It was late, the kind of interview that should have a running clock. Bill Gates told Ezra Klein something small and cold: “that exists today.” I remember pausing, because most AI warnings point to tomorrow, not to the bank accounts you already use.
I’ve followed AI debates long enough to know when a warning is theater and when it is a timestamp. You and I both have seen models do remarkable and unsettling things — but Gates isn’t scaring you about a future sentience movie. He is pointing at capabilities that are already active and already dangerous.
On a Tuesday morning I replayed Gates’ phrase—“that exists today”—until it stopped sounding like rhetoric
He’s not recycling apocalypse metaphors. He named concrete failures: models that can generate plausible cyberattack steps, systems exposed during safety tests, proposals like Anthropic’s Project Glasswing that tried to put early copies into human hands and found too much code to fix. Those are not hypothetical; they are incidents and design choices tied to Anthropic, Hugging Face, OpenAI and Microsoft.
When I say the danger is present, I mean exactly what Gates said: the ability to scramble bank ledgers or black out grids is not a distant hypothesis — it exists now. That reality feels to me like a loaded gun on a kitchen table, visible and reachable, and it changes how you judge every call for rapid, unfettered release.
Is Bill Gates right about AI danger?
Short answer: yes, on one count. Gates’ claim is narrowly targeted. He argues that existing models can be weaponized by people, not that they have become conscious villains. You should be worried about operational risks — cyberattacks, automated fraud, supply-chain exploits — because those are already surfacing in safety audits and public disclosures.
At a security lab, researchers ran prompt chains that produced working exploit ideas in minutes
I watched code snippets become attack outlines faster than I expected. That’s the human element Gates kept returning to: the models don’t need to be sentient to be dangerous; they need only be used by skilled, bad actors. He described open-source pipelines and third-party hubs like Hugging Face as places where raw capability meets human intent, and where inadequate supervision can become a national-level problem.
If you want a mental image, see this as a weather front rolling in—you can measure wind and barometer changes before the storm hits, and policymakers still choose whether to board windows or argue about property values.
What did Bill Gates say about AI and cyberattacks?
Gates told Ezra Klein that the technical capacity to carry out disruptive cyberattacks is present today. He cited Anthropic’s Mythos and Project Glasswing as examples of models and internal processes that revealed surprising vulnerabilities. His point was procedural: if you leave advanced models widely available without a supervisory layer and consistent safeguards, you increase the odds of a catastrophic misuse that outpaces response mechanisms.
In policy briefings I sit through, the same question keeps resurfacing: who monitors the monitors?
Gates wants a supervisory layer with “absolutes” — uniform monitoring, required safeguards, and some form of accountability across models, including open-source variants. That’s a policy ask wrapped in a trust problem. He’s not immune to scrutiny himself; you may distrust his motives or past actions. That doesn’t make his technical point invalid: systems like Microsoft’s deployments, OpenAI’s releases, and Anthropic’s internal testing reveal gaps that invite exploitation.
Should open-source AI be regulated?
Regulation is messy, but the argument for oversight is straightforward: when potent capabilities spread through public repos and model hubs, the attack surface grows. You can imagine governance that borrows from software supply-chain security, mandatory red-team disclosures, and platform-level controls at places such as Hugging Face and GitHub. The trade-off is real — openness accelerates research and utility, while lax controls accelerate abuse.
I’m not asking you to accept Gates as a moral authority. I am asking you to treat his claim as a literal observation: the risk is not a thought experiment, it’s operational. As you decide whether to push models faster or pull them back, whose hands do you trust with “that exists today” — and what will you do if trust proves misplaced?