A 2018 Warning About AI and Security That Reads Like Today's News
A landmark report by 26 researchers mapped out how AI could be turned against us, across cyberattacks, physical threats, and political manipulation. Six years later, almost every warning has aged badly in the wrong direction.

Key points
- A 26-author research report published on arXiv on 20 February 2018 warned that AI would expand the scale, speed, and reach of malicious attacks across digital, physical, and political domains.
- Co-authored by Dario Amodei (now CEO of Anthropic) alongside researchers from Oxford, Cambridge, and several US security institutions, the paper made four high-level recommendations for AI developers and policymakers.
- The report was updated on 1 December 2024, keeping the original findings intact.
- Authors identified three broad threat areas: automated cyberattacks, AI-assisted physical attacks, and AI-generated disinformation at scale.
Twenty-six researchers sat down in 2018 and tried to think like the bad guys.
The result was a paper that reads less like a forecast and more like a checklist someone has been quietly ticking off. First flagged by Hacker News, the report laid out how artificial intelligence, software that learns patterns and makes decisions, could be weaponised across the internet, the physical world, and the political sphere.
What did the report actually warn about?
The authors argued that AI wouldn't create entirely new categories of attack. It would make existing ones faster and harder to stop.
On the cyber side, that means automated hacking tools scanning millions of systems in the time it once took a human team to probe a handful. The physical concern was AI guiding drones or other hardware with minimal human oversight. Then there's disinformation: AI generating convincing fake text or video, what we now call deepfakes, at a scale no human propaganda operation could match. New York's seizure of twelve deepfake websites in the largest takedown of its kind shows how quickly that prediction became a prosecution.
The team didn't predict exact tools. They predicted the logic, and the logic held.
Why does a 2018 paper matter right now?
The update timestamp says December 2024, not 2018. That gap between warning and reality is the whole story.
When the report was written, large language models, the technology powering chatbots like ChatGPT and Claude, barely existed in public form. The authors were already worried. Now those tools are free and available to anyone with a phone. Our 16 September story on AI CEOs warning about dangers for years tracked the same disconnect: loud caution, quiet acceleration.
The four recommendations were broad: treat security as a design concern rather than an afterthought; share threat information across industry and government; keep laws pace with capability; and build defenses alongside better models. None of those asks have been fully answered.
Amodei co-founded Anthropic, a company that places AI safety at the centre of its work. That's either reassuring or complicated depending on your read, and our coverage of his essay urging Washington to slow China's AI progress shows he's still trying to make policymakers listen.
Should you worry?
The paper got the shape of the problem right. The defenses it called for have moved nowhere near as fast as the attacks. That gap is what security researchers are living inside right now, and it's the gap that matters most.



