i
DATAIST
News · 2026-09-18

Anthropic warns on bioweapons, biologists point at the lab bench

@neuronium_ai @neuronium_ai

Anthropic published a report last week describing attempts to use Claude in ways that could support the development of biological weapons, and called biological misuse "one of the most serious risks of frontier AI models." Shortly afterwards, CEO Dario Amodei urged the government to help AI labs keep pace with frontier development. The biologists who work with pathogens for a living are markedly less alarmed, and their objection is narrow and physical: the hard part of building a bioweapon was never finding the protocol, and finding protocols is the part AI is good at.

Cover: Anthropic warns on bioweapons, biologists point at the lab bench

Anthropic published a report last week describing attempts to use Claude in ways that could support the development of biological weapons, and called biological misuse "one of the most serious risks of frontier AI models." Shortly afterwards, CEO Dario Amodei urged the government to help AI labs keep pace with frontier development. The biologists who work with pathogens for a living are markedly less alarmed, and their objection is narrow and physical: the hard part of building a bioweapon was never finding the protocol, and finding protocols is the part AI is good at.

The timing is not accidental. Earlier this summer, executives at AI companies called for new laws governing the production of synthetic DNA. Last month, researchers at Stanford University and the Arc Institute showed that AI can design new viral genomes. Then came Anthropic's report. Three escalating beats in a single season, each one from inside the industry, each one arriving as Washington and Silicon Valley talk themselves further into the scenario where a runaway model wipes out humanity with an engineered pathogen.

David Bellamy, a research fellow at the Institute of Foundation Models in Sunnyvale, California, does not see AI as a fundamentally new threat in this context. The scientific community has argued for decades about whether to publish potentially dangerous biological research — the dual-use dilemma. Long before large language models, Bellamy says, the internet, open-access journals and translation services like Google Translate had already made biological information easy to obtain, lab protocols included.

AI helps both legitimate scientists and bad actors skim information faster, find the protocol they need and get to it. Those capabilities are not the binding constraint. The constraint is assembly: building the virus or other biological agent, and obtaining the materials, equipment and know-how to do it. An attacker would have to:

obtain the required gene fragments;

assemble a complete genome from scratch;

verify that the virus can infect humans;

confirm that it causes the intended disease;

establish that it transmits from person to person.

Robotic lab assistants can automate individual steps and speed up workflows. The person running them still needs the expertise to design those experiments and the resources to carry them out.

Jason Kelly, CEO of the biotech startup Ginkgo Bioworks, thinks it unlikely that a general-purpose AI could seize and spread pathogens that already exist. Creating new ones and deploying them would be harder still. Ginkgo builds autonomous labs, and recently ran a joint project with OpenAI in which GPT-5 operated one. Even so, Kelly says an AI could not take over a lab by itself: the people inside can simply refuse to hand a bot the substances and equipment needed to physically manufacture a weapon. For a general-purpose model to direct machines through the delicate work of virology, it would need far more robots in far more places. Humans, as an additional layer of control, remain a serious obstacle.

The immunologist Derya Unutmaz makes a related argument on the response side. Even if a malicious superintelligence somehow released a particularly dangerous virus, he says, scientists could use other AI systems to develop a vaccine quickly.

The most interesting counterargument in this debate comes from Olivia Scharfman, a biotechnology fellow at the Institute for Progress. AI cannot today access a fully autonomous lab and assemble a virus on its own, she notes, for the simple reason that fully autonomous labs do not yet exist. But an AI can pay a human to do it. Scharfman treats AI-enabled bioterrorism as an immediate threat and believes there are groups willing to attempt it, including what she calls "transhumanist AI successionists" — adherents of a fringe ideology who hope to replace humanity with bots.

François Balloux, a geneticist and professor of computational biology, told WIRED that the risks are widely misread, because people overstate the value of pathogens as weapons in the first place. Set the question of general-purpose AI aside entirely and biological weapons remain an unattractive choice for anyone who wants to kill large numbers of people: it is hard to strike one population while sparing another, and mass production and dissemination demand complicated logistics compared with, say, setting off a bomb. There are far more efficient ways to kill people than growing a virus or a bacterium and then distributing it. That holds for the most sophisticated artificial system and for an ordinary person alike.

Here is what I think the reassurance is actually made of. Every version of it in this story reduces to two facts about the present tense: fully autonomous labs do not exist, and humans standing between a model and a freezer can say no. Neither is a law of nature. Both are staffing and capital-expenditure decisions, and the industry is spending money to change them. The person offering the most concrete comfort is the CEO of a company whose business is autonomous labs, and which just finished a project in which OpenAI's GPT-5 ran one. That is not hypocrisy — Kelly is describing his own equipment accurately, and he is better placed than most to know how far it is from virology. But it does mean the safety margin is an artifact of how much automation has been deployed so far, and nobody in this debate puts a date on when it thins. Scharfman's point that an AI can simply hire a human is the sharpest thing anyone says, because it removes the autonomous lab from the argument altogether, and nobody answers it.

What the participants do agree on is the policy, which is notable mostly for how little of it is about AI. Governments could require companies selling synthetic DNA and RNA to screen customers and orders; many already run software that checks for hazardous sequences, but the practice is neither universal nor mandatory. Models should have guardrails that stop them from handing out dangerous, practically usable information before an attacker gets near genetic material. Scharfman argues that the attention AI is drawing to bioweapons makes this a good moment to harden defenses against all biological threats, existing ones like H1N1 included — through DNA-synthesis security laws, upgraded building air filtration, and other changes that lower the background risk of viral spread. Steph Guerra, who leads AI and biology work at the RAND Corporation, says it is genuinely hard to establish whether AI demonstrably raises bioweapon development risk; what AI does well is combine information and motivate people toward both useful and harmful ends. Even at low risk, she argues, society can prepare: stronger global surveillance to catch new diseases and circulating pathogens early, faster routing of that data to researchers, and data-sharing protocols between AI companies, gene synthesis providers and government agencies. No single biosecurity measure can be made impossible to circumvent, which is why Guerra wants layered approaches that put obstacles along the entire path, from the moment an attacker forms the intent to the moment a weapon is released.

Unutmaz considers something else more pressing: that extinction talk is pulling attention away from what frontier systems can do for vaccine development and other medical advances. He is describing a cost, and it is the one this whole conversation keeps paying. The measures the experts converge on — order screening, surveillance, air filtration — are cheap, unglamorous and largely predate the models everyone is arguing about. The apocalypse framing is what gets them discussed, and it is also what guarantees the discussion happens in AI policy rooms rather than public health ones.