Strategic Report  ·  2026-09-20

Open-Weight AI Models May Increase Biological Misuse Risks: Assessing Anti-Refusal Tampering, Capability Enhancement, and Publicly Available Uncensored Models

Strategic ReportHigh impactGlobal
RAND's Center on AI, Security, and Technology tested whether frontier open-weight LLMs can be modified for malicious biological purposes, examining anti-refusal tampering, capability enhancement, and publicly available uncensored model variants. Headline finding: removing an LLM's safety training is 'highly feasible,' while enhancing an LLM's biological capabilities beyond baseline is harder. A custom biosecurity evaluation suggests that safety removal alone — without capability uplift — could still aid a realistic bioweapons threat pathway.
Directly informs the open-weight vs. closed-weight AI release policy debate and export-control discussions; security and policy leaders need this evidence base for decisions on model release safeguards.
Brief national security and trust & safety teams on anti-tampering safeguards for any open-weight model releases or deployments.
RAND Corporation — Open-Weight AI Models May Increase Biological Misuse Risks
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →