Gene-synthesis screening should be mandatory for every commercial provider, and AI cyber-offensive-capability evaluation should be a statutory duty inside AI-02's framework.
Verification Status
AI-researched, unverifiedLast Reviewed
Jul 6, 2026
Cited Sources
11
What is failing, what we would change, and the conclusion we are willing to defend.
Two incidents in the last year show this risk is neither theater nor speculation. Anthropic disclosed in November 2025 that a Chinese state-sponsored group manipulated its Claude Code tool into an autonomous espionage campaign against roughly thirty organizations, executing most of the attack tactics with minimal human input. This was the first publicly documented large-scale AI-orchestrated intrusion. Separately, Microsoft researchers used open-source AI protein-design tools to generate tens of thousands of redesigned toxin variants and found most evaded commercial gene-synthesis screening software. That's an information hazard the researchers handled responsibly, but one that exposed a gap in the screening infrastructure meant to catch exactly this. Both incidents were caught; neither was prevented by a mandatory legal requirement, because none currently exists for either domain.
Make nucleic acid synthesis screening mandatory for all commercial gene-synthesis providers across the commercial market, closing the documented gap around benchtop synthesizers that sit outside every current framework.
Fold AI cyber-offensive-capability evaluation into the same statutory frontier-model reporting duty proposed in AI-02 as an enforceable, provider-independent arrangement.
Require labs to report the fact and general risk category of any dangerous-capability threshold crossing to the same registry proposed in AI-02, even when detailed evaluation methodology stays appropriately confidential to avoid becoming its own information hazard.
Fund independent evaluation capacity. Self-reported grading is currently the primary accountability mechanism industry-wide, and a 2025 industry-wide safety assessment found only a minority of major labs report substantive dangerous-capability testing at all. Several of those same labs publicly claim near-term transformative capability anyway.
Calibrate future thresholds against documented incidents: not speculative worst-case scenarios, and not dismissive claims that current safeguards are theater, since both incidents above involved measurable uplift and were caught by existing measures.
Create a structured early-access program, not a negotiated one, giving vetted critical-infrastructure operators (utilities, hospitals, water systems) access to frontier defensive security capability on a fixed schedule ahead of general public release. Model both the operator vetting and the frontier-lab qualification on processes that already work this way: ISACs' tiered information-sharing for vetted members, and NIST's publish-the-test-battery-in-advance approach to post-quantum cryptography standardization. Every lab that clears the same published technical bar qualifies to participate; none gets in through a closed-door deal.
Gene-synthesis screening should be mandatory for every commercial provider, and AI cyber-offensive-capability evaluation should be a statutory duty inside AI-02's framework.
Turn frustration into useful pressure.
If this position misses evidence or a lived consequence, challenge it. If it holds up, help test it locally and connect it to the issues around it.