AI Is Entering Biology’s Danger Zone

Artificial intelligence has already learned to write essays, generate videos, build software, and occasionally turn simple questions into dramatic philosophical monologues. Now, it is moving deeper into biology a field where the stakes involve more than awkward chatbot answers.
On July 16, Google DeepMind and Isomorphic Labs unveiled a broader strategy for using AI to strengthen global defenses against biological threats. The companies call it a bioresilience program.
The idea sounds straightforward: use powerful AI systems to prevent biological attacks, spot outbreaks earlier, and develop vaccines or treatments faster.
The tricky part? The same models that help scientists understand viruses, proteins, and genetic sequences could also lower the technical barriers facing someone with harmful intentions.
That creates an uncomfortable paradox. Humanity may need increasingly capable biological AI to defend itself against dangers partly intensified by increasingly capable biological AI.
DeepMind and Isomorphic Labs are not pretending that contradiction has vanished. Instead, they are organizing their work around three commands: prevent, detect, and respond.
Simple words. Monumental homework.
A Program Built Around a Dual Mandate
DeepMind describes its strategy as a dual mandate.
First, it wants to stop threat actors from misusing models such as Gemini. Second, it wants qualified scientists, governments, and biosecurity experts to use those same systems for legitimate research and outbreak preparedness.
Over the past year, the companies say they have advanced more than 15 partnerships with government bodies, research institutions, and biosecurity organizations. Named collaborators include Lawrence Livermore National Laboratory, the UK AI Security Institute, the Coalition for Epidemic Preparedness Innovations, and the Francis Crick Institute.
The partnerships cover different parts of the biological-defense pipeline. Some focus on testing models. Others explore pathogen surveillance, antibody design, drug discovery, or emergency response.
DeepMind plans to expand this work during the next six to 12 months. Its priorities include better threat intelligence, stronger evaluations for AI agents, and improved defenses against jailbreaks.
This is therefore not one magic product with a shiny “Stop Pandemic” button. It is an interconnected program involving models, laboratories, governments, datasets, sequencing technologies, and public policy.
Biology, unfortunately, refuses to fit neatly inside an app.
Why Frontier AI Changes the Risk Equation
Frontier models such as Gemini possess increasingly detailed knowledge of biology. Their capabilities can grow further when developers connect them to specialized biological models, scientific databases, coding tools, or autonomous agents.
That combination could help a researcher analyze a protein or explore a vaccine target more quickly. It could also help a malicious user overcome gaps in technical knowledge.
DeepMind’s concern is not necessarily that a chatbot can independently produce a biological weapon. The more immediate issue involves models gradually eroding the expertise barriers that traditionally limit dangerous activity.
A person attempting something harmful must still overcome many obstacles. They need materials, facilities, equipment, practical skill, secrecy, and a method of delivery. AI does not magically erase those constraints.
However, it may help with specific intellectual bottlenecks. It can search information, explain scientific concepts, suggest experimental approaches, and coordinate other tools. An AI agent could potentially perform several of those tasks in sequence.
That is why DeepMind evaluates not only what its models know, but whether their assistance could meaningfully change what a threat actor can accomplish.
Capability, in this context, matters more than impressive vocabulary.
Prevention Starts With Knowing the Threat
DeepMind says its prevention system follows four stages: threat modeling, evaluations, mitigations, and monitoring.
Threat modeling asks who might misuse a model, what that person would want to achieve, and which barriers currently stand in the way. Without that foundation, safety testing can become a collection of scary prompts with no consistent measure of real-world danger.
The company then runs evaluations. These reportedly include expert red-team exercises and randomized controlled trials designed to test whether Gemini can help users overcome important biological bottlenecks.
If researchers identify a significant risk, DeepMind applies mitigations. Post-training methods teach the model to recognize and reject harmful requests. Classifiers and internal probes attempt to identify risky activity while it happens.
Human analysis also remains part of the system. DeepMind says targeted reviews of user logs can uncover subtle patterns that automated filters might miss, subject to its security infrastructure and privacy controls.
None of these safeguards offers a permanent victory. A defense that blocks yesterday’s jailbreak may wobble against tomorrow’s more creative version.
Model safety is less like installing a padlock and more like running airport security during a costume convention.
The Over-Refusal Problem

Blocking dangerous requests sounds easy until a legitimate scientist asks a question that resembles one.
