Abi Olvera’s piece “Why AI-assisted bioweapons won’t kill you,” alongside her three other pieces on the topic, provides a useful voice of reason against some of the most extreme takes in biosecurity. It is good to see that she spoke with people who have actually worked with pathogens at the bench, and I agree that many of the near-term scenarios with single-actor or small-group threats are less likely than some portray. She is right that bioweapons are hard today. She is wrong to infer that they will stay hard, or that this justifies being, as she puts it, “no longer worried” about bioweapons. Technology will continue to improve, and, even if it didn’t, there are capable adversaries today in the form of state actors. The overall argument gets several important technical things wrong and leaves readers with the false impression that biosecurity should not be treated as urgent.
The most significant weakness in the piece is the false assumption that because it is difficult to design and manufacture a bioweapon with current technology, it will remain so. This particular opinion is actually highly pessimistic about the rate of growth of technology. Many things used to be difficult that are no longer so. They become accessible as technology advances.
Synthetic biology is not an exception to this, as we have watched costs fall and accessibility rise without fail since its inception. Before 2012, editing a specific site in a genome meant using zinc finger nucleases: custom-engineered proteins that cost $5,000+ to order, and were never widely adopted because they were so difficult to engineer well. CRISPR replaced this. You order the RNA guide sequence and buy the rest off the shelf, with total cost being as low as $30. This is a strong example of an engineering capability that was once siloed to a handful of specialist labs and is now an undergraduate exercise. Synthesis costs have also plummeted. Synthesizing the poliovirus genome cost about $300,000 in 2002, and the materials would cost under $1,000 today.
AI is now an ordinary tool for synthetic biology. DeepMind’s AlphaFold has mostly solved protein structure prediction, a problem which was once thought to be intractable for computers. Frontier AI models have safeguards because frontier AI labs are concerned about their own models’ capabilities. Some may argue that talking about safety is just for good marketing, but frontier labs are taking actions that hurt their bottom line. Anthropic has gone so far as to make Fable unusable for even basic biology. This would be nonsensical if their concerns were unfounded. Open-source models with lower safeguards continue to advance just a few steps behind. When the enabling technology is improving at such a high speed, I find it surprising to hear people claim that the fact that something in biology is difficult now means it will continue to be so this next decade.
This outlook is striking because Olvera’s blog is called “Positive Sum.” She seems to write optimistically about progress, taking the position that it is institutional friction and regulation preventing everything from becoming cheap and abundant. I agree with this, and to me it stands in contrast to this piece. Everything will get better over time, except the technology to make bioweapons?
She also focuses on lone actors and smaller groups, without acknowledging the likelihood of effective state bioweapons programs. We know that multiple states have active bioweapons programs. As I wrote in a prior post, “the most recent 2025 report from the Department of State affirmed that Russia and North Korea maintain offensive biological weapons programs. It raised continued compliance concerns re: Iran and China, noting that PLA military medical institutions are conducting research with potential bioweapons applications, and warned (for the first time) that China is capable of using publicly available AI/ML tools to advance efforts related to bioweapons.” States already possess both BSL-3 and BSL-4 labs, as well as accompanying trained personnel.
She says of potential adversaries: “For almost any goal they have, a bomb, a gun, a chemical, or a cyberattack is cheaper, faster, and more controllable.” However, the “almost” is critical here. There are several reasons why a threat actor would choose to deploy a bioweapon over other options, not the least of which are their capability for unprecedented, self-propagating destruction and the difficulty of attributing an attack to a particular actor.
She lists five main reasons for bioweapons not being the weapon of choice, which I will address one by one:
“You have to be comfortable killing your own people. Pathogens kill indiscriminately. Few groups are this malicious and extreme. Groups that are tend toward paranoia and rigid hierarchies that make them less effective.”
The two actors we are most worried about, state actors and terrorists, overcome this objection. State actors can stockpile vaccines for their own population and vaccinate their scientific personnel –– the Soviets did both during the Cold War. Terrorists may view loss of life on their side as a form of martyrdom, or even total loss of life as the goal, like Aum Shinrikyo.
