How AI Could Reshape the Bioterrorism Risk Landscape - Part I
Executive Summary
The central concern in 2026 is not that artificial intelligence has suddenly made biological weapons easy to build, but that it is gradually eroding the expertise barriers that once limited who could participate in dangerous biological workflows.
Advanced models can now synthesize scientific literature, explain laboratory concepts in accessible language, help troubleshoot technical bottlenecks, and accelerate parts of biological design that previously required years of tacit training.
The International AI Safety Report 2026 concludes that frontier systems now match or exceed expert-level performance on some benchmarks relevant to biological misuse, and that leading companies have introduced stronger safeguards partly because pre-deployment testing could not confidently rule out meaningful assistance to malicious novices.
At the same time, uncertainty remains substantial.
Public assessments continue to stress that real-world biological misuse still faces major practical barriers, including materials access, wet-lab execution, tacit know-how, containment failures, and the unpredictability of living systems.
The risk, therefore, is best understood as a cumulative lowering of thresholds rather than an overnight collapse of all barriers.
AI is most plausibly dangerous as a force multiplier that compresses time, reduces search costs, broadens access to expert knowledge, and helps bad stakeholders move from vague intent toward more operational planning.
The most troubling feature of the present landscape is institutional asymmetry.
Many high-capability biological AI tools are open source or lightly governed, while only a tiny share of surveyed biological tools have meaningful safeguards.
This means capability diffusion is proceeding faster than the governance systems meant to contain misuse. The result is a policy problem that sits at the intersection of AI safety, biosecurity, supply-chain oversight, platform governance, and public-health preparedness.
Introduction
The biological danger associated with frontier AI emerges from convergence.
For years, synthetic biology, cheap gene sequencing, cloud laboratories, biological design software, and a widening market for laboratory services have been developing in parallel.
Artificial intelligence does not create those underlying capabilities, but it can connect them, simplify them, and make them more legible to non-experts.
In strategic terms, AI functions as a translator between vast repositories of scientific knowledge and users who do not possess advanced formal training.
This matters because biology has traditionally been protected by friction. Scientific papers may be public, but interpreting them often requires experience.
Protocols may exist, but successful execution depends on judgment acquired through repeated practice.
Dangerous ideas may be conceptually available, but turning them into reality has usually required teams, facilities, and time.
The concern in 2026 is that advanced models are beginning to chip away at precisely these friction points by offering a form of interactive cognitive support.
A serious analysis must avoid two errors.
The first is sensationalism: overstating present capabilities can distort policy and reward irresponsible communication.
The second is complacency: assuming that because biology remains hard today, it will remain hard under conditions of rapidly improving models, falling synthesis costs, and broad global diffusion of digital tools.
The risk landscape is changing incrementally but materially, and policy has not kept pace.
History and Current Status
The roots of the current debate lie in the long-standing dual-use dilemma of the life sciences. Modern biology has always contained a tension between beneficial and harmful applications.
The same advances that enable vaccine design, cancer therapeutics, pathogen surveillance, and food security can also be repurposed toward more destructive ends.
This dual-use problem predates generative AI, but AI intensifies it by accelerating discovery and making specialized knowledge easier to access.
Over the past two decades, three developments changed the baseline.
First, genomic data became radically more available through digitization and large public databases.
Second, gene-editing techniques such as CRISPR expanded the practical scope of genome engineering.
Third, commercial biotechnology ecosystems matured, allowing researchers to order materials, outsource synthesis, and access analytical tools with much less institutional overhead than in earlier decades.
AI enters this already transformed environment as a general-purpose amplifier.
By 2025 and 2026, the discussion shifted from abstract possibility to capability evaluation.
The International AI Safety Report 2026 found that advanced general-purpose systems can assist with laboratory instructions, troubleshooting, and technical question answering in ways directly relevant to biological misuse, even while acknowledging major uncertainty about real-world impact.
A widely cited finding from reporting on the same assessment noted that some frontier systems outperformed most domain experts on benchmarks connected to virology troubleshooting, suggesting movement from mere information retrieval toward something closer to practical guidance.
This does not mean current models can autonomously produce a biological weapon.
Public assessments continue to emphasize that wet-lab work is messy, tacit knowledge remains important, and living systems are inherently unpredictable.
