Let’s be honest about the picture most of us have when we hear “AI bioweapon”: a quiet lab, a gleaming robot arm, a rogue superintelligence typing out DNA code and assembling a deadly virus with no human in sight. That picture is still fiction. As Olivia Scharfman, a biotechnology fellow at the policy think tank Institute for Progress, points out, “It is impossible for AI to access a fully autonomous lab and autonomously build a virus today because fully autonomous labs do not exist yet.” In other words, the robot arm and the sterile room and the automated vials are not actually there. But Scharfman adds a sharp and more unsettling twist: “But I do think that an AI could pay someone to do it for them.” That changes the scenario from a machine physically doing science to a machine orchestrating human actions—finding someone on the internet, sending money, and convincing them to act. It doesn’t need hands; it needs influence. Scharfman believes this kind of AI-assisted bioterrorism is not a distant hypothetical but an immediate threat, and she names a strange and chilling group of potential actors: “transhumanist AI successionists,” people who are drawn to a fringe ideology that hopes to replace human beings with artificial minds. To them, getting rid of humanity is not a crime; it’s an upgrade. That is a very different kind of enemy from the usual “lone wolf” terrorist, and it forces us to think about AI security in terms of persuasion, money, and ideology rather than simply lab equipment.
But not every expert is convinced that AI-powered bioweapons are the danger we should lose sleep over. Genetic biologist and computational biology professor Francois Belloux offers a skeptical, even calming counterpoint: “The risks tend to be somewhat misunderstood,” he says, and adds that people tend to “overestimate the value of pathogens as weapons.” His reasoning is refreshingly practical. Biolab diseases are messy, unpredictable, and hard to control. If you want to kill a specific group of people and avoid killing others, a pathogen is almost the worst choice you can make—viruses and bacteria do not read identity cards or respect political borders. They drift through the air, move with travelers, and mutate. If you want to kill a lot of people quickly and efficiently, there are far better methods than engineering a germ. As Belloux puts it, “If you want to kill people, there are much, much, much better ways to kill them than to try to engineer some virus or bacterium and then release it.” He doesn’t limit that observation to ordinary humans; it applies just as well to the most sophisticated artificial mind ever created. A truly unconstrained AI could hack into power grids, weaponize drones, create economic chaos, or encourage violence through disinformation. Why bother racing to brew a virus in a vat? Belloux’s point is not that bioweapons are harmless—it is that they are strategically clumsy. Disease does not obey commands. It spreads indiscriminately and often backfires on the person who releases it. So while AI could lower the technical barrier to designing DNA sequences, it cannot solve the fundamental unpredictability of biology. That is a humbling reminder that no amount of computing power can fully control a living thing’s behavior in the real world.
Still, Scharfman believes the current spotlight on AI and bioweapons is not a reason to panic, but a reason to build better defenses against all biological threats—including ones we already know about, like H1N1. The conversation about AI and bioterrorism can feel very futuristic, but the underlying vulnerability is very old. We have lived through COVID-19, and we know what a naturally occurring virus can do. We don’t need a superintelligent mind to make a pandemic; we just need an unlucky mutation and a crowded planet. Scharfman argues we should use the attention generated by AI worries to strengthen our protections against ordinary, existing pathogens. That could include high-level policy changes, like passing legislation that enhances security around DNA synthesis technology so that dangerous genetic instructions do not end up in the hands of people who want to use them badly. But it can also include simpler, more democratic improvements, such as upgrading air purification systems in buildings. That might sound mundane compared to a robot-built virus, but clean air would help protect every person from any airborne disease, whether it came from a lab, a marketplace, or a farm animal. This is the heart of “humanizing” the debate: instead of obsessing over a rogue AI as a monster, we can focus on the fact that all people deserve to breathe safer air and know that their medical supply chains are secure. The threat doesn’t have to be futuristic to motivate practical action. We can protect ourselves from known dangers and unknown ones at the same time.