“You need significant resources. Bioweapons capable of harming many people need equipment, chemicals, and professionals trained in different fields.”
First, state actors have significant resources. Second, the resources you need to do this are falling year-over-year. Third, we have already seen cult Aum Shinrikyo recruit scientists and purchase equipment, so we know it is possible. Last, many terrorist groups are in fact quite well-funded. Expecting capital to be the barrier, as costs rapidly fall, does not make sense.
“You need an institution for access. Many items are too niche for black markets. Essential equipment like biosafety cabinets or fume hoods requires professional installation and ongoing manufacturer support. Some materials are restricted; for example, viruses need host cells, cell lines are sold only to institutions, and plasmids require institutional credentials. In the United States, only tens of thousands of people have sustained access to such facilities and supplies.”
You do not need an institution for most specialized equipment and materials. Most things can be found in an average biology lab or acquired used online. A determined actor can find workarounds for any part of the workflow, including finding providers who don’t screen nucleic acid orders, routing orders through proxies, or committing theft. We should also remember that a state actor faces none of these constraints, and that a threat actor could be an insider at an existing institution. The FBI concluded that the 2001 anthrax letters came from a government researcher with institutional access. “Tens of thousands of people” is a lot of people.
“Your team must be both highly competent and completely secret. A contamination incident could destroy the pathogen or infect the team.”
The Soviets ran an effective 30,000-person bioweapons program for two decades. 30,000. The program, Biopreparat, had a civilian cover. It did not completely escape detection. Western agencies had some suspicions, and the 1979 Sverdlovsk anthrax release was noticed internationally but mostly successfully blamed on contaminated meat. However, the existence of a program of that extent was only confirmed when Vladimir Pasechnik and Ken Alibek defected. There were multiple instances of contamination and infection of the scientists who worked on the program, including Alibek himself, and the program continued. One researcher, Nikolai Ustinov, died from contamination with Marburg. His colleagues harvested the mutated virus from his body, found it more virulent, named it Variant U, and weaponized it.
“You need to convince and retain experts from different domains. e.g. biology, chemistry, engineering, aerosolization, or fieldcraft to carry out attacks. Recruiting without detection is hard too.”
Even non-state actors are not limited to poorly trained or low-competence individuals, yet people repeatedly make this assumption. It’s rare, but history shows us clear examples of highly educated and technically capable people who chose to pursue sophisticated terrorism. Consider Ted Kaczynski, a Harvard-trained mathematician who taught at Berkeley before becoming known as the Unabomber, and Ayman al-Zawahiri, a trained surgeon who ran al-Qaeda’s biological weapons effort. Al-Zawahiri recruited Yazid Sufaat, a U.S.-trained biochemist, to do some of al-Qaeda’s benchwork.
She closes this section with Aum Shinrikyo as an example of why bioweapons are hard: “Aum Shinrikyo, a Japanese cult with ~$1 billion, failed in all ten of their attempts to release biological agents.” First, I want to note that Aum’s bioweapons budget was actually something like only $3M/year out of the ~$1 billion. Second, I agree that bioweapons are hard, and that Aum is evidence for this. However, I think Aum is even better evidence that a group has already had the motivation, capital, equipment, and staff to commit a biological attack. In modern times, such a group would have access to significantly better information and technology.
Regarding laboratory benchwork, the piece also overstates how difficult basic techniques are. Olvera cites pipetting as an example. I have spent many hours in the lab pipetting small volumes. It took me ~1 week to get good at it, and the same is true for the dozens of other students I worked with. The idea that benchwork represents some insurmountable barrier is false. I would argue that benchwork is not hard because of technique; it is hard because biology is unpredictable. Sometimes your antibodies just don’t work, etc. This would not be significantly more difficult for a threat actor than for a newer scientist. We should also not assume this threat actor will have no access to training, nor that they could not be a scientist themselves. Even with just a few months of training, there is not a lab technique I can think of that is out of reach. Moreover, soon more cloud labs like Emerald will come online, robotic pipettes and cell culture will become more common, and labs will shift, as all sectors always have, towards increased automation. Soon, a threat actor need not even be in the lab to make a weapon.