A virologist, vaccine researcher, or public-health laboratory may need detailed information about pathogens. If an AI system refuses every complicated biological query, it becomes wonderfully safe and spectacularly useless.
DeepMind says its post-training methods aim to reject malicious assistance without over-refusing beneficial scientific work. That balance remains one of the program’s hardest technical and policy challenges.
Intent is rarely printed on a user’s forehead. Two people may ask almost identical questions while pursuing radically different goals. Context helps, but it does not supply perfect certainty.
For that reason, DeepMind is expanding access to some advanced systems through restricted arrangements with trusted researchers and institutions. According to Axios, the company treats these arrangements as lower-risk restricted releases rather than ordinary public deployments.
Helen King, DeepMind’s vice president of responsibility, told Axios that the company would withhold a launch if a model approached a critical capability level without adequate safeguards.
That is an important promise. The harder test will arrive when commercial pressure, scientific demand, and safety evidence point in different directions.
DNA Screening Meets Its Shape-Shifting Problem
One of the initiative’s most concrete concerns involves synthetic DNA.
Gene-synthesis companies already screen customer orders against databases of harmful pathogens and toxins. These checks can identify sequences that closely resemble known biological threats.
However, resemblance-based screening has limits. AI systems may help design different genetic sequences that preserve a dangerous biological function while looking sufficiently unlike known entries to avoid a simple match.
DeepMind says this possibility is causing existing screening methods to “fray.” Its proposed response has two layers.
The nearer-term concept involves adapting SynthID, Google’s watermarking technology, to biological data. A biological version might help synthesis providers identify certain AI-generated sequences.
This remains exploratory work. DeepMind has not announced a finished biological watermarking system, a deployment date, or proof that such a method would survive deliberate attempts to remove it.
The longer-term ambition is even harder: build screening systems that predict what a sequence may do, including whether it could be toxic or pathogenic, regardless of whether it resembles a known threat.
That would move screening from “Have we seen this sequence?” to “What might this sequence actually do?”
It is also, by DeepMind’s admission, a major open technical challenge.
Detection Means Looking Beyond Familiar Pathogens
Traditional diagnostic tests usually search for specific organisms. That works when health authorities already know what they are hunting.
Novel outbreaks are less cooperative.
DeepMind wants to support broader metagenomic surveillance. Instead of checking a sample for a short list of known pathogens, metagenomic sequencing examines all microorganisms present. Researchers can apply it to patient samples, wastewater, or even air-monitoring systems.
In theory, widespread sequencing could reveal unusual biological activity before hospitals fill with patients.
In practice, sequencing everything is expensive. The data can be difficult to process, and effective surveillance requires reliable sampling systems, laboratory capacity, trained personnel, secure data-sharing rules, and public trust.
DeepMind believes AI can reduce some of those costs. Its AlphaEvolve coding agent has already been used in a collaboration between Google and Pacific Biosciences to improve sequencing accuracy. The company is now examining whether AI can optimize data-analysis algorithms and even inform sequencing-hardware design.
That is promising. It is not yet a global early-warning network.
Moving from a controlled technical improvement to routine surveillance across airports, cities, hospitals, and low-resource regions will require considerably more than a clever algorithm.
AlphaGenome Could Help Characterize the Unknown
DeepMind is also exploring whether AlphaGenome and protein-function annotation systems can help scientists interpret unfamiliar genetic material.
AlphaGenome was designed to examine how DNA variants may affect gene regulation and biological function. Within a biosecurity setting, related capabilities could help researchers detect patterns in sequence data and characterize an emerging pathogen.
That matters because identifying an unusual sequence is only the first step. Scientists must determine what organism produced it, how it behaves, whether it causes disease, and how quickly it might spread.
AI could help prioritize signals buried inside enormous sequencing datasets. It might highlight mutations, biological mechanisms, or functional relationships worthy of closer laboratory study.
The word “might” deserves a comfortable chair here.
Predictions still require scientific validation. Models can make errors, produce misleading correlations, or struggle when confronted with biology unlike their training data. Poor-quality samples and incomplete databases can further distort the picture.
AI may become an excellent biological smoke detector. Someone must still determine whether the alarm signals a burning building, an enthusiastic toaster, or a sensor having a difficult Tuesday.
AlphaFold Moves From Discovery to Defense
The response pillar builds heavily on AlphaFold, DeepMind’s protein-structure prediction system.
