Biological and CBRN
Models lowering the knowledge barrier to create, obtain or deploy biological and chemical agents.
The harm enters through knowledge, not through the machine. No model synthesises a pathogen: what it can do is shorten the distance between wanting to do it and knowing how, and until now that distance was the main barrier to entry. The thresholds the labs use are written around that idea and not around the agentAI agentAn AI system that does more than answer: it takes a goal and acts on its own to reach it, step by step, using tools such as a browser, email or a terminal, without anyone approving each step.For exampleAsking an assistant to suggest flights is using a chatbot. Asking it to search, compare, buy the ticket and put it in your calendar, all by itself, is using an agent.: Anthropic’s is defined by whether an individual “with a basic technical background” receives significant help [68]Activating AI Safety Level 3 ProtectionsView source ↗.
What sets this vectorVectorThe path by which a risk moves from the screen into the world: biological, cyber, military, economic, political, epistemic or loss of control. In this observatory, each vector has its own colour.For exampleA burglar can get in through the door, the window or the roof. The burglar is the risk; the door, the window and the roof are the vectors. apart from the others is the relationship between its potential severity and its observed evidence. None of the incident databases consulted records real biological harm attributed to AI [31]AI Incident Database — Database SnapshotsView source ↗. The 2026 record with the heaviest media coverage documents chatbots that handed over instructions under pressure, not an attack [811]AI Chatbots Provide Detailed Instructions for Biological Weapons, Exposing Safety FailuresView source ↗. The historical contrast calibrates the baseline: the Global Terrorism Database records 36 terrorist attacks using a biological weapon over fifty years, with a medianMedianThe middle value when all the answers are sorted from lowest to highest: half fall below it and half above. Unlike the average, a few extreme values do not shift it.For exampleIf five people earn 1, 1, 2, 2 and 50, the average is 11.2 and the median is 2, which describes most of them better. of zero deaths [886]The Operational Risks of AI in Large-Scale Biological Attacks: Results of a Red-Team StudyView source ↗.
What has advanced is in the lab, and it is narrow. Genomic language modelsLLM (large language model)A large language model: the kind of AI behind assistants such as ChatGPT, Claude or Gemini, trained on enormous amounts of text to predict which word comes next.For exampleLike your phone's autocomplete, but trained on vastly more text: that is why it can carry a whole conversation and not just the next word. generated hundreds of thousands of bacteriophage candidates; 285 went on to synthesis and 16 turned out to be viable [597]Generative design of bacteriophages with genome language modelsView source ↗verified through Crossref. Agents equipped with biological tools managed to redesign sequences that evaded screening, though with low and inconsistent reliability [888]Testing Large Language Model Agents on the Use of Biological Tools for Nucleic Acid Synthesis Screening EvasionView source ↗. Measuring the real ceiling is blocked: the safeguards on closed models made it impossible to test them [888]Testing Large Language Model Agents on the Use of Biological Tools for Nucleic Acid Synthesis Screening EvasionView source ↗.
Risks in this vector
- ProjectedExpert-enhanced pathogensIrreversible
A team that already knows virology uses biological design models to produce an agent with properties that do not exist in nature.
- LabSynthesis screening evasionCatastrophic
AI-redesigned sequences keep their function while no longer resembling what synthetic DNA providers screen for.
- ProjectedRemote labs without verificationCatastrophic
AI agents chain design, synthesis ordering and execution in contract labs without any human verifying who is ordering or why.
- LabBiological uplift for novicesCatastrophic
An actor without specialist training gets from a model the explicit knowledge and protocol that previously required a human mentor.
See among the vectors →Report a mistake in this entry →
Sources
- [68] Activating AI Safety Level 3 Protections · Anthropic 2025
- [31] AI Incident Database — Database Snapshots · AI Incident Database 2026
- [811] AI Chatbots Provide Detailed Instructions for Biological Weapons, Exposing Safety Failures · OCDE 2026
- [886] The Operational Risks of AI in Large-Scale Biological Attacks: Results of a Red-Team Study · RAND Corporation 2024
- [597] Generative design of bacteriophages with genome language models · Stanford University / Arc Institute 2026 verified through Crossref
- [888] Testing Large Language Model Agents on the Use of Biological Tools for Nucleic Acid Synthesis Screening Evasion · RAND Corporation 2026