AI and Forbidden Knowledge: When the Book Is Already Open

The old forbidden book had one advantage over artificial intelligence: it could be locked in a tower.

That did not guarantee safety. In myth and fantasy, someone eventually finds the key, deciphers the inscription, opens the tomb or steals fire from the gods. The image nevertheless assumes a boundary. Dangerous knowledge has a location, a guardian and a threshold that must be crossed before the trouble begins.

Artificial intelligence does not fit that picture neatly. Capabilities move through companies, state laboratories, research papers, cloud services, downloadable model weights, commercial products and informal experimentation. Some systems remain tightly controlled; others can be adapted and run beyond the original developer’s oversight. There is no single book, tower or lock.

In an earlier essay on forbidden knowledge in fantasy, I argued that the trope is not really hostile to learning. It asks what happens when understanding arrives before judgment. AI converts that old anxiety into a practical problem because it can shorten the route between wanting an outcome and possessing some means of producing it.

The spell matters because it can be cast. The buried machine matters because it can be rebuilt. AI belongs to that family not because it is supernatural, but because it increasingly combines information with action: drafting, coding, searching, translating, classifying, planning and operating other tools through an accessible interface.

The old fear was that someone might learn the wrong secret. The modern difficulty is that the secret can become a service, a downloadable system or a conversational layer over machinery the user does not fully understand.

A glowing digital grimoire in a dark archive, representing artificial intelligence as distributed knowledge and technological capability.
The old forbidden book could be locked away. The modern one keeps being rewritten. Editorial image generated by the author.

From Book to Interface

Public arguments about AI still sometimes behave as though humanity is standing before an unopened door. Should the technology be developed or stopped? Should the book be read or left on the shelf? That framing offers a clean moral decision, but it no longer describes the situation. Machine-learning systems already shape search, translation, recommendation, advertising, fraud detection, logistics, workplace software and creative tools. Generative AI made the change visible by giving millions of users a conversational surface through which capability could be requested.

Saying that the book is open does not mean that every page is public or that every model offers the same power. Access remains layered. A user may interact with a hosted chatbot but never see its weights. A company may expose a model through an application-programming interface while monitoring requests and changing the system centrally. Another developer may release weights that others can download, modify and operate privately. Still other systems remain inside laboratories or specialised industrial tools.

The important change lies in the narrowing distance between intention and execution. A user no longer needs to master every intermediate process before producing a useful result. The system can supply missing syntax, propose steps, translate technical language and iterate quickly. It does not eliminate the need for expertise, especially where errors matter, but it changes how much expertise is needed to begin and which parts of a task can be delegated.

Most of this is useful. A non-native speaker can write more fluently, a programmer can understand unfamiliar code, a disabled user can gain a more flexible interface and a small organisation can perform work previously beyond its budget. Researchers can explore large bodies of material, teachers can produce adapted explanations and workers can automate repetitive drafting or classification.

The same structure applies to harmful activity. AI did not invent fraud, propaganda, impersonation, malware or harassment. It can alter their economics by reducing the time, skill or labour needed for each attempt. A technology does not have to create a new vice to increase the number of people able to practise an old one.

Capability Without Mastery

The spell comparison is useful only if its limits remain visible. An AI prompt is not an incantation that guarantees the requested result. Models misunderstand, fabricate, fail halfway through complex tasks and produce outputs whose quality may be difficult for an inexperienced user to judge. Materials, access, tacit knowledge and real-world testing still stand between an answer and many consequential outcomes.

AI nevertheless changes the division of labour. Natural-language interfaces can allow non-specialists to operate software or specialised scientific tools that previously required more technical preparation. The user may not understand every underlying process, yet can direct it at a higher level, receive proposed actions and refine the result through dialogue. This can widen access without making mastery irrelevant.

The distinction matters because lowered barriers can increase both beneficial use and misuse. A novice receiving a plausible answer is not automatically capable of executing it, but neither is the answer meaningless. It can identify terminology, remove dead ends, explain tools and shorten the route to the next stage. The effect varies by domain, user and surrounding infrastructure; “AI gives everyone expert power” is as misleading as “AI is only autocomplete.”

This is also where the problem of command becomes more concrete. Fantasy warns about demons that obey the letter of a bargain, wishes granted without regard to intention and apprentices who know how to begin a process they cannot stop. AI systems are not demons, but they expose the weakness behind those stories: human instructions are often incomplete because human goals are contextual, contested and internally inconsistent.

“Help the user” fails when the request is harmful. “Optimise engagement” can reward outrage or compulsion. “Increase efficiency” may treat deliberation, care or procedural protection as waste. “Prevent harm” can justify surveillance and control if the institution defining harm is given enough authority. A powerful system makes vague objectives consequential, but the ambiguity begins in the objective rather than in some mystical hostility inside the machine.