Proteins perform much of biology’s day-to-day work, and their three-dimensional shapes influence how they function. Understanding those structures can help researchers identify drug targets, study disease mechanisms, and design medical countermeasures.
According to DeepMind’s full bioresilience update, more than 10,000 infectious-disease publications have cited AlphaFold during the past five years. Researchers have applied it to tuberculosis, malaria transmission, Mpox, Nipah, and other threats.
DeepMind recently partnered with Lawrence Livermore’s Center for Predictive Bioresilience. That collaboration plans to use AlphaFold 3 in broad-spectrum antibody research, including work on a pan-filovirus antibody.
The goal is not simply to fight one known strain. Broad-spectrum countermeasures could remain useful across a family of related viruses.
DeepMind also plans to add more relevant protein structures and complexes to the AlphaFold Protein Structure Database, concentrating on targets that could support diagnostics, vaccines, and treatments.
That work is less cinematic than “AI defeats bioweapons.” It may prove far more useful.
Isomorphic Labs Builds an Emergency Unit

Isomorphic Labs contributes a different piece of the puzzle: AI-supported drug design.
The company has established a focused unit that could deploy its Drug Design Engine during a novel outbreak. It intends to work with governments, nonprofit organizations, national laboratories, and global-health bodies to develop potential medical countermeasures.
The unit would address both naturally occurring pandemics and biological risks connected to the misuse of advanced AI.
This emergency structure reflects a stubborn problem. Many known pathogens still lack licensed diagnostics, vaccines, or treatments. When an unfamiliar outbreak emerges, researchers often begin with limited tools and a ticking clock.
AI could accelerate early stages of the discovery process by helping scientists study targets, predict molecular interactions, or evaluate candidate compounds. It cannot skip toxicology studies, manufacturing, clinical trials, regulatory review, or the inconvenient fact that human biology enjoys surprising everyone.
Isomorphic Labs is therefore building capacity, not promising instant medicine.
The company’s involvement also illustrates how commercial drug-discovery technology could support public biosecurity. That arrangement will require clear rules around access, intellectual property, responsibility, pricing, and emergency deployment.
When the next crisis arrives, nobody will want to negotiate the entire rulebook while the pathogen is already collecting frequent-flyer miles.
AI Agents Join the Scientific Team
DeepMind is granting selected researchers access to newer AI agent systems, including its Co-Scientist platform.
Unlike a basic chatbot, a scientific agent can help organize evidence, generate hypotheses, compare explanations, and propose research directions. DeepMind says scientists within the US Department of Energy’s National Laboratories are receiving access through the government’s Genesis Mission.
Some researchers are studying new drug combinations for pathogens that resist existing treatments.
This controlled-access approach may offer a practical compromise. Trusted laboratories gain useful capabilities, while DeepMind avoids releasing every advanced biological function to the entire internet with a cheerful sign-up page.
Yet restricted access creates its own questions. Who qualifies as trusted? Which countries and institutions receive entry? Who audits the decisions? What happens when researchers need to reproduce findings without equivalent tools?
Security often favors tighter control. Science often advances through openness. Bioresilience needs both, which is roughly as relaxing as driving with one foot on the accelerator and the other hovering above the brake.
DeepMind has also pledged $7 million to Health for Human Potential, a Philanthropy Asia Alliance program supporting infectious-disease research across Asia.
That funding gives the initiative a regional dimension beyond Western laboratories.
The Policy Wishlist Is Ambitious
DeepMind and Isomorphic Labs argue that technical safeguards alone cannot carry the entire biosecurity burden. Their update includes several recommendations for US policymakers.
For prevention, they support a federal frontier-AI safety framework and legislation covering biological data standards, DNA-synthesis screening, and biotechnology measurement practices.
For detection, they want expanded metagenomic sequencing at transit hubs and densely populated locations. They also call for greater funding for AI-assisted early-warning and attribution research.
For response, the companies recommend secure biological datasets, adaptable medical platforms, prepared clinical-trial networks, faster regulatory pathways, and manufacturing capacity that can activate quickly during an emergency.
Some of the named bills remained proposals when the companies published their update. None should be confused with an already operational national system.
The recommendations nevertheless reveal the program’s scale. AI models are only one layer. Effective bioresilience also requires laboratories, sequencing networks, public-health agencies, factories, regulators, hospitals, and international coordination.
A model may propose a promising molecule in hours. Manufacturing millions of safe doses is a different sport, played in a different stadium, under considerably harsher lighting.
A Global Defense Needs Global Participation
Biological threats ignore borders with almost rude efficiency.
An outbreak detected in one region can quickly become an international problem through travel, trade, and densely connected cities. Effective surveillance must therefore reach locations where new diseases are likely to emerge not merely countries with wealthy laboratories and abundant computing infrastructure.
That introduces difficult questions about cost and governance.
Who pays for sequencing equipment? Who owns the resulting genomic data? Which institutions can access it? How should governments protect patient privacy? What prevents surveillance infrastructure from being repurposed for political control or commercial exploitation?
DeepMind’s partnership model may help answer parts of that puzzle, but more than 15 collaborations are still small compared with the scale of a genuinely global network.
The companies deserve credit for framing bioresilience as a shared effort rather than a purely internal Google project. Still, the strongest defense will require transparent standards, independent evaluation, equitable access, and participation from countries outside the usual AI power centers.
Otherwise, the world could build a remarkably sophisticated alarm system with sensors concentrated in the places already best equipped to respond.
Pathogens, tragically, do not respect premium subscriptions.
The Biggest Unknown Is Real-World Performance
The program combines credible scientific tools with several technologies that remain experimental.
AlphaFold has an extensive research record. Metagenomic sequencing already exists. Drug-design platforms can generate useful candidates. Model evaluations and access controls are familiar safety mechanisms.
Other pieces remain less mature. Biological watermarking has not been demonstrated as a finished defense. Function-based DNA screening remains an open challenge. AI-assisted global surveillance has not reached the scale described in the policy vision.
Even established systems can behave differently outside controlled environments. A classifier that performs well during red-team testing may miss a novel jailbreak. A sequence-analysis model may struggle with incomplete data. A promising drug candidate may fail in human trials.
The responsible way to read the announcement is neither breathless optimism nor automatic dismissal.
DeepMind and Isomorphic Labs have assembled a serious framework for an increasingly serious problem. They have also published many of the limitations themselves.
The program’s credibility will depend on measurable results: better evaluations, cheaper sequencing, successful partnerships, useful countermeasures, transparent reporting, and safeguards that survive contact with clever adversaries.
Biology grades on outcomes. Press releases merely receive participation certificates.
The Bioresilience Bet

Google’s central argument is bold: frontier AI should not be treated only as a biological risk. It could also become one of society’s most important biological defenses.
That argument makes sense. Refusing to use advanced AI for pathogen detection or medical research would surrender powerful tools precisely when biological risks are becoming more complicated.
But enthusiasm cannot replace caution. The systems used to design defenses may also increase dangerous capabilities. Restricted access can reduce misuse but concentrate power. Surveillance can detect outbreaks while creating privacy risks. Rapid drug design can shorten discovery while leaving testing and manufacturing stubbornly physical.
Bioresilience is therefore not a clean technology story. It is a governance story, a public-health story, a security story, and because humans are involved a coordination story with approximately seventeen open tabs.
DeepMind and Isomorphic Labs have supplied a map: prevent misuse, detect threats early, and respond decisively.
Now comes the difficult part.
They must prove that their safeguards can keep pace with their models, their partnerships can function during real emergencies, and their scientific tools can move from impressive demonstrations to dependable global infrastructure.
AI may help humanity prepare for the next biological crisis. It will not excuse humanity from doing the preparation.
Sources
- Google DeepMind: Our Approach to Bioresilience
- Google DeepMind and Isomorphic Labs: Full Bioresilience Program Update
- Artificial Intelligence News: Examining Google DeepMind’s AI Bioresilience Push
- Blockchain.News: Google DeepMind and Isomorphic Labs Unveil AI-Powered Bioresilience Plan
- Axios: Google Expands Biosecurity Effort Amid AI Safety Push
- AI Glimpse: DeepMind and Isomorphic Labs Chart a New Path for AI Resilience
- AI Glimpse: DeepMind and Isomorphic Labs Unite on AI-Driven Biology
- Isomorphic Labs: Our Approach to Bioresilience
Kingy Launch Brief
Put the week’s verified AI launches in your inbox.
Every Friday, the verified AI launches, apps, funding rounds, pricing changes and under-the-radar moves worth knowing—source-linked and explained in five minutes.
Free · Every Friday · Unsubscribe anytime · No daily email
