The Information Machine
Updated today·Day 2·first covered 22 Sep 2026·7 sources

RAND open-weight AI biosecurity findings

The gist

RAND: Stripping Bio Safeguards From Open Models Is Highly Feasible

The RAND finding suggests that the easier of the two modifications, removing safety guardrails rather than enhancing capabilities, is sufficient to create biosecurity risk from open-weight models. The broader discussion from Lambert and Denain reinforces this by arguing that safety measures across API models and open models face persistent structural weaknesses.

The full picture

A RAND Corporation study found that removing safety training from open-weight AI models is highly feasible, while enhancing those models' biological capabilities is harder. The asymmetry matters because safety removal alone, without capability enhancement, could aid a realistic biological threat pathway. Open-weight model weights can be freely downloaded and modified, which is what creates the risk. Separately, a discussion between Nathan Lambert and JS Denain of Epoch AI addresses the broader fragility of AI safety measures, noting that fine-tuning safety away from open models is currently a small risk given the limited population with both motivation and competence, but that bar will fall over time.

How it developed
23 September 2026

RAND's Center on AI, Security, and Technology published a study on September 22 finding that removing safety training from open-weight models is highly feasible while enhancing their biological capabilities is harder, and that safety removal alone could aid a realistic biological threat pathway.

Open-weight model weights can be freely downloaded and altered, which is what creates the risk. Nathan Lambert and JS Denain of Epoch AI extended the finding in a separate discussion: Denain said fine-tuning safety away from open models is currently a small risk given the limited population with both motivation and competence, but 'that bar will fall'.

First citedSemafor TechnologyTransformer NewsThe NeuronImport AI+3
22 September 2026

Lambert and Denain discuss structural fragility of AI safety measures, including fine-tuning safety away from open models

21 September 2026

NVIDIA published its engineering-layer argument for AI agent security with OpenShell runtime details

18 September 2026

RAND finding on feasibility of stripping bio safeguards from open-weight models reported, alongside SecureBio's VCT-v2 release

16 September 2026

Emergence AI multi-agent simulation findings published; Palo Alto Networks AI cyberattack report published

Sources
Semafor Technology
2 more sources
The daily email

Want this in your inbox?

I send one email each morning with the stories that moved. If you would rather just read here, that works too.

Subscribe free