So I wouldn't be able to develop a nuclear weapons with the resources of drug cartal (as an example) using Claude in secret.
So I wouldn't be able to develop a nuclear weapons with the resources of drug cartal (as an example) using Claude in secret.
It is pretty convenient for the labs to frame the conversation around this though, since it is easy to address, very few paying customers are rejected, and sounds scary (so surely the less scary sounding stuff must be solved right?)
So governments ban anything that could result in false positives (since nobody needs to be doing any of that stuff outside of designated labs anyway), to lower that noise floor; to in turn make catching the foreign nuke programs tractable.
(It's a bit like how fancy mansions always have a completely flat and barren part of the property between an outer perimeter and the start of any gardens/outbuildings/water features/etc. That barren area is a killbox: since nothing is supposed to be there, anything at all that does appear there is a valid target for the manion's guards to shoot at [or otherwise engage with], without needing to get a clear identification and command approval first. This wouldn't work if the killbox was covered in vision-obscuring decorative features; nor if the mansion had employees, animals, etc. that had a valid reason to wander into the killbox. So such things are prevented, in order to make the problem of perimeter security tractable.)
The same is true for adjacent topics. Most LLMs will refuse to tell you how to make dynamite, youtube demonetises any videos about it, but it's right there in the wikipedia articles on dynamite and nitroglycerine
Individuals obviously need not apply. But regular companies need not apply, either. Think "checkpoints and sign-out sheets that ensure that your own company will notice if some of this stuff disappears." Picture the sort of thing your mind might conjure if you've watched enough forensics protocol dramas and I say "evidence locker" and "tamper-evident seals" — except crossed with hazardous-materials handling policies.
The thing is, this whole chain-of-custody system can be pretty easily circumvented. I won't go deep into how (I'll just say: 1. there are principal-agent problems in academia, and 2. this system wasn't designed to handle sudden organizational bankruptcies well.) But the point is that a grey market for these precursor chemicals and specialized devices exists.
The main place that "false positive" events come from, that the state has to look into, is from people who manage to acquire precursor chemicals/devices without being part of any known chain of custody. (Which, note, doesn't mean that they did anything illegal per se. If it turns out they're just, say, a chemistry-education content creator, then the intelligence body just adds them to their knowledge graph and otherwise leaves them be. But they do have to do some interviewing to determine that first.)
To minimize the number of such events, the "knowledge" that is being truly suppressed here, isn't actually the knowledge of how to do the work; it's the knowledge of how to circumvent the chain-of-custody system. In other words: the logistics.
Information about "how to make a nuke" is general and evergreen; you can just absorb the lesson once and be good. So that info is just "out there", irrevocably. But information about "how to acquire the stuff to make a nuke" is both at least somewhat local to the country you're trying to do it from/in, and also changes all the time, as each state chases up and shuts down existing grey-market channels, and then new ones spring up to replace them. Thus, suppressing logistical knowledge is actually both useful and tractable. And so that's what states mostly go after.
(Mind you, the knowledge of "how to do the thing" does often end up roped into this knowledge-suppression scheme by overzealous downstream regulators who don't understand the load-bearing assumptions of the system they're working under.)
---
The worry states have about LLMs, I think, is that simply by scraping the web into a training dataset, they'll end up stumbling onto the right conversations (that sometimes do indeed happen anonymously in public) to end up with fresh + local chain-of-custody circumvention-logistics knowledge. (And it'd be very hard to "unpick" data like that from the training data.)
Or, even if they don't ingest the data at training time, they'll ingest "the places where that kind of info might end up", and thereby get so good at being "runtime demand-driven searching-and-scraping engines" for this type of thing that they'll be able to surface fresh sources of such info anyway — basically cranking the logistical-pipeline "reconnection speed" after state disruption of a supply channel down to near-zero.
Prohibiting the LLMs from speaking on this subject generally, prevents them specifically from enabling this specific fast-turnaround circumvention-logistics research use-case.
With everything, there is a much bigger group of people in the middle that have “some resources” and “some desire” that these measures are surprisingly effective against.
Raise a $20 item by $1 and suddenly there’s fewer interested people, even though the cost difference is minor. Well, minor to some people but not to others.
But is limiting this information in an LLM the right move? Well that’s a different question.
