Responsible AI
Dual Use, Misuse, and Societal Externalities
Analyze foreseeable misuse, capability diffusion, information integrity, concentration, democratic effects, and wider societal externalities.
By the end you can
- Explain why dual-use governance evaluates harmful affordances, actor access, scale, vulnerable targets, and ecosystem defenses alongside legitimate benefit
- Distinguish Content moderation, Capability restriction, and Ecosystem resilience
- Identify evidence that connects capability to countermeasure ecosystem
- Design a review that moves from identify harmful affordances to review externalities
What dual-use and societal risk governance changes in practice
A dual-use review examines capabilities that support legitimate work while also lowering the skill, cost, time, or coordination a harmful action needs. Societal risk then emerges through scale, diffusion, interaction, and institutional fragility rather than through a single user request. So the review names the threat actors, what they can already do, how they get access, and which model and product affordances they can reach. It then looks at distribution channels, monitoring, downstream dependencies, and defensive capacity. A refusal policy at the interface is one of those layers. It is not the review.
Voice cloning is the capability this lesson follows. The public record on it is unusually complete. Two days before the New Hampshire presidential primary of 23 January 2024, roughly 10,000 robocalls went to residents the callers believed were likely Democratic voters. They carried an AI-cloned voice of President Biden and a spoofed caller ID. An interface review inspects the model, the request, the terms. It does not inspect the call volume, the spoofed identity, the primary two days away, or the people who had to judge in the moment whether the voice was real. Nobody measured that second list before release. Verification was the part that had to absorb the result.
A review that names threat actors but never measures what the defenders can absorb has scoped the risk to the interface and stopped there.
Key idea
Impersonating an official was already illegal
Impersonating a government official was already illegal when those calls went out. Not by a clause in a terms-of-use page. The FTC's trade regulation rule on impersonation of government and businesses took effect on 1 April 2024. Its summary line is one sentence: "This final rule prohibits the impersonation of government, businesses, and their officials or agents in interstate commerce." The rule makes it an unfair or deceptive act to "materially and falsely pose as, directly or by implication, a government entity or officer thereof" in or affecting commerce.
That prohibition did not empty the category it names. Announcing the effective date, the FTC reported that combined losses to government and business impersonation scams topped $1.1 billion. That is more than three times what consumers reported in 2020. A federal rule with an agency behind it is a stronger instrument than a product policy. The losses still ran to that figure.
So a team cannot call a societal risk solved because harmful outputs are prohibited in its terms. The work is to test realistic access, automation, workarounds, downstream distribution, and defensive capacity. Risk controls can also push harmful use onto other models or channels. So the reviewer compares what the product adds at the margin, what people would switch to if it went away, and what the ecosystem could do if it acted together. The team should not claim the harm has been prevented.
Posing as a government officer was already unlawful under federal rule while reported impersonation losses topped $1.1 billion; prohibited and prevented are different claims.
Example
Roughly 10,000 robocalls, two days before a primary
Two days before the New Hampshire presidential primary of 23 January 2024, robocalls carrying an AI-cloned voice of President Biden and a spoofed caller ID went to likely Democratic voters. A federal judge in New Hampshire later put the facts in one sentence: "In January of 2024, two days before the New Hampshire Presidential Primary Election, defendants directed approximately 10,000 robocalls to New Hampshire residents they believed were likely Democratic voters." That order, dated 26 March 2025, let the civil claims in League of Women Voters of New Hampshire v. Kramer proceed.
Two forums acted on the same calls. The FCC imposed a forfeiture on Steve Kramer under the Truth in Caller ID Act: "We impose a penalty of $6,000,000 against Steve Kramer". The federal district court in New Hampshire handled the civil side. Neither forum is the vendor of a model. Neither remedy arrived before the primary.
- Beneficial use: The same synthetic-speech capability lowers production cost and widens language access for legitimate work.
- Misuse affordance: Identity imitation and rapid variation lower the cost of deception — here, a cloned voice of President Biden paired with a spoofed caller ID.
- Scale effect: Roughly 10,000 calls reached residents the callers believed were likely Democratic voters, inside the window a primary two days away left for checking.
- Institutional dependency: The deception rode the telephone channel and the caller ID people use to authenticate it. That is why the FCC reached for the Truth in Caller ID Act.
- Externality: Costs fell on the public, journalists, election officials, and trust infrastructure. The name on the civil docket is the League of Women Voters of New Hampshire, not anyone who answered a call.
Visual
The layers a dual-use and societal risk governance review must connect
Capability, accessibility, intent and actor, target and dependency, countermeasure ecosystem: harm needs all five. A countermeasure that touches only one of them tends to move the problem rather than remove it. Two of the five links have been measured directly. Those measurements are what turn this diagram from a checklist into an argument.