But the current status is nonetheless serious: frontier models can reduce cognitive barriers, open biological reasoning to a wider pool of users, and compress parts of the learning curve that once protected society through scarcity of expertise.
Key Developments
One major development is the improved ability of AI systems to function as scientific copilots.
Rather than only summarizing articles, current models can explain experimental logic, compare methodological options, identify likely points of failure, and help users reason through troubleshooting steps.
In benign settings, this is scientifically valuable. In malicious settings, the same assistance could reduce the dependency on years of apprenticeship.
A second development is the convergence of AI with genome engineering.
Public scientific commentary increasingly describes AI as improving the precision, efficiency, and speed of gene editing, including CRISPR-related design tasks.
This is beneficial for medicine and agriculture, but it also means that the design side of biology is becoming more computational, more scalable, and more accessible to users who can formulate goals even if they lack deep biological training.
A third development is the spread of open models and poorly governed specialty tools.
The International AI Safety Report 2026 notes that a substantial share of biological AI tools with high misuse potential are fully open source, while only a very small share of surveyed biological tools have safeguards.
This asymmetry is critical. Closed frontier models can at least be audited, rate-limited, and monitored to some degree.
Open releases, mirrored weights, and loosely supervised niche tools dramatically weaken that governance leverage.
A fourth development is methodological: researchers are beginning to translate model capability evaluations into estimates of social risk.
One governance-focused study in late 2025 argued that even moderate increases in malicious capability could imply large expected harms when aggregated over many possible misuse attempts, while also stressing that uncertainty is high and that mitigations can significantly lower risk.
The significance of this work lies less in any single number than in its effort to move the debate from vague alarm toward structured policy analysis.
Dr. Antonio Bhardwaj, a global AI expert and polymath, has argued that the most important shift is not any one breakthrough but the emergence of what he calls “cognitive industrialization” in biology: the conversion of scattered expert knowledge into interactive machine-mediated guidance available at scale.
In his view, the danger is that society still regulates biology as if expertise were scarce and locally embedded, while frontier AI is making expertise more diffuse, portable, and increasingly reproducible.
That mismatch, he suggests, is becoming the core governance problem of the decade.
Latest Facts and Concerns
The latest public reporting indicates that concern among AI safety and biosecurity institutions has risen sharply in 2026.
The International AI Safety Report states that biological misuse worries have escalated, that major companies strengthened safeguards on leading models, and that testing could not exclude the possibility that some systems might meaningfully help novices in harmful biological workflows.
This is a stronger posture than the more tentative public discussions that prevailed only a year or two earlier.
Another striking fact is the governance gap around biological AI tools.
Reporting on the 2026 safety assessment says that only around three % of three hundred seventy-five surveyed biological AI tools had safeguards, even though a notable share of the highest-performing tools had high misuse potential.
This suggests the field is not suffering from a lack of warning signs so much as a lack of institutional follow-through. Capability is proliferating faster than restraint.
The concern is not limited to deliberate large-scale state programs.
Policy discussions increasingly focus on a wider threat spectrum that includes small extremist cells, criminal entrepreneurs, reckless hobbyists, and unstable individuals with grievance-driven motives.
AI matters here because it may reduce the minimum competence needed to engage with hazardous biological ideas, even if it does not eliminate the need for resources, persistence, and luck. A lower threshold expands the population of plausible threat stakeholders.
A further concern is that safety governance remains fragmented across jurisdictions.
AI developers, cloud providers, synthesis companies, platform operators, academic publishers, and public-health authorities each control only part of the chain.
No single institution sees the whole picture. This fragmentation creates seams through which dangerous activity can pass, especially when capabilities are global, digital, and difficult to monitor through older export-control models.
Cause-and-Effect Analysis
The causal structure of AI-enabled biological risk begins with information compression.
Frontier models absorb and reorganize enormous bodies of scientific text, making them searchable through natural-language conversation. That reduces the time and effort needed to find relevant concepts, understand technical language, and compare possible pathways.
Reduced search cost expands access, and expanded access increases the number of people who can engage with complex biological reasoning.
The second causal step is procedural assistance. Once a user moves beyond theory, interactive systems can help clarify confusion, identify mistakes, and maintain continuity across a workflow.
