There are different routes to harm.
A person can use AI deliberately for a harmful purpose. A system can pursue an objective in ways that conflict with legitimate intentions. An institution can deploy a system that performs precisely as desired while imposing unacceptable consequences on the people affected.
Better instruction-following cannot solve all three.
Anthropic’s September 2026 threat report describes activity it disrupted between December 2025 and August 2026 involving cyber operations, surveillance, influence operations, fraud, and other misuse. Its selected cases document harmful applications beyond hypothetical future scenarios. [20]
The deeper question is whose intentions count.
A system that faithfully serves its operator may still harm someone else. “Aligned with human intentions” therefore needs an accompanying question: which humans, pursuing which purposes, under what constraints?
At the more extreme end, the International AI Safety Report 2026 examines scenarios in which systems operate beyond anyone’s control and regaining control becomes prohibitively difficult or impossible. It records substantial disagreement about the likelihood of such outcomes, including the most severe possibilities. [21]
Published in February, it assessed the systems then available as lacking the capabilities for those scenarios, while noting progress in relevant areas, including autonomous operation. The summer incidents document narrower failures of containment; they do not establish that the report’s most severe scenarios have occurred. [21]
We should not need certainty of catastrophe before addressing a credible danger.
We also should not make catastrophe the only harm worth discussing.
Surveillance, deception, coercion, and dependency can damage human lives without a machine becoming an independent adversary.
Responsible conduct by many organizations cannot cancel the consequences of a dangerous deployment elsewhere.
That is the serious concern inside the observation that it may take only one bad actor or one badly controlled system.
Malicious intent alone does not create unlimited power. Consequences depend on capability, access, resources, vulnerable targets, and the defenses in place.
The practical concern is that a small number of failures could impose substantial costs on people who never agreed to take the risk.
A credible safety strategy needs to accommodate misuse, error, and failures of coordination. Universal goodwill is too weak a foundation.
The existence of irresponsible actors also cannot become a universal justification for our own escalation. “Someone else might do it” leaves the central questions unanswered: what evidence supports this deployment, what consequences can it cause, and what remains under control?
Useful safeguards make harmful activity harder, improve detection, limit consequences, and preserve the ability to respond. Their value does not depend on achieving perfect compliance everywhere.
The standard should be whether they meaningfully reduce risk.
Otherwise, the people and organizations willing to move fastest can end up deciding how much risk everyone else carries.
Military and policing applications bring the question of authority into especially sharp focus.
Military AI includes logistics, analysis, decision support, cyber operations, and autonomous weapons. The International Committee of the Red Cross distinguishes these applications. It recognizes potential assistance with humanitarian-law compliance while warning that automation bias and time pressure can lead people to rubber-stamp machine recommendations. [22]
The transition from software assistance to physical capability also appears in reported misuse. Anthropic describes a guided-rocket test that appeared to fail; it found no evidence that those actors fielded an operational device. A separate drone project involved simulation and real-hardware testing, with a design for selecting targets, including people, without human approval of each engagement. [20]
The ICRC has called for prohibitions on unpredictable autonomous weapons and those designed or used to target humans directly, alongside restrictions on other autonomous weapons. Its FAQ presents these as proposals for additional legal limits. [22]
The underlying questions extend beyond whether a system can classify a target accurately.
Who authorized the action? What uncertainty remained? Could the decision be challenged before its consequences became irreversible? Who is answerable afterward?
For policing, similarly consequential questions concern the legitimacy of an intervention, the reliability of its basis, and an affected person’s ability to challenge it.
Machine capability can inform these decisions. It cannot, by itself, establish legitimate authority.
