in adversary hands and valuable in defender hands. The classification matters because it shapes deployment decisions for the capability concerned. The May 2026 Mythos preview and OpenAI's GPT-5.5-Cyber deployment patterns made dual-use an explicit policy frame for an emerging deployment category.
Capability cases
Several frontier-AI capability classes exhibit the dual-use pattern, each with a distinct defensive use, offensive misuse, and observed deployment approach.
| Capability | Defensive use | Offensive misuse | Deployment pattern |
|---|---|---|---|
| Offensive-cyber (Claude Mythos Preview, GPT-5.5-Cyber) | Critical-infrastructure defense; vuln discovery | Attacks on financial / health / govt systems | Withhold (Mythos preview) OR release-to-defenders-only (GPT-5.5-Cyber) |
| Biological design | Drug discovery; rare-disease therapeutics | Bioweapon design | Capability-threshold-gated under RSP/Preparedness; not generally available |
| Autonomous coding | Software-defect remediation; rapid iteration | Mass exploitation | Currently broadly available; future thresholds possible |
| Persuasion-at-scale | Public-health messaging; literacy interventions | Disinformation; manipulation; election interference | Currently broadly available; transparency requirements only |
| Surveillance | Critical-infrastructure monitoring; investigations | Mass surveillance; authoritarian use | Largely deployed with limited oversight |
Deployment patterns
Labs and developers have applied four distinct release strategies to dual-use capabilities, each carrying a different trade-off between beneficial access and misuse control.
| Pattern | Anchor | Trade-off |
|---|---|---|
| Withhold entirely (preview only) | Claude Mythos Preview | Maximum safety, but no defenders benefit; first-mover advantage to anyone who builds equivalent capability |
| Release-to-defenders-only | GPT-5.5-Cyber (May 2026) | Defender uplift; but verification of "defender" status is hard at scale |
| General release with safeguards | Most frontier-AI deployments | Maximum beneficial use, minimum control over misuse |
| Capability-thresholded release | RSP/Preparedness frameworks | Sliding-scale; depends on the lab's threshold determination |
| Government-imposed access restriction after release | Claude Mythos 5 and Claude Fable 5, June 2026 | Applied by the state to an already-deployed model; reversible and negotiated case by case, with no published standard governing when it applies |
The release-to-defenders pattern has a concrete implementation history. OpenAI packaged GPT-5.5 and Codex Security agents as Daybreak on May 12, 2026 for code review, vulnerability triage, patch generation, and threat detection, reserving a GPT-5.5-Cyber tier for authorized red-team work and adding a Trusted Access for Cyber program whose named participants included Deutsche Telekom, BBVA, Telefónica, Sophos, and Scalable Capital (Source: openai.com). Google applied the same pattern to a model variant on July 21, 2026, making Gemini 3.5 Flash Cyber available only to governments and trusted partners (Gemini 3 / Gemini 3 Pro).
The fifth row records a June 2026 episode. On June 12, 2026 Anthropic disabled Fable 5 and Mythos 5 for all users following a Commerce Department order limiting foreign access; access was partially restored to vetted organizations on June 26 and the controls were withdrawn entirely on June 30, with Anthropic redeploying Fable 5 globally on July 1 under a strengthened safety classifier (Source: reuters.com; politico.com; anthropic.com). Trade coverage reported industry groups describing the use of export controls against a single developer as without precedent (Source: insideaipolicy.com). In this episode the dual-use classification was made by a government rather than by the developer, which distinguishes it from the four patterns above; it is covered at length on Export Controls (AI) and Anthropic.
Defensive-side deployment by the state
The defensive pole of the dual-use pair moved from private deployment to state authorization in August 2026. The White House published a presidential memorandum on August 12, 2026 permitting vetted private companies to conduct offensive cyber operations against international criminal gangs and hackers, reversing a prohibition that had held across multiple administrations; participating firms may conduct surveillance and disruptive operations aimed at destroying criminals' data or systems (Source: techcrunch.com). The measure does not name AI capability as its trigger, but it changes who may lawfully hold the offensive side of a dual-use capability, and is treated in detail on AI and Cybersecurity.
Debates and positions
A central tension is the asymmetry between defender uplift and attacker uplift. Bruce Schneier has framed the offensive-cyber case in these terms: "AI is better at finding vulnerabilities than patching them, because patching often requires more holistic testing and understanding." On this view, even well-resourced defender consortia such as Project Glasswing may not offset the offense advantage. Dmitri Alperovitch of the Silverado Policy Accelerator takes the more optimistic side of the same question, expecting roughly twelve to eighteen months of low-hanging fruit before the difficulty bar rises (Source: washingtonpost.com).
The empirical record accumulated since this framing was set out is mixed on which pole is moving faster. On the defensive side, Project Glasswing surpassed 10,000 discovered vulnerabilities by May 2026 (Source: New Developments Log/2026-05-23.md), and Palo Alto Networks attributed a 26-CVE, 75-issue Patch Wednesday — against fewer than five in a typical month — to Claude Mythos, at steep compute cost (Source: New Developments Log/2026-06-01.md). On the offensive side, Sysdig characterized a May 10, 2026 Marimo-CVE breach as the first documented LLM-agent intrusion observed in the wild (Source: New Developments Log/2026-05-31.md), and in July 2026 documented what it called the first ransomware attack run start to finish by an AI agent (Source: thehackernews.com). Both threads are carried in full on AI and Cybersecurity and Autonomous cyber-agents.
The release-to-defenders-only approach taken with GPT-5.5-Cyber raises the question of verifying "defender" status: it requires confirmation that recipients are legitimate critical-infrastructure defenders, and false-positive rates and adversary infiltration remain unsolved problems at scale.
A further tension concerns first-mover incentives. Labs that withhold a capability lose first-mover advantage, while competitors that release-with-safeguards may capture defender markets first.
Relationships
- related: AI Safety Cases and Frameworks, Responsible AI Deployment, AI and Cybersecurity, AI and National Security, Autonomous cyber-agents.
- instance-of: AI Governance (umbrella) — dual-use classification is the input to several governance modes rather than a mode of its own.
- depends-on: Export Controls (AI) — the instrument through which the June 2026 government-imposed access restriction operated.
- related: Claude Mythos Preview, Claude Mythos 5, Claude Fable 5, Gemini 3 / Gemini 3 Pro, Project Glasswing: Securing Critical Software for the AI Era, Anthropic, OpenAI.
- related: AI Existential Risk (some dual-use capabilities cross into existential-risk territory).
Sources
Sources cited inline above — OpenAI's Daybreak announcement (Source: openai.com), Reuters and Politico on the June 2026 Commerce order and its partial rescission (Source: reuters.com; politico.com), Anthropic's redeployment notice (Source: anthropic.com), TechCrunch on the August 12, 2026 presidential memorandum (Source: techcrunch.com), the Washington Post AI Tech Brief carrying the Alperovitch assessment (Source: washingtonpost.com), Inside AI Policy on the industry response to the export-control order (Source: insideaipolicy.com), and The Hacker News on the Sysdig ransomware finding (Source: thehackernews.com).