AI's Dual-Use Problem Has 6 Proposed Fixes. Most Won't Work

11 min readBy Nathan House

Everyone agrees frontier AI can now do things we don't want in the wrong hands — find zero-days, walk someone through a pathogen, write malware that works. What nobody agrees on is what to do about it. And in the last few months that argument stopped being theoretical: the US government pulled two Anthropic models off the internet with an export-control letter, a senator filed a bill to make government access mandatory, and Google DeepMind's CEO proposed a Wall Street-style regulator for AI. Six serious fixes are now on the table.

Most of them won't work. Not because the people proposing them are naive, but because they're all quietly trying to solve a problem that can't be solved the way they're aiming at it. We'll go through all six, score each one on the same five questions, rank which have teeth and which are theatre, and then I'll give you the test I think every one of them fails. If you work in security, one of these regimes will decide whether you're allowed to use offensive-capable AI at all, so it's worth knowing which way the wind is blowing.

TL;DR — if you've only got 30 seconds

The root problem: dangerous AI knowledge is dual-use — the same capability that finds a bug for a defender finds it for an attacker. You can't split the knowledge, only decide who gets it.

6 fixes on the table: voluntary government vetting, a mandatory-access bill, vendor gatekeeping, export controls, baking removal into the weights (GRAM), and a "FINRA for AI", plus open weights as the counter-proposal.

Scored on 5 questions: does it gate the capability, who vets and who holds them accountable, who gets locked out, does it survive open weights, and is there a route in for independents.

Verdict: no single fix works; the voluntary ones are mostly theatre; the honest answer is layered.

The test they all fail: a control only works if it reduces what attackers can actually do without stopping defenders keeping pace. Gating the frontier buys months. The open-weight gap shrank from 6-10 months to 4-7 in a year.

First, Why This Is So Hard

The 6 proposed fixes for AI's dual-use problem at a glance, each with a verdict badge: voluntary vetting (theatre), mandatory bill (teeth, US-only), vendor gatekeeping (works today), bake into weights (strongest gate), FINRA for AI (doesn't exist yet), open weights (the counter-case)

Every fix below is aimed at the same target, so it's worth being precise about what the target actually is. The reason dangerous AI knowledge is so hard to control is that it's dual-use: the exact capability that lets an AI find a vulnerability so a defender can patch it is the capability that lets it find the vulnerability so an attacker can exploit it. It's one body of knowledge, not two. We went deep on why that entanglement defeats even clever technical fixes in our piece on GRAM, the off switch for AI knowledge, and on how the government's attempt to grab control played out in Who Controls AI Now. I won't re-tread either here.

The one thing to carry forward is this: because you can't cleanly separate the good use from the bad use inside the model, every proposed fix, even the technical ones, eventually collapses into the same decision. Who is allowed the dangerous capability, who decides that, and who gets left out? That's the lens. So I'll score all six fixes on five questions:

1

Does it actually gate the capability? Or does it just signal that someone's trying?

2

Who vets — and who holds them accountable? A gatekeeper nobody can appeal to is a different thing entirely.

3

Who gets locked out? Students, solo researchers, small consultancies: the people without a compliance department.

4

Does it survive open weights? Where anyone can download the model and no switch remains.

5

Is there a path in for an independent? Or only for a big employer? This is the one that decides your access.

Keep those five in mind. They're what separate the fixes with teeth from the theatre.

Fix 1: Government Vetting — From Voluntary to Mandatory

The first fix is the one the US actually reached for, and it comes in two temperatures of the same lever: government review before a model ships.

The mild version is live. On 2 June 2026, President Trump signed Executive Order 14409, "Promoting Advanced Artificial Intelligence Innovation and Security," setting up a voluntary framework where developers of "covered frontier models" can give the government up to 30 days of pre-release access for cybersecurity testing. The order goes out of its way to say what it is not: it expressly disclaims any mandatory licensing, preclearance, or permitting requirement. In other words: please show us your dangerous model before you ship it, if you feel like it.

The hot version wants to remove the "if you feel like it." On 21 July 2026, Senator Mark Warner introduced the Secure AI Development Act (S.5061), which would require frontier developers to give the NSA access at least 21 calendar days before a model enters commerce, register every covered model in a public NIST registry, and face a penalty of not less than $100,000 a day for every day a model stays available without going through the testing process. The Attorney General would have to give notice and a seven-day window to comply first. Same lever, government pre-release vetting, turned from optional to enforceable.

So how does the lever score? Voluntary vetting barely gates anything: a lab that judges its model too valuable to delay can simply decline, and the disclaimer guarantees no consequence. That's the definition of signalling. The mandatory bill has real machinery behind it. But note what it does and doesn't do. It compels access for testing; it does not require government approval before release, and it doesn't compel a developer to act on what the testing finds. It's a checkpoint you must pass through, not one that can stop you. Both versions also share a fatal blind spot: they bind US developers only, and neither touches a model whose weights are already downloaded.

⚠️ Verdict

Voluntary vetting is theatre. The mandatory bill has teeth — but it stops at the border, and it's still a bill, not a law.

Fix 2: Let the Labs Be the Gatekeepers

The second fix is already running, and you may have used it: the labs vet you themselves. Anthropic's Cyber Verification Program and OpenAI's Trusted Access for Cyber both relax their models' safety refusals for professionals who apply and get approved, while keeping clearly malicious use blocked for everyone. Anthropic went further in 2026 with Project Glasswing, deciding one model was too dangerous for open release and handing it only to vetted partners. I've covered exactly how to get through these programmes in Best AI for Hacking — that's the how-to, and I won't repeat the application mechanics here. What matters for this article is who's holding the gate.

And the answer is: two private companies. On the scoring, vendor gatekeeping genuinely gates the capability — it works today, in production, which is more than most fixes here can say. But look at the other four questions and it gets uncomfortable. Who vets? Anthropic and OpenAI, reviewing applications by their own criteria, accountable to no one but themselves and their commercial incentives. Who gets locked out? The independent. CVP is organisation-scoped, OpenAI's programme leans on enterprise security certifications, and a solo pentester or a student has a far weaker hand than a company with a compliance department. There is a path in, which is the one bright spot, but it runs through a corporate-shaped keyhole. And it does nothing about open weights.

⚠️ Verdict

Works today — but it makes two companies the unelected licensing authority for offensive-capable AI.

Fix 3: Export Controls — Treat the Model Like a Munition

The third fix isn't a proposal; it's already been used, and it was the bluntest instrument anyone has swung. On 12 June 2026, at around 5:21pm Eastern, the Commerce Department's Bureau of Industry and Security — under Secretary Howard Lutnick, in a letter to Anthropic CEO Dario Amodei, issued an export-control directive barring access to the freshly-launched Claude Fable 5 and Claude Mythos 5 by any foreign national, inside or outside the US, including Anthropic's own non-citizen staff. The models had been public for three days. Because no consumer platform can sort users by passport in real time, Anthropic disabled both worldwide within hours.

"The government banned a model" obscures what actually happened. The directive works as a licensing requirement under the Export Administration Regulations, the same body of rules BIS uses to control the export of sensitive commodities, software and technology. The models became items requiring a licence before they could be exported, re-exported, or even transferred domestically to a covered person, with Anthropic obliged to file individually validated licence applications. The machinery built for controlling weapons technology, pointed at a language model.

Two things get blurred here. Export controls control the capability. They decide whether the technology can move to a given recipient or country. What they don't do is vet the operator, judging whether a specific person is competent and authorised. That's a different job, and it's the one CREST and security clearances do in our field. Export law is a border tool, not a licensing tool for practitioners.

Scored: it gates hard. A global shutdown in hours is as hard a gate as exists, and it's wielded by an accountable government body. But it's a sledgehammer. It locked out everyone, defenders included, with no path in for anyone until a partial exemption was negotiated weeks later. And it has the open-weights hole plus a worse one: it only reaches models a US company still controls, and it pushes demand straight toward ungoverned foreign and open models — the exact outcome it's meant to prevent.

⚠️ Verdict

Real teeth — but so blunt it hits defenders as hard as attackers, and leaky at the edges.

Fix 4: Bake the Removal Into the Weights

The fourth fix is the only technical one. Instead of controlling access to a dangerous model, build the model so the dangerous knowledge can be physically removed. That's GRAM (gradient-routed auxiliary modules), Anthropic and AE Studio's method for routing dual-use knowledge into deletable compartments. I've written the full explainer in GRAM, AI's off switch and won't re-run the mechanism here. For scoring, what counts is that it's the only fix on this list where removed knowledge is genuinely non-jailbreakable, because the weights that held it are gone.

But, and this is the through-line of the whole article, even the technical fix ends in an access decision. GRAM doesn't delete the dangerous capability from existence; it lets a provider ship a version with the module off to the public and a version with it on to the vetted. So "who gets the module-on model?" is exactly the same vetting question as Fix 2, just moved earlier in the pipeline. It gates well, but it inherits every accountability and lock-out problem of vendor gatekeeping — and, critically, it's useless the moment the full-capability weights are open, because you can't ablate a module on a model someone already downloaded.

✅ Verdict

The most robust gate here — and still just a fancier way of deciding who's trusted.

Fix 5: A "FINRA for AI"

The fifth fix tries to plug Fix 2's accountability hole. In July 2026, Google DeepMind CEO Demis Hassabis proposed a Frontier AI Standards Body modelled on FINRA, the industry-funded self-regulatory organisation that polices Wall Street brokers under SEC supervision. Under his proposal the labs would fund it, but the board would include independent technical experts and open-source community representatives. It would set the capability benchmarks defining what counts as "frontier," run independent safety and security testing, and work with government agencies where national security is involved. Companies would submit models voluntarily at least 30 days before release. Once the evaluations proved themselves, submission would become mandatory for anything sold in the US.

The idea gained traction fast. Microsoft's Satya Nadella and Mustafa Suleyman backed it, as did Jack Dorsey and Aaron Levie; OpenAI's Sam Altman called it "thoughtful"; Elon Musk called it "a thoughtful framework overall." Even David Sacks, generally hostile to anything resembling a licensing regime, said it beat having the government regulate frontier AI directly. Bloomberg reported that the administration was reviewing a version developed with Treasury Secretary Scott Bessent's involvement, with the SEC as the overseeing body, which makes sense, since the SEC is the only federal agency with statutory authority to delegate powers to a self-regulatory organisation.

It's a better shape than "trust the two labs," because it puts one body under government oversight instead of leaving each vendor to grade its own homework. But the criticism that dogs FINRA in finance applies double here: an industry-funded body regulating its own funders is a standing invitation to regulatory capture, and it risks setting incumbents' practices as the standard newcomers must meet. On the practitioner questions it's silent. It decides which models are safe to deploy, not who's allowed to use the dangerous ones. And it's a proposal, not a programme; nothing is enforceable yet.

⚠️ Verdict

The most accountable design on the board, undermined by who pays for it — and still vapour.

Fix 6: Don't Gate at All — Open Weights

The sixth fix rejects the entire premise. Its loudest voice is Mark Zuckerberg, who put the case in a Wall Street Journal op-ed titled "The AI Future Is for Everyone": "The defining question of our age isn't whether superintelligence will exist, but who will have access to it. Will it be centralized and restricted to a few institutions, or will it be a tool that empowers everyone?" He aimed a fairly direct swipe at Anthropic's Dario Amodei and OpenAI's Sam Altman, saying he was surprised that the people leading the technology's development offered perspectives "so filled with doom" — and added the line that lands hardest: "I don't understand why anyone who believes that AI will eliminate most jobs and much of humanity's relevance would rush to build that future." The open-weights case is that gating concentrates dangerous power in a handful of labs, and the safer path is releasing weights openly so no single company, or government, holds the switch.

Here's why I've put it last, and why it doubles as the stress test for every fix above it: open weights is the scenario that breaks the other five. On the scoring, it's the mirror image of export controls. It scores worst on gating the capability — it deliberately doesn't gate at all. And it's the only approach that makes dangerous capability permanently unrecoverable once it's out, because released weights can't be recalled and can be stripped of their safety training. But it scores best on the questions the others fail: nobody is locked out, there's no gatekeeper to be unaccountable, and the path in is "download it."

That's the genuine tension, and I won't pretend it away. My position: for the sharpest-edged capabilities, autonomous exploit generation and real bioweapon uplift, "release it to everyone" is the wrong answer, because you can't un-release it and the worst actors benefit most. For the broad middle, the concentration-of-power worry is real and open weights are a healthy check. The mistake is treating it as all-or-nothing.

💡 Verdict

The essential counterweight — and a catastrophe if applied to the genuinely dangerous tier.

So What Actually Works? The Ranking

Scorecard ranking the 5 gates on 5 criteria: GRAM ranks first but fails on surviving open weights and doesn't exist in production; voluntary vetting ranks last, failing to gate the capability at all; export controls rank fourth because they lock out solo practitioners

So here's the ranking. Five of the six are gates: attempts to control who gets the capability. The sixth, open weights, isn't a gate at all; it's the counter-proposal, and it doubles as the reality check every gate has to survive. So I'll rank the five gates, then hold them all against open weights.

1

GRAM / architectural removal. The only genuinely non-jailbreakable option — you cannot prompt your way to knowledge that isn't in the weights. Catch: it still just decides who's trusted, it isn't in any production model yet, and it dies the moment weights are open.

2

Mandatory vetting (Warner's S.5061). Real enforcement machinery: a public NIST registry and a penalty starting at $100,000 a day. Catch: it's a bill, not a law; it's US-only; and it compels access for testing, not compliance with the findings.

3

Vendor gatekeeping (CVP, TAC). Ranked third for one reason: it's the only thing on this list protecting anyone today, in production, at scale. Catch: two private companies hold unaccountable licensing power over an entire profession.

4

Export controls. The hardest technical gate anyone has demonstrated: global shutdown in hours. So why fourth? Because the test I'm about to lay out is the one it fails worst: it locked out every legitimate defender, achieved nothing against open weights, and pushed demand toward ungoverned models. Maximum force, wrong target.

5

Voluntary EO vetting. The purest theatre: a review you can decline, attached to an order that expressly promises no licensing consequence for declining.

FINRA for AI sits unranked. It's the most accountable design anyone has proposed and it may well be where this lands, but it doesn't exist, it isn't enforceable, and it governs which models ship rather than who may use them. Ask me again when it has statutory teeth.

And the whole ranking carries an asterisk: the moment a capable model is open-weighted, every gate above applies only to the law-abiding.

Which is the real conclusion, and it's not a tidy one. No single fix works, because none of them can. They're all answers to an access question dressed up as a technical or legal one. The least-bad approach is layered, built from the top of that ranking down: architectural removal for what can be cleanly separated, an accountable vetting body rather than two companies' discretion for the residual, and the export-control sledgehammer held in reserve for the genuinely catastrophic tier, never as a first move.

But ranking the fixes is the easy part. The harder question is whether this whole exercise is aimed at the right target. I don't think it is.

The Test Every One of These Fixes Fails

After 30 years watching this field handle dual-use knowledge, my read is bleaker than the ranking above.

Gating buys months, not years — and the number is shrinking

In July 2026 the UK's AI Security Institute published its first public measurement of this, and the finding is the one number every defender should know. In their words: "Recent open models GLM-5.2 and DeepSeek V4-Pro perform similarly to frontier closed models released 4 to 7 months before them — a narrower gap than the 6 to 10 months we measured through most of 2025."

Two details stop that being a doom stat. First, the gap is wider on the hard tasks: on long-horizon cyber ranges, where a model has to chain capabilities into a full hacking operation, GLM-5.2 only reaches a model released nearly 7 months earlier, and DeepSeek V4-Pro falls below a sub-frontier model of the same vintage. Frontier models keep a real lead exactly where sustained autonomous operation matters most. Second, the frontier itself is moving, so the gap measures distance to a target that's accelerating, not a fixed line.

But AISI's own conclusion is the one to sit with: defenders have "a short window to prepare" before today's frontier cyber capability is available to anyone with a laptop. Any policy built on permanent capability exclusivity is planning around a lead measured in months and shrinking. Gating the frontier is a delaying action. It's worth doing. It isn't a solution.

The arms race isn't coming — it started

I want to be precise here, because "AI will change security" is the kind of thing people have been saying for years without evidence. Now we have the evidence, and the cleanest example is DARPA's AI Cyber Challenge. In the final, competitors' autonomous systems found 54 of the 63 planted vulnerabilities, 86%, and patched 68% of them without a human in the loop. And while they were at it, those same systems turned up genuine zero-days nobody had planted, in real open-source software: 9 for one team, 6 for the winners, more for the rest. Separately, the International AI Safety Report records an AI agent that identified 77% of vulnerabilities in real software at a major cybersecurity competition, placing it in the top 5% of over 400 mostly-human teams. Google's Big Sleep agent did the same in production, finding a memory-corruption flaw in SQLite (CVE-2025-6965) that was patched before anyone could exploit it.

