The White House's Real AI Fears: Cyberattacks, Not Killer Bots
White House tech chief Michael Kratsios explains which AI risks the administration takes seriously and which fears he sees as overblown.

What AI risks does the White House actually worry about?
According to Michael Kratsios, director of the White House Office of Science and Technology Policy, the administration’s current risk list has two main entries: cyber risk from increasingly capable models, and biological risk from models that could eventually help someone design a bioweapon. Everything else in the public AI safety debate, in his framing, gets weighed against those two before it earns serious policy attention. Kratsios made these comments during a conversation about the administration’s AI strategy, distinguishing between risks he considers live and present versus ones he thinks have been overstated for years without materializing.
TL;DR
- Cyber risk tops the list because increasingly capable models can both find and exploit software vulnerabilities, and the same capability that makes a model dangerous also makes it useful for defense.
- Bio risk is treated as real but overblown so far, with Kratsios noting that warnings about AI-enabled bioweapons have circulated since roughly 2021-2022 without a materialized incident, even as the government keeps building testing infrastructure for it.
- Dual-use capability is the core policy headache: a model that can strengthen a company’s cybersecurity is functionally close to one that could be used to attack it, which makes clean bans hard to write.
- The administration avoids hard thresholds like fixed compute caps, arguing that rigid rules set today get outpaced by model capability within months and are politically difficult to revise once written.
- The EU AI Act is cited as a cautionary example, a regulatory framework finalized before ChatGPT existed that now has to be stretched to cover large language models it wasn’t designed for.
- Open-source and open-weight models remain a stated priority, with the administration’s AI Action Plan explicitly backing a mixed closed and open ecosystem rather than restricting open weights.
- Risk policy gets made through federated agency coordination, not a single White House office, because the US has no dedicated technology department the way it has a health or defense department.
Built like a system. Not vibe-coded.
Remy manages the project — every layer architected, not stitched together at the last second.
How does the White House decide which AI risks are real?
Kratsios described a rough triage: look at what frontier labs are already testing for before releasing a model, and calibrate government attention to match. He pointed to the release of Anthropic’s Claude model line (referred to in the conversation as “Fable” during discussion of a specific release) as an example where labs had to evaluate what guardrails were needed before shipping, particularly around cyber capability. That lab-level evaluation process, in his account, is effectively doing risk triage before regulators get involved, and the government’s job is to make sure the testing and evaluation infrastructure keeps pace with what models can do “past the frontier.”
This is a narrower and more pragmatic framing than the broad “existential risk” conversations that dominated AI policy discourse in 2023. Instead of trying to legislate against speculative future harms, the approach described here focuses on capabilities that are demonstrably emerging now: models that can identify software vulnerabilities, write exploit code, or in principle assist with dangerous biological research.
Why is cyber risk considered the most urgent AI threat?
The reasoning is straightforward: as models get better at general reasoning and code generation, they get better at both attacking and defending software systems. Kratsios called this an inherent trade-off rather than a problem with a clean fix. A model good enough to identify a zero-day vulnerability is also good enough to help a security team patch it first. That dual-use nature means the policy conversation isn’t about banning capable models, it’s about deciding what guardrails should sit around them at release, who tests for misuse potential, and how quickly that testing can adapt as models improve.
This matters for anyone building on top of frontier models. Cyber capability testing is increasingly a standard part of how labs evaluate models before release, and that testing regime, not new federal legislation, is currently doing most of the practical risk management work in this area.
Is the bioweapon risk from AI overblown?
Kratsios thinks so, at least for now. He noted that concerns about AI models enabling bioweapon design have been circulating since around 2021-2022, and in his view the threat hasn’t materialized in the years since. That said, he didn’t dismiss the category entirely. The administration still wants testing and evaluation infrastructure built for bio risk specifically, treating it as a risk “coming over the horizon” rather than one to ignore. The distinction he’s drawing is between a risk worth building institutional capacity for and a risk urgent enough to justify hard restrictions on model development or release today.
This is a notable position because bio risk has often been treated in AI safety circles as one of the more severe catastrophic scenarios, alongside cyber risk, in frontier lab risk frameworks. Hearing a senior White House official describe it as overblown, while still funding the infrastructure to monitor it, reflects the administration’s general preference for capacity-building over prohibition.
Why doesn’t the government just set hard limits on powerful models?
Seven tools to build an app. Or just Remy.
Editor, preview, AI agents, deploy — all in one tab. Nothing to install.
Kratsios argued that fixed thresholds don’t survive contact with a fast-moving field. He pointed to two examples. First, the EU AI Act, finalized before ChatGPT existed, which now has to apply rules written for a pre-LLM world to the current generation of large language models. Second, the prior US administration’s approach under Biden, which set a specific compute threshold above which developers had to make disclosures to the government. In Kratsios’s telling, thresholds like that “do not stand the test of time” because capability keeps moving past whatever line was drawn, and once a government sets a line, it’s politically difficult to revise it later.
The alternative approach favored here is closer to continuous evaluation: testing models as they’re released, adjusting guardrails based on what labs and independent evaluators find, and avoiding legislative language that locks in assumptions about capability that may be obsolete within a product cycle.
Where does open-weight AI fit into the risk conversation?
Open weights came up directly in the discussion because of a wave of concern in the startup and open-source community that the administration might be preparing an executive order restricting open-weight model releases. Kratsios pushed back on that, saying the administration’s position hasn’t changed since the AI Action Plan was published in July of last year: a commitment to supporting both closed and open-source AI development. He framed open weights as compatible with the broader risk framework, arguing that a healthy AI ecosystem needs both closed frontier labs and an open-source layer, and that restricting one doesn’t obviously reduce cyber or bio risk if the underlying capability still exists in closed models.
The episode also illustrates how AI policy actually gets shaped: not through a single top-down decision, but through public pressure, industry letters, and direct conversations between builders and officials, which Kratsios described as a healthy and necessary part of getting the balance right.
Frequently Asked Questions
What are the two biggest AI risks according to the White House?
Michael Kratsios named cyber risk and biological risk as the two primary concerns currently shaping AI policy discussions, with cyber risk treated as the more immediate and active concern.
Does the White House think AI bioweapon risk is a serious threat?
Kratsios described it as an area worth building testing and evaluation infrastructure for, but characterized the alarm around it as overblown given that warnings have circulated since 2021-2022 without a materialized incident.
Why doesn’t the government set firm rules on AI capability thresholds?
Officials argue that fixed thresholds, like specific compute caps, get outpaced by how quickly model capability advances, and pointed to the EU AI Act as an example of regulation finalized before large language models existed.
Does the White House support open-weight AI models?
Yes. Kratsios said the administration’s AI Action Plan, released in July of the prior year, explicitly supports a mixed ecosystem of closed and open-source AI development, and that this position has not changed.
How does the government evaluate whether a new AI model is risky?
Risk evaluation currently leans heavily on frontier labs’ own pre-release testing for dangerous capabilities like cyber exploitation, with government policy focused on building evaluation infrastructure that can keep pace with model improvements rather than imposing fixed rules in advance.