Olvera points out correctly that AI uplift for benchwork is not currently a major concern. She writes, “The largest such study to date, by ActiveSite, indicated that non-experts with access to mid-2025 LLMs performed better on individual virology tasks but saw no meaningful improvement in end-to-end workflows. Success rates on these basic workflows remained below 8%.” Though the measurable uplift for non-experts is small, meaningful improvement on individual tasks eventually leads to improvement in end-to-end workflows, even if it does not now. Let’s do the math. Assume we have five sequential steps at 60%. I chose 60% because this would yield a 7.8% success rate, close to the sub-8% figure the study reports. If you got each step to 80%, the same workflow would make a big jump to a 33% success rate. AI is highly capable of benchwork troubleshooting, as indicated by SecureBio’s Virology Capabilities Test, which demonstrated that o3 performed better than 94% of expert virologists, even in April 2025. This is evidence that AI will be able to provide uplift to some of the steps, especially as it improves. The ActiveSite study was also a time-restricted study. In biology, it takes time to get every step right. This means that things go from not working at all to working well, very quickly. A study like this run over a year, I believe, would have substantially different outcomes. And that is the experiment we are running in the real world right now.
The claims Olvera makes that I disagree with most are: “Any pathogen that a team could plausibly create is one that already exists in nature. An engineered version of COVID-19 would have about the same effect as an infected person coughing in a crowded room.”
First, progress in generative biology undermines the claim that any plausible engineered pathogen would be something that already exists in nature. AI model Evo has already successfully designed novel viral genomes and the Arc Institute demonstrated them as functional in the lab. She argues that this particular example is irrelevant: “Some people cite bacteriophages as evidence of AI-created novel viruses; however, practitioners don’t consider them truly novel. These are 7% different from nature, which is seen as normal evolutionary change.” 7% different is meaningfully different, enough to be considered a new species under some taxonomies. For instance, under criteria from the International Committee on Taxonomy of Viruses, a phage genome below 95% ANI to any known relative qualifies as a new species. Evo’s most divergent viable design from this trial, at 93.0% ANI, qualifies. Calling this normal evolutionary change is only true in the sense that speciation is normal. “Normal evolutionary change” at the pace of a lab and not at the pace of evolution is decidedly not normal.
Olvera then writes, “These engineered bacteriophages don’t need to evade the immune responses that even bacteria possess, making it unclear whether they’re viable compared to natural viruses that have survived that selection pressure.” The point of the Arc Institute project was not to make more infectious bacteriophages, just novel ones. They made them intentionally similar to ΦX174, so this is not relevant to the issue at hand. Even if this were not considered a “novel virus,” technology is clearly progressing towards this. One can argue about the timeline, but we will be able to do this. We have seen attempts to make chimeric viruses even without the aid of AI. The design space is demonstrably larger than simple modifications of existing viruses.
Second, the claim that “an engineered version of COVID-19 would have about the same effect as an infected person coughing in a crowded room” is dependent on the type of engineering. I think Olvera is trying to say that it would just make COVID more transmissible, glossing over the fact that even if that were all the engineering was able to accomplish, this would still have resulted in millions more deaths. We have in some sense already run the transmissibility experiment: Alpha and Delta spread faster than the original strain, and each drove a wave of deaths far larger than the original strain would have caused. While I think significant changes in lethality and transmissibility are possible, even a modest change to one parameter does not mean a modest outcome.
Olvera adds to the argument above by pointing out that releasing 1918 influenza today would not be “1918-bad,” because we have cross-immunity as most immune systems recognize flu descendants and we have antivirals and antibiotics for the secondary pneumonia that killed most victims. This is of course true, especially since we also have much better medical infrastructure and medicines now. The point I want to make in response is that cross-immunity is precisely the kind of property an engineered modification would target. (Also, the antibiotic argument assumes that we have some very solid supply chains.)
