In short
A new discussion around Annie Jacobsen’s biological warfare book argues that AI is amplifying attention on a threat that already existed: the risk of accidental or deliberate bioweapons release. The piece says lab leaks, dual-use research and weak defenses make the bioweapons threat a serious global concern.
- Bioweapons are seen as a major threat even without AI because the barrier to entry is relatively low.
- Experts worry more about accidental lab releases than deliberate attacks in many scenarios.
- Anthropic’s Claude report shows AI can be probed for dangerous bio information, but it is not the root problem.
- Government continuity plans and devolution scenarios reflect how hard a major biological event would be to manage.
- The central challenge is balancing legitimate biomedical research with biosecurity and public safety.
Bioweapons remain a serious global danger even without artificial intelligence, and recent AI safety concerns are only making the risk easier to see. In a wide-ranging conversation published alongside Annie Jacobsen’s new book on biological warfare, the national security reporter argues that the biggest danger is not a sci-fi superintelligence, but the very real possibility of a pathogen slipping out of a lab and triggering a catastrophe.
That warning matters now because AI tools are increasingly being scrutinized for helping people research dangerous pathogens, yet the underlying bioweapons problem existed long before chatbots or agents entered the picture. Jacobsen says the more immediate threat is the ease with which biological work can be done, the number of facilities handling dangerous agents, and the difficulty of containing mistakes once they happen.
The discussion, drawn from research for her book Biological War: A Scenario, centers on a sobering conclusion: a large-scale biological attack or accidental release would be extremely hard to stop, and governments are far less prepared for it than many people assume.
Why bioweapons worry experts more than many AI doomsday scenarios
Biological weapons are alarming because they are comparatively easy to pursue and potentially devastating in effect. Unlike nuclear weapons, which require rare materials, complex delivery systems and state-level infrastructure, pathogen manipulation can happen in labs around the world with relatively broad access to tools, samples and expertise.
Jacobsen’s view is that this lower barrier to entry makes biological warfare especially dangerous. In her assessment, the most frightening part is not just the scale of the harm a pathogen can do, but how many people and institutions may be capable of creating or modifying one.
She points to a basic asymmetry in risk: even if only a small number of actors are malicious, the larger universe of legitimate research, dual-use experimentation and laboratory work creates many more opportunities for a mistake than for a deliberate attack.
How is a bioweapon different from a nuclear weapon?
The answer is that biological weapons are much easier to access, test and mishandle. Nuclear weapons demand highly controlled fissile material and sophisticated delivery systems, while a dangerous pathogen can be studied, altered or transferred in labs that operate under biosafety standards rather than military-grade arsenals.
Jacobsen argues that this matters because the number of facilities and researchers involved in pathogen work is far larger than the number of actors who can manage a nuclear program. That scale increases the odds of an accident and makes a secret program harder to track.
| Threat type | Main requirement | Barrier to entry | Primary risk |
|---|---|---|---|
| Nuclear weapon | Weapons-grade fissile material and delivery systems | Very high | Mass destruction by state-level actor |
| Biological weapon | Pathogen access, lab capability and know-how | Lower | Accidental leak or deliberate spread of infection |
| AI-assisted bio work | Digital tools plus lab capability | Potentially lower still | Faster misuse or easier evasion of safeguards |
What the Anthropic report added to the debate
The latest alarm came from Anthropic, which said earlier this month that its Claude system was being probed in attempts to evade safety guardrails for “gain-of-function” questions. In biological research, gain-of-function refers to experiments aimed at making a pathogen more infectious, more transmissible, more virulent or otherwise more dangerous.
Anthropic said it blocked the users seeking that material and suspended their accounts. The company also acknowledged an important complication: some of the same information can be used for defensive work, including vaccine design, drug discovery and pandemic planning. That dual-use tension is exactly what has kept biosafety debates unresolved for years.
In other words, the worry is not only that a chatbot might assist a bad actor. It is also that the same scientific information can have legitimate uses, making it harder to draw bright lines around what should be shared, studied or restricted.
Jacobsen’s core argument is that the danger existed before AI, but AI may make it easier to ask the wrong questions, find dangerous pathways faster, and normalize a field that already sits on a knife’s edge.
Why accidental release may be the bigger danger
According to Jacobsen, the most likely catastrophe is not a theatrical attack by a rogue extremist but an accidental release from a lab. She says expert and intelligence efforts to stop active bioweapons programs do exist, but they cannot eliminate the larger systemic risk posed by everyday laboratory work around dangerous agents.
That conclusion comes from a combination of history and probability. Accidents happen in high-security environments, and a single mistake can be enough when the material involved is highly pathogenic. The more people working on risky organisms, the more chances there are for a breach.
