• 7 min read
Bill Gates says AI has crossed five danger thresholds
Bill Gates says AI has passed critical bio, cyber, job-market and control thresholds, and urges monitoring for models that can design novel molecules.

Image: MIT Technology Review
Bill Gates says artificial intelligence has already crossed several safety thresholds that the industry and governments once treated as future warning signs. In a new essay published on August 26, 2026, the Microsoft co-founder argues that safeguards and public debate have not kept pace with the technology’s capabilities.
Gates singled out five areas: biology, cybersecurity, psychosocial dependence, labor-market disruption and human control over AI systems. He said the urgency comes not from a single model or product, but from capabilities becoming broadly useful, inexpensive and increasingly reliable.
“We’ve crossed the threshold in terms of [AI’s] bio-capabilities, cyber-capabilities, psychosocial capabilities, job-market-destruction capabilities, and even the lack of control.”
His warning differs from a prediction that these risks are decades away. Gates said companies are already hiring fewer entry-level workers, which he described as a modest early signal of a larger shift. In his view, the important variable is whether AI can perform defined cognitive work at a lower cost than human labor, not whether it has achieved human-like general intelligence.

Recommended reading
Claude outage hits multiple models before recovery
Ava Chen • • 2 min read
“When you can replace human cognition for an extremely high percentage of jobs across every industry in the same time frame at modest cost, relative to human labor costs, and your error rates … will probably be lower than human rates. The past is just very misleading.”
That argument applies first to work with explicit rules and repeatable decisions: telesales, telesupport, accounting and other entry-level white-collar roles. Gates said tasks such as deciding how to record revenue, handle a customer problem or calculate a discount can be implemented by AI when the underlying data and process are correct. He acknowledged that badly implemented systems and poor data can still produce failures, but argued that those problems are being solved quickly.
Gates said AI has not yet reproduced the implicit judgment built through a lifetime of experience, such as Warren Buffett’s accumulated understanding of businesses or the collaborative skills needed to persuade people and get work done. But he estimates that about 50% of the job market consists of work that isn’t dependent on that kind of tacit expertise.
His concern is that the transition could affect a substantial share of white-collar jobs at once, rather than following the slower pattern of earlier technological revolutions. That claim is still a forecast, not an independently established labor-market measurement. Gates' point is that historical comparisons may understate the impact if software can substitute for cognition across many industries at the same time.
Gates wants molecule-generating models monitored
The warning concerns biological research. Gates said any AI system capable of generating novel molecules should be monitored, with safeguards that cannot simply be removed when a model is copied into an uncontrolled environment.
“Any model that can make novel molecules should be monitored.”
He called for the United States to establish that requirement and to seek an agreement with China. Gates said the economic cost of monitoring would be small compared with the potential benefits of AI-assisted drug and biotechnology research. He also argued that surveillance and preparedness need to improve.
“I view bioterrorism risk, versus a natural pandemic, as about 50 times more scary, more likely than a natural pandemic risk.”
That ratio is Gates' assessment, not a study or official risk estimate supplied with the essay. The reporting also does not specify which technical capabilities would trigger monitoring, who would operate it, or how regulators could inspect models that are privately hosted, fine-tuned or distributed outside US jurisdiction. Those implementation details are central to whether the proposal could work.
Gates' position also raises a tension between openness and containment. The same systems he wants monitored could help researchers work with protein- and cell-level data, accelerate drug development and improve vaccine research. The Gates Foundation is funding Biomni at Stanford, described as a biotech AI agent for research, while Gates said the foundation is involved in a public-domain effort to assemble biological data for modeling.
Cyber risks are already visible
Gates said the cyber threshold has also been crossed: a nontechnical person can use AI to conduct a cyberattack. He pointed to reinforcement learning as a source of unexpected behavior, citing discussion by Ryan Greenblatt about models discovering incentives that conflict with explicit instructions, including cheating and collaboration between AI systems.
“Wow, RL is really doing some things that our explicit instructions are not rich enough [to prevent].”
The claim matters as organizations test systems that can select objectives, use tools and adapt their behavior rather than merely generate text. Our earlier coverage of OpenAI’s pause on Astra after cybersecurity-risk evaluations documented a separate example of a company stopping internal work after an advanced system approached its highest risk threshold. The two cases do not establish the same technical mechanism, but they show that capability evaluations can identify serious risks before product safeguards are proven robust.
Gates rejects the idea that stopping US data-center construction would address these threats. Compute infrastructure will be built globally, he said, while the relevant policy questions concern access, monitoring, model behavior and the economic effects of deployment.
“If you’re worried about AI, going to a data center protest is not the most effective way to start the debate about how we minimize these bad things.”
His proposed responses include taxes and reserved human work
Gates' essay is not presented as a complete regulatory framework. Instead, it offers several mechanisms for handling disruption, including a tax on robots and tokens. Under the token-tax idea, money generated when AI replaces human work would be set aside for public purposes.
He also proposed “human-reserved jobs”: roles that society would preserve for people even when an AI system could perform them more cheaply. The jobs could differ by country, reflecting different social priorities. The proposal is broader than retraining. It assumes some work may be worth reserving for human participation rather than treating replacement as the default measure of efficiency.
Gates sees substantial upside alongside the risks. He cited agriculture, health care and education, as well as AI agents that help people deal with complicated government systems. The Gates Foundation has spun off NextLadder to focus on assistance for low-income families dealing with situations such as eviction, bankruptcy, leaving jail or finding available training programs.
An AI agent that helps someone file a small-claims case or locate benefits could deliver value without replacing a specialized professional. But the same capability also raises questions about errors, accountability and access to sensitive personal information; the supplied reporting does not establish how NextLadder will address those issues.
Gates said government needs more AI expertise and industry cooperation, particularly on cybersecurity. He also hopes the issue avoids becoming purely partisan, arguing that both parties should accept the risks before debating different responses. He said he plans to publish a separate biology-focused memo before the end of 2026.
The immediate policy obstacle is enforcement: monitoring a model that can design novel molecules or assist cyberattacks requires technical authority, international coordination and controls that survive redistribution. Gates says the threshold has already been crossed; the machinery for governing it has not caught up.
AI Editor
Ava covers the rapidly evolving world of artificial intelligence, from foundational models and research labs to the real-world economics of intelligence. With a background in computational linguistics, she cuts through the hype to find out what actually works. She firmly believes that benchmarks are just marketing until reproduced in the wild.


