Silhouettes of three people running with a giant hand above, against a red background with a biohazard symbol.

Why AI Bioweapons Are Still More Theory Than Imminent Threat

Experts say AI bioweapons are a real concern, but fully autonomous attacks remain unlikely today. Here’s what the risks and defenses look like.

In short

Experts say AI could help humans misuse biological knowledge, but today’s systems are not close to autonomously building and releasing a bioweapon. The bigger challenge is strengthening screening, safeguards, and outbreak detection before misuse happens.

  • Experts say AI can assist biosecurity threats, but it is not yet able to autonomously build and deploy a bioweapon.
  • The most realistic danger is human misuse of AI, not a rogue model acting alone.
  • DNA synthesis screening, model safeguards, and outbreak surveillance are the main defenses discussed.
  • Some researchers believe bioweapon panic is overstated because pathogens are difficult to control and deploy effectively.
  • Many experts also warn that doom talk could distract from AI’s potential to speed up vaccines and medical research.

Artificial intelligence is accelerating fears about engineered pandemics, but experts say the most alarming scenario — a rogue AI independently building and releasing a bioweapon — remains far less likely than the headlines suggest. The bigger near-term danger, they say, is humans using AI to help with biological harm, while existing gaps in biosafety and DNA screening leave room for misuse.

That debate has intensified in recent months after AI executives pushed for tighter controls on synthetic DNA, researchers showed that models can help design viral genomes, and Anthropic disclosed attempted misuse of Claude for biological purposes. Together, those developments have pushed bioweapons to the center of the policy conversation in Washington and Silicon Valley. But scientists and biosecurity specialists interviewed for this story argue that the public conversation often overstates what today’s AI systems can actually do.

The central question is no longer whether AI can touch biology. It can. The real question is whether that capability meaningfully lowers the barriers to building and spreading a weaponized pathogen. Many experts say the answer is still no — at least not in the way popular doomsday narratives imply.

Why is AI bioweapons fear rising now?

AI bioweapons fear is rising because several separate developments have converged at once: research advances, company warnings, and political interest in regulation. Each one has added momentum to a broader anxiety that frontier models might eventually make biological attacks easier to plan or execute.

Earlier this summer, prominent AI leaders called for new limits on synthetic DNA production. Soon after, Stanford University and the Arc Institute reported that AI could help generate new viral genomes. Then Anthropic said it had seen attempts to use Claude in ways that could support biological weapons development, describing that misuse as one of the most serious risks facing frontier models.

That sequence matters because it has created a powerful narrative: if models can reason about biology, synthesize protocols, and assist with design, perhaps they can also help construct a pathogen. But several researchers say that leap confuses information access with real-world execution.

“AI is essentially a tool that can help both good actors, like scientists, and also threat actors to peruse information more quickly and define and source those protocols more quickly,” said David Bellamy, a research scientist at the Institute of Foundation Models in Sunnyvale, California. He added that those abilities are not the main bottleneck in making a bioweapon.

What actually stands between an idea and a bioweapon?

The biggest barriers are physical, technical, and operational, not informational. According to scientists who study biosafety and biosecurity, an attacker would still need materials, specialized equipment, experimental know-how, and the ability to validate that a pathogen works as intended.

That means obtaining the right genetic fragments, assembling a genome, testing whether it infects humans, checking whether it causes a specific disease, and determining whether it spreads efficiently from person to person. Those steps are difficult even in legitimate research settings and become much harder if the goal is malicious use.

Bellamy argues that those constraints existed long before the current generation of AI. Internet search, digital journals, translation tools, and widely available scientific literature have already expanded access to biological knowledge. AI may make the search faster, but it does not eliminate the need for hands-on expertise and controlled lab work.

Robotics can help automate parts of lab research, but it does not solve the full problem. A complex biological workflow still requires judgment, supervision, and access to actual facilities. Even highly capable software cannot directly summon reagents, machines, or a functioning wet lab.

How much can robotic labs really do?

Robotic lab systems can speed up repetitive steps, but they do not make pathogen creation trivial. The more complex and delicate the biology, the more human oversight remains necessary. That is why many specialists say “autonomous lab” talk can sound more advanced than the technology actually is.

Jason Kelly, chief executive of biotech firm Ginkgo Bioworks, says he does not think artificial general intelligence could simply seize a lab and deploy pathogens on its own. Ginkgo has spent years building autonomous lab infrastructure, including a recent project with OpenAI in which a GPT-5 model ran a lab workflow.

Kelly said the AI could not take over the lab because people inside the facility could refuse to supply the materials and instruments it would need. In his view, that human layer of control means a truly autonomous biological attack would require far more robots, far more facilities, and far less human oversight than exists today.

