Bioethics

Can AI Help Build a Bioweapon? RAND's 9-Layer Plan to Stop It

RAND says no single safeguard can stop AI-assisted bioweapons, and lays out nine layered defences. Here is what the report argues, why it lands now, and where it is still guesswork.

Ask a biosecurity researcher what keeps them up at night and, until recently, the honest answer was cost and skill. Designing a dangerous pathogen took rare expertise, expensive kit and a lot of failed attempts. Artificial intelligence is quietly eroding all three. On 18 August, the RAND Corporation published a report arguing that the safeguards we rely on were built for the old world, and that no single fix will do. Its proposed answer is not one wall but nine, layered together.

The report, Building a Defense-in-Depth Biosecurity Strategy for the AI Era, is not a scare story. It is a sober attempt to map where AI actually changes the risk, and where our defences leak. For a field as young as AI biosecurity, one that often swings between hype and denial, that restraint is the interesting part.

What happened#

RAND's Center on AI, Security, and Technology released a 77-page, peer-reviewed report that sets out a "defence-in-depth" strategy against the misuse of AI-enabled biology. The premise, stated plainly in the press release, is that "no single safeguard can prevent an actor from using artificial intelligence to help build a biological weapon," but that nine interventions, working together, could meaningfully lower the odds of a high-consequence attack.

The authors traced the full path an attacker would have to walk, from first idea to a weaponised agent, and asked where a defender could add friction at each step. Their conclusion is that different threat actors need different obstacles. A lone individual with little money or training might be stopped by cutting off access to materials and know-how. A well-funded group or a state programme can usually work around access controls, so the better lever there is raising the cost and the chance of getting caught.

Lead author Steph Guerra, who heads RAND's AI x Bio work, put the core problem bluntly: today's safeguards are "fragmented across companies, governments and countries and are not designed to work together." The report was picked up the same week by the Center for Bioethics and Human Dignity's news service, bioethics.com, which flagged it under research ethics and biotech. This is a governance paper, not a lab result, but it sits on top of a very real experiment I will get to shortly.

The dual-use problem, in plain terms#

To see why this report lands now, you need two pieces of background.

The first is what AI has done for protein design. A protein is a chain of amino acids that folds into a specific three-dimensional shape, and the shape determines what the protein does. For decades, predicting that shape from the sequence alone was one of biology's hardest problems. Then DeepMind's AlphaFold cracked structure prediction at scale, and David Baker's lab in Seattle went further, designing entirely new proteins that do not exist in nature. That combined achievement won the 2024 Nobel Prize in Chemistry. The same tools that let a researcher design a new enzyme or vaccine can, in principle, be pointed at something harmful. That is what "dual-use" means: one technology, two possible ends.

The second piece is how we currently guard the physical chokepoint. To build most proteins, you need DNA, and much of that DNA is ordered from commercial gene-synthesis companies. Many of these firms voluntarily screen orders against databases of known dangerous sequences, refusing anything that looks too much like a listed toxin or pathogen. The whole system leans on one assumption: that a dangerous sequence will resemble a dangerous sequence we already know about.

AI breaks that assumption. Generative design tools can rewrite a harmful protein so it keeps its function while sharing very little of its original sequence. To a screening tool that hunts for similarity to known threats, the redesign can look unremarkable. The wall is real, but it was built to catch a burglar who resembles a photo in the file, and AI can change the burglar's face.

Why this matters#

This is not hypothetical. In October 2025, a team led by Microsoft's Eric Horvitz, working with the International Biosecurity and Biosafety Initiative for Science and the gene-synthesis firm Twist Bioscience, published in Science a demonstration of exactly this weakness. They used open-source AI tools to generate more than 76,000 synthetic versions of proteins of concern, then ran them past the screening software that synthesis providers use. Many redesigns slipped through. After the group quietly developed and deployed patches over ten months, detection improved sharply, yet by Science's own account roughly 3% of the potentially functional toxins still evaded the upgraded tools.

That study, done as a confidential "red-teaming" exercise before public disclosure, is why RAND's argument carries weight. It shows the leak is real, that patching helps, and that patching alone does not close the gap. It also shows something more encouraging: the biosecurity community can find and fix a hole responsibly, without publishing a recipe.

RAND's contribution is to zoom out from that single chokepoint. Its nine mitigations split roughly into three jobs. Three of them restrict access to dangerous information and powerful models, including safeguards for open-weight systems and managed-access programmes for the most sensitive AI. One expands screening of the physical precursors, the DNA and reagents. Three aim to deter attacks through early warning, attribution and faster outbreak response, so that even an actor who gets past the fence expects to be caught. The final two focus on detection: real-time monitoring of how AI models are used, and sharing warning signs across companies and governments. The insight tying them together is that suspicious signals which look harmless in isolation, one odd model query here, one unusual synthesis order there, form a clear pattern only when someone can see them together.

Critical analysis#

The strengths first. The report resists the two easy stories. It does not claim AI has already handed bioweapons to teenagers, and it does not wave the risk away as science fiction. Its central move, matching the defence to the attacker rather than hunting for one silver bullet, is the right frame, and it is honest about trade-offs. Restricting open models, for instance, protects against misuse but slows the open research that drives medicine forward. RAND does not pretend that tension disappears.

Now the limits. Most of these nine layers do not exist yet in any coordinated form. A shared system for pooling threat signals across rival AI companies and national governments is, for now, an aspiration, and the report admits several mitigations "will take years to build, test and implement." There is a hard collective-action problem here: the strategy loses much of its value if any major country opts out, because synthesis capacity and open models are global. The report says international coordination is essential, which is true and also the part history suggests is hardest to deliver.

There is also an unresolved question the report cannot settle: how much AI actually uplifts a would-be attacker over what a determined person could already find in the literature. Studies disagree, and the honest position is that we do not yet have a stable measurement. RAND's case does not depend on the uplift being enormous, only on it being real and growing, but readers should know the size of the threat is still contested. And a strategy this dependent on monitoring raises its own ethical questions about surveillance, privacy and who holds the keys. RAND names these concerns; it does not resolve them.

Expert perspective#

Set this against the recent past and the shift is clear. The older biosecurity playbook, embodied in voluntary industry screening and export-control lists, treated dangerous biology as a catalogue of known items to be gated. That worked reasonably well when the threat resembled its own file photo. What is different now is that AI can generate novelty faster than any static list can absorb it, which is why RAND, Microsoft and others are converging on the same word: layers.

The report also fits a wider governance push. Microsoft used its June 2026 policy blog to call for mandatory nucleic-acid screening and verified customer identities, rather than the current voluntary patchwork. Harvard's Belfer Center reached similar conclusions in its August report on the dual-use frontier of AI-enabled biotechnology. Even the US Congressional Research Service has an August briefing noting the federal framework remains fragmented, with no single AI-biosecurity regulator. What makes RAND's version stand out is less any one idea than the systems view: it treats the nine measures as a network that reinforces itself, and it is candid that the weakest link is coordination, not technology.

None of this exists in a vacuum of principle. The WHO's guidance on AI for health and UNESCO's Recommendation on the Ethics of AI both insist that safety and human welfare sit at the centre of how these tools are built. RAND's report is, in effect, an attempt to turn that principle into an operational plan for one of the highest-stakes corners of the field.

Key takeaways#

  1. There is no silver bullet. RAND's core claim is that no single safeguard stops AI-assisted bioweapons, so defences must be layered and mutually reinforcing.
  1. The threat is demonstrated, not imagined. A 2025 Science study showed AI-redesigned toxins can evade DNA screening, and about 3% still slipped through even after fixes.
  1. Different attackers need different obstacles.** Access controls can stop under-resourced individuals; deterrence and detection matter more against well-funded or state actors.
  1. Detection depends on sharing. Warning signs are only obvious when scattered signals from models, vendors and labs are pooled, which no one company or country can do alone.
  1. Coordination is the bottleneck. The technology is buildable; the harder task is getting rival firms and governments to act together before the risk becomes undeniable.

Frequently asked questions#

Is this a new discovery about making bioweapons? No. The RAND report is a policy and governance analysis, not laboratory research, and it contains no operational instructions. It draws on published work, most notably a peer-reviewed 2025 Science study, to argue for stronger, layered safeguards.

Has AI actually been used to create a bioweapon? There is no public evidence of that. The concern is about lowered barriers and demonstrated vulnerabilities in our defences, such as AI-designed proteins evading screening in a controlled test, not a real-world attack.

What is "defence-in-depth"? It is a security idea borrowed from cybersecurity and nuclear safety: instead of relying on one perfect barrier, you stack several imperfect ones so that a failure at any single layer does not lead to disaster.

What is DNA synthesis screening? When researchers order custom DNA, many synthesis companies check the order against databases of known dangerous sequences and refuse suspicious ones. The weakness is that AI can redesign a harmful protein to avoid resembling anything on those lists.

Does this mean AI protein design should be banned? The report does not argue for that. The same tools are driving advances in medicine, vaccines and diagnostics. RAND's aim is to manage the dual-use risk while preserving the benefits, which is why it favours layered safeguards over blanket restriction.

Why does the report stress international coordination? Gene-synthesis capacity and open-source AI models exist worldwide. If one major country declines to participate, attackers can route around national controls, which is why several of the nine measures weaken if the effort is not global.

Is the RAND report peer reviewed? Yes. RAND states that its research reports undergo peer review, and the underlying Science paper it draws on is also peer reviewed. Where this article cites preprints or opinion pieces, they are identified as such.

References#

This article is for information and discussion. It is not medical, legal or security advice.

Related observations

Adjacent work from the same lines of enquiry.

Two Doors Into Biology

OpenAI is giving 100,000 academic researchers free frontier model access with 75+ life science skills. Anthropic's newest flagship refuses to explain mitochondria. Both companies claim to be managing the same biosecurity risk — and the gap between their answers tells you how unsettled AI-for-biology governance really is.