AI Companies Race to Stop Their Models Being Used to Create Bioweapons and Novel Viruses
AI Has Already Designed Complete Working Viral Genomes
The Threat Has Moved Beyond Science Fiction
The world's most powerful artificial intelligence companies are entering a new kind of arms race: not simply to build smarter models, but to stop those models being turned into tools for biological harm. OpenAI, Anthropic and Google DeepMind are tightening safeguards as AI becomes increasingly capable of reasoning about genetics, laboratory science, drug discovery and biological design.
The timing is uncomfortable. Scientists have now demonstrated that generative AI can design complete viral genomes capable of producing functioning viruses in laboratory experiments, while several leading general-purpose AI systems are already being treated by their developers as possessing sufficiently powerful biological capabilities to require heightened security. The promise is enormous. So is the possibility of misuse.
The Threat Has Moved Beyond Science Fiction
For years, fears about AI-assisted biological weapons rested largely on a future scenario: a powerful model might eventually lower the expertise required to understand dangerous pathogens or help an already skilled actor move faster.
That future is getting closer to the present. Modern frontier models can reason across scientific literature, genetics, chemistry and experimental workflows with a competence that would have seemed extraordinary only a few years ago. Specialist biological AI systems are advancing alongside them.
The central concern is not that an ordinary chatbot can simply be asked to create a pandemic and obediently produce one. Biological weapons remain enormously difficult real-world undertakings requiring materials, facilities, expertise and experimentation.
The concern is instead one of acceleration. As AI improves, it could potentially remove pieces of the technical friction that currently protect society by making complex biological work difficult, expensive and dependent on scarce expertise.
That distinction matters. Catastrophic risks do not necessarily require AI to replace a laboratory scientist. A system capable of making an already dangerous actor substantially more capable could be enough to alter the threat landscape.
AI Has Already Designed Complete Working Viral Genomes
One of the most striking demonstrations arrived from researchers working with the genome language models Evo 1 and Evo 2.
Scientists used the models to generate complete genomes for bacteriophages — viruses that infect bacteria rather than people. Researchers experimentally tested hundreds of candidate designs and ultimately produced 16 viable phages.
This was not an experiment in engineering a human pandemic pathogen. Bacteriophages are an important area of medical research because they could potentially be used to attack dangerous bacteria, including strains resistant to antibiotics.
That distinction is critical. The experiment demonstrated a potentially valuable therapeutic technology, not the creation of a human bioweapon.
But its broader significance is difficult to ignore. Generative AI had moved beyond analysing biological information or proposing individual molecules. It had contributed to the design of complete biological genomes that could function once physically created.
Researchers analysing the capability have cautioned against overstating the result. Current systems may still operate largely by exploring biological possibilities close to existing natural sequences rather than inventing radically new classes of biological hazard.
Even so, the direction of travel is obvious. AI is beginning to participate in biological design rather than merely biological analysis.
Frontier Models Are Already Being Treated as High Biological Risk
The largest AI companies are not waiting for a proven AI-generated biological attack before responding.
OpenAI currently treats its GPT-5.6 family as having High capability in biological and chemical risk under its Preparedness Framework. That classification triggers stronger safeguards intended to prevent models from supplying assistance that could materially contribute to severe biological misuse.
The company uses multiple layers rather than relying solely on a chatbot refusing an obviously malicious question. These include specialised safety training, monitoring systems, account-level enforcement, red-team testing and restricted or trusted access for particularly sensitive biological research.
Anthropic has reached a similarly serious conclusion.
Its frontier safety framework states that its most powerful relevant models require ASL-3 protections because of their potential ability to provide meaningful assistance connected to chemical or biological weapons.
Anthropic's controls include access restrictions, model safeguards and continued adversarial testing designed to discover ways users could circumvent those protections.
This is important because the debate has shifted. The companies developing frontier AI are no longer discussing biological misuse purely as a remote theoretical possibility. They are building deployment systems around the assumption that sufficiently advanced models require specialised defences.
OpenAI Is Trying to Give the Defenders Better AI Too
Blocking dangerous requests is only one side of the emerging strategy.
OpenAI has increasingly argued that powerful biological AI should also be deliberately placed in the hands of scientists, public-health organisations and other vetted groups capable of strengthening biodefence.
Its Rosalind programme is built around that idea. Advanced biological models could help researchers understand diseases, accelerate drug development and improve the scientific response to biological threats.
Rosalind Biodefense extends the same logic directly into preparedness. The aim is to allow trusted developers and institutions to use advanced AI for tools that could improve detection, pandemic response and biological resilience.
The philosophy is essentially an attempt to win an asymmetric technological race.
If AI makes offensive biological capabilities more accessible, then defensive capabilities must improve even faster.
That could mean faster identification of unusual outbreaks, quicker analysis of emerging pathogens and shorter timelines for designing medicines or other countermeasures.
The most powerful defence against AI-assisted biological threats may therefore ultimately be more AI rather than less.
Google Wants AI Working for the Defenders
Google DeepMind and Isomorphic Labs are pursuing a similar concept through what they call bioresilience.
Their approach starts from an uncomfortable reality: increasingly capable biological AI cannot easily be divided into a harmless category and a dangerous category.
The same ability to understand proteins, predict biological structures or navigate complicated genetic information can support extraordinary medical discoveries while simultaneously creating knowledge that might be valuable to a hostile actor.
Google's proposed answer has two parts. Prevent malicious users from exploiting advanced systems while using those same systems to improve society's ability to detect and respond to biological threats.
That reflects the central contradiction running through the entire AI-biosecurity debate.
The scientific capability creating the risk may also become one of the strongest tools available for controlling that risk.
The Safeguards Are Improving — but They Can Still Be Broken
There is another uncomfortable problem: AI safety systems are not invulnerable.
The UK's AI Security Institute has repeatedly stress-tested safeguards used by frontier AI developers. Its researchers have found ways of circumventing restrictions across systems they examined, although breaking safeguards protecting against biological misuse has become substantially harder in some cases.
That is simultaneously encouraging and alarming.
It suggests developers can materially strengthen their defences. More sophisticated classifiers, safety training and monitoring can make harmful information substantially harder to extract.
But difficult is not the same as impossible.
A determined adversary does not have to behave like an ordinary user. They can repeatedly probe a system, disguise their intentions, break a dangerous task into apparently innocent components or search for weaknesses in the safety architecture.
This creates something resembling conventional cybersecurity.
Software is not considered secure merely because the first attempted attack fails. Defenders must assume sophisticated attackers will search continuously for the one weakness they have missed.
AI biosecurity increasingly has to operate under the same assumption.
The Hardest Problem Is AI's Dual-Use Power
Biology makes this uniquely difficult because dangerous and beneficial scientific knowledge often overlap.
A model capable of understanding how viruses evolve may help scientists predict future outbreaks. A model capable of reasoning about genetic modification may help researchers develop therapies. A system that understands experimental biology deeply enough to accelerate legitimate laboratories will inevitably possess knowledge relevant to less benign goals.
Companies therefore face an increasingly awkward trade-off.
Make the safeguards too weak and dangerous capabilities become easier to obtain.
Make them too aggressive and legitimate scientists may find advanced AI almost useless for precisely the biological work that could save lives.
Trusted-access programmes are emerging as one attempt to solve this problem. Rather than exposing every capability equally to every user, companies can potentially provide advanced scientific tools to verified researchers operating under additional controls.
It represents a significant change from the original consumer-chatbot model of AI, in which essentially everyone received broadly the same product.
The more capable AI becomes, the less realistic that model may be for the most sensitive scientific domains.
Physical Biology Still Creates a Crucial Barrier
There is also an important reason not to turn the emerging risk into science fiction.
Information alone does not create a biological weapon.
The physical world remains an enormous constraint. Biological experiments require laboratories, equipment, materials, expertise, testing and frequently repeated failure before anything works.
That gives governments and industry potential intervention points outside the AI model itself.
Biological synthesis providers, research institutions, laboratory suppliers and scientific infrastructure could become part of a layered defensive system in much the same way that banks, payment companies and cryptocurrency exchanges are used to disrupt financial crime.
AI safeguards therefore cannot be the only line of defence.
If increasingly sophisticated systems can generate biological designs, monitoring what moves from computer-generated sequence to physical biological material becomes more important.
The strongest biosecurity system would make an attacker defeat several independent barriers rather than relying on one chatbot to recognise malicious intent perfectly every time.
AI Is Also Making Biology Much More Powerful
The danger should not obscure why technology companies are reluctant simply to cripple biological AI.
The potential upside is immense.
Models capable of navigating genomic information, molecular structures and experimental data could accelerate drug discovery, improve understanding of genetic disease and help scientists explore biological systems at a scale humans cannot manage alone.
The bacteriophage experiment illustrates that upside almost perfectly.
Antibiotic resistance threatens to make some bacterial infections increasingly difficult to treat. Viruses designed to attack specific bacteria could eventually provide another weapon against resistant infections.
A technology that appears alarming when described as "AI designing viruses" can simultaneously represent a potentially important new form of medicine.
That is what makes this problem fundamentally different from preventing an AI system from producing obviously malicious content.
The capability itself is valuable.
The challenge is controlling who can use it, how much assistance they receive and where the boundary between legitimate scientific support and dangerous enablement should sit.
The Biosecurity Race Is Only Beginning
The most consequential stage may still be ahead.
AI models are improving quickly, biological models are becoming more sophisticated and autonomous AI agents are increasingly capable of performing long chains of work rather than merely answering individual questions.
Those trends could eventually converge.
An AI that can reason about biology is one thing. A system capable of conducting scientific research, using specialist software, interpreting results, coordinating tools and autonomously pursuing complex biological objectives would represent a much more serious governance challenge.
The industry's current defensive architecture is being built before that capability fully arrives.
That explains the urgency.
Developers are experimenting with restricted access, sophisticated classifiers, independent testing, stronger monitoring and specialised programmes that give trusted defenders access to powerful biological AI.
None provides a perfect solution.
But waiting for an AI-assisted biological attack before creating those systems would be a catastrophic way to discover where the weaknesses were.
One Failure Could Change Everything
Artificial intelligence could become one of the greatest scientific tools biology has ever possessed. It could help design medicines, understand diseases and respond to outbreaks faster than anything available today.
It could also make certain forms of dangerous biological knowledge easier to navigate.
Both statements can be true simultaneously.
That leaves AI companies attempting something extraordinarily difficult: accelerate a technology precisely because of its ability to transform biological science while ensuring that the same transformation does not lower the barriers protecting society from catastrophic misuse.
The most important evidence may therefore not be whether an AI has already created a human biological weapon. There is no evidence that it has.
It is that the companies building the world's most capable models are already behaving as though biological capability requires an entirely different level of security.
The race is no longer simply to build the smartest AI.
It is to make sure the smartest AI does not make the world's most dangerous forms of knowledge dramatically easier to use.

