Biosecurity

Biosecurity

Biosecurity encompasses all rules and precautions intended to prevent pathogens from causing harm – whether through accidents or deliberate intent. In the AI debate, the main question is whether language models could help laypeople build dangerous pathogens.

Biosecurity refers to all measures intended to prevent pathogens such as viruses or bacteria from causing major harm. This includes sealed specialty labs, controls on the shipment of genetic material, and laws governing dangerous research. Experts distinguish between two sides here. One concerns accidents: a pathogen escapes from a lab because a safety mechanism fails. The other concerns intent: someone deliberately attempts to use a pathogen as a weapon. In recent years, a third aspect has been added. Because programs that can answer questions in detail may also pass on dangerous specialized knowledge.

Why AI companies are talking about viruses of all things

Knowledge about dangerous pathogens was long hard to access. It was locked away in academic papers, in lab routines, and in the minds of a few specialists. This very hurdle has so far kept many people from even attempting something like this. A chatbot that summarizes complicated technical texts and answers follow-up questions could lower this hurdle. Experts call this a lowering of the entry threshold.

That is why biosecurity ranks near the top of the risk list at major AI labs. Companies like OpenAI and Anthropic name it alongside cyberattacks as one of the few risks that could trigger a genuine catastrophic scenario. The reason lies in the scale involved. A computer virus causes financial damage, whereas a biological pathogen costs human lives and cannot simply be switched off.

How great the actual danger is remains disputed. Critics point out that the real bottleneck is not knowledge but practical lab work. A text does not teach anyone how to handle live cultures without infecting themselves. Others counter that specialized knowledge combined with lab automation could narrow this bottleneck further.

Filters, tests, and red lines

The first layer of protection lies in training. Developers try to avoid including especially sensitive instructions in the training data in the first place. The model is then trained to refuse certain requests. In addition, filters run over inputs and outputs that detect suspicious patterns and halt the process.

Companies check whether this actually works using so-called red-team tests. In these, commissioned experts deliberately try to extract forbidden knowledge from the model. They might hide the question inside a fictional story or break it down into many seemingly harmless individual steps. If the team finds a way through, adjustments are made before the model is released. Some providers draw a firm line here: if a model reaches a certain danger level, it is not supposed to be released publicly at all.

One problem remains. Models with open weights, meaning freely downloadable models, can be modified after download. The refusals trained into them can be removed again with manageable effort. For such models, only what was removed from the training data beforehand has any effect.

Biosecurity in laws and product disclosures

In everyday life, you most often encounter biosecurity in the safety reports that companies publish with every new model. These regularly include a chapter on biological risks. Phrasings such as “the model provides no significant advantage to laypeople” come directly from these tests. If a provider classifies a model as particularly capable, it activates additional safeguards.

The term also appears in politics. The EU’s AI Act requires a risk assessment for very capable models that explicitly mentions biological hazards. In the US, providers of synthetic DNA have been required to screen orders against lists of dangerous sequences. This reveals an important insight: protection does not depend on software alone, but also on the companies that actually supply the biological material.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.