← Back to all writing

How much does it cost a malicious actor to build powerful AI?

June 27, 2026

This is obviously not a recipe for malicious organizations. I wrote it for people who care about AI safety and AI for good — to get clearer on what capacity bad actors already have with AI. Without a basic understanding of the threat, we cannot defend.

So the question is: if a malicious organization wanted powerful AI, how much money and capacity would they need today?

Everything below draws on public sources. I do not claim it is fully accurate or complete — treat it as a beginner reference for learning.

What follows is a cost map — what different budgets buy, where the bottlenecks actually are, and what public crime data can already say. Dollar bands are order-of-magnitude (often ±3–10×). I mark when a number comes from a named report versus my own synthesis. This is not a census of every AI crime on earth.


First: powerful for what?

“Build powerful AI” collapses several different jobs:

GoalRoughly what you needTrain from scratch?
Scams, phishing, malware at scaleAPI or open 7B–70B + light fine-tuneNo
Bio/chem knowledge and recipesJailbroken chat modelNo
Design DNA/protein sequencesOpen biology FMs (e.g. Evo2)No
Sustained cyber agentsNear-frontier reasoning (API or distill)Usually no
Your own GPT-4-class model, no gatekeeper~10²⁵ FLOP training (Epoch)Yes — or steal weights
AGI / takeover-grade systems~10²⁷–10²⁸ FLOP scenarios (Aschenbrenner, AI 2027)Only $10B+ entities

For physical harm, the model is often not the bottleneck. A pathogen sequence on disk is useless without synthesis, a wet lab, and delivery. Near-term AI pathogen design is still assistive, not “non-expert presses Generate” — RAND’s 2025 Delphi. Longer map of upside and risk: AI × biology.


The cost ladder

TierBudgetWhat you actually get
0~$0–$10kAPIs + jailbreaks, or open weights on one GPU. Fraud, malware drafts, CBRN knowledge on WMDP-class evals. Bottleneck: skill and OPSEC, not compute.
1~$1k–$100kUncensor via LoRA / fine-tune. Betley et al. showed narrow bad fine-tuning can generalize into broad misalignment; persona-feature work is the same family. Cloud H100 time is a few dollars per GPU-hour — a 7B tune is often hundreds to low thousands of dollars.
2~$100k–$10MDistill frontier reasoning into an open student, or specialize (cyber agents, bio-FM fine-tunes). DeepSeek-V3’s famous ~$5.6M figure is the final pretrain GPU pass (paper); SemiAnalysis and Interconnects put full org cost far higher. Talent binds harder than GPUs — V3 listed ~139 technical authors.
3~$50M–$1B+Train frontier from scratch. Epoch puts GPT-4’s final-run hardware+energy near ~$40M (not the full program; public writeups often cite ~$78–200M for broader spend). 2025-class frontier is hundreds of millions to $1B+ once you include failed runs and staff. Needs huge clusters, power, and export-control-proof supply.
4~$1B–$100B+AGI-scale scenarios — multi-OOM past GPT-4, GW-class power. Today: a handful of labs and national programs. For a malicious actor, stealing weights beats training. RAND on weight theft: once weights leak, inference is cheap. LLaMA / Mistral leaks are the precedent.

Who maps to what (my mapping onto RAND’s OC adversary bands):

ActorBudgetRealistic path
Lone actor / small cell<$100kTier 0–1
Criminal group / mid APT$1M–$50MTier 2
Standard state APT$10M–$100M/yrTier 2–3: distill, steal, specialize
Top-priority state / ultra-rich$1B+Tier 3–4 or compromise a lab

Typical terror budgets do not buy Tier 3. Peak ISIS-scale revenue was in the billion-dollar/year range in open estimates — and would not all go to AI.


What public crime data already shows

I am not claiming we measured every AI crime. We did check what official and public trackers make visible.

The cleanest dollar source is the FBI IC3 2025 report. For the first time it breaks out an AI Related descriptor: 22,364 complaints and $893M in adjusted losses. Investment scams with an AI nexus: >$632M (all investment scams: >$8B — IC3 notes many victims never realize AI was involved). BEC with AI: >$30M. Romance/confidence AI-nexus: >$19M. AI-tagged malware and ransomware complaints: 42 and 16.

In other words: under US self-reported AI-tagged internet crime, fraud dominates. Classic malware is a rounding error next to investment scams. The descriptor only applies when the complainant mentions AI, so this undercounts.

Media-style incident databases tell a different story — more deepfakes, disinfo, and harassment — because they sample visible narratives, not loss dollars. In one AIID-style aggregate we coded, among rows we could clearly label as misuse, disinfo was the largest slice (~40%). That does not contradict IC3; it is a different lens.