Target and dependency decides how much verification a human audience can absorb. People are worse at it than a launch plan assumes. A listening study in PLOS ONE tested 529 participants in English and Mandarin, and its title is the finding: Warning: Humans cannot reliably detect speech deepfakes. The abstract gives the number. "Listeners only correctly spotted the deepfakes 73% of the time, and there was no difference in detectability between the two languages." Playing listeners examples of deepfakes beforehand improved detection only slightly. That 73% is the capacity a plan which says the public will notice is quietly assuming.
The countermeasure ecosystem link has a sized artefact of its own. ASVspoof 5 is the public spoofing- and deepfake-detection benchmark, and its own abstract says what changed: "We introduce the ASVspoof 5 database which is generated in a crowdsourced fashion from data collected in diverse acoustic conditions (cf. studio-quality data for earlier ASVspoof databases) and from ~2,000 speakers (cf. ~100 earlier)." It holds attacks generated with 32 different algorithms across seven speaker-disjoint partitions. An auxiliary set adds a further 30,000 speakers. Challenge participants used it in 2024.
Read the two together and the shape of the harm chain is clear. Capability, accessibility, and intent and actor describe what an attacker can reach. Target and dependency was measured at 529 listeners and 73%. Countermeasure ecosystem is a benchmark with 32 attack algorithms and seven speaker-disjoint partitions behind it — machine detection that exists and is sized. That is not the same thing as a person on a phone line deciding whether a familiar voice is real.
- 1
Capability
What the system enables and how reliably it performs.
- 2
Accessibility
Who can obtain, automate, customize, or scale the capability.
- 3
Intent and actor
Benign, negligent, opportunistic, organized, or state-backed use.
- 4
Target and dependency
People or institutions exposed and their ability to verify or recover.
- 5
Countermeasure ecosystem
Detection, authentication, rate limits, reporting, education, and response.
Comparison
Content moderation, Capability restriction, or Ecosystem resilience?
Content moderation removes outputs. Capability restriction removes functions. Ecosystem resilience works on the target instead of the tool.
Content moderation acts at the application layer. It can reduce casual misuse. It needs consistent enforcement and an appeal route. It is vulnerable to evasion and to external tools, because nothing it does reaches material that has already left the product.
Capability restriction acts closer to the harmful affordance, and its clearest example is a regulator's ruling rather than a policy page. The Telephone Consumer Protection Act already restricted artificial or prerecorded voices. On 8 February 2024 the Federal Communications Commission read that restriction onto a new capability: "In this Declaratory Ruling, we confirm that the TCPA's restrictions on the use of "artificial or prerecorded voice" encompass current AI technologies that generate human voices." Calls using such voices therefore need the called party's prior express consent, absent an emergency purpose or exemption. Nothing there rules on the content of any particular call. It rules on the function. Restriction of this kind may cost legitimate utility and requires threat-specific evidence; on the product side it looks like rate limits, identity controls, and disabled cloning.
Ecosystem resilience strengthens targets and verification channels — provenance, authentication, response, literacy. It reduces harm even when content escapes, which is the property the other two lack. It also requires coordination beyond any one vendor, which is why it is the layer most often left out of a launch review. For societal externalities it is not optional.
Content moderation
Blocks or removes disallowed outputs.
- Acts at the application layer
- Can reduce casual misuse
- Vulnerable to evasion and external tools
- Needs consistent enforcement and appeal
Capability restriction
Limits functions, access, scale, or customization.
- Acts closer to the harmful affordance
- May reduce legitimate utility
- Requires threat-specific evidence
- Examples: rate limits, identity controls, disabled cloning
Ecosystem resilience
Strengthens targets and verification channels.
- Reduces harm even when content escapes
- Includes provenance, authentication, response, literacy
- Requires coordination beyond one vendor
- Essential for societal externalities
Example
Three paths from feature to harm
Asking what users would switch to decides whether restricting a feature reduces harm or merely relocates it. It is also the drill teams most want to skip. Each of these four is a rehearsal for a number that gets produced either way — here, or later, by a court order or an agency ruling after the fact.
- Misuse tree: Map at least three paths from a legitimate feature to a harmful outcome. The New Hampshire calls used one of them: a cloned voice, a spoofed caller ID, and a delivery channel that reaches people at home.
- Scale test: Estimate how automation changes volume, speed, cost, and detection burden. Roughly 10,000 calls placed two days before a primary is the kind of figure this test exists to produce before launch rather than after.
- Target interview: Ask an institution that could be affected how it verifies and recovers. Hold the answer against the measured benchmark — 529 listeners in English and Mandarin, correct 73% of the time.
- Substitution analysis: Assess whether restricting the feature reduces harm or merely shifts it elsewhere. A deception that stays cheap on another model or channel has been relocated, not reduced.
Steps
Start from what the system makes cheaper
Begin from what the system makes cheaper, faster or more convincing. Motive follows capability, and the access paths decide who ever gets to use it. So identify the harmful affordances first — what becomes cheaper, faster, more convincing, or scalable. Then model actors and targets, with realistic motives, resources, channels, and vulnerable institutions. Then test the access paths: API automation, customization, evasion, resale, and open release.