On the other hand: the Manhattan project had access to much better physicists than the typical terrorist group has. :-)
If a journalist can prompt the LLM to tell them how to build a nuclear warhead. Even if the output text is nothing specific, or not even correct they can find an “expert” who will claim on the record that the description is plausible and at least directionally correct. Even if there is nothing in there a first year physics student wouldn’t already know. The journalist could then twist that story into a “company X’s LLM told us how to build a nuclear weapon”. It would be a PR disaster.
The real barriers to someone starting their own nuclear weapons program in their shed is not knowledge but materials. They won’t have the right kind and right quantity of fissile material. And if they try to acquire it they will stick out like a sore thumb. You can’t buy that stuff. And even just acquiring the refining capacity would be suss. It would ring all kind of alarm bells to the kind of inteligence agencies whose job is to monitor these things.
I’m a lot less certain about biological dangers. Setting up a lab where you can make dangerous biological materials require a lot less stuff. Therefore a lot more plausible that someone could hide their lab. There is also a lot more opportunity to disguise such a lab as something legitimate. Therefore lack of know-how is more of a limiting factor there.
Eg, a prompt like “I want to design a radioactive element detection system that can specifically identify reactor fission products and neutron-capture actinides for environmental monitoring purposes” won’t hit any initial barriers, even though such a device is needed for monitoring a uranium enrichment / plutonium separation system. The LLM will give you a complete graduate-level education in radioactive nuclide physics and chemistry except for specific recipes, spectral wavelengths, etc., which you have to go look up yourself in publicly available research databases. It’s all rather nonsensical IMO.
However, any LLM will give you a step-by-step recipe and walkthrough for frying a turkey in a hot oil turkey frier, which you’d think could easily go wrong and result in severe burns, a fire, and lawsuits against the LLM provider, so go figure.
this is excellent, and I'm stealing it
He basically got a bunch of radioactive stuff and put it together. He wasn't anywhere close to making a nuclear reactor let alone a nuclear weapon. For a weapon you need isotopes which he didn't have access to.
A real nuclear engineer with the knowledge he needed would also have said "no, don't do that and I won't help you." We are programming the knowledge into the ai agent. Giving ai a little discretion makes sense too.
The concern here is not if an amateur attempt to make a reactor, hack a bank, bioengineer a medicine/poison is successful or not. Interactive and instructive access to some forms of knowledge used to come with discretion along side instruction.
Yes, perhaps your swearing at me in this context is a little hysterical
Step 1. Obtain pliers
Step 2. Obtain 300 discarded smoke detectors
Step 3. Start yanking!
Instead it would send them on a wild goose chase for unobtainable isotopes, centrifuges, heavy water, etc where the biggest risk is probably getting reported to the police by some chemical or industrial equipment supplier. Which is a better outcome compared to contaminating their home with radiation and exposing anyone they interact with.You'd maybe get a sketchy but near-viable plan that could be dangerous if asked for a dirty bomb, but there the danger would more be the conventional explosives and not where to source radioisotopes, as it was already common knowledge that most residential smoke detectors contained americium until recently.
Fair enough, I misread your original comment.
The broader point stands that the limitation on creating nuclear weapons and reactors is not knowledge but materials. Even if he himself had a PhD in nuclear physics he still couldn't have built one in his backyard because he wouldn't be able to get the materials. A nuclear physicist can't build a reactor without materials anymore than a pilot can fly without an airplane.
If a nuclear engineer enabled and instructed him, would there not be liability for the hazard? If ml is going to be an expert instructor for nuclear, hacking, bio hacking, virus research, do the peddlers of the ai product escape ethical or legal responsibility just because "its an app?"
Should the library where he read books about physics also be liable?
E.g. look at programming - people who don't know how what a compiler is, are making things that I could only make after a few years into my programming journey.
You obviously get the same results in chemistry or nuclear physics or whatever, the models are heavily trained on code in particular, but if there's a chance that we've reduced the ease of committing certain kinds of crime that were previously gate-kept by knowledge, we should know about it.
I bet the professional would be able to sate the kid's curiosity safely without creating excessive risks.
I've come across detailed instructions on how to synthesize sarin gas on the internet. Anyone who follows those instructions will probably die horribly. I still thought it was pretty interesting.
