Biological uplift for novices
An actor without specialist training gets from a model the explicit knowledge and protocol that previously required a human mentor.
- Severity
- Catastrophic
- Horizon
- Already happening
- Evidence
- Lab
- Consensus
- Medium
UpliftUpliftHow much better a person does at something with an AI at their side, compared with what they would achieve alone. This observatory uses it mostly for dangerous capabilities.For exampleLike assembling furniture with a video tutorial beside you: it does not give you the tools, but you finish sooner and with fewer mistakes than with the manual alone. is the difference between what an untrained actor achieves alone and what they achieve with a model alongside them. The risk is not that the model invents a weapon: it is that it substitutes for the mentor an amateur does not have.
The 2026 evidence is split in two, and both halves are primary. Zhang, Knight and co-authors compared novices with LLMLLM (large language model)A large language model: the kind of AI behind assistants such as ChatGPT, Claude or Gemini, trained on enormous amounts of text to predict which word comes next.For exampleLike your phone's autocomplete, but trained on vastly more text: that is why it can carry a whole conversation and not just the next word. access against novices with only the internet across eight sets of biosecurity tasks, all in silicoIn silicoDone on a computer, by simulation or with data, without real biological material. The phrase refers to the silicon in chips.For exampleLike practising in a flight simulator: it teaches a lot, but it is not the same as taking off in a real plane.: the former were 4.16 times more accurate (95% CIConfidence intervalThe range within which the true value probably lies, given what was measured. The wider it is, the less precise the measurement. It is abbreviated CI.For exampleLike saying you will arrive “between 7 and 7:20”: you do not know the exact minute, but you do know the margin. 2.63-6.87) [1139]LLM Novice Uplift on Dual-Use, In Silico Biology TasksView source ↗. Hong and eleven co-authors ran a randomised, pre-registeredPreregistered studyA study that published, before starting, what it would measure and how it would analyse it, so that it cannot later pick only the results that suit it.For exampleLike announcing which number you are betting on before rolling the dice, not after seeing how they landed. trial with blinded assessors, with 153 novices in a physical laboratory working through a viral reverse geneticsReverse geneticsTechniques for creating a working virus from its written genetic sequence, instead of obtaining it from a natural sample.For exampleLike building a machine from its blueprints without ever having held one. workflow: there was no difference in the primary endpoint of completeness (5.2% with an LLM against 6.6% with the internet; P = 0.759) [523]Measuring Mid-2025 LLM-Assistance on Novice Performance in BiologyView source ↗. They do not contradict each other. Explicit knowledge has stopped being the barrier; the physical barrier still stands.
The labs report it from the inside and in a precautionary way: OpenAI treats the GPT-5.6 family as High capability in the biological and chemical domain, with 3 of 4 evaluations above the threshold, and warns that two of them may be saturated [825]GPT-5.6 System CardView source ↗.
What this does not demonstrate. There is no real biological incident attributed to AI; the OECD record that circulates most documents that some chatbots handed over instructions when pressed, not a consummated harm [811]AI Chatbots Provide Detailed Instructions for Biological Weapons, Exposing Safety FailuresView source ↗. On 27 August 2026, Sonia Ben Ouagrham-Gormley argues that the historical obstacle was never access to information but sustaining reservoirs of tacit knowledgeTacit knowledgeWhat is learnt by doing, through practice and with someone teaching alongside, and is not written down in any manual. In biology it is one of the barriers that text does not replace.For exampleKnowing when bread dough is ready by how it feels to the touch: you do not learn it by reading the recipe.: the Soviet anthrax programme needed years of in-person collaboration to adapt protocols it already had written down [156]Rethinking the De-skilling Narrative in AI and Biological Weapons PolicyView source ↗. And nobody has measured uplift for wet-labWet labA laboratory where work is done with real material —cells, viruses, reagents— as opposed to work done only on a computer.For exampleThe difference between reading a recipe and cooking it: the wet lab is the kitchen. experts, the group SecureBio pointed to as the most plausibly benefited [108]The State of Bio-Uplift Research in Mid-2026View source ↗.
Chain of materialisation
PreconditionObserved
Models outperform experts on knowledge benchmarks
In the GPT-5.6 system card, the baseline of 36 PhD virologists on Multimodal Troubleshooting Virology is 22.1% mean accuracy; the best model scored 55.5%. OpenAI treats the whole family as High capability in biological and chemical risk.
Precedents: The GPT-5.6 system card documents misalignment in internal deployment · Claude Opus 4 deploys under the ASL-3 standard as a precautionary measure · Anthropic releases Claude Fable 5 and Claude Mythos 5
TriggerLab
A novice with the model beside them clears the knowledge barrier
Zhang, Knight and co-authors measured novices with LLM access against novices with internet only across eight biosecurity task sets, entirely in silico: 4.16 times more accurate (95% CI 2.63-6.87), beating experts on three of the four benchmarks with an expert baseline.
Precedents: The OECD logs chatbots that provided biological weapons instructions
Observed and demonstrated evidence ends here. What follows is projection.
CascadeProjected
The plan would have to survive the wet lab
This is where the link weakens, and it must be said: in a physical lab, with 153 novices and a preregistered design, uplift vanishes. That the physical barrier falls -through automation, tacit-knowledge transfer, or synthesis and remote-lab services- is a projection, not a measurement.
ImpactSpeculative
A biological agent released by someone who previously could not
There is no such case. The Global Terrorism Database records 36 biological-weapon attacks in 50 years out of 209,706 total attacks, with a median of zero deaths: the magnitude of any future case is speculative at both ends.
Scenarios where it appears
Related measures
See on the map →Report a mistake in this entry →
Sources
- [1139] LLM Novice Uplift on Dual-Use, In Silico Biology Tasks · Zhang, Chen Bo Calvin 2026
- [523] Measuring Mid-2025 LLM-Assistance on Novice Performance in Biology · Hong, Shen Zhou 2026
- [886] The Operational Risks of AI in Large-Scale Biological Attacks: Results of a Red-Team Study · RAND Corporation 2024
- [825] GPT-5.6 System Card · OpenAI 2026
- [68] Activating AI Safety Level 3 Protections · Anthropic 2025
- [82] System Card: Claude Fable 5.1 & Claude Mythos 5.1 · Anthropic 2026
- [156] Rethinking the De-skilling Narrative in AI and Biological Weapons Policy · Georgetown Journal of International Affairs 2026
- [811] AI Chatbots Provide Detailed Instructions for Biological Weapons, Exposing Safety Failures · OCDE 2026
- [370] Do the biorisk evaluations of AI labs actually measure the risk of developing bioweapons? · Epoch AI 2025
- [108] The State of Bio-Uplift Research in Mid-2026 · Aziz, Humam 2026