Olvera also writes, “Engineering a virus that is both extremely lethal and highly contagious, worse than anything nature has produced, would be bad. But many biologists doubt this is possible even with perfect technology.” However, there is very meaningful disagreement among experts on how difficult it would be to engineer something both highly lethal and highly transmissible. Only mentioning that many biologists consider this impossible even with advanced technology does not at all reflect the full range of assessments in the field. The lethality versus transmissibility tradeoff is just an observation about what natural selection optimizes for. Engineering can bypass the tradeoff, and some natural viruses already do. Smallpox has an R₀ of ~5 with a fatality rate near 30%. HIV is ~100% fatal untreated, and transmits for years with an R₀ of ~2-5. (For comparison, the original COVID strain had an R₀ of ~3 and an infection fatality rate of ~0.5%.) Both bypass the tradeoff by separating the transmission phase from the lethal phase, a technique which could also be engineered into a weapon.
Olvera states that she interviewed dozens of biosecurity experts and lab practitioners, but she does not name any of them (except for Michael Montague) or describe their specific backgrounds or affiliations. This makes it difficult for me to assess how representative their views are, but my conversations with dozens of biosecurity experts and lab practitioners, as someone who has worked both in biosecurity policy and in a lab, have been very different.
Olvera closes by explaining why her piece is not conventional wisdom. She reminds us that often null results don’t get published, and advocacy groups need urgency. You could cynically say that biosecurity people are motivated to keep their jobs. I am sure that some people are. You should also consider the more likely case that most of us are motivated because we believe the threat is real and significant. Speaking as someone who only recently made biosecurity their full-time priority, I can assure the reader that I would love to be working on something else, and for this not to be such an urgent problem. This is also the sentiment of many people I know in the field. I understand this is anecdotal evidence, but so is her claim that “many leaders in biosecurity and national security organizations” thanked her privately for writing this conclusion.
Some claim that AI helps defenders too, and there is a real argument that in cybersecurity AI improvements can favor defense. Unlike cybersecurity, biosecurity has a profound offense-defense asymmetry. An attacker does not have to go through clinical trials or pay for manufacturing. An attacker has time to design a weapon and can choose when to release, but the defender can mostly only start responding after the attack.
At the end of the day, pieces like this encourage complacency. It is unclear exactly how quickly technology will advance over the next few years, and state actors are already capable of massive harm. Complacency is costly: bioweapons can be weapons of unprecedented mass destruction. We should treat biosecurity as urgent.
Disclaimer: This piece represents my personal views and my personal views only. It does not represent the opinion of any organization I work for or with.


Thanks Olivia! First of all thanks so much for writing this! I learned and am so grateful you took the time to consider this so deeply and make a compelling piece! :)
I realize I should have made it much clearer that state actors were outside the scope of my piece! I was particularly focused on lone wolf scenarios, and the difficulty of engineered pandemics predominantly for lone wolf and non-state actors. Those are the ones that I am no longer worried about.
State actors and even experts in institutions could do great harm!
Diving into some of the points:
I definitely agree that automation and humanoid robots will drastically change what is easy. These were the conclusions of 2 of the 3 pieces. Piece 1: theoretical lab automations could make what is easy different, but that's not what's going on now, (so we should track lab automation) Piece 2: lab automations will make some steps easier, though those are good targets for oversight AND the steps between and after these are still hard.
Anthropic's willingness to make Fable unusuable isn't evidence in and of itself. They personify the approach that I'm questioning (hence why I focused on lone wolf / x-risk level engineered pandemic, not the things that the broader biosecurity community focus on). Anthropic been viewed as overstating their claim and being an echo chamber e.g. cyber practitioners couldn't replicate their China cyber agent attack report, for example. The same framework is also the underlying assumption when you highlight "when enabling technology is improving at such a high speed" which implies LLM speed is the thing to watch. I'm saying that we should really prioritize trying to get a better sense of the scale of the tacit knowledge barrier or lab automation.
