A major new RAND Corporation report is warning that artificial intelligence has made it significantly easier for bad actors to design and deploy biological weapons, and that the systems needed to stop them are, to put it charitably, not ready. The report outlines nine specific mitigation strategies targeting everyone from rogue nation-states to lone-wolf researchers with a laptop and a grudge. The good news is that the problem is supposedly manageable. The bad news is that we are very much not managing it.
What the RAND Report Actually Says
According to Axios, the RAND report published this week identifies AI-enabled bioweapons as a "potentially catastrophic yet manageable risk" — which is the kind of phrasing that sounds reassuring right up until you think about it for two seconds. Catastrophic. But manageable. Like a grease fire in a hospital.
The report lays out nine mitigation strategies aimed at a broad range of actors: governments, the scientific research community, the public health sector, and the major tech companies whose AI tools could, in the wrong hands, serve as something close to a bioweapon design assistant. That's a lot of coordination required between a lot of institutions that are historically very bad at coordinating with each other.
The authors are clear that this isn't a fringe concern or a thought experiment. AI systems are already sophisticated enough to meaningfully lower the technical barriers to engineering dangerous pathogens. You no longer need a Ph.D. in virology and a state-sponsored lab. You might just need access to the right model and enough time.
The Gap Between 'Manageable' and 'Managed'
Here is where the report gets uncomfortable. There is already, as Axios notes, "considerable debate" about government oversight and safeguards around AI broadly. That debate has produced a whole lot of think pieces, a handful of executive orders, some congressional hearings where elderly legislators asked tech CEOs to explain what a website is, and not a lot else.
Meanwhile, the specific biosecurity dimension of AI risk has received even less serious institutional attention than general AI safety, which was already getting less attention than it deserved. The research community has raised alarms. The public health sector has raised alarms. The alarms are being raised. The question is whether anyone with actual authority to act is in the building.
The Trump administration, for context, spent much of 2025 systematically dismantling the federal agencies and oversight bodies that would be most relevant to exactly this kind of threat. The CDC lost significant funding. USAID was guttered. The National Security Council's pandemic preparedness directorate, which was rebuilt after COVID, has been treated as an afterthought. We are, in other words, running in the wrong direction.
Who Is Supposed to Stop This, Exactly?
The RAND report is smart to spread the responsibility across multiple actors, because no single institution is going to solve this alone. But that same breadth is also how these things die in committee. When everyone is responsible, no one is responsible. Ask anyone who has ever tried to plan a group dinner.
The tech companies are a particular pressure point. The major AI developers, to their credit, have implemented some guardrails around the most obviously dangerous requests, biosecurity-related prompts among them. But those guardrails are imperfect, frequently bypassed by determined users with some creative prompt engineering, and entirely voluntary. There is no binding regulatory framework in the United States requiring AI companies to maintain biosecurity safeguards. There just isn't.
The scientific community, meanwhile, has been wrestling with dual-use research concerns for decades, long before AI entered the picture. Gain-of-function research debates, publication restrictions on dangerous findings, lab safety protocols — none of it is new. What is new is the speed and accessibility that AI introduces, which makes every existing gap in oversight suddenly much more consequential.
Why This Isn't Getting the Attention It Deserves
Part of the problem is that bioweapons are one of those threats that feels abstract until it isn't. COVID-19 killed over a million Americans and reshaped global society, and within two years large portions of the public had decided the whole thing was overblown. Our collective ability to maintain focus on slow-building catastrophic risks is, to put it generously, limited.
AI risk has suffered from a similar attention problem, except it moves faster and the window for getting the governance right is narrower. The RAND report is trying to draw a clear line between the theoretical danger and the concrete, specific policy interventions that could actually reduce it. That's the right instinct. Nine mitigation strategies is a real roadmap, not a vague call for "more research."
But a roadmap only works if someone is willing to drive. Right now, the people who should be behind the wheel are either asleep, actively hostile to the concept of federal oversight, or busy explaining to Congress why the Department of Education needed to be abolished.
The Dingo Take
You are supposed to read a report like this and feel reassured that smart people are thinking seriously about the problem. And they are. The RAND Corporation employs genuinely brilliant researchers, and a nine-point mitigation framework is more than most institutions have produced on this specific threat. Credit where it's due.
But here's the part that should keep you up at night: the infrastructure required to implement any of those nine strategies has been under deliberate assault for the past two years. Voluntary industry guardrails, hollowed-out public health agencies, a federal government philosophically opposed to regulating the tech sector, and an international coordination framework that looks increasingly rickety. RAND can write the manual. Nobody is required to read it.
AI-enabled bioweapons are not science fiction. They are a foreseeable, near-term risk that experts with serious credentials are sounding alarms about in formal published research. The response from the people running the country has been, essentially, a shrug followed by another round of deregulation. History has a way of being very unkind to that kind of shrug.


Comments