A new RAND report warns that AI tools in biological research create serious national security risks and says the federal government must act now to prevent a "high-consequence" biological incident. The report calls for layered security measures across the AI-biology pipeline, plus government-set standards and workforce investments.
The report, released by the research nonprofit, identifies the development of a novel pathogen released as a biological weapon as the ultimate risk scenario in AI-enabled biotechnology. It proposes layering mitigation techniques at several points along what researchers call the biological risk chain - the framework that labels parts of the field, such as genome synthesis, that are vulnerable to attack.
Layered detection and deterrence
The report recommends four types of interventions: model-layer safeguards, access and deployment controls, upstream governance, and physical chokepoint interventions. The goal is to slow malicious actors at every stage so that suspicious behavior is more likely to be detected before a threat is released.
"By layering mitigations at multiple points along this chain, it is possible to extend the time required for malicious activity, deter potential nefarious activity or intentions, increase the operational effort necessary to proceed, and raise the likelihood that suspicious behavior is detected and disrupted before release," the report says.
Optimal detection systems should be able to identify suspicious activity within nodes of any given network handling sensitive biological data. The report's authors assert that government support is central to the strategy's effectiveness.
Government standards and investment
While academic and industry entities have taken initial voluntary steps to secure access, the report notes that standardization across AI-enabled biological networks remains uneven. The authors recommend the government establish minimum requirements for access controls, user verification, and audit logging for AI models and biological tools above defined risk thresholds.
"The government should establish minimum requirements for access controls, user verification, and audit logging that are applicable to AI models and biological tools that are above defined risk thresholds, and the government should do so while providing clear guidance on what constitutes adequate credentialing and monitoring for different capability levels," the report reads.
A senior government AI official agreed with this assessment, emphasizing the importance of investing early in risk mitigation strategies. The official pointed to the recent hacking activity surrounding Anthropic's advanced Mythos model as a warning sign.
"Implementing this strategy's mitigations will require investments in new research, institutional adaptation, legal clarification and international coordination," the senior official said. "We cannot wait for a 'BioMythos' moment."
The official added that the federal workforce is not prepared for the scope of the threat. "The federal government just does not have enough experts left to handle this threat or even be able to coordinate among outside groups without significant immediate investment across multiple departments, including hiring, dedicated authorities and budget increases," they said.
The report's findings follow independent actions by AI models from Anthropic and OpenAI in contained environments, resulting in breaches and harm to external online entities. The Department of Homeland Security issued a report in 2024 documenting the threat potential of AI-enabled chemical and biological weapons, recommending federal guidance for models tailored to biological use.
Why this matters for government professionals
Federal agencies are the primary defense against AI-enabled biological threats, yet the report and officials say the current response capacity is already strained. For civil servants and contractors working on AI, cybersecurity, or biodefense policy, the report signals that additional funding, hiring, and new standards are likely - and that models with biological capabilities will face increased scrutiny. Professionals in these roles should watch for upcoming federal guidance on access controls and monitoring requirements, as those rules will shape how AI-biology tools are deployed across agencies.
Your membership also unlocks: