
AI cannot yet design a pandemic virus from scratch, but top security bodies say it already lowers the bar enough to demand action.
Story Snapshot
- National Academies: monitor AI tools that could one day design or boost infectious agents.
- International review: general-purpose AI can guide steps relevant to biological weapons today.
- RAND: no single safeguard works; use layered defenses across the pipeline.
- Counterpoint: experts say present systems cannot make a novel, human-pandemic virus.
What top reviews agree AI can and cannot do today
The National Academies drew a clear line in 2025: current AI tools cannot de novo design and build a transmissible pandemic-capable virus, and no tool can design a brand-new virus end-to-end. That sets the floor for the debate. The same review still flags capability uplift to watch. It singles out models that predict transmissibility and pathogenesis, enable design of fully replicating infectious agents, and tighten the loop with automated labs. The message is not “panic,” but “track, test, and gate-keep.”
The International AI Safety Report from 2026 sharpens the near-term risk. It finds that general-purpose systems can already provide step-by-step help relevant to biological and chemical weapon work, including troubleshooting and ways to bypass obstacles. It also highlights biological foundation models that can generate designs for novel pathogens, citing a genome-scale design demo in bacteriophages, which infect bacteria, not humans. That shows direction of travel, not proof of a human pandemic shortcut.
The conservative read: real risk signals, sober limits, practical guardrails
American conservative values prize prudence, boundaries, and accountability. These reports back that stance. They do not hype science fiction. They call for monitoring tools that could push pathogen design from hard to doable if left unchecked. The Center for a New American Security urges screening of foundation models, cloud labs, and gene synthesis providers so bad actors hit a wall early. That approach respects innovation while setting firm lines where misuse risk rises.
RAND adds a key point: no silver bullet exists. A defense-in-depth plan is needed, with nine interventions across data, models, lab services, and supply chains. That mirrors how we secure banks and airports. Spread out the checks. Make every step harder to abuse. The goal is not to stop biology or AI. The goal is to make the wrong kind of help slower, riskier, and easier to catch before damage spreads.
Where the debate pushes back, and why it still supports prevention
Counter-arguments land on present capability. The National Academies states the risk today is likely local, not pandemic-scale, and says AI cannot yet design a novel virus. The Atlantic quotes Kevin Esvelt calling an AI-driven pandemic “quite low,” and Gigi Gronvall noting AI has no way to build and test new pathogens by itself. These points are strong. They argue the sky is not falling. They do not argue for a hands-off policy.
Policy bodies still point to rising help that lowers barriers for the wrong people. The gap between “gives instructions” and “triggers a pandemic” remains. But law enforcement does not wait for a bank robbery manual to become a money printer. The sane move is to fix blind spots now: audit model capabilities, log and screen synthesis orders, require identity checks for cloud labs, and stress-test safety policies against realistic red-team tasks.
What to watch next: proof points that change the stakes
Three signals would shift this conversation fast. First, rigorous, blinded tests showing models can predict transmissibility or virulence from sequence with useful accuracy and not just guesswork. Second, disclosed screening logs from gene synthesis firms and cloud labs that show real blocks of suspicious, possibly AI-assisted requests. Third, vetted red-team trials that measure how much model help speeds risky design or troubleshooting in controlled settings, with results reported in sanitized form.
Same pattern as pandemic response. Warnings existed early. What was missing was a rehearsed response, practiced before the deadline to act arrived. Healthcare and finance run drills for exactly this reason. AI risk still has no equivalent tested playbook.
— Anand Sharma (@AnandNSharma) September 11, 2026
Until then, the prudent course is layered friction with clear thresholds for escalation. Keep the benefits of AI in drug design and surveillance. Bolt doors where misuse risk climbs. Require model developers to test, document, and govern biological outputs before release. Demand paper trails for access to synthesis, automation, and scarce reagents. This is not fear; it is common sense backed by the very experts who reject hype and still tell us where the edge is sharpest.
Sources:
theatlantic.com, nature.com, rand.org, internationalaisafetyreport.org, frontiersin.org, nationalacademies.org, s3.us-east-1.amazonaws.com
© whatnewsdaily.com 2026. All rights reserved.













