The Next Fifteen Years

A forecast built from first principles
Section future / 03-domains / contested / biosecurity.md

Biosecurity - the asymmetry that does not resolve#


Contents

Biology is the one domain in this document where the offense–defense balance does not plausibly recover, and the reason is structural rather than technical.

Attack and defense operate on different clocks. Designing a pathogen is increasingly a computational problem. Developing, trialling, manufacturing, and distributing a countermeasure is a physical, regulatory, and logistical problem measured in months to years. AI compresses the first term far more than the second, because the first has cheap computational ground truth and the second is gated on biology, factories, and institutions. → Medicine, Drug discovery

That gap is the whole concern, and it widens rather than narrows as the technology improves.

Where the actual barrier sits#

The barrier to biological harm has never been primarily informational. It is tacit knowledge, materials access, and laboratory skill - the things that do not transfer through text and that are why the historical record of attempted bioterrorism is a record of failure.

AI erodes the first of those meaningfully. A model that can troubleshoot a failing protocol, explain why a step didn't work, and suggest the fix is substituting for the mentorship that tacit knowledge normally requires. That is the apprenticeship channel running in the wrong direction: the same mechanism that might rescue novice professionals also lowers the skill floor for harm.

It does not erode materials access or the physical requirement for a competent laboratory. Those remain real, and they remain the best available control point.

The chain, step by step#

StepAI effectBest control
Ideation / motivationLowers search cost; not the historical barrierCulture, law (weak)
DesignCompresses computational designEval and access policy (leaky)
Protocol / troubleshootingLargest AI effect - substitutes for mentorshipLab practice norms; hard to regulate
Acquisition of materialsLittle direct effectSynthesis screening, select-agent rules
Synthesis / productionIndirect via protocol helpScreening + physical security
Delivery / disseminationSeparate logistics problemPublic health + security

Two consequences:

Why biology is not cybersecurity#

The two pages in this group look parallel and are not, and the difference is the master asymmetry pointing the other way.

An exploit verifies itself; a pathogen does not. Cybersecurity argues that offensive capability improves at the maximum rate because the feedback is free, immediate, and unambiguous. Biology has no such loop for the attacker. Confirming that a designed construct does what the model predicted requires the wet lab, the materials, the time, and the willingness to be caught doing it - which is to say the offensive learning loop is gated on exactly the physical barrier that AI does not lower. That is the strongest available reason to expect biological offense to improve more slowly than the alarming version of this argument implies, and it follows from the same principle the document uses everywhere else rather than from optimism.

Two things spoil the reassurance. First, the loop does not have to be run by the attacker: published literature, automated cloud laboratories, and legitimate research all generate exactly the validation data that the expensive step would otherwise require, which is the sense in which Science is dual-use at the level of infrastructure rather than at the level of any individual result. Second, and more importantly, the consequence structure is not symmetric with the learning rate. A cyber campaign that fails teaches the attacker and costs the defender a patch cycle; the failure distribution in biology has a tail that no amount of slow learning makes acceptable. Slower offensive improvement is a reason to expect fewer attempts to succeed, not a reason to price the risk lower, because the expectation is dominated by the tail rather than the frequency.

The practical implication is that the control point follows the verification structure. Where the attacker's binding step is physical validation, controls on materials, synthesis, and automated laboratory access do real work, and controls on information do proportionally less. That is the same conclusion the chain table reaches, arrived at independently, which is the main reason to hold it with some confidence.

Why this is the least-discussed serious risk#

Compared to the attention allocated to loss-of-control scenarios, biological risk gets a fraction of the discussion, and the ordering is difficult to defend on the numbers. It sits closer in time, has a well-understood mechanism, has historical precedent for how bad pandemics get, and - unlike most of Part V's tail - has known, cheap, partial mitigations available today.

The likely explanation for the neglect is information hazard: the topic is genuinely hard to discuss publicly without contributing to the problem, so serious analysis happens in closed settings and public discourse defaults to the risks that can be safely elaborated. That is a rational response to a real constraint, and it produces a systematically distorted public risk picture.

a serious AI-attributable biological incident - a near-miss, a screening failure, or a non-state actor progressing further than they otherwise would have - is more likely by 2032 than loss-of-control scenarios, and less likely than a financial or cyber incident. It is the middle probability band of Part V row 3 mechanisms, and the one with the worst tail if it scales.

The defensive side is real and worth stating#

The same capabilities that create the concern are the strongest tools available against it, and the asymmetry is not total:

The gap is not in design; it is in the physical and regulatory pipeline. That is where the defensive investment should go, and it is the least glamorous part.

The regulatory half of that gap has a specific and available fix that is worth stating because it is the only mechanism that compresses the slow term without lowering safety standards. Approve the platform rather than the product. A manufacturing process and a delivery technology can be validated once and then reused for a novel sequence, which is roughly what happened under emergency conditions in 2020 and is what the standing regime does not permit outside them. The design-to-authorization timeline is dominated by process validation rather than by molecule discovery, so a platform-level authorization pathway converts the asymmetry from structural into merely difficult - the same conclusion the surge-manufacturing item below reaches from the industrial side. → Drug discovery, State capacity

Failure mode: platform authorization concentrates risk in the platform. A regime that has approved one process and then runs every countermeasure through it has a correlated failure surface of exactly the kind Uncertainty 6 describes, and the political survivability of that regime after a single bad batch is doubtful. The honest version is that the speed gain is bought with concentration risk, and it is probably still worth buying.

Interaction with Game 2 and state capacity#

A bio near-miss is a candidate Game 2 forcing event - less likely than cyber/finance, worse if it opens the window under panic. The architecture written then skews toward access controls and lab rules, not compute treaties.

State capacity binds hard: screening enforcement, stockpile logistics, and trial authorization are administrative. A high-capacity state can run surveillance and manufacturing surge; a low-capacity one imports rules and fails to staff them. International coordination faces the same verification problems as AI generally - plus dual-use research politics.

What would change this assessment#

What to watch (non-hazardous)#

SignalReading
Share of synthesis providers with robust screeningControl point health
Time from novel pathogen detection to sequenced alertSurveillance defense
Countermeasure design-to-IND timelinesDefensive design half
Public funding for surge manufacturingWhether the slow term is resourced
Lab-accident and near-miss disclosure regimesLearning rate on physical risk

Asymmetric clocks are the whole page#

Offense can improve on design and troubleshooting timescales; defense must still clear surveillance, manufacturing surge, trial authorization, and distribution - institutional clocks. That is why "AI helps both sides equally" is the wrong framing even when both sides use models. A year of faster design without a year of faster surge manufacturing is a worse net for defense if it widens the gap at the design step while the slow steps stay fixed. Score the chain by its slowest necessary defensive step, not by design-tool demos. → state capacity

Screening coverage at synthesis providers is the quiet control point. It is measurable, commercial, and does not require solving design-tool dual-use. Prefer share-of-orders-screened over model capability debates when scoring near-term defense.


Related: Cybersecurity · Medicine · Science · Game 2 · Game 4 · Part V · State capacity

View markdown source

select · Enter open · Esc close