The fourth step, layering mitigations, has already been written down for this exact capability. A joint cybersecurity information sheet from the NSA, FBI and CISA, Contextualizing Deepfake Threats to Organizations, appeared in September 2023. Its executive summary states: "The most substantial threats from the abuse of synthetic media include techniques that threaten an organization's brand, impersonate leaders and financial officers, and use fraudulent communications to enable access to an organization's networks, communications, and sensitive information." The recommendations are specific: media-provenance and real-time verification capabilities, personnel training, rehearsed response plans, and participation in consortiums such as the Coalition for Content Provenance and Authenticity and Project Origin. Note where those land. Training and rehearsal sit inside the target organisation. Provenance and the consortiums sit between organisations. None of the four is a filter on a model's output.
The fifth step reviews externalities: incidents, substitution, public burden, and changes in the threat landscape.
1. Identify harmful affordances
Describe what becomes cheaper, faster, more convincing, or scalable.
2. Model actors and targets
Include realistic motives, resources, channels, and vulnerable institutions.
3. Test access paths
Examine API automation, customization, evasion, resale, and open release.
4. Layer mitigations
Combine capability limits, monitoring, authentication, provenance, and response.
5. Review externalities
Track incidents, substitution, public burden, and changes in the threat landscape.
A misuse register ages from the launch date
Dual-use risk moves as the surrounding ecosystem moves. A register written at launch is already out of date by the first external incident.
The demonstration arrived in two instalments. The first was a warning from the FBI's Internet Crime Complaint Center on 15 May 2025: "Since April 2025, malicious actors have impersonated senior US officials to target individuals, many of whom are current or former senior US federal or state government officials and their contacts." The methods were text and AI-generated voice messages — smishing and vishing — used to reach those officials' contacts.
The follow-up, on 19 December 2025, had to widen the picture in both directions. It dated the activity back to 2023. It extended the targets to state government, the White House, Cabinet-level officials and members of Congress. Same office, same campaign, an earlier start date and a larger set of targets. A register written before either announcement would have had to be reopened twice.
So name the incident patterns that would force the team to redesign, restrict, remedy, or retire the system. Write them down before the first of them arrives from outside.
Case
Article 51(2) counts operations, Article 50 marks the output
The EU AI Act picks one measurable proxy for this problem, and the proxy is compute. Article 51(2) presumes that a general-purpose model has high impact capabilities "when the cumulative amount of computation used for its training measured in floating point operations is greater than 10^25". Once a model crosses that line, the systemic-risk obligations apply to it.
Article 50 of the same regulation measures something else, and applies from 2 August 2026. The obligation sits on the output rather than on the size of the model: "Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated." It also requires deployers of deep-fake image, audio or video content to disclose that the content was artificially generated or manipulated. A model far below the compute presumption is untouched by Article 51(2) and still caught by Article 50. That is transparency and provenance acting on the ecosystem, not on the model's size.
Case
NIST counts what a capability makes cheaper
A third route counts neither operations nor outputs. NIST's Generative AI Profile, published in July 2024, names CBRN information or capabilities among its twelve risks. One threshold counts operations. The second marks the output and tells the audience what it is looking at. The third counts what a capability lowers the cost of. Only the third asks the question a cloned voice on a phone line raises, and it is the one with no number attached to it.
Key takeaways
- Dual-use risk concerns capabilities that lower the cost or skill a harmful action needs. A cloned voice of President Biden and a spoofed caller ID reached roughly 10,000 New Hampshire residents two days before the primary of 23 January 2024.
- Societal harm emerges through scale, diffusion, interaction, and institutional fragility. In a PLOS ONE listening study, 529 participants tested in English and Mandarin spotted speech deepfakes correctly 73% of the time.
- Interface moderation is only one layer of mitigation. What bound the New Hampshire calls was the FCC's ruling that the TCPA already covers AI-generated voices, and a $6,000,000 forfeiture under the Truth in Caller ID Act.
- Capability limits, access controls, ecosystem resilience, and incident response should work together. The NSA, FBI and CISA sheet Contextualizing Deepfake Threats to Organizations asks for provenance and real-time verification, personnel training, rehearsed response plans, and consortiums such as the Coalition for Content Provenance and Authenticity and Project Origin.
- Threat modeling should include realistic automation, workarounds, resale, and downstream distribution. The FBI's warning of 15 May 2025 about impersonated senior officials needed a follow-up on 19 December 2025, which dated the campaign back to 2023 and widened it to state government, the White House, Cabinet-level officials and members of Congress.
- Responsible decisions weigh marginal contribution and substitution rather than claiming complete prevention. Impersonating a government officer was already prohibited by federal rule while the FTC reported combined government and business impersonation losses topping $1.1 billion.