Whether AI actually increases the risk of bioweapon development is almost impossible to answer with certainty. Steph Guerra, head of AI and bio at the Rand Corporation, a policy think tank, says the question is genuinely hard. We do not have enough data, and we cannot run experiments to prove a negative. What we do know, she says, is that “AI has been shown to be very good at integrating information together and being motivational to people for doing good and bad things.” That is a subtle and important point. AI doesn’t need to invent new knowledge to be dangerous; it can be dangerous by connecting pieces of information that are already public, organizing them into a clear and compelling guide, and pushing a specific person toward action. That is the human making the final choice, but AI is the spark and the map. Even if the risk is relatively low, Guerra says, there are practical steps society can take to reduce it. One of the most obvious is to require companies that sell synthetic DNA and RNA to screen both their customers and their orders. Many companies already use screening software to look for “sequences of concern”—genetic pieces that could be used to create dangerous pathogens. But this practice is not universal and not enforced by law. That means there is a gap: a reasonable, low-cost security measure exists, and yet not everyone uses it. Governments could close that gap by passing laws that make screening mandatory. The idea is simple: if you are selling the building blocks of life, you should know who you are selling them to and what they plan to do with them. That is not a heavy-handed surveillance system; it is just responsible commerce.
Even with good screening, no single protective layer will be perfect. Guerra emphasizes that “with pretty much almost any biosecurity control, there are going to be ways that they can be circumvented.” That sounds discouraging, but her solution is not to give up; it is to build layered, redundant defenses. She calls for robust global surveillance systems that can detect outbreaks of new diseases and share information with researchers as early as possible. If a dangerous virus emerges, whether it is natural or artificial, the world should know in days, not weeks. Data-sharing protocols across AI companies, gene synthesis providers, and government agencies could also help prevent misuse. An AI company might see a suspicious pattern in how someone is using its model; a DNA synthesizer might see a suspicious order; a public health agency might see an unusual cluster of illness. None of those pieces alone is enough. But if they are connected, each layer creates a little more “friction”—a little more difficulty for someone trying to move from bad intentions to a real bioweapon. Guerra’s image of friction is powerful. We do not need a perfect shield that stops every attack. We need enough speed bumps, checkpoints, alarms, and locked doors along the entire pathway—from the moment a person starts thinking about doing harm, to the moment they acquire materials, to the moment something is released—that most bad actors give up or get caught. Security, in that sense, is not a single wall; it is a maze that makes the whole effort feel too hard, too risky, and too likely to fail.
Before anyone even reaches the point of ordering DNA, most experts agree that AI systems themselves should have safeguards so they do not provide actionable, dangerous information to people. But there is another side to this conversation that sometimes gets lost. Biologist and researcher Unutmaz says he has an even more pressing worry: all the talk about AI doom is distracting us from the powerful ways AI can help humans develop vaccines and make other medical breakthroughs. We spend so much time imagining an AI that designs a deadly virus that we forget about an AI that designs a life-saving protein, predicts how a virus will mutate, or finds a drug candidate that would have taken human researchers years to discover. In the same way that COVID vaccines were developed faster because of modern technology, AI could be the tool that helps us outrun the next pandemic. Unutmaz’s message is simple but profound: “We really need to focus on the positive aspect of it.” That does not mean we should ignore the risks. It means we should be mature enough to hold two ideas at once. Yes, AI could be misused; yes, biosecurity needs better funding, better laws, and better collaboration; and yes, we should be careful about handing dangerous knowledge to unstable people. But we should also be careful not to let fear make us blind to the enormous good that AI can do in medicine. The same machine-learning techniques that might help someone design a toxin can help someone design an antidote. The same models that could motivate a bad actor could motivate a good one—a scientist working late in a lab, hoping to save lives. If we let the nightmare scenario consume all our energy, we may miss the very real, very practical ways that AI can help humanity be healthier, stronger, and more prepared for whatever comes next. That is perhaps the most human thing of all: not to be paralyzed by fear, but to use intelligence, caution, and hope in equal measure.