Somewhere right now, an AI model is helping design biological experiments, and the people responsible for making sure that doesn't end civilization are still figuring out the rules. According to Axios, this week's wave of urgent warnings about unchecked AI has forced a reckoning with a specific and terrifying reality: these systems are already being used in dangerous bioscience research, and the guardrails are essentially nonexistent. AI-enabled bioweapons are not a hypothetical. They are the scenario.
The Scenario Everyone Was Hoping to Avoid Is Already Here
Let's get something straight before we talk about anything else. The doomsday framing around AI and bioweapons is not science fiction written by nervous academics with too much grant money. Axios reports that researchers have specifically identified AI-designed viruses as one of the worst-case catastrophic risks on the table, the kind of outcome measured not in economic damage or political disruption but in mass casualties and potential civilizational collapse.
The thing that makes this particularly hard to sit with is the timeline. This isn't a warning about what could happen in twenty years if we don't act now. This is a warning about what is happening, in labs, with tools that are already widely accessible, while the policy infrastructure needed to manage it is still a rough draft on someone's desk in Washington.
And on the specific date that Axios published this piece, September 11, the symbolism is not subtle. The country has spent twenty-five years and trillions of dollars hardening itself against the last catastrophic attack. The question now is whether anyone in power is paying attention to the next one before it arrives.
The Core Problem: Nobody Knows What These Systems Will Do
Here is the part that should keep you awake. Axios flags a fundamental technical problem sitting underneath all of the policy arguments: there is no reliable way to predict how some AI systems will behave. You cannot write a law around a system you cannot fully audit. You cannot build a guardrail you cannot attach to anything.
This is not a gap in the regulations. This is a gap in the science. Researchers studying AI safety have been raising this issue for years, and the response from the industry has been, broadly speaking, to keep shipping products and promise that alignment research will catch up eventually. It has not caught up. The models got bigger and faster and the interpretability tools did not keep pace.
Apply that uncertainty to biological research and the math gets genuinely ugly. A pharmaceutical researcher using AI to accelerate drug discovery and a bad actor using AI to optimize a pathogen for transmission are working with variations of the same underlying technology. The difference between those two outcomes is not a technical barrier. It is intent, and AI cannot read intent.
What Guardrails Actually Exist Right Now
The honest answer is: not many, and not consistent ones. The major AI labs have implemented some biosecurity filters on their frontier models, with restrictions intended to prevent the systems from providing detailed technical assistance with weapons development. OpenAI, Anthropic, and Google DeepMind have all published usage policies that prohibit using their tools to create biological weapons.
But policies are not the same as enforcement, and enforcement is not the same as prevention. Independent researchers have repeatedly demonstrated that safety filters can be bypassed with creative prompting, and the red-teaming efforts at even the most safety-conscious labs are racing against a much larger and less coordinated global population of people actively trying to find the holes. The labs that are most worried about this are not the ones setting the pace of development.
The regulatory picture at the federal level is, to use a clinical term, a mess. The executive orders and guidance documents issued over the past few years created some frameworks for AI oversight generally, but biosecurity-specific rules for AI-assisted research remain thin. The agencies with jurisdiction over biological research and the agencies with jurisdiction over AI do not have a unified approach. They barely have a shared vocabulary.
Why the Warnings This Week Hit Different
Axios frames its reporting around a fresh wave of dire warnings from the AI research community that pushed bioweapons risk back into the conversation. That framing matters because we have been through several cycles of alarm at this point, and there is a real risk of the public treating each new warning as more noise from the same anxious crowd.
This time, the context is different in a few specific ways. The capability of the models has jumped substantially. Tasks that required significant domain expertise two years ago can now be partially scaffolded by AI tools that are cheap, fast, and globally accessible. The barrier to entry for dangerous biological experimentation has not disappeared, but it has lowered, and it is lowering further with each major model release.
The people sounding the alarm are also increasingly not just AI safety researchers. Biosecurity experts, former government officials with actual classified context, and public health researchers who spent the pandemic years watching institutional failure in slow motion are all saying a version of the same thing: the window to build the right systems is open, and it will not stay open indefinitely.
Who Is Actually Responsible for Fixing This
Congress, in theory. The executive branch, in practice. International bodies, in aspiration. None of them, in reality.
The United States has not passed comprehensive AI legislation. The current administration has shown little interest in imposing restrictions on an industry it views primarily as a source of economic and geopolitical competitive advantage. The argument that safety regulations will slow American AI development relative to China is doing a lot of work in those conversations, and it is an argument that tends to win in rooms full of people whose primary concern is the competition, not the catastrophe.
At the international level, there have been discussions, conferences, and non-binding agreements. The Bletchley Declaration from 2023 got a lot of attention and produced limited concrete action. The fundamental problem is that any international agreement on AI and biosecurity requires buy-in from every major player, and the incentive structure for the countries most capable of causing harm is not aligned with the incentive structure for the countries most motivated to prevent it.
The Dingo Take
You are supposed to believe that the people in charge of managing this are on top of it. They are not. The institutions that failed to prepare for a naturally occurring pandemic, that watched the biosecurity infrastructure built after 9/11 slowly defund itself, that cannot agree on a basic framework for AI governance after years of trying, are now the institutions standing between the current state of AI-assisted biological research and whatever comes next. That is the actual situation.
The AI industry's response to biosecurity concerns has followed a familiar pattern. Acknowledge the risk, point to internal safety teams, publish a policy document, and keep building. The safety teams are real and some of the people in them are genuinely brilliant and deeply worried. They are also not in charge. The people in charge are thinking about product timelines and market share and what the competitors are shipping. The incentives are not pointed at caution.
What makes the bioweapons scenario specifically maddening is that it does not require a nation-state, a massive budget, or decades of specialized expertise to become catastrophic. The democratization of AI capability is mostly a good thing. In this particular application it is a nightmare. There is no version of this that gets better if the policy response stays as slow and fragmented as it has been. The warnings are getting louder because the gap between what these tools can do and what the oversight systems can handle is getting wider, not smaller. At some point the warnings stop and something else happens instead.

Comments