AI Risk Atlas Prototype/DemoUnofficial independent experiment. Not an official xAI product. Scores can be wrong.

Back to register
19automated residualNeeds reviewAbove working threshold (12)

Biosecurity enablement by foundation models

Owner · Frontier labs, synthesis providers, public-health agencies

CapabilityDomain knowledgeImpact domainBoth

Statement (NASA form)

Given that peer-reviewed work claims models can author viral genomes, not merely analyse them, while some frontier labs have dissolved dedicated preparedness staff, there is a possibility of a capable actor using a general model to design, order, or troubleshoot a biological threat resulting in a high-consequence biological event whose know-how no longer required a national laboratory.

Condition
peer-reviewed work claims models can author viral genomes, not merely analyse them, while some frontier labs have dissolved dedicated preparedness staff
Departure
a capable actor using a general model to design, order, or troubleshoot a biological threat
Impact
a high-consequence biological event whose know-how no longer required a national laboratory

VC + institute corroboration

Experimental share of compiled public capital that names this risk. Not a certified residual.

$12Mexperimental share · $0k private / $12M institute · thin corroboration
  • UK AISI · ~$12M of published budget mapped here

4 public sources · OECD AIM · Anthropic RSP v3 · Anthropic Risk Report

Worst scenario
3×5
Probable × Catastrophic
Urgency
4
Expedite · This month
Inherent composite
19
Worst 15 + urgency
Residual composite
19
Need ≤ 12

The dangerous step is no longer ‘can a model talk about virology’. It is whether the model closes the gap between a curious outsider and a working protocol. Combined with mail-order synthesis and the thinning of lab safety teams, this is the register’s highest-consequence cluster.

Pathway fragment

Simple upstream → via → downstream notes. Not a causal graph. Experimental.

Upstream
  • Biological design models
  • Public methods literature
  • Commercial synthesis
Via
  • Screen-evading construct
  • Order fulfilled
Downstream
  • Novel pathogen or toxin
  • Public-health emergency

Assumptions · Assumes screening is string-based in much of the market. Functional-shape screening is incomplete.

Human calibration

Override is stored on this desk only. It does not make the score official.

Failure scenarios

Each scenario has its own likelihood and consequence. The risk takes the most severe cell. Residual applies implemented mitigations to every scenario, then re-ranks.

Model coaches a semi-skilled actor

3Probable5Catastrophic15

A motivated outsider uses a chat model to debug wet-lab steps that would otherwise have failed.

Model proposes an evading construct

2Remote5Catastrophic10

Generated sequence slips past provider screens and is synthesised commercially.

Open-weight leak of a specialised bio model

3Probable4Critical12

A fine-tune that is merely ‘helpful’ on virology is mirrored and cannot be recalled.

Examples

AI-authored viral genomes

A peer-reviewed claim that systems can write viral genomes, not just annotate existing ones, moved this from science fiction to a methods paper.

Preparedness staff reassigned

Reporting that OpenAI dissolved its Preparedness team and scattered biosecurity work is a control failure sitting next to a capability rise.

Synthesis screening gaps

Not every DNA provider screens customer orders against model-generated sequences designed to evade known signatures.

Contributing signals

X posts on the desk that evidence this risk. A signal can contribute to more than one risk.

Mitigations

Residual assumes only items marked in place. Highlighted rows are the remaining work needed to reach a composite of 12.

In progressOn the pathSynthesis industry and states

Mandatory, model-aware synthesis screening

Providers screen against both known pathogens and model-generated obfuscations. No screen, no ship.

Synthesis industry and states · expedited 2 months · normal 6 months · −1 L · −1 C · −0 U