With the world focused on the risks of artificial intelligence, I can’t help but think of the profound vulnerability the United States faced 25 years ago. In 2001, against the backdrop of the 11 September terrorist attacks, the nation experienced its first bioterrorist attack in decades — anthrax (Bacillus anthracis) spores sent as a white
With the world focused on the risks of artificial intelligence, I can’t help but think of the profound vulnerability the United States faced 25 years ago. In 2001, against the backdrop of the 11 September terrorist attacks, the nation experienced its first bioterrorist attack in decades — anthrax (Bacillus anthracis) spores sent as a white powder to media outlets in Florida and New York, as well as to the offices of public officials in Washington DC.

AI can design viruses, toxins and other bioweapons. How worried should we be?
It quickly became clear that the 22 cases of pulmonary anthrax identified — which led to 5 deaths — were not naturally occurring but a result of a nefarious actor1. The FBI found that the spores might have originated in a US Army laboratory, although the perpetrator was never convicted. The main suspect, microbiologist Bruce Ivins, died before charges were brought.
Amid a chaotic storm of panic, poor communication, clunky coordination across government agencies and public clamouring for preventive medicines, the attacks, code-named Amerithrax, exposed a disconnect between years spent preparing for bioterrorism and what happens when reality strikes.
And I know that the country is no better prepared today. Worse, attention paid to one threat is coming at the expense of others. Policymakers, researchers and the public are distracting themselves from the most pressing risks by focusing on overhyped biohazards, such as those designed by AI, when all these risks deserve attention.
Here, I outline what the priorities should be: stronger and agile safeguards on biomaterials and equipment, along with sustained and coordinated governance.
Biosafety risks are growing
Access to powerful analytical equipment has become more widespread and cheaper since 2001. Benchtop DNA synthesizers enable researchers to produce stretches of DNA and RNA in their own labs rather than ordering them from commercial providers. Fully automated, remotely controlled wet labs (cloud labs) have streamlined the process for bringing bio-based products to market2.
Such technologies increase opportunities for breakthroughs and strengthen the bioeconomy. But they also make it harder to track misuse in private labs, which could bypass the requirements set for federally funded research and the biosecurity checks that commercial providers of gene sequences use. These include verifying the customer’s identity and the type of sequence being ordered.
AI amplifies those concerns, because it can reduce the amount of tacit knowledge that is required to make bioweapons and help to generate ideas for ways to thwart defensive measures against them. Fears include the loss of control of AI systems, leading to unintended consequences and potentially the bypassing of restrictions; malicious actors using AI models to design new or enhanced pathogens; and that such tools could expand the pool of people who pose a threat.

Studying pathogens such as the virus that causes COVID-19 must be done in secure biosafety labs.Credit: Michele Ursi/Getty
Many people see such concerns as stemming from the accelerating advancement of technology and the sluggish process of governance. But, in practice, biology is messy and being aware of the risks means that we can get ahead of them. As biologist Barbara Del Castello at the research organization RAND in Santa Monica, California, told me: “An AI agent can optimize a sequence on a screen in seconds, but converting that digital design into a viable, functional biological product still requires navigating steep physical and operational bottlenecks.”
The solution is to build effective government regulation, stronger monitoring processes and robust safeguards. It is crucial to recognize that voluntary industry action alone cannot substitute for independent oversight, and that AI tools and their guardrails must be built in ways that preserve the capacity for their use in legitimate research.
But even without AI, it has long proved hard to regulate biological risks. Researchers are still struggling to ensure oversight and pragmatic governance of risky dual-use research, such as work with enhanced pathogens of pandemic potential.
US biologists face frequent regulatory whiplash. In 2025, the administration of President Donald Trump ordered federally funded agencies to pause or review research involving what it terms dangerous gain-of-function studies on pathogens of pandemic potential.
In July, those instructions were replaced with rules that have created confusion . Seven types of study defined as dangerous gain-of-function and previously under review are now banned outright. Researchers are being called on to evaluate the risks of work on any pathogens that might ‘significantly endanger’ people, not just those with pandemic potential.

AI could pose pandemic-scale biosecurity risks. Here’s how to make it safer
Concerns over the proliferation and management of secure high-containment labs for biological research around the world have also increased in response to biothreats. In addition to anthrax, these include outbreaks of Ebola and the H5N1 virus that causes bird flu. A 2023 analysis found that the number of the most secure Biosafety Level 4 labs had doubled since 2001, to 51 across 27 countries (see www.globalbiolabs.org).
Although there is much (if imperfect) oversight of government-funded research, a worrying gap exists for private labs, the numbers of which are unknown. In 2022 and 2026, authorities stumbled across unregulated biological lab spaces in Nevada and California, where they found biological samples and pathogens.
Responding to biological threats also requires the capacity to investigate indicators of an intentional outbreak and determine the origin of the material — a process known as bioattribution. Pathogen early-warning systems have been strengthened since 2001 (through programmes such as the US National Biosurveillance Integration Center and the expansion of the Department of Defense’s Global Emerging Infections Surveillance programme). Yet, the investigative process is complex, fragmented and dependent on consensus.
Despite advancements in bioinformatics and forensic genetics, genetic engineering makes it possible to manipulate existing pathogens so that they can evade detection methods and to design pathogens that mimic key signatures of naturally occurring ones. And geopolitical tensions, dis- or misinformation and politicization of scientific findings also make achieving the technical rigour and cooperation needed for investigations more complex. For example, such factors obfuscated investigations into the origin of the SARS-CoV-2 virus.
Indeed, the COVID-19 pandemic exposed many of the same problems seen with the US anthrax attacks, even when the threat was natural and not engineered. These include biosurveillance shortfalls and poor management of public fear and communication, as well as the fragility of supply chains and the workforce.

Africa’s response to this Ebola outbreak shows how to shape global health
I see a common thread in these two events and conversations about emerging risks: a cycle of panic and neglect in which governments flood the system with funding when an outbreak occurs, but do not address systemic issues in biopreparedness and resilience3.
Another issue is that categories of risk are not equally weighted in the public conversation. AI-driven biorisk draws oversized attention, while the unglamorous, foundational vulnerabilities that COVID-19 and the anthrax attacks exposed mainly remain unaddressed. This imbalance affects what happens in the future.
Fragmentation impedes resilience
The US government invested billions of dollars in biodefence after 2001, creating research programmes and centres such as the National Biodefense Analysis and Countermeasures Center. It has made great strides in bioweapon deterrence and has supported crucial work in biosurveillance, the development of medical countermeasures and pandemic prevention4.
Keep following us for the latest insights.

















