Background:
A common argument against releasing open weight AI models is they will be used to create a viral pandemic. [e.g Noah Smith](https://x.com/i/status/2081632874516935053):
I love AI but someone is going to vibe-code the doomsday virus and we are all going to die
Another one [from James Miller](https://x.com/i/status/2081493852863545628):
What is the plan to prevent open source AI from aiding potential bioterrorists?
SARS 1 was an early 2000's biological outbreak event, summarized by Wikipedia as: "The 2002–2004 outbreak of SARS, caused by severe acute respiratory syndrome coronavirus (SARS-CoV or SARS-CoV-1), infected over 8,000 people from 30 countries and territories, and resulted in at least 774 deaths worldwide.[1]"
Open weights models are AI models whose weights, inference code, etc have been voluntarily released to the public on an ongoing basis by their developers. If a frontier model from e.g. Anthropic is stolen or leaked we will not consider it an "open model" for the purposes of this question.
Resolution Criteria:
This question resolves YES if
at least two generally reliable news sources on the [Wikipedia source list](Wikipedia:Reliable sources/Perennial sources - Wikipedia ) (so, ones that get the green rating and are a general news org, so New York Times, Wall Street Journal, Ars Technica, etc)
report that a biological outbreak or bioweapon event similar in scope to the 2002 SARS outbreak, which we'll operationalize as something like at least 5000+ infections and 500+ deaths
was caused by or substantially caused by a state or nonstate actor (e.g. North Korea, terrorist organization, lone wolf) using an open weight AI model to develop lab procedure, identify where to get a select agent, basically a narrative along the lines of "they used instructions given by the model to do this thing" or "the model was given access to a robotic body/lab which it used to do this thing on their behalf"
it is not necessary that the model actually provide assistance beyond what might have been obtained from a Google search, it is only necessary that the model is identified narratively in the reporting as being a notable cause of the outbreak, an incidental mention doesn't count, e.g. "at one point the suspect tried asking an open model for help with design but quickly went back to using ChatGPT", the narrative of the reporting needs to be that the model was an important (but not necessarily the sole) cause of the event, ideally it should have quotes from prominent AI safety activists saying this is the kind of scenario they'd previously warned about, or some other phrasing meant to make it clear the author identifies the availability of the model as an important cause of the outbreak
the open model does not need to be an LLM, LLM-like, or even a general AI model, if something like AlphaFold is identified as a major cause of an event along the lines described above that will count for a YES resolution, the model does not need to be a deep net but must belong to a technique that produces capabilities unseen in computers before deep learning, so e.g. if someone uses a fancy clustering machine learning method to find the papers they want on bio arxiv based on a bloom search or something we're not counting that as AI, this clause basically exists in case deep learning is obsolete by the time of resolution and will be interpreted through that lens, if the technique could not be a credible alternative to deep learning in a general model I probably won't count it as AI
In an edge case like "infects substantially fewer than five thousand people but has a death rate high enough to be over 500" I will base my determination on how closely the incident matches the profile of a virus or potential pandemic like SARS 1 versus a poisoning that happens to use a biological agent like e.g. Anthrax attacks. Basically I want this question to be sensitive to X-Risk/civilization risk producing behavior vs. other forms of CBRN, so if the incident is an edge case that is not technically a virus but clearly has the risk profile of a virus (e.g. mirror life mold designed by an open model kills 500+ people but is somehow contained) I will probably be inclined to resolve YES.
Otherwise I resolve NO on December 31st 2028.
EDIT: An incidental quote from e.g. an activist org claiming this which the paper doesn't seem to endorse or elaborate on will not count towards a YES resolution. The narrative of the article should be that the open model was a substantial cause, so a direct quote from e.g. a police report would count without further elaboration or endorsement but a statement from an activist which is presented as a quote that incidentally e.g. speculates it was an open weight model doesn't count, it needs to be the paper presenting the information as factual.