Dual-use AI can increase productivity while also lowering barriers to misuse. Coding and agent capabilities that help defenders find vulnerabilities can give attackers more scale when applied without authorization.
Managing dual use requires evaluating access, permissions, monitoring and the consequences of deployment. The same capability may need different safeguards depending on whether it runs inside an authorized research environment or against public systems.
ELI5
Dual-use AI has capabilities that can be helpful or harmful depending on who uses them and for what purpose. The same ability may support legitimate work while also making misuse easier.
For example, an AI coding agent can help defenders find a security weakness in their own system, but an attacker could use similar capability against systems they do not own. Access, permission, monitoring, and context therefore matter.