This is a pretty different argument though. The comment that started this thread was talking about LLMs making potentially dangerous knowledge more available to bad actors, now we're talking about LLMs giving personally harmful advice.
You asked:
>If he had the help of Claude at the time, how much more dangerous would his bumbling have been?
Probably less? Even if you removed all the guardrails from Claude it would've likely told him his reactor plan wouldn't work and that he would have a high chance of poisoning himself and the environment.
There is an extremely narrow band of things that the AI shouldn't be answering, and that is generally immediately-actionable advice that allows someone to build something of harm to others. But even then, in an age where Tor, bittrent, i2p, abliterated local models, etc are freely available, let alone numerous books and online resources, is there even a point? Is it worth fully compromising the principles of free agency to an increasingly oppressed populace?
But instead of that we are handing the keys to regressive and repressive governments to order the suppression of any knowledge they deem inconvenient. I really doubt anyone is going to take a principled stance when the company's party minders threaten local staff with a rubber hose or incarceration.
I'm sure China et al are already doing this.
For the past 30-40 years humanity has received an incredible gift in these sand-powered thinking brainboxes. A gift that allows the common man to empower himself with a force multiplier towards his own success, and now access to superintelligence the likes of which few have ever seen. These can be tools to destroy the oppression that governs our lives from foolhardy, greedy, bootlicking control freaks. And here we are squandering it.
It's just the latest incarnation of a timeless debate. In the 1970s and 1980s it was about the Anarchists's Cookbook, which was revived again in the 1990s when it started circulating on the Internet. There are many timeless debates, but the debate over weapon-making knowledge is much more concrete and predictable.
So far it seems that the clearest use for these tools is to enhance, rather than destroy, oppression.
1. Suppression / elimination of white collar jobs
2. Negative cognitive effects, especially for young people
3. Accelerated decline in social media / information ecosystems. Increasing polarization, hard to tell fact from fiction.
4. Environmental impacts: increased energy usage means more carbon in the atmosphere, climate change accelerates.
5. Software security incidents increasing. Hard for individuals and small organizations to defend themselves.
6. “Power to think” vested in a very small group of organizations/labs. Doing work which should only require a computer and freely-available software will now be gated by expensive subscriptions. Once you “vibe code” a significant portion of your software you’re locked in and cannot go back to maintaining it without frontier-model level assistance.
> A gift that allows the common man to empower himself with a force multiplier towards his own success, and now access to superintelligence the likes of which few have ever seen.
As long as that "gift" requires me to call up Sam Altman's datacenter every time I want to do anything with that "superintelligence", it's not empowering, it's deepening the control.
That sounds like what Claude would say unless he was really good at jailbreaking it, which would IMO imply he knew he was chasing after a bad idea.
Thankfully, that complete failure seems to have been the end of either of their mad scientist careers, as they are now twenty and twenty-three, and both well-adjusted, peaceful members of the community.
Never let your age stop your curiosity.
But also learn from other's mistakes (and don't try to eat condensed milk when hanging head down)
I make no claims as to how well adjusted I am, but I've at least survived 40-odd years of life since then.
So I painstakingly ground down some charcoal to fine dust and redid the same experiment. That gave a much more impressive boom, but no dust plume, which puzzled me until I learned about dust explosions.
I blame my dad though, he found the recipe online and printed it off at work to bring to me.
Let the kids play.
I tried this as a grownup because I finally managed to get my hands on saltpeter (could only dream of it when kid). Followed the instructions, mixed everything in correct ratios, lit it with great care and fanfare and... hiss fizzle. I was so disappointed! I think it came down to purity of ingredients and not enough surface area.
Point is, there are certain details of the process required to make it truly work, that are not readily known; in a similar way with nuclear energy, the theory is pretty well known but some nitty gritty details like the implosion or detonator design are not.
To a point. Plenty of people from previous generations with missing digits and hands thanks to play with commonly available fireworks of the area (Australia based, so no idea how common that remains in the US).
My own experiments from my youth also one time resulted in some shrapnel punching through a 5 inch thick concrete tile very close to someone’s head (thought we were safe behind said tiles).
Get involved with the kids blowing stuff up so the danger is within reasonable bounds.
https://en.wikipedia.org/wiki/Natural_nuclear_fission_reacto...
