Epistemic status: We are quite confident that Biological AI models (BAIMs) safety requires further work, but uncertain about its scale. The apparent gap may be refuted by one experiment, filled by a few researchers working for a year, or prove to be substantial enough to call for an entire subfield.
Disclaimer: this post has been written with a colleague, that due to her current job can't post out of her own forum account
What we’re looking for: please poke holes in this. In particular, we’d value:
- Arguments against prioritizing this work;
- Important research or organizations we’ve missed;
- Reasons the research questions below would not actually change decisions;
- Information-hazard or capability-externality concerns we’re underweighting;
- Better questions than the ones we propose
The case in brief
Biological AI models (protein, genomic, and single-cell models trained directly on biological data) enable increasingly capable biological design. That carves the path to new vaccines and therapeutics, but also to biorisk scenarios.
These models exist for beneficial scientific or defensive purposes. However, the underlying capabilities could also be applied to harmful objectives. They are currently an important step for designing novel pathogens, and as they improve we expect them to remain a part of the design pipeline.
At the same time, we think we know surprisingly little about the capabilities of these models, especially from a safety perspective.
In particular, we still lack robust, general answers to questions such as:
- Will text-based AI eventually be able to reason over raw genomes, or is biological data too fundamentally different?
- How much training data will biological models need before qualitatively new capabilities emerge, or they “grok”?
- What is the tradeoff between evading sequence-based screening and preserving biological function?
- If a model was never trained on viral sequences, how well will it generalize to viruses from other domains of life?
The answers to these questions imply different biosecurity strategies.
Therefore, our tentative view is that there is a case for substantially more empirical research on biological AI model safety, particularly research designed to inform policy and funding decisions.
Biological AI models are becoming more capable
Biological AI models are models trained directly on biological modalities rather than natural language (proteins, genomes, cells and related data).
Some recent results are striking.
- A model trained only on pre-2020 sequences predicted 66% of the high-frequency SARS-CoV-2 receptor-binding-domain mutations that later emerged
- A protein language model improved antibody affinity up to 37-fold against escaped SARS-CoV-2 variants
- Generative protein-design methods produced variants of 72 proteins of concern that bypassed existing DNA synthesis screening
- Evo2 was used to generate viable bacteriophages: 16 of 285 synthesized designs worked, with several sufficiently divergent to plausibly constitute new species
- AlphaFold demonstrated that AI can infer protein structures with near-experimental accuracy, even for proteins whose structures had never been measured directly
These results demonstrate that already now BAIMs can provide some advantage at making catastrophic biological risks substantially greater. Given the substantial progress we’re currently seeing with AI we suspect these models will get much closer to 100% design accuracy. This seems sufficient to motivate a question:
What can these models actually do, how quickly is that changing, and which interventions would matter if their capabilities continue improving?
We are missing some basic measurements
There is now significantly more work on biological risks from general-purpose AI.
SecureBio has developed VCT, BioTIER and ABC-Bench. Active Site and METR have run an RCT measuring LLM assistance on novice biological work.
There is also growing attention to biological AI models specifically. Epoch AI now catalogues more than a thousand of them. RAND Europe is developing a risk observatory for AI-enabled biological tools relying on literature reviews. NTI | bio and Concordia AI recently launched a working group on evaluation practice.
This is useful progress. But there seems to be less published work directly measuring the security-relevant capabilities of the biological models themselves. We also suspect there is scarce classified work, because multiple classes of these models are nascent, and as a result:
- There is little non-security evaluation work
- There are few people with the current skill set, and
- These people are either still being trained in academia or drawing large salaries in industry
A catalogue can tell us that a model exists, how large it is, whether its weights are available and whether its developer reports safeguards. It cannot necessarily tell us what the model enables.
Similarly, parameter count may be a particularly weak proxy here. Across several classes of biological models, larger models do not consistently outperform smaller ones.
So we think there is a missing empirical layer on what is the risk-management strategy we should adopt.
Research questions that could change what we do
The case for this research is that we believe there are several empirical questions where different answers would point toward different interventions.
Will general-purpose AI subsume biological AI models?
It’s unclear whether increasingly capable general-purpose AI will eventually reason directly over biological sequences, or whether specialized biological models will remain necessary. Biological data, architectures, and scaling behavior differ substantially from text, but we do not know whether those differences will persist.
What drives BAIM performance?
It’s unclear what drives improvements in BAIM capabilities. Relative to text-based AI, biological models seem to have only modest or inconsistent scaling effects. Current experts suspect that this is because these models are more constrained by data than compute.
How well do capabilities generalize?
A model trained on one set of organisms may acquire capabilities that transfer to others because biological sequences are linked through common ancestry. How far this transfer extends matters for data policy- if pathogen-relevant capability comes from pathogen data, restricting access to some viral datasets could potentially reduce risk (while preserving most biological research). However, if the same capability can be recovered from distant organisms, restricting viral data alone may only accomplish little.
How should BAIM safeguards work?
Many BAIMs are open-weight and commonly fine-tuned, which may make safeguards developed for API-based language models less useful. We therefore think BAIM safety may require a somewhat different flavor. Technical research could help identify which safeguards are most effective and when: model hardening as an additional barrier, tiered access for higher-risk capabilities, sequence screening, data controls, and other downstream safeguards. It can guide how these interventions are best combined and where the possible gaps are. Culture too matters here: unlike in AI safety, most BAIM development is still done in academic labs. Researchers may be more resistant to closed-source models, but they can also be more amenable to instilling a culture of responsibility and adopting safety practices.
