Discussion about this post

User's avatar
Abi Olvera's avatar

Thanks Olivia! First of all thanks so much for writing this! I learned and am so grateful you took the time to consider this so deeply and make a compelling piece! :)

I realize I should have made it much clearer that state actors were outside the scope of my piece! I was particularly focused on lone wolf scenarios, and the difficulty of engineered pandemics predominantly for lone wolf and non-state actors. Those are the ones that I am no longer worried about.

State actors and even experts in institutions could do great harm!

Diving into some of the points:

I definitely agree that automation and humanoid robots will drastically change what is easy. These were the conclusions of 2 of the 3 pieces. Piece 1: theoretical lab automations could make what is easy different, but that's not what's going on now, (so we should track lab automation) Piece 2: lab automations will make some steps easier, though those are good targets for oversight AND the steps between and after these are still hard.

Anthropic's willingness to make Fable unusuable isn't evidence in and of itself. They personify the approach that I'm questioning (hence why I focused on lone wolf / x-risk level engineered pandemic, not the things that the broader biosecurity community focus on). Anthropic been viewed as overstating their claim and being an echo chamber e.g. cyber practitioners couldn't replicate their China cyber agent attack report, for example. The same framework is also the underlying assumption when you highlight "when enabling technology is improving at such a high speed" which implies LLM speed is the thing to watch. I'm saying that we should really prioritize trying to get a better sense of the scale of the tacit knowledge barrier or lab automation.

On the "some groups meet the malicious bar": the existence of one group doesn't negate that the rule acts as a huge filter. Because biosec requires prioritization, natsec circles see these filters and weigh them.

I agree resources will get cheaper, but that's probably the thing to watch. I'm not sure how much AI will make equipment like pulverizers, fume hoods, etc. cheaper nor the labor associated with lack of tacit knowledge, etc. It's much more expensive than a bomb or chemical attack, and again, this point was mostly only geared for non-state actors. State actors have nearly unlimited funds sometimes!

On institutional access, you're pointing to what's easy to skirt (which I hope will be closed ofc) but you're not pointing at what's harder to skirt. Those bottlenecks become more important. Also, the fact that only tens of thousands can access these is why, realistically, why natsec circles worry less. Some worry should be focused on those tens of thousands, but there's also tradeoffs on whether making it hard for institutions to buy makes bioresilience efforts harder too since pretty much all the work is for vaccine/learning/etc.

You mention seeing Aum Shinrikyo as proof that a group that has all the things to commit a bio attack, though they failed 10 times and never succeeded. I think how one construes this evidence depends on one's pre-existing framework. (I think when I was at CSR, I would have only applied the biosec lens, but here I tried to learn the biosec/military-strategy lens) On whether they'd succeed today: the framework I'm explaining highlights that the tacit knowledge barrier is the thing to measure and appears not greatly changed. Given ActiveSite results, it seems unlikely that LLMs help much more than YouTube or paying a lab student (participants said they found YouTube more helpful than LLMs). A lot of the stuff Aum Shinrikyo would have needed to have the skill to do, to properly aerolize the spray, get the right concentration, is pretty advanced hands-on lab work, the kind that you can't really automate with lab automation out in the field nor with LLMs.

Pipetting seems to be hard partly because of what you're working with too. So I don't think someone successfully pippetting in a week means pipetting is mastered in all tasks nor all materials. All lab work takes time and it's pretty specific to the materials and processes you're doing. I agree (and point out in part 3) that some parts of the process can easily be done by lab students. Honestly, you can just buy a lab tech or probably a skilled lab student, though you don't need AI for that. Though cloud labs and robotic cells are specialized workflows and seem easier to have oversight on. I don't agree with the claim that because lab automation exists, that it will necessarily make things easier. It leaves out the fact that there's likely to be KYC type of process AND that it doesn't make life easier for those not using lab automation. It seems nuanced.

You say LLMs could get people to 80% success on tasks, but that is probably an example of the framework I was trying to counter. 80% success is a *huge* claim that would really need evidence - it rests on the assumption that all you need is someone telling you how to do something for you to do it right. It assumes there's no tacit knowledge or lab hands skill or real-life obstacles. That framework is the same reason why the SecureBio virology tests don't convince people in DC. The test cannot make claims about how much tacit knowledge or hands on skill there is to know. The size and importance of that aspect is the framework I'm explaining. Ideally the ActiveSite study had more time, I did advocate in my Part 3 for more studies like that. Though it's probably helpful that there was a realistic time frame, it's not like non-state actors have infinite time. Though notably, it was also much easier than real-life scenarios because students were handed the materials.

The 7% change is probably a figure that matters in the context of what you're looking at. Bacteriophages are much simpler, almost template-like from what I remember. I'm less confident here as that was a side debate that I didn't delve into deeply. Thanks for flagging about Arc Institute's goals, I didn't realize that their goal was narrower. BUT the difficulty lies in editing a virus that will then have to survive on everything (whether it be lettuce, lung or stomach lining, mucus, saliva, blood, air, etc.). Hence why there wasn't the same level of alarm outside of the AIxbioxXrisk community about bacteriophages. Even if it's a step, the hard part is making something that survives in all the different environments it has to survive in. So the size of the step to those who weight "survival in all conditions is incredible hard" is much smaller.

On the COVID-19, I only meant unedited COVID-19. This was my non-Gain of Function segment.

Again, sorry for not clarifying the narrowness of my claim. I do think part of it is that I try to "not write for my critics" which would probably defined here be as people who don't buy claims about LLMs are all that matter and are unhappy with the discourse. In terms of bio, it seems a lot of people are aware that we've made leaps in bioresilience that dont factor in risk headlines.

I didn't point out that some biologists see a kill-most-humans engineered pandemic as possible because 1. this seemed to be more of a minority opinion when I did interviews 2. I'm responding to claims that a kill-most-humans engineered pandemic is possible. It's a bit of a tradeoff to write succintly, which I notice you have to do to too :) E.g. when you say "Engineering can bypass the tradeoff" "by separating the transmission phase from the lethal phase, a technique which could also be engineered into a weapon". HIV nor smallpox are not existential risk level AND "engineering into a weapon" is theoretical only still (even x-risk people will clarify that there's no single gene-like or Lego-like on/off switch for "transmissibility" or "lethality" in viruses for humans.)

I don't name the participants so that I would get more off-the-record type of responses. I specifically prioritized getting people who actively worked in laboratories for 5-10+ years but also work on biosecurity, and who are not just from EA / X-risk / AI policy organizations. You mentioned that you're in this space because the evidence led you to believe this is urgent; this likely means your circles will be similar though. I run in X-risk / EA circles a lot hence I specifically got the the steelman of the other sides repeatedly, until their framework clicked. Happy to intro you to people. :) You seem very thoughtful and thorough. :)

Thank you for this! Biosecurity is one of my favorite topics, it's so important and I've added an update to clarify that biosecurity is still ridiculously important!

fox's avatar
Aug 13Edited

Nice post, it’s great there is a healthy debate.

Ironically, the discussion in here about how dangerous state bioweapons programs are is why I’m *less* worried about the impact of AI. State actors are already incredibly capable of producing bioweapons and have been for decades. AI doesn’t really move the needle on their ability to launch a devastating attack because they can already do it with existing techniques. This implies that 1) AI shouldn’t be that big of a threat update on this front, and 2) the strategic dynamics that currently constrain states’ use of bioweapons will not be significantly altered by AI, because merely adding marginally more capabilities doesn’t change the existing calculus.

As far as technological improvements enabling more lone wolves or unaffiliated groups, I think you are underestimating the scope of a successful bioweapons program and overestimating how much the technology will dissolve all the existing bottlenecks, but I would completely agree that future automated labs and other providers should have robust auditing and KYC. This would be an example of a threat that I think is legitimate and takes vigilance but is solidly manageable with normal governance responses.

On the work done by Arc that you cite, those viruses showed *less* variation than natural evolution and little evidence of functionally directed novelty (Black et al., 2026). Given how poor the scaling and generalization have been in gene language models and other bio foundation models (Jiang et al., 2026; Tzanakakis et al., 2026), I’d say it’s entirely non-obvious that those techniques will scale to producing truly novel pathogens (which also requires predicting pathogenicity, which in itself is a major challenge). This could turn out to be incorrect, and progress in the field is very much worth watching, but I’d say the early evidence suggests that the bio models are on nothing like the progress curve of LLMs.

Black, J.R.M., Maiwald, A., Pannu, J. & Crook, O.M. (2026). *Quantifying evolutionary novelty and design efficiency in generative genome design.* bioRxiv. https://doi.org/10.64898/2026.06.12.731871

Jiang, S., Liu, X. & Wang, Z.J. (2026). *Evaluating DNA Function Understanding in Genomic Language Models Using Evolutionarily Implausible Sequences.* ACS Synthetic Biology, 15(6), 2256–2263. https://doi.org/10.1021/acssynbio.6c00024

Tzanakakis, G. et al. (2026). *[Independent evaluation of Evo 2 genomic sequence generation].* bioRxiv. https://doi.org/10.64898/2026.01.17.700093

19 more comments...

No posts

Ready for more?