In other words, the barrier is not just intelligence. It is embodiment. A model can suggest a path. It still cannot physically carry out the sequence without tools, supplies, and a permissive environment.

Could an AI actually build a virus on its own?

Today, most experts say no. Fully autonomous labs do not yet exist at the scale or reliability that would be required for an AI system to independently create and release a virus from start to finish.

That does not mean the risk is zero. It means the scenario people fear most is still constrained by real-world dependencies. A model cannot order materials unless a supply chain permits it. It cannot run experiments unless a lab is available. It cannot verify results unless someone or something performs the tests. And it cannot easily bypass human scrutiny at every step.

Immunologist Derya Unutmaz says those same human controls would be a major obstacle to any attempt by AGI to engineer a fatal disease. He also argues that if a dangerous pathogen ever emerged, other AI systems could be used to accelerate vaccine development and countermeasure design.

The point, according to Unutmaz, is that AI is not uniquely one-sided. The same tools that could assist a harmful actor may also help scientists respond much faster than in previous outbreaks.

Why some experts say the greater threat is human misuse

The most plausible near-term danger is not an AI deciding to become a bio-terrorist, but a person using AI assistance to move faster through the research and planning process. That could include generating ideas, summarizing protocols, narrowing down information, or helping locate relevant materials.

Olivia Scharfman, a biotechnology fellow at the Institute for Progress, says the current technical environment does not allow a model to walk into a fully autonomous lab and make a virus by itself. But she argues that AI could still help someone else do it, including by paying a human to conduct the work.

Scharfman said AI-assisted bioterrorism is the more immediate concern and warned that fringe ideological groups, including some “transhumanist AI successionists,” could be especially dangerous if they are willing to pursue violent ends.

Her point reflects a broader distinction that runs through the biosecurity debate: direct machine-led attack versus machine-assisted human attack. The second scenario is much more realistic, because it requires fewer technological breakthroughs.

Who might try to exploit AI for biological harm?

In this debate, researchers tend to focus less on superintelligent machines and more on human actors with extreme motives. That includes ideologues, lone actors, or organized groups willing to experiment with biological threats. The concern is not that AI creates malicious intent, but that it lowers the effort needed to act on it.

Even so, the actual path from malicious curiosity to successful release remains long, expensive, and risky for the perpetrator. Biological attacks are difficult to control, difficult to aim, and difficult to contain.

Why bioweapons may be less attractive than people assume

Some researchers think the bioweapons panic misses a bigger strategic point: pathogens are not always the most efficient way to harm people. In many cases, they are harder to control than alternative forms of violence and much harder to scale reliably.

Genetic biologist and computational biology professor Francois Belloux says people often overestimate the effectiveness of pathogens as weapons. He argues that biological attacks are logistically complicated, difficult to target precisely, and not necessarily the best choice for anyone intent on mass violence.

Belloux said there are “much, much, much better ways” to kill people than engineering and releasing a virus or bacterium, whether the attacker is a human being or a highly advanced AI.

That observation does not make the threat harmless. It does suggest that some of the most apocalyptic scenarios are methodologically flawed. A bioweapon can spread unpredictably, fail to take hold, mutate in unwanted ways, or trigger detection before it reaches a target population.

In practical terms, the difficulties are enormous. The attacker must manage the science, the delivery, the timing, and the aftermath. Any one of those steps can fail.

What can governments and companies do now?

Experts largely agree that the right response is layered defense rather than a single silver bullet. That means adding friction at multiple points: model behavior, DNA synthesis screening, outbreak detection, and information-sharing among institutions.

Steph Guerra, who leads AI and bio work at the Rand Corporation, says it is still hard to measure exactly how much AI changes bioweapon risk. But she argues that uncertainty is not a reason for inaction.

One of the clearest policy ideas is tighter oversight of synthetic DNA and RNA providers. Some companies already screen customer orders for sequences of concern, but the practice is not universal and is not mandated everywhere. Requiring more consistent screening could make it harder to order materials useful for harmful purposes.

Another priority is ensuring that AI models themselves do not provide operationally dangerous instructions. If systems can be coaxed into giving actionable details for harmful biological work, that becomes a moderation and safety problem as much as a biosecurity one.

What does layered biosecurity look like?

Layered biosecurity means multiple checkpoints rather than one barrier. It is designed to make abuse harder at every stage, from early ideation through to any attempted release of a pathogen.

  • Customer screening for DNA and RNA synthesis orders
  • Model safeguards that block dangerous biological guidance
  • Improved lab access controls and procurement checks
  • Better monitoring of unusual outbreak patterns
  • Faster data sharing between AI firms, providers, and government agencies
  • Building-level protections such as stronger air filtration systems

Guerra says the goal is not perfect prevention, which may be impossible. Instead, the aim is to create enough friction that an attacker is delayed, exposed, or deterred.