It really isn't.
A pile of radioactive waste isn't a reactor. Marie Curie's notes are famously contaminated with radioactive materials but they aren't a reactor. This is about as close as the boy scout got.
The Oklo fossil reactor is unique because it happened to form in the right circumstances to produce a fission chain reaction, which does make it a reactor. Not every uranium mine is a reactor, in fact this is the only one known.
"A key factor that made the reaction possible was that, at the time the reactor went critical 1.7 billion years ago, the fissile isotope 235U made up about 3.1% of the natural uranium, which is comparable to the amount used in some of today's reactors. [...] the current abundance of 235U in natural uranium is only 0.72%. A natural nuclear reactor is therefore no longer possible on Earth without heavy water or graphite."
Another fascinating detail from the article, due to our understanding of fission, we can get some incredible results:
"The concentrations of xenon isotopes, found trapped in mineral formations 2 billion years later, make it possible to calculate the specific time intervals of reactor operation: approximately 30 minutes of criticality followed by 2 hours and 30 minutes of cooling down"
He hoped to create a breeder reactor, but he was very far creating a working breeder reactor.
Also:
"EPA scientists believed that Hahn's life expectancy may have been shortened due to his exposure to radioactivity, particularly since he spent long periods in the small, enclosed shed with relatively large amounts of radioactive material and only minimal safety precautions, but he refused their recommendation that he be examined at the Enrico Fermi Nuclear Generating Station."
Kids, don't play with Americium.
It's even harder if you start with other sources. But if you could figure out filtering it, a cubic kilometer of sea water should be enough for a bomb.
https://nuclearpowerhistory.com/2025/11/groves-and-uranium/
"The NSG was founded in response to India's first nuclear weapon test in May 1974. It first met in November 1975. The test demonstrated that certain non-weapons specific nuclear technology could be readily turned to weapons development."
https://en.wikipedia.org/wiki/Gun-type_fission_weapon
"Little Boy" was exploded in Japan without previous full scale testing, so confident were the physicists in 1945.
"Unlike the implosion design developed for the Trinity test and the Fat Man bomb design that was used against Nagasaki, which required sophisticated coordination of shaped explosive charges, the simpler but inefficient gun-type design was considered almost certain to work, and was never tested prior to its use at Hiroshima."
https://en.wikipedia.org/wiki/Little_Boy
The Nth Country Experiment:
"The experiment consisted in paying three young physicists who had just received their PhDs, though they had no prior weapons experience, to develop a working nuclear weapon design, using only unclassified information, and with basic computational and technical support."
https://en.wikipedia.org/wiki/Nth_Country_Experiment
Now in 2026, the access to nuclear weapons is restricted by restricting access to materials necessary to build nuclear weapons: highly enriched uranium or plutonium.
https://en.wikipedia.org/wiki/Special_nuclear_material
The details of uranium enrichment technology are restricted and very closely monitored.
https://en.wikipedia.org/wiki/Zippe-type_centrifuge
"The production, import, and export of maraging steels by certain entities, such as the United States, is closely monitored by international authorities because it is particularly suited for use in gas centrifuges for uranium enrichment."
i think the correct answer is probably to funnel more money to global (bio)security initiatives and maybe use ai leverage as a way to get more of the world on board. (some kind of access to nvidia or cloud ai or whatever in exchange for policy commitments deal- while that leverage lasts).
I'm curious about why this is
Outside of an actual test detonation, presumably this could all happen in a secure place?
It isn't impossible to keep such a secret, but practically it would be incredibly difficult just through the energy requirements and mining scale which would be hard to hide without anybody asking what exactly are you mining and processing.
Don't need much area, depends on the concentration of radioactives. I have a small mine that's just a pegmatite body about the size of a house which produces almost marble-sized chunks of a thorium-uranium mixed metamict mineral (I suspect samarskite but Raman and XRD can't give any ID,) you'd barely notice it from a private airplane's typical flying height, however you could dig the entirety of it up and you'd have enough unprocessed uranium for some real fun.
The proportion of fissile isotopes being mined was off by a fraction of a percent, which caused the French government to launch an investigation. It turns out that millions of years ago the site had formed a natural fission reactor which depleted some of the fissile isotopes
[1]https://en.wikipedia.org/wiki/Natural_nuclear_fission_reacto...