That's the defensive column. The attacking column filled up just as fast: Anthropic disrupted a Chinese state-sponsored espionage campaign in which AI performed an estimated 80-90% of the operational work across roughly 30 targets, with humans stepping in at only 4-6 decision points. Anthropic calls it the first documented large-scale cyberattack executed without substantial human intervention.

Notice what that pairing means: the same underlying capability finds the bug for the defender and finds it for the attacker. That's the double-edged sword arriving in production, and it's the reason none of the six fixes can win outright.

But I wouldn't assume the defenders come out ahead

I used to think we would. Defenders control their own environment, own the telemetry, choose what gets deployed, and that ought to compound. Where a team genuinely has that control, I still think there's an edge to be had. But look at where we are. A survey of 500 CISOs run by Wakefield Research in late June 2026 found 63% believe attackers currently hold the advantage because of AI, and while 89% said their organisation was prepared for AI-driven attacks, only 28% described themselves as very prepared. (It was commissioned by a vendor selling autonomous defence, so read it with that in mind; the direction still matches everything else I'm seeing.)

And the structural point stands on its own: attackers carry no compliance burden, no change-control board, no QA gate, and no liability when they break something. They need one route in. We defend an estate sprawling across cloud, SaaS, identity, and a supply chain we don't own. Any defensive edge has to be earned against that. It isn't structural.

Which is why the answer has to be defence that moves at machine speed

If attacks run at machine speed and defence runs at human speed, the gap does the damage. It's that simple. That means continuous AI-assisted detection and remediation now, and more autonomy as teams build the governance to trust it. The direction is settled. The bottleneck is organisational, and the numbers are stark. Arctic Wolf's 2026 trends report, based on 1,350 security and IT decision-makers, found 94% of organisations now use LLMs — but only 14% have made AI central to their security operations, and just 53% trust AI to take even a narrowly defined action like blocking a malicious IP at the firewall, for fear of a false positive. The CISO survey found the same picture from another angle: 65% still do at least half their vulnerability management manually, and 60% take more than a week to remediate a critical vulnerability. Against attackers operating at machine speed, that is the whole problem in two statistics. This is the agentic engineering skill set, pointed at defence.

And my prediction, which you can hold me to

I think governments will end up trying to cap how powerful AI is allowed to get: compute thresholds, mandatory reporting, and some form of international oversight, driven not just by cyber and biology but by the fear of not being able to control a system smarter than us. The EU AI Act and the US executive order already have reporting duties tied to training compute, so the machinery exists in embryo.

But it won't work like nuclear non-proliferation, and I'd push back on anyone who says it will. Fissile material is scarce, physical, and detectable; model weights are a file you can copy. The control point isn't the knowledge, which is already out. It's the concentrated compute needed to push the frontier further. Cap the reactor, not the maths. And if that cap is written carelessly, it will slow the defenders who follow rules while doing nothing to the attackers who don't.

✅ The test I'd apply to every proposal above

The danger isn't only that AI gets too capable. It's the gap: attackers wielding capable, unrestricted tools while legitimate defenders are locked out of comparable ones by policy. Raw capability matters too. I'm not going to pretend a freely available autonomous exploit engine is fine because it's fairly distributed. But of the two risks, the access gap is the one we're actively creating with our own policy choices, and it's the one nobody's scoring for.

A control isn't successful because it restricts access on paper. It's successful only if it reduces what attackers can actually do without stopping defenders keeping pace. Judge all six fixes on that, and most of them look considerably worse.

What This Means for You

Two ways to gate a dangerous thing: control the capability (export controls, blocks by destination, hits everyone equally) versus vet the operator (CREST, OSCP, clearances — judges the person, independent path in)

The part that touches your career follows straight from that test. If the danger is the access gap, then the question that decides your future isn't which fix wins. It's whether the vetting underneath it has an independent path in, or only a corporate one. That's the difference between a regime where a competent solo practitioner can keep pace and one where only people with an employer's compliance department can.

And our field has answered this question before, which is the quietly hopeful part. We've spent decades gating the exact same double-edged sword — offensive security skills — and we didn't do it by making the knowledge illegal. We did it with competence you can demonstrate, authorisation you can prove, and accountability you carry: CREST registration, OSCP and the cert ladder, security clearances, signed engagement scopes. That's a vet-the-operator system, and it's a far better template than "two labs decide", because it has an independent path in. Anyone can earn OSCP; you don't need an employer's permission to become demonstrably competent.

So the move, whichever regime wins, is the same and it's within your control: become the person any vetting scheme has to say yes to. That means skills you can prove and a track record someone can check. Increasingly it also means being able to direct AI rather than just prompt it. That last one is doing double duty now: it's what gets you approved, and it's the actual job. If defence has to run at machine speed, the valuable person is the one who can build and supervise systems that detect and remediate continuously — which is exactly what AI-driven cyber security jobs are hiring for. Build toward the credentials mapped in our AI security certifications guide and the fundamentals in our cyber security training that no gate can take away.

The regimes will keep fighting over who holds the switch. Your job is to be too useful to lock out, and fast enough to matter when the attackers don't wait.

Controlling Dangerous AI: Your Questions Answered

Is AI licensing actually happening?

Not yet, and not the way people assume. The current US policy — Executive Order 14409, signed 2 June 2026 — is explicitly voluntary and disclaims any mandatory licensing, preclearance or permitting regime. A mandatory bill exists (Senator Warner's Secure AI Development Act, S.5061), but it's a proposal, not law. What's real today is narrower: export controls, and the labs' own vetted-access programmes.

Who decides which AI is dangerous enough to control?

Right now, a mix. The NSA and Commerce Department for the government's review and export actions, and Anthropic and OpenAI themselves for their vetted-access programmes. That's precisely the accountability problem — there's no single transparent, appealable authority, which is what proposals like a FINRA-style standards body are trying to create.

Can any of these fixes stop open-weight models?

No — and that's the hole running through all of them. Once a model's weights are released openly they can't be recalled, and every gate discussed here applies only to models a provider still controls. Restricting hosted models often just pushes demand toward ungoverned open and foreign alternatives.

Will defenders or attackers benefit more from AI?

Unsettled, and anyone certain either way is ahead of the evidence. The same capability serves both sides — in DARPA's AI Cyber Challenge final, autonomous systems found 86% of the planted vulnerabilities and patched 68% of them with no human involved. But right now attackers have the head start: in a June 2026 survey of 500 CISOs, 63% said attackers hold the advantage because of AI, and defenders carry compliance, change control and liability that attackers simply don't.

Will AI be capped like nuclear weapons?

My guess is governments will try — through compute thresholds, mandatory reporting and some international oversight — driven by cyber risk, biology, and the fear of not being able to control a system smarter than us. The EU AI Act and the US executive order already tie reporting duties to training compute. But it won't work like nuclear non-proliferation: fissile material is scarce and detectable, while model weights are a file you can copy. The realistic control point is concentrated training compute, not the knowledge itself.

What does all this mean for a security professional?

Whichever regime wins, access to offensive-capable AI will run through some form of vetting. The durable move is to be the person that vetting approves — demonstrable skills, a verifiable track record, and the ability to direct AI on authorised work. Our field already gates this way with certifications and clearances; the AI world is reinventing the same idea, so far with less of an independent path in.

About the Author

Nathan House

Nathan House, Founder & CEO of StationX

Nathan House has 30 years of hands-on cybersecurity experience and is Cambridge-educated, holding CISSP, CISA, CISM, OSCP, CEH, and SABSA. He founded StationX in 1999 — one of the UK’s first cybersecurity companies — and has secured £71 billion in UK mobile banking transactions and the London 2012 Olympics, advising clients including Microsoft, Cisco, BP, Vodafone, and VISA. He authored the world’s most popular cybersecurity course — a #1 Udemy bestseller taken by over 500,000 students — and was named Cyber Security Educator of the Year 2020, AI Security Educator of the Year, and a UK Top 25 Security Influencer 2025. A DEF CON speaker and featured expert on CNN, Fox News, NBC, and the BBC, Nathan leads StationX’s training of more than half a million students worldwide.