Compliance

Dual-Use AI

AI systems or models that can be applied for both beneficial civilian purposes and potentially harmful applications.

Definition

Dual-Use AI refers to artificial intelligence systems, models, or capabilities that can serve both beneficial purposes and potentially harmful applications, including misuse for weapons development, cyberattacks, disinformation, or other threats to security and safety.

US Regulatory Definition: Executive Order 14110 defines "dual-use foundation model" as an AI model trained on broad data, applicable across a wide range of contexts, that could pose serious risks to security, national economic security, public health or safety, including models that have high-level performance at tasks that pose such risks.

Regulatory Approaches:

  • US: EO 14110 requires developers of dual-use foundation models to report to government, share safety test results, and implement security measures. Commerce Department establishes reporting thresholds
  • EU: The AI Act addresses dual-use concerns through GPAI with systemic risk provisions (Chapter V) and prohibited practices that could enable mass surveillance or manipulation
  • Export Controls: Wassenaar Arrangement and national export control regimes may apply to dual-use AI technologies

Examples of Dual-Use Capabilities:

  • Advanced language models (creative writing vs. disinformation)
  • Protein structure prediction (drug discovery vs. bioweapons)
  • Computer vision (accessibility vs. surveillance)
  • Cybersecurity AI (defense vs. offensive hacking)

Mitigation Measures: Responsible disclosure, capability evaluations, access controls, monitoring, and collaboration with governments on safety testing.

Related concepts: Systemic Risk, Misuse Risk, AI Safety, Red Teaming

Sources

  • Export Control Regulations
  • Wassenaar Arrangement