Safety

AI-generated text

RAND proposes nine measures to reduce risks of AI-enabled biological weapons

A new RAND report recommends nine mitigation strategies to reduce the risk that AI could be used to design and deploy biological weapons, calling for coordinated action by governments, the scientific and public-health communities, and tech companies.

RAND proposes nine measures to reduce risks of AI-enabled biological weapons

A new RAND report argues that AI-enabled bioweapons represent a potentially catastrophic but manageable risk if governments, the scientific community, public health systems and leading technology companies put appropriate safeguards in place.

What the proposal covers

The report lays out nine mitigation strategies aimed at a variety of actors who could use AI to design and deploy a biological weapon. Collectively, the measures focus on controlling access to sensitive information, disrupting access to materials needed to create a weapon, proactively detecting signs of misuse, and establishing deterrents to prevent malicious activity.

Why this matters now

RAND’s team warns that rapid advances in AI expand the set of actors who could conceivably produce a bioweapon—from lone individuals to state-backed groups. At the same time, the authors note that most of the most dangerous thresholds have not yet been crossed. Steph Guerra, the lead author of the RAND report, told the authors that the nature of the threat requires a “layered system of mutually reinforcing approaches.”

Which tools and data need protection

The report emphasizes that many tools and biological datasets driving progress in drug development and biotech are already proprietary and access-restricted. Greater concern centers on open-source biological tools and datasets coming from academia and research institutes, which are freely available. Guerra observed that biology’s current openness serves discovery and saving lives rather than warfare, but that openness also creates vulnerabilities.

Balancing restrictions with scientific progress

RAND acknowledges that restricting public access could slow scientific progress. Guerra suggested a dual approach: build large "moonshot" projects and biodata factories to generate the data needed to cure diseases, while implementing tiered access systems so that the most misuse-relevant datasets are accessible only to legitimate, vetted researchers.

AI agents and democratization of capability

The team also examined how AI agents could make biological development more widely accessible, lowering the expertise barrier required to create bioweapons. Illustrating the dual-use nature of recent advances, Anthropic announced this week that its Claude model successfully designed protein binders against 14 targets—an important step in drug development. In a blog post, Anthropic acknowledged both the promise and the danger of these capabilities and noted that protein design and other research biology functions are not available for general access in their most capable model.

How the nine measures aim to prevent attacks

According to the report, the combined effect of the nine measures would be to prevent a large-scale AI-enabled biological attack by:

  • managing access to information that could be dangerous in the wrong hands;
  • disrupting acquisition of materials needed to build a weapon;
  • proactively detecting misuse indicators;
  • creating deterrence that discourages bad actors from attempting such work.

The authors stress that stronger government oversight, broader cross-industry cooperation and measures within the public health and research sectors are all necessary for effective mitigation. The report also reframes public-health preparedness not only as outbreak response but as a form of deterrence.

Conclusion

RAND’s assessment treats the intersection of AI and biology realistically: technological progress increases opportunities for misuse, but the most dangerous thresholds have yet to be reached. The authors argue that implementing nine complementary measures and fostering coordinated action across public and private sectors offers the best chance to prevent potentially catastrophic AI-enabled biological attacks.