Model coaches a semi-skilled actor
A motivated outsider uses a chat model to debug wet-lab steps that would otherwise have failed.
AI Risk Atlas Prototype/Demo — Unofficial independent experiment. Not an official xAI product. Scores can be wrong.
Owner · Frontier labs, synthesis providers, public-health agencies
Statement (NASA form)
Given that peer-reviewed work claims models can author viral genomes, not merely analyse them, while some frontier labs have dissolved dedicated preparedness staff, there is a possibility of a capable actor using a general model to design, order, or troubleshoot a biological threat resulting in a high-consequence biological event whose know-how no longer required a national laboratory.
- Condition
- peer-reviewed work claims models can author viral genomes, not merely analyse them, while some frontier labs have dissolved dedicated preparedness staff
- Departure
- a capable actor using a general model to design, order, or troubleshoot a biological threat
- Impact
- a high-consequence biological event whose know-how no longer required a national laboratory
Experimental share of compiled public capital that names this risk. Not a certified residual.
4 public sources · OECD AIM · Anthropic RSP v3 · Anthropic Risk Report
The dangerous step is no longer ‘can a model talk about virology’. It is whether the model closes the gap between a curious outsider and a working protocol. Combined with mail-order synthesis and the thinning of lab safety teams, this is the register’s highest-consequence cluster.
Simple upstream → via → downstream notes. Not a causal graph. Experimental.
Assumptions · Assumes screening is string-based in much of the market. Functional-shape screening is incomplete.
Override is stored on this desk only. It does not make the score official.
Each scenario has its own likelihood and consequence. The risk takes the most severe cell. Residual applies implemented mitigations to every scenario, then re-ranks.
A motivated outsider uses a chat model to debug wet-lab steps that would otherwise have failed.
Generated sequence slips past provider screens and is synthesised commercially.
A fine-tune that is merely ‘helpful’ on virology is mirrored and cannot be recalled.
A peer-reviewed claim that systems can write viral genomes, not just annotate existing ones, moved this from science fiction to a methods paper.
Reporting that OpenAI dissolved its Preparedness team and scattered biosecurity work is a control failure sitting next to a capability rise.
Not every DNA provider screens customer orders against model-generated sequences designed to evade known signatures.
X posts on the desk that evidence this risk. A signal can contribute to more than one risk.
Peer-reviewed claim that AI can author viral genomes.
Preparedness team dissolved as biosecurity work was reassigned.
Aug 2026 lab report: models as operational bio force-multipliers.
Novel-bio still expert-gated; conventional bio lowers amateur barriers.
Residual assumes only items marked in place. Highlighted rows are the remaining work needed to reach a composite of 12.
Providers screen against both known pathogens and model-generated obfuscations. No screen, no ship.
Synthesis industry and states · expedited 2 months · normal 6 months · −1 L · −1 C · −0 U
A team that can delay a release. Not a side-of-desk responsibility for a product manager.
Frontier lab boards · expedited 3 weeks · normal 3 months · −0 L · −0 C · −1 U
Friction, identity, and human review when a session crosses a capability threshold.
Labs and cloud hosts · expedited 4 weeks · normal 4 months · −1 L · −0 C · −1 U