Artificial intelligence and biosecurity: capabilities, threat pathways, and defense-in-depth governance

Artificial intelligence and biosecurity: capabilities, threat pathways, and defense-in-depth governance

人工智能与生物安全:能力、威胁路径及纵深防御治理

Abstract: Artificial intelligence is reshaping biological research across an increasingly connected digital-to-physical workflow. General-purpose large language models can retrieve and integrate scientific information, support experimental planning, and computational analysis; biological foundation models can predict, optimize, and generate proteins, genes, and genome-scale sequences; agentic systems can coordinate multistep research tasks; automated laboratories can partially close the design-build-test-learn cycle. These technologies could greatly benefit medicine, public health, and biotechnology.

摘要: 人工智能正在重塑生物学研究,贯穿于日益紧密连接的“数字到物理”工作流程中。通用大语言模型能够检索并整合科学信息,支持实验规划与计算分析;生物基础模型能够预测、优化并生成蛋白质、基因及基因组规模的序列;智能体系统可以协调多步骤的研究任务;自动化实验室则能部分实现“设计-构建-测试-学习”循环的闭环。这些技术有望为医学、公共卫生和生物技术带来巨大裨益。

However, their biosecurity risk depends not only on what the AI can do, but also on who uses it, their expertise and intent, their access to laboratory tools and materials, and the safeguards in place. Current evidence shows that AI uplift exists but primarily affects digital rather than physical tasks. Frontier systems have exceeded expert baselines on in-silico, and screening-evasion benchmarks, whereas controlled wet-laboratory studies find that tacit knowledge and physical execution remain substantial barriers.

然而,其生物安全风险不仅取决于人工智能的能力,还取决于使用者是谁、其专业知识与意图、对实验室工具和材料的获取权限,以及现有的防护措施。目前的证据表明,人工智能确实带来了能力提升,但主要体现在数字任务而非物理任务上。前沿系统在计算机模拟(in-silico)和规避筛查的基准测试中已超过专家水平,但在受控的湿实验室研究中,隐性知识和物理执行仍是巨大的障碍。

This review describes the different biological threats from AI tool use, from information gathering and biological design to procurement, synthesis, testing, scale-up, and potential release. We further examine why alignment techniques for general-purpose models transfer poorly to biological ones, and the emerging role of interpretability in auditing whether hazardous capabilities are genuinely removed. We argue for defense-in-depth governance that links capability thresholds to proportionate responsibilities across the biological AI ecosystem, reducing high-consequence risk while preserving beneficial use.

本综述描述了使用人工智能工具所带来的各类生物威胁,涵盖了从信息收集、生物设计到采购、合成、测试、规模化生产及潜在释放的各个环节。我们进一步探讨了为何通用模型的对齐技术难以迁移至生物模型,以及可解释性在审计危险能力是否被真正移除方面所发挥的新兴作用。我们主张建立一种纵深防御治理体系,将能力阈值与生物人工智能生态系统中的相应责任挂钩,在降低高后果风险的同时,保留其有益用途。