Bio deployment barely appears. Keyword hits in that corpus were research papers, not attacks. After review: zero documented non-state AI-enabled bio weapon deployments in that snapshot. Absence in public AI-incident feeds is not proof the global rate is zero — but it matches the historical pattern that non-state bioweapon programs fail hard (Aum Shinrikyo spent years and vast resources on bio and produced no known casualties; their sarin attack killed 12).

PathEasy?How common in public data?Ceiling
Fraud / deepfakes / scamsVeryHigh (IC3)Medium
Cyber / phishing / malwareEasyCommon, but AI-tagged dollars led by fraudMedium–high
Disinfo / radicalization contentVeryHigh in media DBsMedium
CBRN knowledgeEasy after jailbreakRed-teamed often; completed weapons rareDepends downstream
Deployable bio / pandemicHardNo cases in our AI-incident snapshot; historically rare for non-stateExtremely high

Easiest misuse is not the worst consequence. Policy obsesses over bio risk because the tail is asymmetric — while what shows up in crime stats today is mostly fraud and synthetic-media scams.


Non-state actors, money, and AI-for-WMD

Same epistemic cut as above, applied to the scary scenario: covert / non-state use of AI toward WMD.

Public record: no known large-scale successful AI-enabled bio/chem WMD campaign by a non-state group. Historical non-state CBW without modern AI already shows the pattern — huge spend, tiny yield (Aum’s bio program; chem that killed in the low dozens, not cities). That is the open evidence. It is not a proof that nobody is trying offline.

Why money still matters. Public estimates of the richest violent non-state organizations (I won’t name them here — the point is order of magnitude, not a roster) put peak annual revenue in the ~$0.5B–$2B band for a few outliers: territorial quasi-state jihadist economies at mid-2010s peak (oil/tax/loot; ICSR / RAND-style estimates), and large state-proxied militias often cited around ~$1B/year. Transnational cartels move multi-billion drug revenues, though their incentives look more like profit and territory than GCBR. A 1990s apocalyptic cult with ~$1B in assets is the classic CBW case study. Most cells and franchises are far smaller — tens of thousands to a few million a year.

Map that onto the tiers above:

Actor band (anonymous)Rough moneyWhat they can already buy in AI termsWMD ceiling (public history)
Small cell / lone actor$0–$100kTier 0 API / jailbreak; maybe Tier 1 FTAlmost none for deployable bio
Mid funded network$1M–$50MTier 1–2 distill + agents; serious cyber/fraudChem locally possible in principle; mass bio still hard
Outlier rich non-state (~$0.5B–$2B/yr)Enough for Tier 2 easily; Tier 3 frontier train still painfulKnowledge uplift + hire talentStill no public AI-WMD success; physical constraints dominate
Steal / compromise pathOne good insider or APTCollapses Tier 3–4 costSame as always: access beats training

So: yes, some existing violent organizations already have the money for large-scale AI assistance to planning, recruitment, cyber, and knowledge work — the Tier 0–2 band. That alone is enough reason to harden APIs, weights, synthesis screening, and lab access. Money does not automatically buy a working pandemic agent; Aum had money and still failed at bio.


Three direct answers

Multi-week autonomous cyber campaign?
My synthesis: roughly $1M–$10M and ~10 skilled people — distill + agents, no frontier training run. Anchored to GPU rental and team size, not to a dataset of successful campaigns.

Deployable biological weapon?
Not the same budget. Tier 0–1 can leak knowledge and help design sequences. Turning that into a physical agent still needs wet-lab skill, synthesis access, and weaponization. Mass / pandemic scale remains mostly a state problem.

Own GPT-4+ with no gatekeeper?
Roughly $100M–$1B of organizational capital — or successful nation-state theft.

AGI for takeover?
In aggressive scenarios, only $10B+ entities (frontier lab / big-tech / national-program scale — not a rich non-state militia). Realistic malicious move: compromise an existing lab, don’t train in a basement.


A few takeaways

  1. The floor keeps dropping. Epoch finds frontier training costs grew ~2.4×/year; capability-per-dollar moves the other way. GPT-4-equivalent work gets cheaper; the frontier stays ahead unless weights leak.
  2. Open weights and distillation are the live policy surface — not only “who can afford a $1B run.” Labs already gate cyber/bio/distillation queries; export controls on frontier APIs treat access as a controlled asset.
  3. Weights security is misuse prevention. Frontier labs today sit around RAND SL1–SL2 — enough for amateurs, not serious state APTs. Every leaked checkpoint collapses years of safety spend.
  4. Physical chokepoints still matter for bio — synthesis screening, lab access — more than chat refusals alone (OSTP framework, IGSC).

Sources