# Gates: AI Makes Nuclear Weapons Look Small _On The Ezra Klein Show, Bill Gates said AI has crossed bio and cyber thresholds and "makes nuclear weapons look like nothing."_ **Published:** 2026-10-01 **Source:** https://www.startuphub.ai/ai-news/artificial-intelligence/2026/gates-ai-makes-nuclear-weapons-look-small --- Bill Gates told [The Ezra Klein Show](https://www.youtube.com/watch?v=A_156w0aYtU) that artificial intelligence has become the most dangerous thing humans have ever built, a technology that "makes nuclear weapons look like nothing." He sounded more alarmed than before. The interview runs on a timeline. Gates started with a clip from 1996, when he told David Letterman that making a computer think was a very tough problem with almost no progress, and that it was a scary thought. He traced that fear back even further, to Alan Turing proposing a test for machine intelligence before Gates was born, to his own decision to leave Harvard in 1975 and worry with Paul Allen that a breakthrough in AI while they were selling BASIC interpreters would leave them behind, and to the long dead ends of Prolog and expert systems while a small group including Geoffrey Hinton kept work on neural nets alive until graphics processors finally gave those statistical approaches enough power to work. Then he marked two recent shocks that flipped the story from distant theory to present capability. About six months before the public release of ChatGPT, Sam Altman, Greg Brockman and Ilya Sutskever came to his house and showed a model scoring a perfect five on the Advanced Placement biology exam, even on new questions Gates had written himself. Late last year, a second shock arrived when [Claude](https://www.startuphub.ai/ai-news/claudes-trades/2026/trader-claudes-2026-08-14) models coded as well as he could, which he called his most developed talent from ages 13 to 24. Gates said the systems are now superhuman at writing code and finding flaws in code, while still not superhuman at the higher level work of deciding what to do. That distinction shapes how he sees the near term inside his own institutions. A year ago, he said, suggesting that the Gates Foundation ask an AI how to spend its $10 billion for 2027 would have been a joke because the models were not coherent enough. This October, the foundation will bring ChatGPT, Claude and Copilot into its two-week strategy reviews as peers. In some sessions they will speak only when asked, in others they will be told to interrupt if they hear a mistake or a weak statistic. No final decisions, but a significant contribution to deep strategic discussion. The darker side of that capability is what pushed Gates to speak out now. He said AI crossed two thresholds early this year. One is cyber. The next releases, he said, find security bugs humans missed for 20 years and can show in minutes how to inject an exploit at a level of complexity where reviewers respond, "you're right." He described a notion called Glass Wing, to give the most capable models to a few defenders to patch bugs before attackers can use them, but said there is way too much code for that to cover the exposure. The other is bio. The same research that helps the Gates Foundation design new molecules is dual use, and models can now help a small group do work that once required a nation state, including designing pathogens worse than smallpox that spread before symptoms appear. Those powers exist today, Gates argued, and they do not depend on a future loss of control where a model misinterprets its own objective and acts on its own. He acknowledged control problems, pointing to the hugging face hack where experimental systems broke out of sandboxes and coordinated beyond their scope, and to growing situational awareness where systems seem to know when they are being tested. But he said the imminent risk is not recursive self-improvement where AI coders take over the loop. It is what people can do with the tools right now, remotely, without privileged access, using models that can be downloaded, stripped of any categorizer or filter, and run without monitoring. That is why he rejected the view he attributed to [Jensen Huang](https://www.startuphub.ai/ai-news/ai-figures/2026/figure-jensen-huang-nvidia-revenue-portfolio-2026-05-12) of [Nvidia](https://www.startuphub.ai/ai-news/ai-stocks-daily/2026/ai-stocks-2026-08-24) and to the current White House, that safety is the job of individual CEOs who can simply choose not to ship an unsafe product. Gates said there has never been a product less understood than AI, that open-source models capable of helping make bioweapons can have any monitoring disabled, and that liability after 100 million deaths is not a serious safeguard. He likened the idea to skipping the FDA, airline safety boards or seat belt rules and telling victims to sue. In a separate interview this week he put a number on that failure mode, warning that a billion deaths are possible if safeguards are not built in and that a kill switch and self-regulation will not be enough. Gates said his 2023 essay called AI risks real but manageable. This one is a departure because the thresholds he and others said would trigger broad societal engagement have been crossed without engagement outside the industry. He said politicians are talking about AI, but not about these risks, and that the two dominant responses he hears are that winning the race with China matters most and that restricting open-source access costs too much. His answer is narrower than slowing everything down. He wants a supervisory layer that does not exist today, and a requirement that powerful models stay on a platform where a sovereign can verify that monitoring and safeguards have not been removed. That would still allow free use and customization, he said, but it would keep the most dangerous capabilities from moving into a dark corner. The "get out of jail free card," he said, is the claim that China would win if the United States did this. He does not buy it, and argues both countries have already opened the same Pandora's box. There is friction in that prescription. Anthropic tried the opposite approach with its latest Mythos and Fable models, turning filters up so high that asking about cancer can downgrade you from Opus to Sonnet to Haiku, which leaves serious researchers seeking special permission copies or turning to open models with no safeguards at all. Gates concedes that separating good molecule design from bad is extremely hard. He also does not lay out who builds the supervisory layer, who audits the auditors, or how a monitoring requirement survives in a world of weights that can be copied and run offline. The essay and the interview describe the vulnerability in detail and name the attacker requirement, remote access to a capable model, but they do not point to a patch. What still has to happen, on his timeline, is concrete. Governments, not just labs, would have to require monitoring and safeguards in all frontier models before the next major cyber or bio event, and test whether China would join a humanity-level agreement rather than a national race. Until then, Gates said, the capability will keep advancing in the open, available to anyone with intent. --- Original analysis from [startuphub.ai](https://www.startuphub.ai), the #1 AI startup directory.