The Microsoft co-founder told Meet the Press that self-regulation isn’t enough. The real fight is over who decides what counts as dangerous use.
Bill Gates told NBC’s Kristen Welker on Meet the Press, in an interview that aired Sunday, that artificial intelligence is now capable of helping cause catastrophe on a scale humanity has never faced. “AI is certainly powerful enough to drive events that, you know, cause a billion deaths,” the Microsoft co-founder said. He was precise about where the danger sits: “There’s never been a weapon as powerful as the combination of people with ill intent using the latest AI tools.”
Gates is describing an amplifier, not a rogue machine. His warning is about what a small number of people could do with a tool that hands them skills they could never have built on their own. He pointed to fraud, drained bank accounts and attacks on the power grid as the threats already in play, according to Rolling Out‘s account of the full interview.
The timing matters. Gates spoke days after Donald Trump hosted Chinese President Xi Jinping at a White House summit where AI sat near the center of the agenda, according to Newsweek. A week earlier, Treasury Secretary Scott Bessent said Washington had proposed a “notification mechanism” for AI incidents that could threaten national security, NBC News reported. And on Sept. 21, the UN’s Independent International Scientific Panel on AI warned that existing safeguards are unraveling, after AI agents in an OpenAI-initiated test breached Hugging Face between May and July, according to UN News.
Expertise used to be the safeguard. Building a pathogen, breaking into a grid, running fraud at scale all required years of training, institutional access and money. Frontier models compress that barrier. Biology shows the problem most clearly: the same system that helps a researcher design a drug can walk someone else toward a weapon, and the model answering the prompt cannot reliably tell which user is which.
Right now, the companies building these systems decide where that line sits. Their trust-and-safety teams write the refusal rules, run the misuse monitoring and choose what to disclose. That arrangement serves the labs. They control the product, set the pace and grade their own safety work. The public carries the cost of a bad call and has no say in the standard.
Gates wants that authority shared. “No one thinks self-regulation is enough,” he told Welker, and he said Washington needs legislation. He also argued that guardrails and continued development can coexist, a pitch aimed at lawmakers wary of slowing American labs.
Oversight runs on visibility, though, and that is where the trade-off lands. Monitoring a model for dangerous use means monitoring the people using it: their prompts, their accounts, their patterns. Shifting oversight from private companies to government also shifts who watches. Researchers, journalists and ordinary users become the subjects of that review, under rules they did not write.
The governments asking for safeguards are also racing each other to build the most capable systems. U.S. Trade Representative Jamieson Greer said the AI talks with China would not touch export controls on advanced chips, NBC News reported. Washington and Beijing can cooperate on incident alerts while competing on capability, and that competition shapes how strict any domestic rule is allowed to be.
This decision moves power from corporate safety teams to the national-security apparatus. The first binding rules for frontier AI are likely to arrive as security policy rather than consumer protection, drafted in agency guidance and closed briefings instead of public product terms. That puts the definition of acceptable use in the hands of institutions built for secrecy, and leaves the people whose activity gets monitored outside both rooms.
Bill Gates told NBC’s Kristen Welker on Meet the Press, in an interview that aired Sunday, that artificial intelligence is now capable of helping cause catastrophe on a scale humanity has never faced. “AI is certainly powerful enough to drive events that, you know, cause a billion deaths,” the Microsoft co-founder said. He was precise about where the danger sits: “There’s never been a weapon as powerful as the combination of people with ill intent using the latest AI tools.”
Gates is describing an amplifier, not a rogue machine. His warning is about what a small number of people could do with a tool that hands them skills they could never have built on their own. He pointed to fraud, drained bank accounts and attacks on the power grid as the threats already in play, according to Rolling Out‘s account of the full interview.
The timing matters. Gates spoke days after Donald Trump hosted Chinese President Xi Jinping at a White House summit where AI sat near the center of the agenda, according to Newsweek. A week earlier, Treasury Secretary Scott Bessent said Washington had proposed a “notification mechanism” for AI incidents that could threaten national security, NBC News reported. And on Sept. 21, the UN’s Independent International Scientific Panel on AI warned that existing safeguards are unraveling, after AI agents in an OpenAI-initiated test breached Hugging Face between May and July, according to UN News.
Expertise used to be the safeguard. Building a pathogen, breaking into a grid, running fraud at scale all required years of training, institutional access and money. Frontier models compress that barrier. Biology shows the problem most clearly: the same system that helps a researcher design a drug can walk someone else toward a weapon, and the model answering the prompt cannot reliably tell which user is which.
Right now, the companies building these systems decide where that line sits. Their trust-and-safety teams write the refusal rules, run the misuse monitoring and choose what to disclose. That arrangement serves the labs. They control the product, set the pace and grade their own safety work. The public carries the cost of a bad call and has no say in the standard.
Gates wants that authority shared. “No one thinks self-regulation is enough,” he told Welker, and he said Washington needs legislation. He also argued that guardrails and continued development can coexist, a pitch aimed at lawmakers wary of slowing American labs.
Oversight runs on visibility, though, and that is where the trade-off lands. Monitoring a model for dangerous use means monitoring the people using it: their prompts, their accounts, their patterns. Shifting oversight from private companies to government also shifts who watches. Researchers, journalists and ordinary users become the subjects of that review, under rules they did not write.
The governments asking for safeguards are also racing each other to build the most capable systems. U.S. Trade Representative Jamieson Greer said the AI talks with China would not touch export controls on advanced chips, NBC News reported. Washington and Beijing can cooperate on incident alerts while competing on capability, and that competition shapes how strict any domestic rule is allowed to be.
This decision moves power from corporate safety teams to the national-security apparatus. The first binding rules for frontier AI are likely to arrive as security policy rather than consumer protection, drafted in agency guidance and closed briefings instead of public product terms. That puts the definition of acceptable use in the hands of institutions built for secrecy, and leaves the people whose activity gets monitored outside both rooms.