Instead, his tone has changed because he believes AI capabilities are improving more quickly than governments and public institutions are preparing for their consequences.
In an earlier interview with The Atlantic, Gates said new systems were crossing important danger thresholds in areas such as computer coding, cyberattacks and bioterrorism.
He argued that AI differs from earlier technologies because it can perform cognitive tasks across many fields and may eventually be connected to capable, relatively inexpensive robots.
The internet transformed communication and commerce, but it did not independently reason through scientific problems or generate executable computer code. Generative AI systems increasingly can.
That difference is central to Gates’ concern.
The Bioterrorism Risk
Bioterrorism is one of the most serious scenarios Gates has raised.
Creating an effective biological weapon has traditionally required specialized knowledge, laboratory access, technical experience and the ability to overcome numerous practical obstacles.
Reading scientific instructions is not enough. A person would also need to acquire materials, avoid detection, conduct experiments and produce an agent capable of causing real harm.
AI does not eliminate all those barriers.
Nevertheless, Gates worries that increasingly capable systems could lower some of them. An AI assistant might help a malicious user understand scientific literature, troubleshoot technical problems, identify biological targets or improve plans that would otherwise require advanced training.
This does not mean an ordinary chatbot can currently create a pandemic on command. It means the quality of future assistance could make dangerous knowledge more accessible.
Gates has called for monitoring AI systems’ ability to design molecules or provide information that could facilitate biological attacks.
The challenge is to preserve legitimate scientific applications while preventing dangerous assistance.
The same models that might help researchers design a vaccine could potentially be misused to investigate harmful pathogens. Safety rules must therefore consider both the user’s intention and the capability being requested.
AI as a Force Multiplier
The phrase “AI weapon” may create the impression of a single machine acting independently.
Gates’ concern is broader.
AI can function as a force multiplier—a tool that allows one person or organization to operate with speed, scale or expertise that previously required a much larger team.
A criminal group could use AI to identify weaknesses in computer networks. A propaganda operation could generate messages, images and videos in enormous quantities. A hostile organization could automate research across scientific literature. An attacker could produce customized phishing messages for thousands of targets.
None of these examples requires an AI system to possess consciousness or personal motives.
The danger comes from human intention amplified by automation.
A hammer does not decide what to strike, but it increases the force a person can apply. AI is far more versatile than a hammer because it can assist with language, planning, coding, research and analysis.
That versatility is precisely what makes the technology useful—and potentially dangerous.
Cyberattacks and Critical Infrastructure
Gates has also highlighted AI-assisted cyberattacks.
Modern societies depend on interconnected computer systems controlling hospitals, banks, communications networks, transportation, electricity and government services.
Cybersecurity specialists already use automation to detect vulnerabilities and protect networks. Attackers can employ related technologies to find weaknesses, write malicious code and adapt their methods.