Agentic AI
,
Artificial Intelligence & Machine Learning
,
Cyberwarfare / Nation-State Attacks
Experts Warn AI Could Lower Barriers to Malicious Use and Risky Scientific Mistakes

Life sciences, pharmaceutical and biotechnology firms, and research institutions are embracing powerful artificial intelligence tools to speed the discovery of scientific breakthroughs and the development of new medical innovations. But what biological threats does AI pose in the hands of malicious actors – or even through benign mishaps?
See Also: How Skilled Attackers Weaponize AI Faster
The White House in late July issued a policy paper aimed at tamping down potential “high-risk” life sciences research and dangerous “gain-of-function” research funded by the U.S. government. That research could involve a biological agent that seeks or has “a substantial risk of achieving significant negative societal consequences,” including threats to public health, biosecurity or national security.
The White House’s new policy prohibits federal support for dangerous gain-of-function research conducted in the United States and abroad, establishes independent review for certain high-risk life sciences research and restricts federal funding for such research conducted in countries or institutions “that lack appropriate biosafety, biosecurity and oversight standards.”
The 12-page policy paper says relatively little about AI-related threats, but it does acknowledge the risks. Under the plan, the White House Office of Science and Technology Policy will convene “an interagency group to monitor advancements at the intersection of biological sciences and AI, including in silico life sciences research.”
So what AI risks and threats worry experts most? Novel bioweapons or dangerous unintended accidents, according to biosecurity experts.
AI tools, such as powerful frontier models, large language models and other systems, could make it easier to design biological agents that evade existing defenses and allow less-skilled users to perform increasingly sophisticated biological research, creating dangerous substances.
At the same time, significant scientific and laboratory barriers still stand between AI-generated instructions and the creation of novel pathogens that could pose a danger, they said.
“Biological risk can be hard to quantify, because nearly every advance in AI-enabled biological science could benefit both legitimate researchers and malicious actors,” said Barbara Del Castello, an associate physical scientist at research institution and think tank RAND Corp.
Emerging threats involving AI extend beyond powerful large language models, she said. For instance, specialized biological AI models can help scientists predict pathogen properties, engineer proteins and explore biological designs, while AI agents are becoming increasingly capable of navigating those tools and assisting with complex scientific workflows.
“It’s best to imagine biological risk in the AI space as a house,” she said. “Large language models ‘lower the floor,’ meaning more bad actors who have less skill can enter the space. I am increasingly more concerned with how LLMs, with the help of a smaller subset of AI tools called ‘biological tools,’ or ‘BTs’ for short, can raise the ceiling on risk – meaning they are capable of doing something much worse than they could achieve previously,” she said.
“These BTs are much narrower, trained on specific biological data such as predicting pathogen properties or engineering proteins.”
Evading Existing Defenses
One of the most significant concerns is whether AI-enabled biological design could outpace defenses intended to identify dangerous biological material.
Crystal Grant, a senior fellow at the security policy institute Council on Strategic Risks’ Center on Strategic Weapons, said tools capable of helping researchers design biological agents that evade existing defenses are among the top risks.
“What concerns me most is tools that can aid in biodesign that evades our known defenses,” Grant said.
That could include designing mutations that help pathogens escape human immunity or reduce vaccine effectiveness, as well as generating sequences capable of evading gene synthesis screening designed to identify known sequences of concern, she said.
Indeed, generative AI systems could design proteins that retain the function of a dangerous original while using substantially different genetic sequences, Del Castello said.
“It is effectively like designing a weapon that can pass through a digital metal detector unnoticed,” she said.
How Much Can AI Really Help a Novice?
A critical question for policymakers is whether AI could enable people without significant scientific training to develop dangerous biological threats.
Historically, “tacit knowledge” – the practical experience required to successfully perform sophisticated laboratory work – has been a major barrier, experts said.
“We are witnessing an erosion of the expertise barrier,” Del Castello said. “AI is effectively digitizing tacit knowledge and turning complex biological protocols into software-guided tasks.”
RAND research has found that frontier AI models are approaching human-expert performance in troubleshooting some laboratory procedures. Researchers also have examined whether LLM agents can independently select specialized biological tools and navigate their documentation and code repositories.
“We found these agents can not only identify the right specialized tools for a design task with high accuracy but can also autonomously navigate code repositories and perform basic operations,” Del Castello said.

The capability could allow someone without specialized computational training to interact with biological engineering models that would otherwise require substantial expertise.
But Grant cautioned against concluding that AI has eliminated the expertise barrier for bad actors or even less-experienced scientists.
Although studies indicate LLMs can help novices progress further through scientific protocols, “a lot of deep biological knowledge and expertise is needed to successfully create a novel pathogen,” Grant said.
Even when AI is used for biological design, researchers must iteratively test and validate their work in laboratories using specialized equipment, she said.
AI can therefore shorten the biological “design-build-test-learn” cycle and serve as a scientific collaborator for literature reviews, hypothesis generation and biological design, she said. But for now, “the strongest uplift will continue to be with subject matter experts with in-lab experience,” Grant said.
That distinction could prove important in assessing near-term biological threats from AI.
Rather than enabling an untrained individual to create an entirely novel pathogen from scratch, AI may pose a more immediate risk by helping less-skilled actors work with known pathogens or biological threats whose genetic information is already available, Grant said.
“The use of AI to aid actors without sufficient science expertise may be more likely if their aim is to generate known threats and pathogens – for example, a strain of a virus whose genome is known and available online – or to leverage AI to aid in the spread of a known pathogen once acquired,” she said.
“Scientists have noted that AI can be helpful in thinking up novel dispersal methods,” she added.
For instance, the New York Times in April reported that researchers using OpenAI’s ChatGPT, Google Gemini and Anthropic’s Claude received responses in chat conversations that could have enabled bad actors to figure out how to produce a novel toxin and distribute it over populated areas.
From Chatbots to AI Agents
But some researchers are particularly concerned about the transition from AI systems such as chatbots that answer questions to autonomous AI agents capable of performing portions of scientific workflows.
Del Castello said RAND researchers have demonstrated that AI agents can design biologically coherent DNA sequences and provide laboratory road maps for producing biological products.
Agents can also navigate documentation and code repositories associated with sophisticated biological models, including EVEscape, a method for predicting the likelihood of antibody escape for viral mutations, and the ESM3 protein design model, she said.
ESM3 is a powerful multimodal generative language model developed by EvolutionaryScale that reasons over the sequence, structure and function of proteins.
“We have data that suggests that LLM agents can autonomously navigate the documentation and code repositories of high-risk tools like EVEscape and ESM3 to execute workflows that previously required years of training,” Del Castello said.
“We often understand LLMs through the lens of chatbots where they are coaching individuals through information, but we have data that suggests that LLMs can act as agents and perform some of these tasks without the need for much human input,” Del Castello said.
“When you combine this with the rise of automated labs, a bad actor could potentially conduct high-risk experiments without ever setting foot in a physical laboratory,” she said.
“This pivot toward agentic AI in the lab space could allow bad actors to ‘outsource’ their biological weapon production.”
Open-Source Model Risks
Another concern is what happens after powerful biological models are publicly released, the experts said.
RAND’s “Global Risk Index for AI-Enabled Biological Tools” research released last year found that more than 60% of the highest-risk models it examined were fully open source, Del Castello said.
Unlike centrally hosted commercial AI systems, an open-source model cannot effectively be recalled once it has been released and copied. “Once these tools are released, they cannot be ‘un-invented’ or withdrawn, creating a permanent shift in the global security landscape,” she said.
That creates a mismatch between the potentially dangerous capabilities of some biological AI tools and the mechanisms available to govern their use, Del Castello said.
AI vendors are also aware of the potential biological threats involving their technologies. Microsoft, in a statement provided to ISMG, said its Frontier Governance Framework manages potential national security and at-scale public safety risks that could emerge as AI models increase in capability, including risks related to bioweapons.
“Our most advanced models are screened for these capabilities at multiple points from pre-training through deployment, and any model showing frontier capabilities goes through a deeper assessment involving adversarial testing, capability elicitation and evaluation by qualified third parties.”
Meanwhile, Google referred ISMG to a recent paper describing its approach. “To ensure that Gemini is safe, but still useful to scientists and experts, we use threat modeling to understand which actors are most likely to be willing and able to carry out an attack. We draw on various evaluation methods – from expert red-teaming to randomized controlled trials – to help judge whether Gemini could help threat actors overcome the primary bottlenecks they face,” Google said.
