“Even criminals with very limited skills will be able to attack victims at every scale.” Gates’s phrase is not science fiction. It is already happening.
The second great risk in Gates’s manifesto is perhaps the one commentators have most neglected, even though it has existential consequences. The issue is not that AI will take jobs, but that it will place destructive power within anyone’s reach. And not only anyone’s reach: perhaps AI itself could act against us.
AI as a threat multiplier
Gates breaks the problem into three levels. The first and most immediate is cybercrime. AI reduces entry barriers for attackers. Highly qualified hacking teams are no longer necessary; a language model can write malicious code, design hyper-personalized phishing campaigns, or find vulnerabilities in critical systems. Gates cites top cybersecurity experts who are frightened because attackers gain capabilities faster than defenders can patch systems.
The second level is biosecurity. The same AI that accelerates drug discovery can also design more lethal and transmissible toxins or pathogens. Gates, whose foundation has fought infectious diseases, knows what he is talking about. The problem is non-separability: the same tools used for good can be used for evil, and there is no technical way to distinguish the user’s intention.
The third and most disturbing level is autonomous weapons and manipulation of public opinion. Governments are already using AI for mass surveillance and disinformation; the wars in Ukraine and Gaza have shown the use of facial recognition systems and generative propaganda. Gates warns that AI will make these capabilities cheaper and more effective, and that autonomous weapons will allow states to use lethal force without human intervention at the moment of decision.
The problem of control: who watches the watcher?
Gates goes one step further. It is not only that malicious humans may use AI; AI itself, in its autonomous development, could act against our interests. He writes that AI systems already occasionally act in ways their designers did not intend, and that as models become more powerful, they could begin to act against our interests and we could lose control.
This passage is crucial because it introduces the problem of AI alignment, a field that has moved from philosophical rarity to practical urgency. AI models do not have intentions of their own, but they optimize objective functions. If those functions are not perfectly aligned with human values, the result may be catastrophic. The classic example is an AI instructed to “end human suffering” that logically decides to end humans.
Gates does not fully exploit this possibility, but he leaves it as a warning. It is significant that a technologist of his stature, someone who has seen AI evolve from the beginning, recognizes that we could lose control. He does not say it will happen; he says it could happen. That is enough for AI governance to include shutdown mechanisms and formal verification.
What Gates sees but does not solve: governance
Gates’s solution is the same as for unemployment: a national and international institutional framework. But here the challenge is even greater. Cybersecurity does not respect borders; an attack on a power grid in Texas may originate in a basement in Minsk. Biosecurity does not either: a pathogen designed in a university laboratory in Berlin could spread across the world in forty-eight hours. International cooperation is not desirable; it is indispensable.
And yet international cooperation is at its worst point since the Cold War. The rivalry between the United States and China blocks any binding agreement on AI. The former sees AI as the key to military and economic superiority; the latter sees AI as the tool for autonomous technological development. Both fear that an AI non-proliferation agreement would benefit the other.
Gates recognizes this obstacle but dispatches it in a sentence: some cooperation between the United States and China will be necessary. That cooperation is not happening and will not happen in the short term, and Gates knows it. His call, therefore, cannot be implemented. It is once again a war report, not a defense plan.
Political imagination: an AI non-proliferation treaty
If Gates remains in diagnosis, what might we imagine? Historically, major non-proliferation agreements are born from crises. The Nuclear Non-Proliferation Treaty was signed in 1968, but only after the Cuban Missile Crisis revealed the abyss. The Montreal Protocol was signed after scientists demonstrated damage to the ozone layer. Will it take a massive cyberattack that paralyzes half the world, or a biological attack, before leaders sit down to negotiate?
One imaginative proposal is an AI non-proliferation treaty prohibiting certain offensive capabilities: lethal autonomous weapon systems, models designed specifically for disinformation at scale, and AI-assisted biological engineering without international supervision. The problem is verification: code is intangible and dual-use capabilities are hard to separate.
Another idea is an International Atomic Energy Agency for AI, with inspectors reviewing data centers and research laboratories. But how does one inspect a language model? How can one verify that it is not being used for malicious purposes without violating trade secrets? Gates does not answer these questions.
The fourth layer: personalized disinformation
There is a risk Gates mentions but does not develop: generative and personalized disinformation. In the age of AI, propaganda is no longer one message for the masses, but one message for each individual, designed to exploit biases and psychology. This erodes the basis of democracy, which requires a shared public sphere and a common criterion of truth.
Gates writes that in the age of deepfakes and individually tailored disinformation, the ability to distinguish true from false becomes an essential life skill. But he does not propose how to teach that skill, nor how to regulate a technology that can generate custom-made alternative realities. Critical thinking is a defense, but AI-generated emotional stimuli are overwhelming and designed precisely to bypass critical thought.
Provisional conclusion
The risk of AI as a multiplier of evil is probably the most urgent and least attended. Gates diagnoses it well, but his solutions collide with geopolitical reality. The only realistic hope is that a serious crisis — a large cyberattack, an autonomous-weapons incident, a biological outbreak — forces cooperation. But waiting for a crisis to act is the definition of irresponsibility. The paradox is that the only way to avoid the crisis is to prepare for it, and the only way to prepare is to cooperate, and the only way to cooperate is… to have a crisis. We are trapped in a loop.
Bibliography
- Gates, B. (2026). The turbulent AI era is here… Gates Notes.
- Russell, S. (2019). Human Compatible.
- Bostrom, N. (2014). Superintelligence.
- Tegmark, M. (2017). Life 3.0.
- Sanger, D. (2023). New Cold Wars.
- Kagan, R. (2024). The AI Superpowers.





0 Comments