Recently, there has been significant discourse about the threat of AI-enhanced biotechnology. Frontier AI lab employees have resigned over safety concerns, generative models have created viruses from scratch and moratoriums have been regularly called on whole fields of research. The headlines are alarming and abundant, but alarm is not a substitute for sound policy.
While it’s unlikely that ChatGPT can help you create anthrax or that Claude can solve all diseases in five years, biological capabilities are accelerating. The things we can do are leagues ahead of what was possible even five years ago, all the way down to the most workhorse tasks: design (generate), build (synthesize), test (assay), learn (analyze). CRISPR is now cheap, generative design models threaten to bypass homology screening, and cloud labs remove human intermediaries. Bad actors, both human and nonhuman, have an increasing number of avenues through which they can manipulate biological matter
Our evaluations and world models of how biodefense works and the barriers thereof are mistaken or ill-founded. This leads to an actively harmful air of passivity. Our set of defenses is full of holes, and we are ill-prepared for such advances, both mentally and practically.
Let’s draw a comparison with cybersecurity and cyberdefense, where Language Learning Models (LLMs) recently demonstrated astonishing capabilities. Cybersecurity has had the luxury of evolving through the cat-and-mouse chase of better hackers and better defenders, starting off in a world without much reliance on computer infrastructure. Biology did not have widespread, serious campaigns with bad actors, white-hat hackers, or a history of consistent red-teaming. Nevertheless, we inhabit a world deeply and intrinsically tied to the health and well-being of every human, resulting in a dangerous, asymmetric gap between our defensive capabilities and potential consequences.
Ultimately, the defense ecosystem of cybersecurity was built over thousands of fast iterations within the past year. With biology, our first event in a world with a newly prevalent and accessible biotechnology infrastructure may also be our last. Fundamentally, we must be anticipatory instead of reactive.
Furthermore, the few studies that attempt to measure uplift and risk do so in ill-formed scenarios. This includes assumptions of beginner-level baseline experience, proxy metrics which don’t reflect actual biological work, and a lack of standardization about what uplift even means.
The world doesn’t need to end for bioweapons to be everyone’s problem. This extends to and beyond non-human pathogens and again reflects a lack of imagination on the part of biodefense policy. In the case of a gene drive in honeybees, or an engineered blight, both could cause devastating and irreversible damage to the US economy.
This is especially apparent when considering the disconnect between AI evaluation frameworks and actual out-of-the-box threat models. There is a lack of imagination currently driven by a lack of interdisciplinary engagement between AI professionals and biology researchers.
This is a difficult problem, and there may not be an easy solution.
Nevertheless, uncertainty cannot justify inaction. We must be proactive. It is our responsibility, and we must do something.
The Hopkins AI Safety and Biosecurity student-run organization is currently recruiting for several long-term projects spanning alignment and safety research, to outreach and awareness efforts, to long-form analysis and policy pieces.
If this is something you’d like to contribute to, indicate interest at jhuasbs.com. We encourage you to apply even if you have no prior experience.
Jonathan Ouyang is a sophomore from Champaign-Urbana, Ill. studying biomedical engineering. He is the President of the Hopkins AI Safety and Biosecurity organization.