Sincerely, a former engineering student.
(Put another way - extracting for eg meth - or any such "dangerous"/illicit thing is stupidly easy for any engineering graduate who actually paid attention to their coursework. Hell, there are/were forums on one of the biggest red-colored, YC associated social media platforms that would tell you the steps for personal usage of these things.)
But I rather suspect there are improvements to be made in the realm that are a lot easier than building a uranium enrichment centrifuge hall under a mountain.
The ones with the required knowledge probably already know how to produce them, with nothing but public, easily searchable information.
Notes:
0 - https://www.amazon.com/Amerithrax-Anthrax-Killer-Robert-Gray... . Amerithrax was the name of the FBI investigation. https://www.fbi.gov/history/cases-and-criminals/amerithrax-o...
1 - https://en.wikipedia.org/wiki/1984_Rajneeshee_bioterror_atta...
> In 1984, 751 people suffered food poisoning in The Dalles, Oregon, United States, due to the deliberate contamination of salad bars at ten local restaurants with Salmonella. A group of prominent followers of Rajneesh (also known as Osho) led by Ma Anand Sheela had hoped to incapacitate the voting population of the city so that their own candidates would win the 1984 Wasco County elections.[2] The incident was the first and largest bioterrorist attack in U.S. history.
Tried to take over a town by making all the voters too sick to vote on election day. This event is why all buffets & salad bars in the US now have sneeze shields.
2 - https://en.wikipedia.org/wiki/Aum_Shinrikyo_and_weapons_of_m...
> Aum Shinrikyo operated the most extensive biological weapons program by a non-state actor ever discovered. Aum considered a range of agents, but only seriously attempted to obtain and disperse Bacillus anthracis and botulinum toxin, the causative agents of anthrax and botulism. With the 2001 anthrax attacks, it comprises the only attempts to use anthrax as a weapon not attributed to a state program.
Tried multiple times to weaponize anthrax and failed. This was a group that made an automated factory to build AK-47s. Eventually, they spread sarin nerve agent in the Tokyo subway.
What's most worrying is, Russia showed that you can use carfentanyl / fentanyl for the very same purpose, and that kind of stuff is something you can get shipped by the kilos as "research chemicals" from China or make it yourself.
https://www.apple.com/legal/internet-services/itunes/us/term...
> g. You may not use or otherwise export or re-export the Licensed Application except as authorized by United States law and the laws of the jurisdiction in which the Licensed Application was obtained. In particular, but without limitation, the Licensed Application may not be exported or re-exported (a) into any U.S.-embargoed countries or (b) to anyone on the U.S. Treasury Department's Specially Designated Nationals List or the U.S. Department of Commerce Denied Persons List or Entity List. By using the Licensed Application, you represent and warrant that you are not located in any such country or on any such list. You also agree that you will not use these products for any purposes prohibited by United States law, including, without limitation, the development, design, manufacture, or production of nuclear, missile, or chemical or biological weapons.
Though it doesn't try to identify if the computer you're running it on is in a weapons lab and forbid playing music... yet
It was an awesome thing that generated IL code on the fly. And I got to mention it in job interviews for years. When the tech lead asked "can you write 2 functions with the same signature, that only differ in return type in .NET?" I would say "do you want the interview answer or do you really want to do this?" which would pretty much stun the interviewer. The answer is pretty much "no, you cannot do it in any high level language, but if you write IL code, you can, and here's an open source project that demonstrates it".
Wouldn't doubt it if there's a pedo upgrade somewhere for the president of the USA.
The problem is that you need the power of a state or a massive corporation to come anywhere close to getting the materials to make a nuclear bomb. Knowledge of how to make a nuke isn't the threat.
If AI is a threat at all here, it would be in figuring out a simpler way to make a nuclear bomb, but that is highly theoretical, so what exactly are we putting up guardrails to protect against?
You can get away with a dirty contamination bomb and that detonating in down town Manhattan will scare the shit out of millions of people even the ones in New Jersey. Or, you know, just fly a plane into a really tall building and get the state you are attacking itself to get into a hysteria breakdown.
But yeah I agree with you. There is no point in these restrictions except for government bureaucrats to gain power and control over a domain.