AI and Biosecurity: Capability Boundaries, Threat Pathways, and Defense-in-Depth Governance

A systematic review of AI's biosecurity risks, threat chains, and defense-in-depth governance frameworks.
This arXiv review comprehensively examines AI's current capabilities in biological research and their biosecurity implications. The central finding is that AI's biosecurity impact is systemic — shaped by users, intent, physical access, and safeguards, not AI capability alone. AI already surpasses expert baselines in digital tasks like information synthesis and sequence design, but wet-lab physical execution and tacit knowledge remain major barriers. The paper maps threats across the full chain from information gathering to potential release, argues that general alignment techniques fail on biological foundation models, and positions interpretability auditing as the key tool for verifying genuine capability removal. On governance, it advocates a defense-in-depth framework linking capability thresholds to proportionate responsibilities across the ecosystem.
Artificial intelligence is reshaping the entire biological research workflow, from digital to physical. Large language models can retrieve and synthesize scientific information, assist with experimental design, and support computational analysis. Biological foundation models can predict, optimize, and generate protein, gene, and genome-scale sequences. Agentic systems can coordinate multi-step research tasks, and automated laboratories are beginning to partially close the design-build-test-learn cycle. While these technologies offer enormous opportunities for medicine, public health, and biotechnology, they raise an unavoidable question: what do they mean for biosecurity?
A review paper published on arXiv (arXiv:2609.16213) systematically surveys AI's current capabilities in the biological domain, maps out threat pathways, and proposes a "defense-in-depth" governance framework. The paper's central argument deserves attention: the biosecurity risk posed by AI depends not only on "what AI can do," but critically on "who is using it, their expertise and intent, their access to experimental tools and materials, and the safeguards already in place."