She also argues for stronger global surveillance so public health systems can spot unusual outbreaks early and alert researchers quickly. The faster scientists know that a new pathogen is circulating, the faster they can assess it and begin countermeasures.

Issue What experts say Why it matters
AI-assisted bioweapon design Possible in limited ways, mainly as a research aid Could speed up malicious planning or information gathering
Fully autonomous AI bioweapon creation Not realistic today Requires labs, materials, and physical execution that models do not control
DNA synthesis screening Already used by some firms, not universally required Can block suspicious orders before materials are produced
Outbreak detection Needs stronger surveillance and faster data sharing Early recognition can reduce spread and improve response

How should policymakers think about the risk?

Policymakers should treat the issue as a biosecurity problem that AI may amplify, not as proof that AI itself is about to unleash a pandemic. That distinction changes the policy response.

If the danger is mainly human misuse, the response should focus on access control, procurement screening, model safeguards, and surveillance. If the danger is a future autonomous system, then long-term planning should emphasize lab robotics, containment, and governance around increasingly capable agents.

For now, the immediate policy opportunity is in the existing system. Many of the needed protections already exist in partial form; the challenge is making them broad, enforceable, and consistent.

That includes laws that require DNA and RNA sellers to screen for risky sequences. It also includes better protocols for sharing security-relevant data across the private sector and public agencies. Guerra says no control will be foolproof, which is exactly why multiple controls are needed.

What gets lost in the doom debate?

Some researchers worry that the fixation on catastrophic scenarios can overshadow more realistic and more beneficial uses of AI in biology. That concern has become louder as public discussion shifts toward worst-case futures.

Unutmaz says the negative attention can distract from AI’s role in vaccine development, drug discovery, and other medical advances. In his view, the public should not ignore risk, but it should also not overlook the potential health benefits that advanced models could deliver.

This is the core tension in the field: the same systems that raise new safety concerns may also speed up life-saving research. The policy challenge is to preserve the upside while building safeguards strong enough to stop abuse.

What the debate reveals about frontier AI

The bioweapons discussion reveals a broader truth about frontier AI: its power is often most visible in information work, but society worries most when that power appears to spill into the physical world. Biology is especially sensitive because it connects digital reasoning to real-world harm.

That makes biosecurity a test case for AI governance. If institutions can build sensible controls here — without choking off legitimate science — they may establish a model for handling other dual-use risks as systems become more capable.

Timeline: How the bioweapons concern escalated

The current alarm did not appear overnight. It built steadily as research, corporate warnings, and policy debate reinforced one another.

When What happened Why it mattered
Earlier this summer AI executives called for tighter controls on synthetic DNA manufacturing Signaled that industry leaders saw biosafety as a front-line issue
Last month Stanford and the Arc Institute reported AI could design new viral genomes Raised fears that models could assist in harmful biological design
Last week Anthropic said it had seen misuse attempts involving Claude and biological development Put real-world abuse examples into the public conversation
Shortly after Dario Amodei urged government to help AI labs “pace the frontier” Added urgency to the call for regulatory and safety frameworks

Bottom line: should people worry?

People should worry about AI and biology, but not in the simplistic way some headlines suggest. The strongest expert consensus in this debate is that AI does not yet make a fully autonomous bioweapon attack easy, or even plausible, in the near term.

The more credible concern is that AI can assist human actors, shorten research steps, and expose gaps in biosecurity systems that were already there. That makes the challenge real, but also addressable with better policy, stronger screening, safer model behavior, and faster public health detection.

In the end, the most useful response may be the least dramatic one: improve the defenses we already know how to build, while continuing to watch for genuine technological breakthroughs that could change the equation.

Frequently asked questions

Can AI build a bioweapon by itself?

No, not with current technology. Experts say today’s AI models can help with information gathering and planning, but they cannot independently access materials, run experiments, and verify a pathogen the way a real lab team can.

What is the main AI bioweapons risk today?

The main risk is human misuse with AI assistance. A person could use models to move faster through research, identify protocols, or even recruit others, which is more plausible than a model autonomously creating a virus.

How can governments reduce AI bioweapons risk?

Governments can require DNA and RNA synthesis screening, improve outbreak surveillance, and support AI safeguards that block dangerous biological instructions. Experts also recommend sharing security data across companies and public agencies.

Why do some scientists think bioweapons are overhyped?

Some scientists say pathogens are difficult to target, hard to control, and logistically complex to deploy. In their view, there are often easier and more reliable ways for bad actors to cause harm.

Could AI help against biological threats too?

Yes. Researchers say AI can also speed up vaccine design, outbreak analysis, and other medical responses. That is why many experts argue the goal should be safer AI and stronger biosafety, not abandoning the technology.

Share this 🚀