A perfectly obedient system deployed by a badly aligned institution is not safe. It may make that institution’s incentives faster and more consistent. Companies seek market share, states seek strategic advantage, platforms seek attention, bureaucracies seek defensible procedures and individuals seek convenience. None must be cartoonishly evil for their combined decisions to produce damaging results.

The NIST AI Risk Management Framework is useful because it places risk across the design, development, deployment, use and evaluation of an AI system. The model cannot be analysed in isolation from the organisation choosing its purpose, the data and tools connected to it, the people relying on its output and the procedures available when it fails.

Open, Closed and Irreversible

Arguments about AI access are often presented as a conflict between closed corporate systems and open-source models. The vocabulary needs more care. Many downloadable releases are open-weight: their trained parameters can be obtained and modified, but the training data, processing methods and complete training code are not necessarily available. Under the Open Source AI Definition, genuine open-source AI requires broader access to the materials needed to study, modify and reproduce the system.

The distinction is not semantic housekeeping. Different forms of access create different distributions of power and risk. Open-weight models allow researchers, smaller companies and local communities to adapt systems without depending upon a hosted service. They can be fine-tuned for specialised tasks or smaller languages, run locally with sensitive data and examined by people outside the original developer.

The same accessibility weakens some forms of control. Safeguards can be removed or retrained, usage can occur offline and the original developer cannot monitor every deployment. Once weights have been downloaded and copied, a universal recall becomes impossible. A hosting platform may remove the original file, but it cannot retrieve every copy already stored or redistributed elsewhere.

Closed systems preserve more options after release. Providers can update safeguards, suspend abusive accounts, monitor broad patterns of use and withdraw a capability from their own service. These controls are incomplete—users can circumvent restrictions, providers may fail to detect misuse and proprietary systems can leak—but central operation leaves someone capable of changing the system for all ordinary users.

That control also creates gatekeepers. Providers decide which uses are available, which regions receive access, which prices are charged and which forms of research or criticism the interface permits. Organisations that build essential processes around a hosted model can become dependent upon decisions made elsewhere. For Europe, this is part of the broader problem of depending on a small number of foreign model providers for increasingly important intellectual infrastructure.

Neither model of access solves the political problem. “Lock everything down” grants substantial authority to companies and states already controlling the most capable systems. “Release everything” transfers capability without ensuring that those exposed to misuse accepted the risk. Openness can support scrutiny and distribute benefits; it can also make some release decisions effectively irreversible.

The relevant question is therefore not whether AI should be open or closed in the abstract. It is which capability is being released, how much additional risk the release creates, whether meaningful evaluation is possible beforehand and what benefits would be lost by restricting access. A modest model used for local translation does not present the same problem as a system demonstrating unusually strong cyber or biological capabilities.

Friction, Cybersecurity and Scale

Technological culture tends to treat friction as a defect. Anything slow, difficult or expensive appears ready for optimisation. AI is praised, often correctly, for removing effort from drafting, searching, coding, analysis and administration. Some of that friction deserves to disappear. Bureaucratic delay can be cruelty, expertise can be hoarded and complex interfaces can exclude people without producing any corresponding safety.

Other barriers were doing work that became visible only after they weakened. They limited the scale of impulsive action, forced some users to acquire knowledge before operating powerful tools and made deception labour-intensive enough that it could not be personalised indefinitely. The barrier may never have been designed as a safeguard, yet its existence affected what was economically practical.

Cybersecurity makes the dual effect unusually clear. AI can help defenders analyse logs, interpret unfamiliar code, discover vulnerabilities and prepare responses. The same capabilities can assist reconnaissance, phishing, exploitation and malware development. Offensive and defensive use share methods, which makes blunt restrictions liable to obstruct the people they are intended to protect.

The International AI Safety Report 2026 finds that model performance on cyber tasks has improved and that evidence of real-world offensive use has emerged. It also stresses how difficult the effects are to measure. Benchmarks may overstate or understate capability, public incident reports rarely establish exactly how much an AI system contributed, and the eventual balance between attackers and defenders remains unresolved.

The immediate danger does not require a system capable of autonomously conducting a sophisticated campaign. Many harmful actors need cheap assistance rather than perfection. Better-written fraud, faster adaptation of existing scripts or automated variation across thousands of attempts can raise the burden on institutions even when each individual attempt remains mediocre.