Google added that it also deploys various mitigations to counter these risks. “Our post-training methods teach the model to identify and refuse to assist queries with harmful intent, while aiming to avoid the over-refusal of beneficial science queries. Our classifiers and probes detect and block risky user activity, while our targeted analysis of user logs helps detect more subtle patterns of misuse and ensures that our mitigations are working effectively. These mitigation efforts are complemented by robust security infrastructure and privacy controls.”
Google said it is also “closely” partnering with government bodies, external experts and peers across this risk reduction process. “In the next 6 to 12 months, our priorities include threat intelligence, evaluation methods for AI agents and jailbreak mitigations. We are also working with our peers at the Frontier Model Forum to align on best practices for difficult questions, such as how to treat riskier datasets – for example, in virology.”
Neither OpenAI nor Anthropic immediately responded to ISMG’s requests for comment and details on the strategies they are taking to address evolving biological threats involving their AI products.
OpenAI has previously said its AI models are trained to refuse or safely respond to harmful requests, and Anthropic similarly said it “blocks” its models from responding “on a narrow selection of bioweapons-related queries.”
But experts told ISMG that mitigating AI-enabled biological threats will require safeguards throughout the biological research ecosystem rather than relying on AI developers or even DNA synthesis companies alone.
Aurelia Attal-Juncqua, a policy researcher at RAND, said the approach requires a defense-in-depth approach.
“Building safety does not depend on a single inspection. It relies on several layers, such as construction standards, controlled access, alarms, firebreaks and emergency response,” she said. “AI-bio governance can be approached in a similar way.”
Depending on the system and the level of risk, that could include evaluating high-capability models; securing sensitive models and biological data; using appropriate access controls, cybersecurity, logging and monitoring; screening at points where digital designs are translated into physical materials; and creating ways for relevant warning signals to be shared and acted on, she said.
“Early-warning, attribution and response capabilities may also be important if prevention fails. The goal is not to assume that any one safeguard will be perfect, but to create multiple opportunities to make misuse or accidents harder to carry out, easier to detect and less likely to escalate into a major biological event.”
Grant described a similar strategy as a “Swiss cheese approach to biosecurity,” with safeguards at every level of the AI-bio technology stack.
“The biological data being collected and used to develop the most powerful narrow biological AI models must be secured, and these models themselves must be secured, with well-enforced managed access,” Grant told ISMG.
The interaction between autonomous AI agents and specialized biological models also requires scrutiny as agentic capabilities improve, she said.
Grant also called for stronger “know-your-customer” requirements and legally mandated gene synthesis screening for both synthesis providers and companies providing benchtop synthesis devices.
She said Congress and antitrust regulators could help clarify how competing AI companies can collaborate and exchange information about biological threats for the sake of biosecurity without running afoul of competition rules.
“Frontier companies have already expressed their eagerness to harden their tools to a wide variety of biothreats,” she said. “International standards around data and cyber-biosecurity in the age of agentic AI are also needed. These are some of the most promising steps.”
Attal-Juncqua said governments and organizations also need early-warning, attribution and response capabilities in case preventive controls fail.
Balancing Biosecurity and Scientific Research
Meanwhile, efforts to regulate AI-enabled biological research face a fundamental challenge: The same technologies that create security concerns can accelerate medical research and the development of countermeasures against biological threats, the experts said.
“It’s important to remember this science is dual-use and nuanced,” Grant said. “What may seem to be a dangerous application in one setting enables deeper knowledge into human health and medical countermeasure development in another.”
That makes collaboration among biological researchers, AI developers, biosecurity specialists and national security officials particularly important, Grant told ISMG.
“Those in the biosecurity space working in tandem with biological researchers can best clarify what risk levels can be associated with different research contexts,” she said.
Researchers working directly with the technology can help policymakers understand its capabilities and limitations, while security specialists can provide perspective on how emerging technologies could be weaponized, Grant said.
For healthcare and life sciences security leaders, the debate also expands the scope of AI governance.
Protecting an organization against AI-related biological threats may increasingly require security teams to look beyond employees’ use of GenAI chatbots and consider who can access specialized biological models, genomic and other sensitive research datasets, DNA synthesis infrastructure and automated laboratory systems, the experts said.
“It’s important that this remain an ongoing dialogue, with those hands-on in the research community able to address the realities and limitations of these novel technologies, while those in the biosecurity and national security community can speak to the realities of past and present successful attempts to weaponize novel technologies and the need to limit how widely some technologies are shared,” Grant said.
