Closed models are also used for nefarious usage.
You could limit what it was training on in the first place - however that would damage capability - and it's difficult to curate the input, especially when the models can do 2+2. ie the choice is between model power and safety - and they choose power and everything else is a sticking plaster.
One thing I find amusing is the refusal of a lot of the models to now output a lab based protocol because of fears about 'weapons' - yet I can buy a textbook or simply read papers for exact protocols.
I find it hard to reason that a person who isn't motivated enough to read a paper or buy a book, is somehow enabled to make a biological weapon because of ChatGPT - despite them needed to buy a whole bunch of specialist equipment and reagents to do it.
Are there a whole bunch of proto-terrorists who are frustrated simply because they don't know where to start?
Maybe the only place their might be radicalized teenagers - but then that's perhaps a reason for keeping them off the internet full stop :-)
The knowledge to create weapons is already widespread, the idea that terrorists need chatgpt for that is laughable
Hence copy cat kind of attacks - I mean why focus on all this complicated stuff with explosives etc when you can just fly a plane into a building or a car through a crowd.
Obviously due to the self replicating nature of biologics weapons - just one instance could be catastrophic - but the only real barrier is the hope that the Venn diagram of people who might want to do it doesn't overlap with the people with the get up and go to actually make it happen. Don't see having the knowledge as a additional filter - as if you have the get up and go - as you say, you can acquire the knowledge LLM or not.