1AI is changing who can develop biological threats
Historically, advanced biological weapons capabilities have remained concentrated within a handful of state programs and sophisticated institutions, tracked annually by the Department of State1. This concentration made deterrence a tractable strategy. AI proliferation is changing that calculus by eroding one of the greatest barriers to entry: access to highly specialized, PhD-level expertise in virology and experimental know-how. As this expertise becomes broadly available, capabilities once confined to state programs may move within reach of far less capable adversaries, including non-state groups.
Unlike nuclear capability, which requires state-scale resources, traceable infrastructure, and long development timelines, biological capability is distributed and accessible, and its prerequisites are embedded in a landscape of tools and knowledge that can’t be isolated without halting legitimate scientific work. Even mandatory U.S. DNA synthesis screening would cover only U.S. chokepoints, which account for only a small share of global capacity2. This would not prevent biological threats developed elsewhere from reaching the United States.
2Offense scales more easily than defense
Biology is also marked by a stark asymmetry between offense and defense. A biological threat can spread from a small initial quantity, exploiting life’s machinery to survive and multiply. Defense has a much harder task: it needs to identify the threat, understand it, develop a countermeasure, and manufacture and distribute that countermeasure before the damage compounds. If offensive capability continues to diffuse for many years before our defensive systems start to adapt, this delay is going to make this asymmetry harder to close.
3Models are becoming practical experimental collaborators
Fig 1AI systems exceed PhD-level human biologists on selected troubleshooting tasks and have generated viable virology protocols (AISI)
In 2025, OpenAI’s o3 outperformed over 94 percent of expert virologists on questions relating to highly technical laboratory procedures in their own areas of specialization. More recent evaluations show the same broader progression: frontier models exceed PhD-level baselines on critical open-ended biology questions, generate feasible virology protocols, and outperform human-expert baselines on troubleshooting tasks.
Models are moving from retrieving biological knowledge toward providing practical assistance for experimental work. These results do not demonstrate that models can independently produce biological weapons. A model-generated design ultimately still needs to be synthesized and tested by someone with access to laboratory equipment and tacit wet-lab expertise. AI currently does not eliminate those laboratory constraints and is still early in reliably adapting wet-lab protocols. As a result, some have argued that these barriers keep biological risk near its historical baseline.
AI does not need to remove those constraints to change the threat landscape. It is already weakening informational and technical barriers needed to execute on dangerous biological projects: first by making specialized knowledge easier to retrieve, then by improving experimental design and troubleshooting to reach or surpass PhD-expert baselines (Fig 1). As capabilities improve, they may eventually help users navigate more of the operational chain historically limited to highly trained groups.
4Open-weight proliferation makes model safeguards insufficient
Fig 2Open-weight models trail the frontier by months, not years (SecureBio)
Even a comprehensive safeguard regime for U.S. frontier models would not close this gap. Chinese open-weight models lag the capabilities of closed-frontier models by months (Fig 2). Once their weights are released, they can be downloaded, modified, and operated privately, largely stripped of the safeguards imposed by their original developers. Model-level controls matter, but they cannot be humanity’s last line of defense. As access broadens, less capable states and non-state actors may become better able to identify weaknesses in existing screening, diagnostics, and stockpiled countermeasures, or target the biological systems on which economies depend. This is the central asymmetry: on our current trajectory, the capabilities to cause harm will inevitably diffuse, while the defensive systems needed to counter emerging threats do not arise without deliberate partnership between government and industry.
No major emerging threat of this kind has ever been managed through a single intervention. Model safeguards, synthesis screening, and attribution are all critical layers of risk mitigation, but none is sufficient on its own. Achieving biological response superiority requires strengthening the entire defensive chain. That means: detecting threats; rapidly characterizing their likely effects and selecting existing medical countermeasures, or developing new ones; and deploying them before damage compounds.
AI can already compress the time required at every stage, but models alone are not going to create a functioning system of defense by themselves. We need people to build that, and there is a narrow window to get this balance right.
Footnotes
[1] Confirmed dossiers exist on Russia and North Korea, both of which have offensive biological-weapons programs in violation of the Biological Weapons Convention (BWC), as documented by the U.S. Department of State’s compliance reports. The Department of Defense has warned that China is conducting chemical and biological research with potential military applications, while PLA strategic documents describe biology as a new domain of war. Comprehensive public reports by Robert Kadlec, now the U.S. Assistant Secretary of War for Nuclear Deterrence, Chemical, and Biological Defense Programs and Policy, point to China’s Science of Military Strategy, an authoritative PLA teaching text, which describes biology as a new domain of military conflict.
[2]Legislation has been proposed to mandate sequence and customer screening for covered DNA synthesis and equipment suppliers. This is a critical preventative layer to reduce the overall threat but is limited in effective coverage, limiting its effect as a prevention layer for the growth of threats. The U.S. accounts for only 25% of gene-length DNA synthesis providers globally. This alone does not contain the global threat.