What happened
RAND's Center on AI, Security, and Technology tested whether frontier open-weight LLMs can be modified for malicious biological purposes, examining anti-refusal tampering, capability enhancement, and publicly available uncensored model variants. Headline finding: removing an LLM's safety training is 'highly feasible,' while enhancing an LLM's biological capabilities beyond baseline is harder. A custom biosecurity evaluation suggests that safety removal alone — without capability uplift — could still aid a realistic bioweapons threat pathway.
Why it matters
Directly informs the open-weight vs. closed-weight AI release policy debate and export-control discussions; security and policy leaders need this evidence base for decisions on model release safeguards.
Action needed
Brief national security and trust & safety teams on anti-tampering safeguards for any open-weight model releases or deployments.