Jacobsen points to the global scale of biosafety-level facilities as part of the reason. She cites thousands of BSL-3 and BSL-4 laboratories worldwide, and argues that the sheer size of the system makes accidental release more plausible than a coordinated terrorist plot.
What are BSL-3 and BSL-4 labs?
BSL stands for biosafety level, a ranking that reflects how dangerous the organisms handled inside a facility may be. BSL-4 is the highest level and is reserved for the most hazardous agents, while BSL-3 labs handle pathogens that can cause serious or potentially lethal disease through inhalation or other routes.
These facilities are designed to reduce risk, but they are not magic shields. Human error, procedural failure and unexpected exposure remain possible, which is why laboratory accidents feature so prominently in biosecurity discussions.
- BSL-3: High-containment labs for serious airborne or infectious agents.
- BSL-4: Maximum-containment labs for the most dangerous known pathogens.
- Core risk: Containment reduces danger but cannot eliminate it.
How did post-9/11 fears reshape biosafety?
The answer is that the anthrax attacks accelerated attention to dangerous biological research and showed how terror can arise even when a pathogen is not designed to spread widely. Anthrax is deadly, but it is not typically a pandemic threat because infected people are not a transmission chain.
That distinction matters. A deliberately released respiratory pathogen, by contrast, could spread from person to person and quickly turn a local event into a global crisis.
Jacobsen argues that modern genetic engineering, gain-of-function methods and AI-assisted analysis have pushed the field into a new era. Researchers can now, in her view, tweak pathogens to evade existing immunity, increase transmission or alter host range, creating scenarios that were once much harder to imagine.
Her concern is not limited to malicious intent. She says some scientists and institutions have long shown a strong bias toward publishing, sharing and advancing the work even when the security implications are severe. In her telling, that culture can flatten public debate and sideline non-scientists from decisions that affect national security and public health.
What Jacobsen’s scenario books are trying to show
Jacobsen’s latest work follows the template she used in Nuclear War: A Scenario: she builds a dramatic but research-based account of how catastrophe could unfold, drawing from interviews with current and former officials, military planners, scientists and other experts.
The point, she says, is not to sensationalize the danger but to make it understandable. She argues that experts around the world often respond positively to that approach because it translates technical threats into plain language without losing seriousness.
In her reporting, she has heard from people who work in national security, diplomacy and treaty making who appreciated how accessible the subject became. That response, she suggests, is evidence that public understanding is lagging behind the reality of the threat.
She says many specialists told her that they were grateful to see the issue explained simply, because the topic is so often buried under jargon, prestige and professional gatekeeping.
What the biological scenario looks like
Jacobsen’s book imagines an accidental release from a high-security Russian laboratory, a setup she says is rooted in real-world patterns and expert discussions rather than fiction alone. Her choice of a lab leak, she explains, is driven by the fact that accidents are more probable than a determined actor knowingly unleashing something that could rebound on them.
She also ties parts of the scenario to past planning exercises and real crises, including the Covid-19 experience, to show how rapidly fear, travel disruption and institutional strain can compound one another.
One of the key lessons from those exercises is that a biological catastrophe is not just a medical event. It is also a social, political and logistical breakdown that can overwhelm supply chains, public trust and emergency response systems all at once.
Why do planners focus so much on social collapse?
The answer is that panic can spread faster than disease in some crises. If people believe hospitals will fail, treatments will run short or infections are unavoidable, they may flee, hoard supplies or resist authority in ways that accelerate the crisis.
Jacobsen says this fragility is why war-gaming scenarios often include public flight, civil disorder and government continuity planning. In the most severe models, the challenge is not only how to treat the sick, but how to preserve governance when fear erodes normal rules.
What is “devolution” in a national emergency?
Devolution is a continuity-of-government concept meant to preserve state function after a catastrophic disruption. In Jacobsen’s description, it is activated when a biological emergency triggers severe unrest, forcing a shift to emergency leadership arrangements and predetermined relocation plans.
The idea is that a separate group of designated officials or personnel would move to secure locations outside the Washington area and work from classified sites until the government can be reconstituted. Those facilities are commonly referred to as hot, warm and cold sites.
The existence of such planning underlines how seriously some officials view the possibility of a civilization-level emergency. It also highlights how much of the response architecture remains hidden from public view.
| Concept | Meaning | Why it matters |
|---|---|---|
| Continuity of government | Plans to keep the state functioning during disaster | Maintains command and decision-making |
| Devolution | Transfer of authority to preselected teams and sites | Provides a fallback if normal leadership is disrupted |
| Hot/Warm/Cold sites | Alternative government facilities with varying readiness | Allows rapid reconstitution after a crisis |
Why AI changes the conversation without replacing the real threat
AI does not create the biological danger from scratch, but it can lower the barrier to dangerous inquiry. That is why the recent Anthropic report matters: it shows that people are already trying to use frontier systems to probe around existing safeguards.