On the "some groups meet the malicious bar": the existence of one group doesn't negate that the rule acts as a huge filter. Because biosec requires prioritization, natsec circles see these filters and weigh them.
I agree resources will get cheaper, but that's probably the thing to watch. I'm not sure how much AI will make equipment like pulverizers, fume hoods, etc. cheaper nor the labor associated with lack of tacit knowledge, etc. It's much more expensive than a bomb or chemical attack, and again, this point was mostly only geared for non-state actors. State actors have nearly unlimited funds sometimes!
On institutional access, you're pointing to what's easy to skirt (which I hope will be closed ofc) but you're not pointing at what's harder to skirt. Those bottlenecks become more important. Also, the fact that only tens of thousands can access these is why, realistically, why natsec circles worry less. Some worry should be focused on those tens of thousands, but there's also tradeoffs on whether making it hard for institutions to buy makes bioresilience efforts harder too since pretty much all the work is for vaccine/learning/etc.
You mention seeing Aum Shinrikyo as proof that a group that has all the things to commit a bio attack, though they failed 10 times and never succeeded. I think how one construes this evidence depends on one's pre-existing framework. (I think when I was at CSR, I would have only applied the biosec lens, but here I tried to learn the biosec/military-strategy lens) On whether they'd succeed today: the framework I'm explaining highlights that the tacit knowledge barrier is the thing to measure and appears not greatly changed. Given ActiveSite results, it seems unlikely that LLMs help much more than YouTube or paying a lab student (participants said they found YouTube more helpful than LLMs). A lot of the stuff Aum Shinrikyo would have needed to have the skill to do, to properly aerolize the spray, get the right concentration, is pretty advanced hands-on lab work, the kind that you can't really automate with lab automation out in the field nor with LLMs.
Pipetting seems to be hard partly because of what you're working with too. So I don't think someone successfully pippetting in a week means pipetting is mastered in all tasks nor all materials. All lab work takes time and it's pretty specific to the materials and processes you're doing. I agree (and point out in part 3) that some parts of the process can easily be done by lab students. Honestly, you can just buy a lab tech or probably a skilled lab student, though you don't need AI for that. Though cloud labs and robotic cells are specialized workflows and seem easier to have oversight on. I don't agree with the claim that because lab automation exists, that it will necessarily make things easier. It leaves out the fact that there's likely to be KYC type of process AND that it doesn't make life easier for those not using lab automation. It seems nuanced.
You say LLMs could get people to 80% success on tasks, but that is probably an example of the framework I was trying to counter. 80% success is a *huge* claim that would really need evidence - it rests on the assumption that all you need is someone telling you how to do something for you to do it right. It assumes there's no tacit knowledge or lab hands skill or real-life obstacles. That framework is the same reason why the SecureBio virology tests don't convince people in DC. The test cannot make claims about how much tacit knowledge or hands on skill there is to know. The size and importance of that aspect is the framework I'm explaining. Ideally the ActiveSite study had more time, I did advocate in my Part 3 for more studies like that. Though it's probably helpful that there was a realistic time frame, it's not like non-state actors have infinite time. Though notably, it was also much easier than real-life scenarios because students were handed the materials.
The 7% change is probably a figure that matters in the context of what you're looking at. Bacteriophages are much simpler, almost template-like from what I remember. I'm less confident here as that was a side debate that I didn't delve into deeply. Thanks for flagging about Arc Institute's goals, I didn't realize that their goal was narrower. BUT the difficulty lies in editing a virus that will then have to survive on everything (whether it be lettuce, lung or stomach lining, mucus, saliva, blood, air, etc.). Hence why there wasn't the same level of alarm outside of the AIxbioxXrisk community about bacteriophages. Even if it's a step, the hard part is making something that survives in all the different environments it has to survive in. So the size of the step to those who weight "survival in all conditions is incredible hard" is much smaller.
