Skip to content
Menu
Menu

RAND Says AI Is Eroding The Barriers That Kept Biological Attacks Out Of Reach

An attacker had to know a great deal, be good at lab work, and get into a laboratory, and RAND says AI weakens all three at once, putting a pandemic-scale attack within reach of people who could not have attempted one.

Key Takeaways

  • AI expands the number of people who could carry out a successful biological attack, RAND said. Three practical things have limited who could try: knowing enough, being good enough at lab work, and getting into a lab.
  • Cloud laboratories run experiments for customers who are never in the room. The machines do the steps, so customers no longer need years of practice to get them right.
  • Every existing control is physical: entering a lab, buying material, handling a pathogen. Work that AI moves onto a screen passes none of them.
  • Most attackers cannot make accurate genetic material themselves, so they buy it from commercial DNA suppliers, who compare each order against a list of known dangerous sequences. RAND said AI can design a sequence that still does the dangerous thing but looks different enough to get through.
  • Frontier AI companies decided their mid-2025 models might give real help to someone with no experience. RAND noted OpenAI and Anthropic called those decisions precautionary, not a response to evidence that the models had helped anyone.

The three things that previously made a biological attack hard to carry out are weakening at once, and the defenses built around them have not moved, according to a RAND Corporation report published on August 18.

Before, an attacker needed expert-level scientific knowledge, lab access, the skills to run physical experimentation, and access to physical materials. Current biosecurity controls are physical. They govern who can enter a lab, who can buy material, and who can handle a pathogen. Work done with AI circumvents all of these, expanding the number of people who could carry out a successful biological attack.

 

AI lowers the knowledge barrier 

RAND said a model can pull together technical information that would normally take an expert to find, and can talk a novice user through a failed experiment the way a senior scientist would.

Models also close the time between running an experiment and understanding what went wrong, moving the need for physical experimentation to a later stage of development.

 

Cloud labs remove the need to ever be in a laboratory and are more vulnerable to assisting in bio-weapon development

Cloud laboratories run experiments for customers who are never in the room. A user sends a design, the lab runs it, and the results come back. RAND said this lets someone go from a design on a screen to a physical test without ever setting foot in a lab.

The machines also do the steps, so the user does not need years of practice to get them right. Some services now cover the whole sequence: designing the experiment, writing the instructions, ordering the material, and running it. Work that used to require a trained researcher gets done by the service.

Current virtual lab security can’t necessarily detect if it’s developing a biohazard. AI models that design genetic material that never existed can bypass virtual lab security protocols because the lab has nothing on record to match the material against a list of known threats.

 

AI can order dangerous bio-material

Building a pathogen takes physical starting material, and most bad actors cannot make accurate genetic material themselves, so they could buy it from commercial companies that make DNA to order. Those companies check an order by comparing it against a list of known dangerous sequences. RAND said AI can now design a sequence that still does the dangerous thing but looks different enough from anything on the list to get through company checks. Now, the check has to move from comparing sequences to working out what a sequence might actually do.

Benchtop DNA machines make it harder. These are laboratory-grade devices that synthesize, sequence, and/or analyze DNA on a standard work desk. As more labs buy their own, RAND said the check has to be built into the machine itself.

 

Frontier developers already flagged their own models

Several frontier AI companies decided their mid-2025 models might help someone with no experience build a biological weapon, and added refusals and detection software in response. RAND noted that OpenAI and Anthropic called those decisions precautionary, not a response to evidence that the models had helped anyone.

Those safeguards can be worked around by someone with enough time, money, and technical skill. For open-weight models, whose files anyone can download, there are no safeguards at all. The main method for taking a capability out of a model after training can be reversed by training it back in.

 

What happens next

RAND’s AI biosecurity strategy names nine measures. Four can be built with what already exists. They are: 

  1. Checking DNA orders across more suppliers
  2. Setting rules for who can use the riskiest biological AI tools
  3. Watching what users ask AI models and reporting the concerning cases
  4. Expanding environmental testing to catch pathogens early. 

RAND wants those four running by early 2028

Two of the nine do not exist in any form. Nobody knows how to safeguard an open-weight model, and nobody can trace a designed pathogen back to the person or the model that made it. Both need research before anyone can build them.

The remaining three, including a shared system for pooling flagged customer activity across AI companies and DNA suppliers, need new legal authority and federal money first.

RAND’s case for moving now comes down to timing. The defenses take years to build, and AI keeps improving while they are being built. Waiting for proof that a model helped someone make a weapon means starting those years of work against a threat that has already arrived. 

 

Methodology

RAND looked at events roughly ten times the scale of the COVID-19 pandemic or larger, and at prevention only, meaning what can be done before a pathogen is released. It broke the process into seven stages, from deciding to create a pathogen through design, building, testing, and weaponization, and said AI helps most in the early stages.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!