AI and the New Age of Bioweapons
Pathbreaking scientific discoveries can create transformational possibilities. They can also create catastrophic risks. The integration of artificial intelligence, biotechnology, and bioengineering is already enabling life-changing achievements, from combating disease to supercharging agricultural productivity to solving energy challenges. But it is also generating capabilities that can be weaponized more easily than ever by a growing number of actors. The United States is unprepared for these threats.
In the foreseeable future, a terrorist group with minimal skills could access a jailbroken AI model (one that has evaded safety controls) trained on the world’s most comprehensive biological data set. The group could use the model to design a new strain of H5N1 avian influenza that is more lethal and more easily spread from animals to humans than existing strains. Connecting remotely to one of the new generation of fully equipped, contract-for-service “cloud” labs, it could anonymously arrange for the virus to be built and tested and then sent to a biomanufacturing facility to be produced at scale. From there, the group could stealthily disperse the new strain through air-handling systems at major livestock farms across the United States.
Before long, the American poultry, beef, and dairy industries would suffer massive losses. When the virus inevitably jumped to the human population, it would cause severe illness and could result in hundreds of thousands or even millions of deaths. The response from U.S. public and private institutions—lacking both an integrated strategy and adequate tools—would be too slow, too uncoordinated, too underresourced, and too overwhelmed to stop the spread and mitigate the consequences. And soon, the virus would also cross borders, triggering food insecurity, widespread sickness, and mass casualties around the world.
U.S. policymakers have long contended with the possibility of biological attacks from hostile nation-states. Along with surveillance and global risk-reduction initiatives, Washington successfully deterred such attacks with the threat of significant retaliation, including the use of nuclear weapons. Yet that strategy was effective because only a small number of governments were developing the most dangerous biological weapons. It no longer works in a world in which AI allows more actors—rogue states, terrorist groups, even individuals—to develop new bioweapons of their own.
In this new threat landscape, biological attacks are unlikely to be prevented entirely, given the proliferation of biological capabilities and the fact that some actors cannot be deterred by traditional means. Policymakers need a new strategy in response—one that accepts that biological attacks are likely and prepares to contain the harm, helps the country recover more quickly, and uses new tools to identify and hold perpetrators accountable. Ultimately, this resilience to biological attacks could dissuade malicious actors from attempting to use them in the first place, knowing that the effects will be minimized—a strategy of deterrence by resilience.
Consider the attack scenario described above, but with a comprehensive strategy in place. The U.S. government would use a sophisticated biological monitoring system to provide early warning of the emergence of a new viral pathogen. Employing many of the same technologies that enable the threat in the first place, federal laboratories would determine its origin from telltale signatures in the AI model used to design the virus—enabling prompt efforts to track and target the perpetrators. Public health authorities would have the tools to integrate scientific and intelligence data to suppress the disease’s spread. Based on pre-negotiated contracts to provide surge capacity, the biomanufacturing sector would accelerate the production of diagnostics, therapeutics, and vaccines. Although the crisis would not have been prevented entirely, its effects would be speedily and effectively contained: vulnerable human and animal populations protected, contagion minimized, agricultural production recovered, public confidence restored.
Such bioresilience is far from today’s reality. In 2024, H5N1 bird flu spread from poultry to dairy and beef herds and eventually to more than 70 humans. As the White House homeland security adviser at the time, I coordinated the federal response to this potentially catastrophic threat. The virus was naturally occurring, not the result of a deliberate attack. It nevertheless showed that even in this base case, there were considerable weaknesses and gaps in U.S. prevention, monitoring, attribution, and response systems. Data on disease incidence and spread were hard to acquire and exasperatingly incomplete. Mobilizing sufficient preventive action by the poultry and cattle industries proved difficult and slow. And in order to deliver sufficient quantities of human vaccines to protect the American people, we needed to provide substantial new federal funding to rapidly create an mRNA vaccine and divert U.S. pharmaceutical industry production lines to make it at scale, and there would still have been inadequate drug supplies for many months.
The United States urgently needs a new system to generate resilience against AI-enabled biological threats. The reality of this technology means that the very innovation that drives the revolutionary discoveries also creates the new threats—and the same tools that make those threats so dangerous are also essential to countering them. That system, accordingly, will depend on leveraging advances at the intersection of AI, biotechnology, and bioengineering—and staying ahead of adversarial exploitation of the very same advances.
During the Cold War, U.S. security experts warily monitored the Soviet Union’s biological weapons programs. Their concerns focused on the possible weaponization of rare but known pathogens such as anthrax, Marburg virus, and Variola virus (which causes smallpox) that could be used against American forces in combat—or even against U.S. civilians. After the Soviet empire collapsed, I oversaw the Pentagon’s efforts to reduce the threats posed by its arsenal of weapons of mass destruction. We closely tracked and worked to eliminate legacy stockpiles of deadly pathogens in Russia and other newly independent states.
For decades, Washington relied on deterrence to counter the possibility of adversarial biological attacks—but, notably, not by threatening biological attacks of its own. Indeed, in 1969, U.S. President Richard Nixon officially forswore the research, production, and use of offensive biological weapons. Instead, American doctrine was based on credibly threatening nuclear retaliation.
As the Cold War receded and Moscow and Washington shrank their nuclear arsenals through cooperative threat reduction initiatives, national security experts began questioning whether it was moral or effective to threaten the use of nuclear weapons to deter biological attacks. Nevertheless, across multiple administrations, the United States retained deliberate ambiguity on this front. The most recent U.S. Nuclear Posture Review, in 2022, concluded that “our nuclear strategy accounts for existing and emerging non-nuclear threats with potential strategic effect for which nuclear weapons are necessary to deter.” It added that the “fundamental role” of nuclear weapons is to deter nuclear use against the United States and its allies, but it did not go so far as to assert that nuclear deterrence is the “sole purpose” of the arsenal. The current Trump administration has thus far decided that another nuclear posture review is not necessary, pointing to the adequacy of the doctrine promulgated by the first Trump administration in 2018. That review stated that nuclear weapons could be used against “non-nuclear strategic threats,” which, although not specifically referring to biological attacks, is understood to include them.
Policymakers must accept that biological attacks are likely.
Given technological changes at the intersection of AI, biotechnology, and bioengineering, changes that substantially lower the bar to lethal pathogen production and wide diffusion to uses beyond secret state laboratories, this doctrine is no longer fit for purpose, if it ever was. A decade ago, leading experts began to focus on novel pernicious uses of biology. In late 2016, for example, the President’s Council of Advisors on........
