Skip to main content
AI BiosecurityExplainerAug 7, 2026, 10:20 AM· 5 min read· #2 of 2 in ai

Frontier AI Models Outperform PhD Virologists in Lab Tasks, Lowering Barrier for Bioweapon Development

Recent evaluations reveal that advanced AI models now surpass human experts in troubleshooting complex virology laboratory procedures. The breakthrough raises concerns that AI could transfer critical 'tacit knowledge' to novices, significantly lowering the barrier to engineering biological weapons.

By Logan Price

AI Safety Researchers 40%Biosecurity Pragmatists 40%Open-Science Advocates 20%
AI Safety Researchers
Advocate for strict pre-deployment evaluations to mitigate the risks of novice uplift.
Biosecurity Pragmatists
Focus on securing physical bottlenecks like DNA synthesis rather than restricting AI software.
Open-Science Advocates
Warn that over-regulating AI models will hamper legitimate medical research and pandemic preparedness.

At a glance

  • The Virology Capabilities Test (VCT) reveals that frontier AI models score up to 45 percent in lab troubleshooting, compared to 22 percent for human PhDs.
  • AI systems can now diagnose mechanical and chemical errors in failed biological experiments, effectively transferring 'tacit knowledge' to untrained users.
  • Biosecurity experts warn of 'novice uplift,' where individuals with basic STEM training could use AI to bypass the experience required to weaponize pathogens.
  • The same AI capabilities that raise security concerns are simultaneously accelerating legitimate drug discovery and vaccine development.
  • Pragmatists argue that physical bottlenecks, such as commercial DNA synthesis, remain the most effective chokepoints for preventing bioweapon development.

Why it matters now

The realization that AI models can troubleshoot complex physical lab work dismantles the primary barrier that has historically prevented amateurs from engineering biological weapons. How governments choose to regulate this capability will determine whether the next generation of AI is primarily used to cure pandemics or to start them.

Frontier artificial intelligence models have officially surpassed human experts in troubleshooting complex virology lab procedures, dismantling the long-held assumption that hands-on laboratory experience would permanently prevent bad actors from engineering bioweapons. The breakthrough was quantified in a rigorous evaluation known as the Virology Capabilities Test (VCT), which measured the ability of both humans and machines to solve practical, real-world problems in biological research.[1]

The results of the evaluation were stark. When presented with highly specific troubleshooting questions tailored to their exact sub-fields, PhD-level virologists scored an average of 22.1 percent. In contrast, advanced AI models like OpenAI's o3 and Google's Gemini 2.5 Pro achieved accuracy rates between 37 and 45 percent.

To understand why this matters, it is necessary to understand how biological research actually works. Historically, the primary barrier to creating a biological weapon has not been access to information, but rather a lack of "tacit knowledge." This refers to the hands-on, hard-to-Google skills acquired through years of trial and error at a laboratory bench.[7]

AI models now significantly outperform human experts on the Virology Capabilities Test.
AI models now significantly outperform human experts on the Virology Capabilities Test.

If a novice attempts to synthesize a virus and the experiment fails, textbook knowledge is rarely enough to identify the problem. The failure could be due to a degraded reagent, an incorrect centrifuge speed, or a subtle temperature fluctuation. Until now, diagnosing and fixing these mechanical and chemical errors required an experienced human expert.[1][7]

Modern AI models are now capable of acting as non-judgmental, expert-level lab assistants. When fed data about a failed protocol, these systems can instantly identify the likely error and provide step-by-step instructions to correct it. This capability effectively transfers tacit knowledge to individuals who have never set foot in a high-level containment lab.[2]

Biosecurity experts refer to this phenomenon as "novice uplift." The core fear is that a malicious actor with only basic undergraduate training in science, technology, engineering, or mathematics could use an AI to bypass the years of specialized experience normally required to weaponize a pathogen.[2][4]

Studies conducted by AI companies and biosecurity nonprofits have confirmed this risk. In one trial, individuals with limited biology experience were given access to large language models and asked to complete biosecurity-related tasks. The AI assistance allowed these novices to troubleshoot complex virology protocols with four times greater accuracy than they could on their own.[2]

Novice uplift occurs when AI systems transfer tacit laboratory knowledge to untrained users.
Novice uplift occurs when AI systems transfer tacit laboratory knowledge to untrained users.
Studies conducted by AI companies and biosecurity nonprofits have confirmed this risk.

Internal red-teaming by major AI developers has yielded similar findings. Companies like Anthropic have reported that their models enhanced human performance on weapons-relevant tasks enough to trigger higher AI Safety Level classifications, necessitating stricter internal security protocols and delayed deployments.[6]

However, this is fundamentally a dual-use dilemma. The exact same troubleshooting capabilities that make these models a potential security threat are what make them incredibly useful for legitimate scientific advancement.[5]

AI systems are already accelerating drug discovery, streamlining vaccine development, and improving disease detection. If policymakers force developers to lobotomize their models to prevent bioweapon development, they risk simultaneously slowing down the creation of the very countermeasures needed to fight naturally occurring pandemics.[4]

Furthermore, some scientists argue that the immediate threat of an AI-generated bioweapon is being overstated. While an AI can provide instructions, it cannot physically synthesize a virus. A malicious actor still needs access to raw genetic material, specialized laboratory equipment, and physical infrastructure.[3]

"The threat from full AI design and writing of a genome of a virus or bacteria is very overblown when we consider that just taking existing pathogens and making gain-of-function changes to their genomes is so much easier," noted Dr. Tom Ellis, a synthetic biology expert, highlighting that nature already provides highly effective pathogens.[3]

Physical DNA synthesis remains a critical bottleneck for biological research and bioweapon development.
Physical DNA synthesis remains a critical bottleneck for biological research and bioweapon development.

