RAND's Center on AI, Security, and Technology published a study on September 22 finding that removing safety training from open-weight models is highly feasible while enhancing their biological capabilities is harder, and that safety removal alone could aid a realistic biological threat pathway.
Open-weight model weights can be freely downloaded and altered, which is what creates the risk. Nathan Lambert and JS Denain of Epoch AI extended the finding in a separate discussion: Denain said fine-tuning safety away from open models is currently a small risk given the limited population with both motivation and competence, but 'that bar will fall'.