Artificial intelligence tools present dual-use biosecurity risks
Machine learning systems that accelerate therapeutic discovery also lower technical hurdles for assembling dangerous pathogens, creating urgent governance challenges across research and manufacturing.

Software systems trained on the rules of molecular biology are transforming medicine, mapping complex proteins and designing novel therapeutics in hours.12 Yet the computational mechanisms that predict how a molecule binds to a human receptor can operate in reverse. When guided to maximize toxicity or optimize a virus for immune evasion, the same computational foundations offer blueprints for biological harm.31
The biological realm carries consequences that software code cannot match. In cybersecurity, a compromised computer system can be patched, isolated, or rebooted after an intrusion. A replicating pathogen released into an environment multiplies on its own, making the margin for containment far smaller once physical production occurs.
Producing a dangerous biological agent historically required a demanding progression of specialized skills. An actor needed years of tacit laboratory experience to navigate fragile protocols, identify specific genetic sequences, acquire physical starter material, and cultivate viable organisms without self-contamination. Artificial intelligence compresses several links in that chain. Algorithms can search scientific literature, convert broad scientific goals into step-by-step protocols, design viral sequences, and suggest methods to bypass standard synthesis controls. If those digital instructions are sent to commercial synthesis providers, digital designs can become physical biological material.
Why does biological design software present security hazards?
Biological design software presents security hazards because algorithms trained on therapeutic data can be redirected to identify lethal compounds or optimize pathogens.32 In an analysis published by the Belfer Center for Science and International Affairs, Ana Florescu-Ciobotaru and Caleb Workman described this convergence as a three-part system combining artificial intelligence models, biological datasets, and biotechnology manufacturing.1 Tools such as AlphaFold 3 and Evo 2 model biomolecular complexes and genome-scale sequences to accelerate legitimate research, but those capabilities simultaneously reduce the technical expertise, time, and experimental iterations required to design biological threats.1
The ease of repurposing beneficial tools has already been demonstrated in computational experiments. A study cited by Janelle Radcliffe in the William & Mary Environmental Law and Policy Review showed that when generative drug discovery models were instructed to maximize toxicity rather than medicinal value, the software generated tens of thousands of candidate molecules, including compounds similar to VX nerve agent, in less than six hours.4 In another case study conducted at the Massachusetts Institute of Technology, researchers found that standard artificial intelligence platforms could produce pathogen lists, procurement strategies, and screening evasion tactics within one hour.4

How do researchers estimate the probability of an attack?
Researchers estimate the probability of an attack by creating threat models that translate laboratory capability gains into broader epidemic risks.5 In a report published by the research organisation GovAI, author Luca Righetti constructed a risk assessment framework drawing on historical case studies, expert elicitation, and reference class forecasting.5 Righetti calculated that if artificial intelligence tools increased the proportion of university graduates in scientific disciplines capable of synthesizing pathogens as complex as influenza by 10 percentage points, while also assisting in operational planning, the annual probability of an epidemic caused by a lone actor would rise from 0.15% to 1.0%.5
That projected increase represents an estimated 12,000 additional expected deaths per year across the modeled population, corresponding to roughly $100 billion in expected annual economic damage.5 Righetti reported that a review of the model by six subject-matter experts and five superforecasters produced similar median estimates, though every forecast carried substantial uncertainty.5
These mathematical projections are not deterministic predictions of when an incident will occur.5 They represent exploratory risk assessments based on structured expert judgment and simplified assumptions about human intent, pathogen complexity, and baseline technical skill. Furthermore, access to digital blueprints does not eliminate physical constraints. Malicious actors still face major bottlenecks in acquiring physical laboratory equipment, obtaining chemical reagents, and conducting wet-lab validation without specialized facilities.1
What measures can reduce the danger of misuse?
Universal screening of commercial genetic orders provides one of the most direct barriers against digital biosecurity threats.1 Ana Florescu-Ciobotaru and Caleb Workman reported that existing United States guidelines mandate nucleic acid screening primarily for federally funded research, leaving gaps across the broader commercial market.1 The authors recommended requiring universal screening for all synthetic nucleic acid orders exceeding 50 nucleotides, establishing centralized monitoring to detect orders split across multiple providers, and creating federal licensing requirements for sensitive laboratory equipment.1
Technology companies are also implementing internal safeguards, though safety evaluations remain voluntary and non-standardized across the sector.12 Tom Chivers reported for Semafor that major developers test their models against biological risks, yet assessing danger in bioscience remains significantly more complex than identifying vulnerabilities in software code.2 Improving wastewater monitoring, bioaerosol sampling, and automated metagenomic sequencing could help public health agencies identify emerging biological anomalies before widespread community transmission begins.1
This piece was prepared from research reports and public records; the authors have not been interviewed.
References
This article is based on 5 sources, listed in the order they are cited.
- 1 The Dual-Use Frontier of AI-Enabled Biotechnology: Civilian Opportunities, National Security Threats, and the Governance Challenge See the source
- 2 Experts warn of threats of AI bioterrorism See the source
- 3 AI?s Dual-Use Biosecurity Challenge See the source
- 4 Confronting the AI-Accelerated Threat of Bioterrorism See the source
- 5 Dual-Use AI Capabilities and the Risk of Bioterrorism | GovAI See the source