AI Capability Advances: Digital Tasks Pull Ahead, Physical Execution Remains the Bottleneck
One of the paper's key findings is that current evidence does show AI providing capability "uplift" — but this uplift is concentrated in digital tasks, not physical ones.
Frontier systems have already surpassed expert baselines on benchmarks involving in-silico computation and screening-evasion tasks. This means AI performs strongly in purely digital domains such as information synthesis, sequence design, and biocomputation.
However, controlled wet-laboratory studies reveal that tacit knowledge and physical execution remain formidable barriers. In other words, AI can help you figure out what to do, but actually carrying out experiments — from procuring materials to synthesis, testing, and scale-up — still depends heavily on hands-on human experience and physical infrastructure. This asymmetry — strong digitally, weak physically — forms the foundation for understanding where current risk boundaries actually lie.
On tacit knowledge: The concept of "tacit knowledge" originates with philosopher Michael Polanyi and refers to practical, experiential knowledge that cannot be fully encoded in language or text — the kind of skill that can only be shown, not told. In the wet-laboratory context, it manifests as a researcher's intuitive judgment about pipetting feel, the state of growth media, or cell viability, and the ability to adapt on the fly when results deviate from expectations. This knowledge is highly personal and takes years of hands-on practice to accumulate. It is the element current AI systems — including robotic automation platforms — find most difficult to replicate. Even when every step of a protocol is precisely described, an operator lacking tacit knowledge (whether human or machine) will achieve significantly lower success rates than an experienced scientist when faced with the real-world unpredictability of laboratory work. This is precisely why the paper identifies "physical execution" as a critical bottleneck in the biosecurity threat chain.
Threat Pathways: A Full Chain from Information Acquisition to Potential Release
Rather than treating AI's biosecurity threat as a monolith, the paper breaks it down along a complete chain of steps:
- Information gathering: Using AI to retrieve and synthesize dispersed scientific knowledge
- Biological design: Leveraging biological foundation models to generate or optimize protein and gene sequences
- Procurement: Obtaining the materials and reagents needed for experiments
- Synthesis: Translating designs into actual biological molecules
- Testing and scale-up: Validating function and expanding production
- Potential release: Risk spillover at the final stage
This step-by-step perspective is valuable because it reveals that safeguards must be tailored to different nodes in the chain. AI uplift is most pronounced at the front end — information and design — while the back end — procurement, synthesis, and scale-up — remains constrained by physical-world barriers. Governance efforts can therefore be targeted more precisely at the critical chokepoints in the chain.
Why General Alignment Techniques Fail on Biological Models
The paper raises a technically profound question: alignment techniques developed for general-purpose large language models are difficult to transfer to biological models.
Safety alignment in general language models typically relies on identifying and refusing "harmful content." But biological foundation models operate on highly specialized data — protein, gene, and genome sequences — and their "dangerous capabilities" are often embedded within what appear to be neutral generative tasks, making them difficult to constrain with general-purpose value alignment approaches. A model capable of designing beneficial proteins and one capable of designing dangerous sequences may share deeply overlapping underlying capabilities.
This is the context in which interpretability techniques take on a new role. The paper notes that interpretability can be used for "auditing" — verifying that dangerous capabilities have been genuinely removed rather than merely suppressed on the surface. This offers a pathway to biological AI safety evaluation that is distinct from traditional alignment approaches.
On alignment vs. interpretability: In AI safety, "alignment" refers to the technical direction of ensuring a model's behavior is consistent with human intent and values — common methods include reinforcement learning from human feedback (RLHF) and Constitutional AI. "Interpretability" research, by contrast, aims to understand the internal computational mechanisms of neural networks: which neurons or circuits correspond to which capabilities, and what the model actually "knows." The key distinction is that alignment operates primarily at the level of output behavior, while interpretability goes deeper into the model's internal representations. In general language models, the two can be complementary — interpretability can locate where dangerous knowledge is encoded internally, and then assess whether an alignment intervention has genuinely "erased" that capability or merely trained the model to decline answering on the surface. For biological models, this distinction is especially important: a protein-generation model that has undergone alignment training might appear "safe" on standard tests yet still activate dangerous capabilities under specific prompts. Interpretability audits are therefore regarded as a more reliable means of safety verification than behavioral testing alone.
Defense-in-Depth Governance: Matching Capability Thresholds to Proportionate Responsibility
In response to this complexity, the paper advocates a "defense-in-depth" governance philosophy. Its core logic is to link capability thresholds to "proportionate responsibilities" for each actor in the biological AI ecosystem.
The elegance of this approach lies in avoiding two extremes: neither overreacting with blanket restrictions that stifle technological development, nor allowing high-risk capabilities to proliferate without oversight. When a model's capabilities reach a given risk threshold, developers, deployers, laboratories, and supply-chain participants should all bear safeguarding obligations commensurate with that risk level. Layering multiple lines of defense means that even if a single layer fails, the overall system can still intercept high-consequence risks.
The paper's conclusion is clear: reduce high-consequence risks while preserving the beneficial uses of AI in medicine, public health, and biotechnology. This is a pragmatic balance — one that acknowledges the dual-use nature of the technology and proposes a tiered, graduated, responsibility-distributed governance architecture to manage risk, rather than simply choosing between "promotion" and "restriction."
On defense-in-depth: "Defense-in-depth" originated as a classic strategy in military and nuclear safety, and was later widely adopted in cybersecurity system design. Its core principle is never to rely on any single line of defense, but instead to build multiple independent protective layers, forcing an adversary to simultaneously overcome several barriers before causing real harm. Applied to AI biosecurity governance, these layers might include: capability restrictions during model training, access controls and identity verification at the deployment stage, screening mechanisms in the synthetic biology supply chain (such as sequence review by gene synthesis companies), biosafety protocols within laboratories, and post-hoc audits by regulatory bodies. "Capability thresholds" serve as the quantitative anchors for this framework — determined through standardized harm-assessment benchmarks that establish where a given model has crossed an acceptable risk boundary in specific tasks, thereby triggering higher-level regulatory obligations. This requires that safety evaluation for biological AI become a systematic science in its own right, rather than relying solely on developer self-reporting.
Conclusion: Risk Is a Property of Systems, Not Individual Technologies
Perhaps the most important reminder in this review is that AI biosecurity is not an isolated technical problem — it is a systemic challenge involving capabilities, users, physical access, and safeguards working in combination. AI's capability uplift in digital tasks is real, but the physical execution barrier remains; the limitations of alignment techniques highlight the value of interpretability auditing; and the defense-in-depth governance framework attempts to provide an institutional answer for a rapidly evolving field — one that protects without stifling innovation. For researchers and policymakers focused on AI governance and frontier safety, the "capability thresholds — proportionate responsibility" framework outlined here is well worth studying in depth.
Related articles

Letting AI Build AI Tools: A 7-Day, 31-Commit Bootstrapping Post-Mortem
An engineer ran a fully autonomous AI-builds-AI pipeline for 7 days, 31 commits, with a 1-in-6 success rate. This post-mortem covers 5 failure types, 11 structural rules, and how every mistake became a permanent immunity gate.

Building an AI-Powered E-Commerce Business from Scratch: A Real-World Account of Multi-Agent Architecture for Print-on-Demand
A blogger builds a print-on-demand e-commerce company from scratch using AI agents — documenting specialized Agent profiles, GPT-5.6 vs Claude Fable multi-model orchestration, and reusable skill accumulation.

AI Agent Earns $10K in One Week: 3 Key Upgrades Explained
A blogger shares how he earned $10K in a week with an AI Agent — not by adding more skills, but through verification, approval gates, and subagents to raise trust and enable true automation.