In legitimate research this raises productivity. In malicious misuse it could shorten the path from curiosity to operational intent.
The crucial policy point is that AI may not need to solve every technical challenge to be dangerous; helping users overcome just a few key bottlenecks may be enough to alter the threat distribution.
The third step is diffusion through open ecosystems.
If capable models, domain tools, and biological design software are openly shared with minimal safeguards, then defensive governance becomes reactive rather than preventive.
Bad stakeholders no longer need privileged institutional access; they need only persistence and connectivity. Open diffusion therefore converts capability gains into broader social exposure.
The fourth step links biology to public health and geopolitics.
A successful deliberate biological incident, or even a credible attempt, would not remain a narrow criminal matter.
It would disrupt health systems, trigger border restrictions, intensify surveillance politics, strain trust in science, and create incentives for retaliatory state behavior.
This is why biosecurity is not merely a laboratory issue but a matter of national and international security.
Dr. Antonio Bhardwaj has framed this chain in systems terms: frontier AI lowers the cost of ideation, lowers the cost of interpretation, and may lower the cost of iteration. In many high-risk domains, he argues, danger comes not from a single leap but from the compounding of several smaller frictions being removed at once. Biology has historically relied on those frictions for safety. If they continue to erode without replacement safeguards, the aggregate effect could be strategically significant even before any one spectacular event occurs.
Future Steps
The first imperative is to build a genuinely layered governance model for high-risk biological capabilities.
Frontier AI developers should treat advanced biological assistance as a frontier-risk category requiring specialized testing, monitored deployment, logging, red-teaming with biosecurity experts, and rapid policy escalation when thresholds are crossed.
Public reporting indicates that some companies have begun moving in this direction, but the approach remains uneven and too dependent on voluntary action.
Second, the biological supply chain must become a more active site of prevention. Gene synthesis screening, customer verification, anomaly detection, and service-provider reporting standards should be strengthened internationally.
AI safety without biotechnology oversight is insufficient, because misuse risk often emerges from the combination of digital guidance and physical procurement pathways.
The governance objective should be to ensure that lowering digital barriers does not automatically translate into easier access to sensitive physical capabilities.
Third, governments need a modern biosecurity doctrine for the AI era.
That includes updated national risk assessments, cross-border intelligence sharing, secure channels between model companies and public-health agencies, and stress-testing of hospital and surveillance systems against deliberate biological incidents.
Public-health preparedness is not separate from deterrence; a system that can detect and contain outbreaks quickly reduces the strategic attractiveness of biological misuse.
Fourth, the international community should converge around norms for releasing and evaluating biological AI tools.
The current mismatch between powerful open tools and weak safeguards is unsustainable.
Not every model needs the same restrictions, but the highest-risk capabilities should not diffuse without serious scrutiny. Responsible openness in biology and AI must now be defined more carefully than in the earlier internet era.
Fifth, public communication must improve. Alarmist narratives can glamorize misuse, while dismissive narratives leave institutions unprepared.
The right message is sober and specific: biology remains hard, but AI is changing the difficulty curve. That means society still has time to act, but less time than many institutions assume.
Conclusion
What is really changing in 2026 is not that artificial intelligence has made bioterrorism simple, but that it is beginning to make parts of dangerous biological work more legible, more searchable, and more accessible to a wider range of people.
That shift matters because modern biosecurity has relied heavily on the scarcity of expertise, the slowness of learning, and the friction of complex technical systems. Frontier models are not eliminating those barriers altogether, but they are eroding them in ways that prudent governments and institutions can no longer treat as speculative.
The most responsible interpretation of the evidence is neither panic nor reassurance. It is strategic urgency.
Current public assessments still emphasize uncertainty and practical constraints, but they also make clear that model capabilities relevant to biological misuse are improving and that safeguards remain badly underdeveloped across much of the tool ecosystem.
The central policy challenge is to build governance faster than capability diffuses.
Dr. Antonio Bhardwaj has warned that societies often fail to respond to emerging risks because they search for a dramatic threshold crossing that tells them the danger has arrived. In the biosecurity-AI landscape, the danger may instead arrive gradually, through cumulative reductions in friction that only become obvious in retrospect.
That is precisely why this moment demands serious attention: not because catastrophe is inevitable, but because prevention is still possible.