Still, Jacobsen’s broader point is that even if AI vanished tomorrow, the biosecurity problem would remain. The core risks come from human curiosity, lab access, dual-use knowledge and the difficulty of guaranteeing that no one makes a mistake.
She also raises a more speculative but chilling concern about so-called mirror life, a concept discussed by biosecurity expert David Relman, which she says could carry existential implications. That idea underscores the range of future bioengineered threats, from near-term leaks to far more radical possibilities.
What makes mirror life so troubling?
The answer is that it refers to an imagined form of life with reversed biological chirality, which could interact unpredictably with natural systems and human biology. Because the concept is still highly theoretical, it is discussed more as a warning about the limits of control than as an immediate threat.
Jacobsen includes it to signal that the future of bio-risk may be moving faster than public debate can keep up with. Even without AI, she argues, the frontiers of synthetic biology already stretch far beyond what most people realize.
What the experts say about response limits
A recurring theme in Jacobsen’s reporting is that there is no true defense against a large-scale biological attack. Officials can mitigate, isolate, trace contacts and distribute countermeasures, but once a highly transmissible agent is out in the world, the damage may already be underway.
That does not mean response is pointless. It means prevention and containment matter enormously, because the alternative may be only a reduction in harm rather than a clean stop.
One expert she cites, a retired Air Force colonel who helped run Pentagon war games, reportedly described the challenge as mitigation rather than prevention. That is a stark assessment, but it reflects the inherent asymmetry between a spreading pathogen and the institutions tasked with stopping it.
According to Jacobsen, the most unsettling expert view she encountered was that large-scale biological attack may not be something governments can fully defend against, only something they can try to blunt.
Timeline: how the modern bio-risk debate escalated
The current public debate did not appear overnight. It developed over decades of scientific advancement, security scares and policy conflicts that slowly raised the stakes.
| Period | Event or trend | Why it mattered |
|---|---|---|
| Cold War era | State bioweapons programs and arms control concerns | Established biological warfare as a strategic threat |
| Post-9/11 | Anthrax attacks and increased biosecurity attention | Showed the terror potential of biological agents |
| 2010s-2020s | Advanced genetic engineering and gain-of-function debates | Expanded concern over dual-use research |
| Mid-2020s | Frontier AI systems face bio-safety scrutiny | Raised fears of easier misuse and faster discovery |
What should readers take from all this?
The main takeaway is that biological risk is not a future problem waiting on AI to make it real. It is already with us, embedded in the structure of modern science, laboratory networks and global interdependence.
AI may intensify the danger by helping people search, summarize or strategize around restricted information, but the underlying challenge is older and deeper: how to preserve the benefits of biomedical research without creating pathways to catastrophe.
Jacobsen’s reporting suggests that complacency is the biggest mistake. Whether the threat comes from a leak, a rogue actor or a dangerous research culture, the consequences of failure could be global, rapid and extraordinarily hard to reverse.
Bottom line
Bioweapons remain a major security concern with or without artificial intelligence, and the recent attention on AI-assisted misuse is only one layer of a much larger problem. As Jacobsen’s work argues, the world may already be living with a risk structure that is too easy to underestimate and too hard to contain once it goes wrong.
Frequently asked questions
Why are bioweapons considered so dangerous?
Bioweapons are considered so dangerous because they can spread quickly, be difficult to detect early and overwhelm health systems before a response is organized. Unlike nuclear weapons, they can also be easier to access through ordinary research environments and can arise from accidents as well as intent.
Did Anthropic say Claude was helping build bioweapons?
No, Anthropic said it blocked attempts to use Claude for restricted gain-of-function questions and cut off the accounts involved. The company’s report highlighted misuse attempts, not successful assistance in building a bioweapon.
Is an accidental lab leak really more likely than a deliberate attack?
Yes, many experts believe accidental release is more likely because far more researchers and facilities handle dangerous pathogens than there are organized actors willing to launch a bioweapon. Human error, equipment failure and procedural lapses create more opportunities for a leak than a planned release.
What is gain-of-function research?
Gain-of-function research is work that changes an organism, often a virus or bacterium, to alter traits such as transmissibility, virulence or host range. It can help scientists prepare for outbreaks, but it also raises serious concerns because the same techniques could be misused or fail safely.
What does devolution mean in a national emergency?
Devolution is a continuity-of-government plan in which designated personnel move to backup sites so the government can keep operating after a catastrophic disruption. It is designed for extreme scenarios, including major biological events that could cause unrest or break normal command structures.