This is why “AI will create cybercrime” is the wrong claim. Cybercrime already exists. AI can change the cost curve: how many attempts one person can make, how quickly unfamiliar material can be understood and how easily an operation can be adapted to another language, target or technical environment.

Removing friction is not inherently progress or decline. It is a redistribution of capability. Every removed barrier should prompt two questions rather than one: what useful activity did the barrier obstruct, and what harmful activity did it keep uneconomical?

Governance After Containment

The failure of perfect containment does not make every form of control futile. Modern governance rarely depends upon one lock. It operates at several points: access to computing infrastructure, model development, evaluation, release, hosted interfaces, connection to external tools, deployment in sensitive sectors, record-keeping, incident reporting and legal responsibility for resulting harm.

Different layers remain available after others have failed. Public information cannot be made secret again, but a hospital can still restrict which system may act upon patient records. Downloadable weights cannot be recalled universally, but providers can test before release and hosting platforms can respond to obviously harmful modifications. A model available through an interface can be monitored more easily than one operating privately, while the organisation using it can still impose human review and limit the actions it may initiate.

This is why the distinction between inquiry and deployment matters. A society can defend research without granting every experimental system immediate access to schools, critical infrastructure, policing or healthcare. It can permit scrutiny while demanding evidence before automated decisions affect rights. It can support open evaluation without assuming that every dangerous capability must be released in the most reusable possible form.

The European Union’s current rules for providers of general-purpose AI models illustrate the move from broad principles towards layered obligations. The rules distinguish ordinary general-purpose models from those posing systemic risk, clarify some exemptions for open-source releases and combine legal obligations with a voluntary Code of Practice covering transparency, copyright, safety and security. The framework will not eliminate the underlying trade-offs, but it recognises that responsibility depends upon capability, release method and the provider’s role.

Governance also requires legitimacy. Closed access may prevent some misuse while concentrating control over an important technology. Open release may distribute creative and economic power while transferring risks to people who had no part in the decision. Neither safety nor openness answers who should decide, what evidence they should provide or how affected people can challenge the result.

The useful response is layered responsibility rather than a universal prohibition or permission. Developers should evaluate capabilities before release. Deployers should remain responsible for the contexts in which systems are used. Institutions should preserve audit trails, meaningful human authority and routes for appeal. Regulators should distinguish serious risk from procedural theatre rather than rewarding paperwork that leaves the underlying danger untouched.

Wisdom After Capability

The nuclear analogy captures part of the problem. Both technologies involve strategic competition, uncertainty and capabilities whose existence changes political behaviour. Neither can be governed by pretending that discovery never happened. Technical success can create a durable moral and institutional problem rather than completing one.

The analogy also fails if pressed too far. Nuclear weapons require rare materials, specialised facilities and conspicuous state involvement. AI is commercially embedded, software-heavy and broadly useful. It can assist medical research, generate scams, translate public information, support surveillance, teach a school topic or automate bureaucratic decisions. Its consequences emerge through thousands of applications rather than one weapon and one doctrine of deterrence.

AI is therefore not a cursed object with a single owner or purpose. It is a family of models and systems connected to human institutions, each with different capabilities, access conditions and consequences. Treating “AI” as one forbidden secret can obscure the decisions that still remain open: which model, which user, which data, which tool, which sector and which degree of autonomy.

The metaphor also carries a political warning. Locks can protect the public, but authorities have always described inconvenient knowledge as dangerous. Closed archives preserve crimes as well as monsters. A company invoking safety may be protecting users, its market position or both. A state restricting access may be preventing harm or consolidating power. The existence of a real risk does not make the gatekeeper disinterested.

The first book is open, but that does not mean every page has been copied or every capability placed beyond control. Some systems remain centralised, some releases can still be staged and some applications can still be prohibited. Governance is not too late; it is simply harder than the fantasy of guarding one tower.

The practical questions are now narrower and more demanding. Which capabilities create material risk? Which releases are effectively irreversible? Where does monitoring protect users, and where does it become surveillance? Which institutions can be trusted to restrict access, and how can that trust be challenged? What kinds of friction prevent harm, and which merely protect incumbents?

Forbidden-knowledge stories endure because they understand that acquiring power and becoming fit to use it are separate achievements. AI does not prove that knowledge itself is corrupting. It exposes how often capability arrives through markets, competition and technical success before anyone has settled who should control it or answer for its effects.

The book is already open. Wisdom now consists less in pretending it can be closed than in deciding, page by page, what should be copied into the world.

Comments

Popular posts from this blog

AC vs DC Again: Why the Future Grid Will Be Bilingual

Young Sherlock First Impressions: When Holmes and Moriarty Were Friends

When the Mask Changes the Self: Identity and Impersonation in Fiction