Why now?
There are three reasons we think the timing may be unusually important, and it’s important to act fast
- The field is still early enough to shape- BAIM safety is still nascent relative to BAIM development. We have an opportunity to build and instill safety practices around evaluation, release and access.
- Several important uncertainties are experimentally tractable- Questions about evolutionary transfer, data scaling or architecture dependence can be tested
- Policymakers are gearing towards this- Multiple biosecurity-related think tanks, foundations, and research organizations are beginning to assess AI-enabled biological tools. Risk assessment ultimately needs empirical inputs. If we cannot measure capabilities well, we risk basing decisions on proxies such as model size, openness or developer claims.
Reasons we might be wrong
Artificial General Intelligence will eat this problem
Specialized biological models may soon become irrelevant relative to increasingly capable general-purpose systems. If AI models are able to reason over biological sequences the way they are able to reason over text, BAIM safety may have little marginal value over AI safety.
BAIMs may not be the bottleneck
Powerful biological design models may contribute little to global catastrophic biological risk if wet-lab expertise, tacit knowledge, access to equipment, experimentation or other steps remain high barriers to access
Information hazards
This means some research may need restricted dissemination, and some questions may not be worth answering at all. We don’t think the default should be that everything produced by a BAIM-safety research program is published. We think such research should be done carefully and with extreme security practices taken. We also believe in using biological proxies as much as possible.

I think that this diagnosis is basically on target; it points to something that seems relatively under-resourced, despite some focus by think tanks, and something that the major AIxBio safety groups are not as focused on. I also agree that we don't know if AGI will subsume this, and that it's plausible but uncertain if other bottlenecks matter more, but that's an uncertainty we can't resolve without simply waiting for the outcomes, and so this seems very high value in expectation.
I'm less certain about the object level questions, and don't have strong intuitions - so I think that conditional on not hearing from someone more informed about this that there are additional questions or concerns, or literature you should look at, the best way to figure out whether this is needed, and what the risk is, is to start the work - good luck, and I'd be happy to chat about this more!
In addition to these kind of general questions, it could also be valuable to just have a dedicated per-model evaluation to inform decisions BAIM creators do.
That is true. I’m a part of a team building a genome language model. It’s really unclear even to us which models are the best models! and a lot of these fundamental questions can also guide model design.
In that way, if we do it right, and thoughtfully, it’s possible to both become a resource for model construction and improve their safeguards and security.
Agree with the need. As you pointed out, implementing a safeguard into the model itself (either the raw model or the scaffold) is quite challenging for BAIMs, as most capable models are open-weight. Adversarial fine-tuning can easily strip out weight-implemented safeguards. This issue is especially pronounced for BAIMs compared to general-purpose models, due to their limited training data. For scaffolds, you can simply remove them. So most of the control levers for safety live outside the model, as you listed. But to calibrate "where and how much control is needed," we need rigorous empirical study on BAIMs, especially at the scaffold level, since that is where realized capability can be measured.
I disagree with your framing - 2 reasons why:
1. Restrict Implementation, Not Knowledge
I think we shouldn't restrict knowledge build up. That's like stopping knowledge build up for say material and other sciences that can be used in weapons and bombs. Imagine if we stopped doing that, it would have stopped so many good things we have now and can have.
In a sense, enough knowledge about how to build pretty terrible stuff is already public. But decent enough measures are in place for using it which prevents harm.
So, we should have measures that ensure that items that can make things usable by bad actors are restricted.
This also makes sure that we can also safely keep on improving knowledge and get better. Which brings me to the second point.
2. Offense is Sometimes Best Defense
We don't stop harm caused by computer malware and viruses by rolling back or stopping development and cutting off internet. We do it by patching things, being better at it, and moving on.
Now, I know that biosecurity has harsher security needs. But in a sense, the pandora's box is open. Unless you can stop everybody that has and is building BAIM or GAI, creating barriers for yourself is only increasing risk.
And besides, increasing capability also means that you've more room to monitor for threats and take care of it. Yes, it also means potential for bad is there and it needs to be accounted for (which restrict implementation if good enough should do); but the flip side is also true and shouldn't be buried in paranoia.
Looking forward to see your response.
I think it’s a real conflict. I think the situation with BAIMs is different: current models don’t seem to generalize very well at all, and the consensus seems to be that it’s because we don’t have enough publicly available data right now. So in this way, it’s not clear if “the genie is out of the box.”
At the same time yes, actually stopping data collection is both unrealistic and will have major repercussions to a lot of serious improvements to human health in the short term. I think tiered access can mitigate some of that, not all.
I do think Biosecurity is very different than cybersecurity so unfortunately the same interventions won’t work, and we will need different thinking. The whole field is a lot more decentralized, there are ostensibly no security practices to patch against potential attacks. Chris Rodriguez described it better than I could here.
I see. I guess if there's a chance that we can stop genie from being out of box, we should try. You're also correct that tiered access can indeed mitigate issues. And it does seem like general models being as good and 'Bio Mythos' might genuinely not happen. So, exploring tightening access and data makes sense.
All of this requires co-ordinated action though as even one bad actor can significantly turn things for worse. And the fact that covid is fresh in policy makers' minds could help.
My points are more in the case of being or inevitably going to a point where we can 'reasonably freely' edit pathogens and vaccines. If we can do that, making it freer and restricting implementation is generally a better idea. And if possible to do safely, we should aim for that, I think. Because there is a lot of potential of good for everyone: humans, animals, other biological beings and maybe more (like plastic or rust eating bacteria for environment!).