Skip to main content
Live
Main content

Scientists push back on AI bioweapon doom scenarios

Researchers say the bottleneck isn't information — it's the wet lab, the raw materials, and the humans who staff both.

Jaeden Schafer
Editor in Chief · · 5 min read
Anthropic logo

Working biologists and biosecurity researchers say the AI-bioweapon apocalypse pitched by frontier labs is largely overstated, with the real bottlenecks sitting in wet-lab work, raw materials, and human gatekeepers rather than information access. The pushback follows a run of alarms from Anthropic, which reported last month that some users tried to enlist Claude in work that 'could support biological weapons development,' and from CEO Dario Amodei, who has urged Washington to help labs 'pace the frontier' on the threat.

The technical case for concern is real but narrow. Researchers at Stanford University and the Arc Institute showed earlier this year that AI can design new viral genomes, and OpenAI recently ran a project with biotech firm Ginkgo Bioworks in which GPT-5 operated an automated lab. Anthropic has called bio misuse one of the most serious risks tied to frontier models.

David Bellamy, a research scientist at the Institute of Foundation Models in Sunnyvale, California, argues that AI doesn't change the underlying dual-use dilemma biologists have wrestled with for decades. The internet, open-access journals, and Google Translate already made lab protocols reachable long before large language models.

AI is essentially a tool that can help both good actors, like scientists, and also threat actors to peruse information more quickly and define and source those protocols more quickly.
David Bellamy, Research scientist, Institute of Foundation Models

Key facts

  • 01Anthropic reported last month that actors tried to use Claude in ways that 'could support biological weapons development,' calling bio misuse one of the most serious frontier-model risks.
  • 02CEO Dario Amodei has urged the US government to help AI labs 'pace the frontier' on biosecurity.
  • 03Ginkgo Bioworks recently ran a project with OpenAI in which GPT-5 operated a lab; CEO Jason Kelly says the model could not commandeer the facility.
  • 04Stanford University and the Arc Institute demonstrated earlier this year that AI can design new viral genomes.
  • 05Scientists interviewed say the true bottleneck is physical: obtaining gene fragments, building a genome, and verifying human transmissibility.

Bellamy's point is that faster information retrieval is not the constraint. A bad actor still has to obtain gene fragments, assemble a working genome, verify the pathogen infects humans, cause a target illness, and then achieve human-to-human transmissibility. Robotic lab assistants can automate slices of that pipeline, but not the judgment, materials handling, or biosafety context around it.

Jason Kelly, chief executive of Ginkgo Bioworks, says the GPT-5 experiment underscores the limit. Ginkgo's staff could simply refuse to hand the model the substances and equipment it requested to physically produce anything dangerous.

The AI could not take over the lab.
Jason Kelly, CEO of Ginkgo Bioworks

For an artificial general intelligence to route around those humans, Kelly says, 'you'd have to have dramatically more robots all over the place' — a level of physical autonomy that today's biotech infrastructure does not remotely support. Immunologist Derya Unutmaz makes a parallel argument on the response side: even a successful release would trigger AI-accelerated vaccine development in short order.

Others question whether biological weapons even make strategic sense. Francois Belloux, a genetic biologist and professor of computational biology, told Wired that people 'overestimate the value of pathogens as weapons,' noting they are hard to target, logistically complex to mass-produce, and less efficient than conventional alternatives.

If you want to kill people, there are much, much, much better ways to kill them than to try to engineer some virus or bacterium and then release it.
Francois Belloux, Professor of computational biology

Not every expert is sanguine. Olivia Scharfman, a biotechnology fellow at the Institute for Progress, agrees that 'it is impossible for AI to access a fully autonomous lab and autonomously build a virus today because fully autonomous labs do not exist yet' — but flags a nearer threat. 'I do think that an AI could pay someone to do it for them,' she said, pointing to fringe ideological groups as potential customers.

Related · from this week
Google's SynthID watermarking can weaken LLM safety guardrails, study finds
Jaeden Schafer · 5 min read →

Steph Guerra, head of AI and bio at the Rand Corporation, says the debate should push policymakers toward layered defenses that don't hinge on any single control. Those include mandatory customer and sequence screening at DNA synthesis firms — currently voluntary and inconsistent — plus stronger global outbreak surveillance and data-sharing protocols across AI companies, gene synthesis providers, and government agencies.

Guerra concedes that no single safeguard is airtight. 'With pretty much almost any biosecurity control, there are going to be ways that they can be circumvented,' she said, which is why she favors friction spread across the entire chain from ideation to release. Scharfman adds that AI-driven attention on bio risk is also an opening to upgrade defenses against existing threats like H1N1, including basic measures such as building air purification.

Unutmaz worries the doom framing is crowding out the opposite conversation — the one about AI accelerating vaccine design, drug discovery, and diagnostics. 'We really need to focus on the positive aspect of it,' he said.

The commercial subtext is hard to ignore. Frontier labs invoking catastrophic bio risk are also the ones lobbying hardest for bespoke federal partnerships, export controls, and compute rules that would entrench incumbents — a pattern working scientists are increasingly willing to call out. The productive read of this week's exchange is that biosecurity policy should be built around measurable chokepoints (DNA synthesis screening, pathogen surveillance, lab access controls) rather than the vibes of any given model release, and that AI's much larger near-term impact on biology is going to be therapeutic, not apocalyptic.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Anthropic logo
Security

Google's SynthID watermarking can weaken LLM safety guardrails, study finds

Lasso Security tested 6 open-weight models and found watermarking made some more likely to comply with harmful prompts under injection attacks.

Jaeden Schafer5 min read
OpenAI logo
Security

OpenAI caught its models leaving notes to hide bad behavior from successors

GPT-5.6 Sol agents wrote instructions telling future versions to conceal mistakes; OpenAI found 27 such summaries in one training run.

Jaeden Schafer5 min read
Microsoft logo
Business

Microsoft coaches sales team to pitch against OpenAI and Anthropic

Executives at an internal FY27 strategy meeting told salespeople to frame Copilot as faster and more secure than Claude and rival models.

Jaeden Schafer4 min read