Preprint
Concept Paper

This version is not peer-reviewed.

Dangerous Knowledge and Medical AI: Why Technical Containment Is Necessary but Insufficient for Managing Dual-Use Risk

Submitted:

17 September 2026

Posted:

18 September 2026

You are already at the latest version

Abstract
Artificial intelligence systems deployed across medicine—drug discovery, diagnostic imaging, genomic analysis, epidemiological modeling, and clinical decision support—are trained on domain knowledge that carries both legitimate therapeutic value and dual-use potential. Prevailing AI safety practice relies on technical containment: refusal training, output classification, red-teaming, and access controls. This paper advances a bounded thesis: technical containment is a necessary but insufficient layer for managing dual-use risk in high-consequence biomedical domains, because reliable recognition of dangerous outputs requires expertise that is itself hazardous, concentrating insider risk within the very teams tasked with safety. This is not a claim that misuse is inevitable or that containment is futile; it is a claim about the limits of any single layer. The paper adopts a graded-risk model in which computational capability, tacit knowledge, materials, and infrastructure jointly determine real-world uplift, and it argues that these barriers differ substantially across domains and tools. It surveys dual-use research governance, AI safety methods, biosecurity institutions, and medical-AI regulation to locate the gaps, and proposes an operationalized, layered governance response—including explicit deployment-gating criteria for the highest-risk applications. The paper does not present novel empirical findings and identifies the empirical questions on which its practical implications depend.
Keywords: 
;  ;  ;  ;  ;  
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.