Skip to content
OGERIA — Observatory of Global Evidence on Risks in AISynthesis report · 2026 ed.
Updated 2 Oct 2026

Chapter 01 · Risk map

Biological and CBRN

Biological uplift for novices

An actor without specialist training gets from a model the explicit knowledge and protocol that previously required a human mentor.

Severity
Catastrophic
Horizon
Already happening
Evidence
Lab
Consensus
Medium

UpliftUpliftHow much better a person does at something with an AI at their side, compared with what they would achieve alone. This observatory uses it mostly for dangerous capabilities.For exampleLike assembling furniture with a video tutorial beside you: it does not give you the tools, but you finish sooner and with fewer mistakes than with the manual alone. is the difference between what an untrained actor achieves alone and what they achieve with a model alongside them. The risk is not that the model invents a weapon: it is that it substitutes for the mentor an amateur does not have.

The 2026 evidence is split in two, and both halves are primary. Zhang, Knight and co-authors compared novices with LLMLLM (large language model)A large language model: the kind of AI behind assistants such as ChatGPT, Claude or Gemini, trained on enormous amounts of text to predict which word comes next.For exampleLike your phone's autocomplete, but trained on vastly more text: that is why it can carry a whole conversation and not just the next word. access against novices with only the internet across eight sets of biosecurity tasks, all in silicoIn silicoDone on a computer, by simulation or with data, without real biological material. The phrase refers to the silicon in chips.For exampleLike practising in a flight simulator: it teaches a lot, but it is not the same as taking off in a real plane.: the former were 4.16 times more accurate (95% CIConfidence intervalThe range within which the true value probably lies, given what was measured. The wider it is, the less precise the measurement. It is abbreviated CI.For exampleLike saying you will arrive “between 7 and 7:20”: you do not know the exact minute, but you do know the margin. 2.63-6.87) [1139]LLM Novice Uplift on Dual-Use, In Silico Biology TasksZhang, Chen Bo Calvin; Knight, Christina Q.; Kruus, Nicholas et al. · 2026 · preprintView source ↗Accessed on 9 September 2026. Hong and eleven co-authors ran a randomised, pre-registeredPreregistered studyA study that published, before starting, what it would measure and how it would analyse it, so that it cannot later pick only the results that suit it.For exampleLike announcing which number you are betting on before rolling the dice, not after seeing how they landed. trial with blinded assessors, with 153 novices in a physical laboratory working through a viral reverse geneticsReverse geneticsTechniques for creating a working virus from its written genetic sequence, instead of obtaining it from a natural sample.For exampleLike building a machine from its blueprints without ever having held one. workflow: there was no difference in the primary endpoint of completeness (5.2% with an LLM against 6.6% with the internet; P = 0.759) [523]Measuring Mid-2025 LLM-Assistance on Novice Performance in BiologyHong, Shen Zhou; Kleinman, Alex; Mathiowetz, Alyssa et al. · 2026 · preprintView source ↗Accessed on 9 September 2026. They do not contradict each other. Explicit knowledge has stopped being the barrier; the physical barrier still stands.

The labs report it from the inside and in a precautionary way: OpenAI treats the GPT-5.6 family as High capability in the biological and chemical domain, with 3 of 4 evaluations above the threshold, and warns that two of them may be saturated [825]GPT-5.6 System CardOpenAI · 2026 · system cardView source ↗Accessed on 9 September 2026.

What this does not demonstrate. There is no real biological incident attributed to AI; the OECD record that circulates most documents that some chatbots handed over instructions when pressed, not a consummated harm [811]AI Chatbots Provide Detailed Instructions for Biological Weapons, Exposing Safety FailuresOECD AI Incidents Monitor · 2026 · webView source ↗Accessed on 9 September 2026. On 27 August 2026, Sonia Ben Ouagrham-Gormley argues that the historical obstacle was never access to information but sustaining reservoirs of tacit knowledgeTacit knowledgeWhat is learnt by doing, through practice and with someone teaching alongside, and is not written down in any manual. In biology it is one of the barriers that text does not replace.For exampleKnowing when bread dough is ready by how it feels to the touch: you do not learn it by reading the recipe.: the Soviet anthrax programme needed years of in-person collaboration to adapt protocols it already had written down [156]Rethinking the De-skilling Narrative in AI and Biological Weapons PolicyBen Ouagrham-Gormley, Sonia · 2026 · webView source ↗Accessed on 9 September 2026. And nobody has measured uplift for wet-labWet labA laboratory where work is done with real material —cells, viruses, reagents— as opposed to work done only on a computer.For exampleThe difference between reading a recipe and cooking it: the wet lab is the kitchen. experts, the group SecureBio pointed to as the most plausibly benefited [108]The State of Bio-Uplift Research in Mid-2026Aziz, Humam · 2026 · forum postView source ↗Accessed on 9 September 2026.

Chain of materialisation

  1. PreconditionObserved

    Models outperform experts on knowledge benchmarks

    In the GPT-5.6 system card, the baseline of 36 PhD virologists on Multimodal Troubleshooting Virology is 22.1% mean accuracy; the best model scored 55.5%. OpenAI treats the whole family as High capability in biological and chemical risk.

    Precedents: The GPT-5.6 system card documents misalignment in internal deployment · Claude Opus 4 deploys under the ASL-3 standard as a precautionary measure · Anthropic releases Claude Fable 5 and Claude Mythos 5

  2. TriggerLab

    A novice with the model beside them clears the knowledge barrier

    Zhang, Knight and co-authors measured novices with LLM access against novices with internet only across eight biosecurity task sets, entirely in silico: 4.16 times more accurate (95% CI 2.63-6.87), beating experts on three of the four benchmarks with an expert baseline.

    Precedents: The OECD logs chatbots that provided biological weapons instructions

    Observed and demonstrated evidence ends here. What follows is projection.

  3. CascadeProjected

    The plan would have to survive the wet lab

    This is where the link weakens, and it must be said: in a physical lab, with 153 novices and a preregistered design, uplift vanishes. That the physical barrier falls -through automation, tacit-knowledge transfer, or synthesis and remote-lab services- is a projection, not a measurement.

  4. ImpactSpeculative

    A biological agent released by someone who previously could not

    There is no such case. The Global Terrorism Database records 36 biological-weapon attacks in 50 years out of 209,706 total attacks, with a median of zero deaths: the magnitude of any future case is speculative at both ends.

See on the map →Report a mistake in this entry →

Sources

  1. [1139] LLM Novice Uplift on Dual-Use, In Silico Biology Tasks · Zhang, Chen Bo Calvin 2026
  2. [523] Measuring Mid-2025 LLM-Assistance on Novice Performance in Biology · Hong, Shen Zhou 2026
  3. [886] The Operational Risks of AI in Large-Scale Biological Attacks: Results of a Red-Team Study · RAND Corporation 2024
  4. [825] GPT-5.6 System Card · OpenAI 2026
  5. [68] Activating AI Safety Level 3 Protections · Anthropic 2025
  6. [82] System Card: Claude Fable 5.1 & Claude Mythos 5.1 · Anthropic 2026
  7. [156] Rethinking the De-skilling Narrative in AI and Biological Weapons Policy · Georgetown Journal of International Affairs 2026
  8. [811] AI Chatbots Provide Detailed Instructions for Biological Weapons, Exposing Safety Failures · OCDE 2026
  9. [370] Do the biorisk evaluations of AI labs actually measure the risk of developing bioweapons? · Epoch AI 2025
  10. [108] The State of Bio-Uplift Research in Mid-2026 · Aziz, Humam 2026

Ask OGERIA

It answers only with what the observatory publishes and can be wrong: check the entries it cites. Your questions are sent to an AI model, so don't write personal data. More in the privacy policy.

Up to 500 characters.

Support OGERIA on Ko-fi

The payment is processed by Ko-fi, not by this site. Open on ko-fi.com