On the COVID-19, I only meant unedited COVID-19. This was my non-Gain of Function segment.
Again, sorry for not clarifying the narrowness of my claim. I do think part of it is that I try to "not write for my critics" which would probably defined here be as people who don't buy claims about LLMs are all that matter and are unhappy with the discourse. In terms of bio, it seems a lot of people are aware that we've made leaps in bioresilience that dont factor in risk headlines.
I didn't point out that some biologists see a kill-most-humans engineered pandemic as possible because 1. this seemed to be more of a minority opinion when I did interviews 2. I'm responding to claims that a kill-most-humans engineered pandemic is possible. It's a bit of a tradeoff to write succintly, which I notice you have to do to too :) E.g. when you say "Engineering can bypass the tradeoff" "by separating the transmission phase from the lethal phase, a technique which could also be engineered into a weapon". HIV nor smallpox are not existential risk level AND "engineering into a weapon" is theoretical only still (even x-risk people will clarify that there's no single gene-like or Lego-like on/off switch for "transmissibility" or "lethality" in viruses for humans.)
I don't name the participants so that I would get more off-the-record type of responses. I specifically prioritized getting people who actively worked in laboratories for 5-10+ years but also work on biosecurity, and who are not just from EA / X-risk / AI policy organizations. You mentioned that you're in this space because the evidence led you to believe this is urgent; this likely means your circles will be similar though. I run in X-risk / EA circles a lot hence I specifically got the the steelman of the other sides repeatedly, until their framework clicked. Happy to intro you to people. :) You seem very thoughtful and thorough. :)
Thank you for this! Biosecurity is one of my favorite topics, it's so important and I've added an update to clarify that biosecurity is still ridiculously important!
Nice post, it’s great there is a healthy debate.
Ironically, the discussion in here about how dangerous state bioweapons programs are is why I’m *less* worried about the impact of AI. State actors are already incredibly capable of producing bioweapons and have been for decades. AI doesn’t really move the needle on their ability to launch a devastating attack because they can already do it with existing techniques. This implies that 1) AI shouldn’t be that big of a threat update on this front, and 2) the strategic dynamics that currently constrain states’ use of bioweapons will not be significantly altered by AI, because merely adding marginally more capabilities doesn’t change the existing calculus.
As far as technological improvements enabling more lone wolves or unaffiliated groups, I think you are underestimating the scope of a successful bioweapons program and overestimating how much the technology will dissolve all the existing bottlenecks, but I would completely agree that future automated labs and other providers should have robust auditing and KYC. This would be an example of a threat that I think is legitimate and takes vigilance but is solidly manageable with normal governance responses.
On the work done by Arc that you cite, those viruses showed *less* variation than natural evolution and little evidence of functionally directed novelty (Black et al., 2026). Given how poor the scaling and generalization have been in gene language models and other bio foundation models (Jiang et al., 2026; Tzanakakis et al., 2026), I’d say it’s entirely non-obvious that those techniques will scale to producing truly novel pathogens (which also requires predicting pathogenicity, which in itself is a major challenge). This could turn out to be incorrect, and progress in the field is very much worth watching, but I’d say the early evidence suggests that the bio models are on nothing like the progress curve of LLMs.
Black, J.R.M., Maiwald, A., Pannu, J. & Crook, O.M. (2026). *Quantifying evolutionary novelty and design efficiency in generative genome design.* bioRxiv. https://doi.org/10.64898/2026.06.12.731871
Jiang, S., Liu, X. & Wang, Z.J. (2026). *Evaluating DNA Function Understanding in Genomic Language Models Using Evolutionarily Implausible Sequences.* ACS Synthetic Biology, 15(6), 2256–2263. https://doi.org/10.1021/acssynbio.6c00024
Tzanakakis, G. et al. (2026). *[Independent evaluation of Evo 2 genomic sequence generation].* bioRxiv. https://doi.org/10.64898/2026.01.17.700093