Opinion: AI is eroding the barriers that kept biological weapons rare
Anthropic earlier this month reported five cases in which people used its models for work that could support biological weapons development. The cases included help preparing a proposal for gain-of-function research on a mosquito-borne virus at a military institute and planning experiments intended to help bird flu get better at infecting mammals. Anthropic had no way to determine the intent behind the work but blocked it anyway; the author says that ambiguity is the core problem.
The same tools that scientists might use to design a vaccine can help design a worse pathogen, and tools that help design a cancer drug sparing healthy cells can be tweaked to build a drug that targets healthy cells alone. Misuse does not require someone to ask Claude to 'build a bioweapon,' only to look like scientists working on important biological problems. Anthropic shut the accounts down and has been the most public about AI risks to bioweapons development; OpenAI has also put in guardrails, while other AI companies, especially with open-weight models whose code anyone can download and modify without oversight, generally release products with far fewer safeguards and little monitoring.
Much of the industry safety debate is about whether to 'pace the frontier' — slowing model development so guardrails and defenses can catch up. The author says that is worth doing, but only works if it is a bridge to building biodefense. Slowing model development has no impact on who can order synthetic DNA or on what national governments are doing to build up their capabilities.
For decades, biological weapons were rare for a reason: building them takes expertise that is hard to acquire and harder to combine. Immunology, virology, growing a pathogen, and stabilizing a dangerous mutation all require different skills, and few people could connect those pieces. AI is closing those gaps: models trained on the biological literature can connect ideas across subfields that few researchers have mastered alone, and can make someone with relevant training in one area more capable and dangerous by helping them learn key steps in another area.
Two reports this year — one from Harvard, one from RAND — examined these issues and independently reached similar conclusions: AI could broaden the range of actors able to mount a large-scale biological attack while making existing state programs more capable, too. Neither claims the most dangerous thresholds have been crossed, though neither rules it out. The safer assumption, the author argues, is that we are already close enough not to wait and find out.
The State Department's annual declassified intelligence report has repeatedly concluded that Russia and North Korea have offensive biological weapons programs, while raising concerns about China and Iran. In 2024, The Washington Post documented a major expansion at Sergie...