1. They may be trained, in theory, to inject subtle back-doors into certain kinds of generated code.
2. They may be also trained to include back-doors when deployed in public-facing services where user can provide text or image input.
3. Chained with (2) they may be also trained to exploit their inference environments, which though a big feat, not outside the capability of nation-state hackers.