Skip to main content

What AI Can and Cannot Do in Biosecurity

AI is fundamentally changing everything from how we do good and important public health and health care work to how we develop biosurveillance systems that keep pace with the rapid escalation of capabilities enabled by this technology.

"Security" (Unsplash license) | Peter Conrad | pconrad

Things have gotten intense with AI in the past week. People working in AI, from researchers to CEOs, think it could threaten humanity. One researcher put the probability of doom, as those in the field call it, at over 10%: the chance that mankind is wiped out by 2030.

Is this accurate? Is this a ploy to hype AI powers ahead of an IPO valuation? Or maybe a distraction from other unpopular AI issues, such as amassing power and wealth and disproportionately using natural resources? I don’t know; it’s probably somewhere in the middle of it all.

Underneath the recent debate over hypothetical scenarios lies a fascinating, critical public health question: Where does biosecurity risk actually intersect with superintelligence?

I texted my friend Dr. Claire Dillavou out of pure curiosity. She is a highly trained applied epidemiologist and has been in the tech and AI world for a while now. We got to talking through feasibility, challenges, and the solutions needed from a health perspective. We thought we’d bring the YLE community along for the ride, too.

Here’s what we know, what we don’t know, and what the field is doing to try to close that gap.

What we know

 

Biosecurity is a massive field. Threats can range from something natural, like a virus or an antibiotic-resistant bug, to something engineered, like a toxin modified to be more potent. All of these have different probabilities and feasibility of actually happening, with or without AI.

Biological trade-offs are real. Changing nature can be very hard. Take viruses. They face a fundamental biological trade-off: highly lethal or highly contagious, but typically not both. Ebola, for example, can have a fatality rate of up to 90%, but it only spreads through close contact with other people. When a virus kills its host (like a human), it can’t spread widely to other people. Measles, by contrast, is the most contagious virus on earth. It’s a horrible disease, but it doesn’t have a high mortality rate. This tradeoff isn’t impossible to get around, but it is very hard to go against biology.

AI can lower barriers to knowledge. Tasks that used to require years of specialized training, a well-funded lab, or slow trial-and-error can now be meaningfully accelerated by current AI systems. This includes tasks such as literature synthesis (ask any graduate student how painful this was!), predicting how proteins fold, designing novel and efficient gene-editing tools, and helping design and facilitate experiments. While these are amazing advances, they are built on a compendium of physical work in a lab, actually growing, modifying, and handling dangerous pathogens. This physical work will remain necessary for the foreseeable future.

Unsurprisingly, some people are already trying to use AI to do harm. Anthropic recently published five case studies exploring the use of Claude to assist with biological weapons development. Several centered on that same lethality/contagiousness trade-off:

If you like this article, please sign up for Snapshot, Portside's daily summary.

(One summary e-mail a day, you can change anytime, and Portside is always free.)

  1. Making a virus spread more easily between people and dodge the immune system (chikungunya virus). This work may have been tied to a state or military research group.
  2. Helping a virus jump to a new species (bird flu). Someone used Claude to help bird flu adapt so it could spread more easily between mammals (a step toward spreading in humans).
  3. Making toxins more dangerous (venom peptides). Someone used Claude to build a big catalog of venom toxins and a system to make them more harmful.
  4. Studying how viruses dodge immune defenses (orthopoxviruses) like studying the genes that control how the immune system fights off viruses, like smallpox.
  5. Redesigning toxins to make them more dangerous, like a virus that causes severe, deadly bleeding.

Anthropic detected this activity, banned the accounts involved, and used what it learned to strengthen safeguards in newer models. But all of this was sped-up knowledge, and it doesn’t get around the needs of the physical world for this to actually be executed.

But the same capabilities cut the other way. AI can also help us:

  • Decipher the makeup of a novel virus and help us develop a vaccine or treatment more quickly and then mass-produce that solution faster.
  • Help clinicians diagnose diseases with higher confidence and more rapidly. We’ve seen this in a number of recent articles.
  • Predict individual disease risk years in advance before symptom onset to enhance prevention and slow or stop disease progression.
  • Provide higher-quality, more affordable, and easily accessible health care for the entire population.

What we don’t know

 

The leap from “AI assists with biology” to “AI enables pandemic-scale bioweapons” involves many steps, and experts have big, unanswered questions:

  • How much of the barrier to creating dangerous pathogens is knowledge versus wet lab skill, equipment access, and iteration time? AI primarily helps with the former.
  • Will truly novel engineered pathogens be more or less dangerous than naturally occurring ones?
  • How effective are the government's and the Frontier model companies’ existing biosurveillance and biosecurity infrastructure as countermeasures?

There is an active debate in the expert community. Some biosecurity researchers treat AI-bio risk as a near-term serious concern. Others argue that the physical and institutional barriers remain the dominant constraint. We can’t honestly say there is a consensus.

AI plausibly increases the risk at the margin. Whether that increase is small or catastrophic depends on factors such as AI capability trajectories, biosecurity responses, governance, etc.

And all of this ultimately leads to the large, unanswered question: Can/will the benefits of AI outweigh the risks in biosecurity?

What needs to happen

 

Nobody has a clear answer yet to these questions, but several efforts are underway to close the gap between “we’re worried” and “we actually know.” Much work needs to be done, but these three priorities come to mind as some of the most urgent in the biosecurity world:

  1. Protect data. We know that the most recent Frontier models are so advanced they can easily hack into weak systems, access highly protected data, cover their tracks, and create entire systems on their own to protect themselves, as seen in the recent OpenAI Hugging Face incident, among others. How can we really protect personal and sensitive data in a meaningful way? And who owns or has a right to use these data, even if de-identified?
  2. Pressure for more transparency. The reality of the gap between what the general public knows/has seen and what’s happening in restricted areas of these companies is significant and widening daily. It is hard for the public and legislators to advocate for specific policies without more transparency and insight.
  3. De-escalate the geopolitical race. The geopolitical tension at the center of the rapid AI progression is a genuine unresolved problem that needs more thought leadership, diplomacy, and action if true “pacing” of this technology is to take place.

Bottom line

 

AI is fundamentally changing everything from how we do good and important public health and health care work to how we develop biosurveillance systems that keep pace with the rapid escalation of capabilities enabled by this technology.

There will always be bad actors trying to abuse novel capabilities enabled by AI, but at this moment we are still in control of what we allow to happen. This window is closing rapidly, so we need to absolutely double down on security, safety, and legislative efforts while we reinforce our biosurveillance systems and ensure our biosecurity measures are well-articulated, practiced, and funded.

Love, YLE and CD


Claire Dillavou, PhD MPH, is a trained infectious disease and behavioral epidemiologist who has worked in applied public health at every level of domestic government, with international governments, and in the private sector in startups and consulting.

Your Local Epidemiologist (YLE) comprises a team of experts, ranging from physicians to immunologists to epidemiologists to nutritionists, working together with one goal: to “translate” ever-evolving public health science so that people are well-equipped to make evidence-based decisions. The YLE suite of newsletters reaches over 475,000 people across more than 132 countries. This newsletter is free to everyone, thanks to the generous support of fellow YLE community members. To support the effort, subscribe or upgrade below: