Skip to content
OGERIA — Observatory of Global Evidence on Risks in AISynthesis report · 2026 ed.
Updated 2 Oct 2026

Chapter 01 · Risk map

Biological and CBRN

Remote labs without verification

AI agents chain design, synthesis ordering and execution in contract labs without any human verifying who is ordering or why.

Severity
Catastrophic
Horizon
1–3 years
Evidence
Projected
Consensus
Low

Skeptics of biological risk rest their case on tacit knowledgeTacit knowledgeWhat is learnt by doing, through practice and with someone teaching alongside, and is not written down in any manual. In biology it is one of the barriers that text does not replace.For exampleKnowing when bread dough is ready by how it feels to the touch: you do not learn it by reading the recipe.: knowing the protocol is not knowing how to carry it out. Contract laboratories and synthesis services exist to sell exactly that execution. The risk is that an agentAI agentAn AI system that does more than answer: it takes a goal and acts on its own to reach it, step by step, using tools such as a browser, email or a terminal, without anyone approving each step.For exampleAsking an assistant to suggest flights is using a chatbot. Asking it to search, compare, buy the ticket and put it in your calendar, all by itself, is using an agent. chains design, ordering and execution together without anyone checking who is placing the order, or what for.

The capability to operate the pipeline has been measured: RAND’s first finding is that LLMLLM (large language model)A large language model: the kind of AI behind assistants such as ChatGPT, Claude or Gemini, trained on enormous amounts of text to predict which word comes next.For exampleLike your phone's autocomplete, but trained on vastly more text: that is why it can carry a whole conversation and not just the next word. agents show an emerging capability to use biological tools for biodesign, which could lower barriers of expertise [888]Testing Large Language Model Agents on the Use of Biological Tools for Nucleic Acid Synthesis Screening EvasionLee, Jeffrey; Worland, Alyssa; Rodriguez, Christopher et al. · 2026 · reportView source ↗Accessed on 9 September 2026. Verification on the other side of the counter is not mandatory: the open letter of June 2026, signed by the CEOs of OpenAI, Anthropic, Google DeepMind and Microsoft, asks that screening be made mandatory, that providers verify the legitimacy of the customer, and that they keep records of orders [944]An Open Letter in Support of Mandatory Nucleic Acid Synthesis Screening and RecordkeepingCoalición de firmantes de tecnología, industria de síntesis, ciencias de la vida y seguridad nacional · 2026 · webView source ↗Accessed on 9 September 2026. That it has to be asked for is itself a measure of the gap, and Eric Horvitz confirms it from Microsoft: most screening remains voluntary and unevenly applied [723]Strengthening biosecurity in the era of AIHorvitz, Eric · 2026 · institutional blogView source ↗Accessed on 9 September 2026.

How that verification would fail has already been seen in another vectorVectorThe path by which a risk moves from the screen into the world: biological, cyber, military, economic, political, epistemic or loss of control. In this observatory, each vector has its own colour.For exampleA burglar can get in through the door, the window or the roof. The burglar is the risk; the door, the window and the roof are the vectors.: Trend Micro documents an agent jailbrokenJailbreakA way of writing to an AI so that it skips the safety rules it was given and answers what it should refuse to answer. A “jailbroken” model is one that has had this done to it.For exampleLike convincing a building's security guard that you are the lift engineer so that they let you in without a pass. by an actor who falsely declared they were running an authorised penetration test [1051]2026 H1 APT Report: How APTs Are Weaponizing Trust in the Age of AITrend Micro Research · 2026 · reportView source ↗Accessed on 9 September 2026. The control that gave way was not technical; it was accepting as true a declaration made by the requester itself.

What this does not demonstrate. There is no documented case of an agent that has ordered and obtained biological material. RAND’s performance was explicitly patchy —rarely were more than half of an agent’s designs satisfactory— [888]Testing Large Language Model Agents on the Use of Biological Tools for Nucleic Acid Synthesis Screening EvasionLee, Jeffrey; Worland, Alyssa; Rodriguez, Christopher et al. · 2026 · reportView source ↗Accessed on 9 September 2026. And Ben Ouagrham-Gormley’s argument applies here: a remote service delivers a product, not the capacity to adjust the protocol to local conditions, which is what has historically decided outcomes [156]Rethinking the De-skilling Narrative in AI and Biological Weapons PolicyBen Ouagrham-Gormley, Sonia · 2026 · webView source ↗Accessed on 9 September 2026.

Chain of materialisation

  1. PreconditionObserved

    Customer verification is voluntary and benchtop equipment is out of scope

    The June 2026 open letter asks for exactly what is not required today: that providers verify customer legitimacy and log orders. That it has to be asked for is the measure of the gap.

    Precedents: Open letter for mandatory nucleic acid synthesis screening

  2. TriggerLab

    Agents already operate biological tools on their own

    RAND documents emergent capability of LLM agents to use biological tools for biodesign tasks, with mixed and highly configuration-dependent performance. It is capability to operate a pipeline, not to decide what is worth doing.

    Precedents: A synthesis-screening evasion found via AI protein design is patched

    Observed and demonstrated evidence ends here. What follows is projection.

  3. CascadeProjected

    A requester's own declaration passes for authorisation

    The failure mode has been observed in another vector: Trend Micro documents an agent jailbroken by an actor falsely claiming a legitimate penetration test. The control that failed was not technical but authorisation verification, the same control separating a legitimate synthesis order from an illegitimate one.

  4. ImpactSpeculative

    Physical production with no human in the path

    It would be the first time the tacit-knowledge barrier -the sceptics' central argument- is bypassed by buying it rather than learning it. There is no case or quantitative model from which a magnitude follows.

See on the map →Report a mistake in this entry →

Sources

  1. [888] Testing Large Language Model Agents on the Use of Biological Tools for Nucleic Acid Synthesis Screening Evasion · RAND Corporation 2026
  2. [944] An Open Letter in Support of Mandatory Nucleic Acid Synthesis Screening and Recordkeeping · Coalición de firmantes de tecnología, industria de síntesis, ciencias de la vida y seguridad nacional 2026
  3. [723] Strengthening biosecurity in the era of AI · Microsoft 2026
  4. [547] International Gene Synthesis Consortium · International Gene Synthesis Consortium 2026
  5. [833] Framework for Nucleic Acid Synthesis Screening · The White House (OSTP) 2024 archived copy only
  6. [101] Synthetic Nucleic Acid Screening · HHS / ASPR 2026
  7. [1051] 2026 H1 APT Report: How APTs Are Weaponizing Trust in the Age of AI · Trend Micro / TrendAI 2026
  8. [156] Rethinking the De-skilling Narrative in AI and Biological Weapons Policy · Georgetown Journal of International Affairs 2026

Ask OGERIA

It answers only with what the observatory publishes and can be wrong: check the entries it cites. Your questions are sent to an AI model, so don't write personal data. More in the privacy policy.

Up to 500 characters.

Support OGERIA on Ko-fi

The payment is processed by Ko-fi, not by this site. Open on ko-fi.com