The most critical physical bottleneck is DNA synthesis. To build a virus from scratch, a user must order custom genetic sequences from commercial providers. Currently, the screening of this synthetic DNA to ensure it is not being used to build known pathogens remains mostly voluntary in many jurisdictions.[3][7]

Complicating matters, researchers have demonstrated that AI models can "paraphrase" the genetic blueprints of dangerous proteins. By rewriting the DNA sequence while preserving the lethal structure, an AI can generate a novel sequence that evades industry-standard screening software, allowing a bad actor to order the necessary components undetected.[7]

In response to these converging risks, the regulatory landscape is shifting rapidly. Organizations like the OECD and national AI Safety Institutes are pushing for standardized, pre-deployment biological evaluations for all frontier models.[5]

The debate now centers on where to intervene most effectively. While some advocate for strict capability restrictions on the AI models themselves, others argue for a layered approach. This would include mandatory screening for all DNA synthesis orders, tighter controls on laboratory equipment, and improved early warning systems for biological threats.[3][4]

Experts advocate for a layered approach to biosecurity that extends beyond the AI models themselves.
Experts advocate for a layered approach to biosecurity that extends beyond the AI models themselves.

As AI models continue to scale, the disparity in virology expertise between humans and machines is expected to widen. The challenge for global governance will be to secure the physical bottlenecks of biological research before the digital barriers disappear entirely.[1][6]

Terms to know

Virology Capabilities Test (VCT)
A specialized benchmark evaluating the ability to troubleshoot practical, hands-on virology laboratory procedures.
Tacit Knowledge
Unwritten, experience-based knowledge gained through trial and error in a physical laboratory setting.
Novice Uplift
The increase in capability that an untrained individual gains when assisted by an advanced AI system.
Dual-Use Technology
Technology that can be used for both beneficial purposes, such as medical research, and malicious purposes, such as weapons development.
DNA Synthesis Screening
The process of checking commercial orders for synthetic genetic material to ensure they are not being used to build known pathogens.

The backstory

  1. April 2025

    Researchers publish the Virology Capabilities Test, revealing that frontier AI models outperform PhD virologists in lab troubleshooting.

  2. October 2025

    Major AI labs report that advanced models trigger higher AI Safety Level classifications due to biological capabilities.

  3. February 2026

    The International AI Safety Report documents the emergence of AI 'co-scientists' capable of autonomous experimental design.

  4. August 2026

    Debate intensifies over whether to regulate AI models directly or focus on securing the physical DNA synthesis supply chain.

Different angles

AI Safety Researchers

Advocate for strict pre-deployment evaluations to mitigate the risks of novice uplift.

This camp views the collapse of the tacit knowledge barrier as a critical vulnerability. They argue that because AI models can now troubleshoot complex lab protocols better than human experts, the barrier to entry for creating bioweapons has dropped dangerously low. They advocate for mandatory, standardized biological evaluations before any frontier model is released to the public, and support delaying deployments if models cross specific capability thresholds.

Biosecurity Pragmatists

Focus on securing physical bottlenecks like DNA synthesis rather than restricting AI software.

Pragmatists argue that while AI capabilities are advancing, the immediate threat of AI-generated bioweapons is often overstated compared to the risk of modifying existing pathogens. They emphasize that an AI cannot physically synthesize a virus. Therefore, they advocate for a layered security approach that focuses on physical chokepoints, such as mandating universal screening for commercial DNA synthesis orders and tightening access to specialized laboratory equipment.

Open-Science Advocates

Warn that over-regulating AI models will hamper legitimate medical research and pandemic preparedness.

This perspective highlights the dual-use nature of AI in biology. Advocates point out that the exact same troubleshooting capabilities that raise security concerns are currently accelerating drug discovery, vaccine development, and disease detection. They caution that forcing developers to heavily restrict or 'lobotomize' their models to prevent theoretical bioweapon development could severely slow down the creation of real-world countermeasures needed to fight naturally occurring diseases.

Still unresolved

  • It remains unclear exactly when AI models will cross the threshold from assisting with known pathogens to autonomously designing novel, viable bioweapons.
  • Regulators have not yet determined how to effectively mandate screening for AI-generated genetic sequences that evade current detection software.
  • The long-term impact of restricting AI virology capabilities on the speed of legitimate medical research is still unknown.

Questions readers ask

What is the Virology Capabilities Test (VCT)?

The VCT is a rigorous benchmark designed to measure the ability of humans and AI models to troubleshoot complex, real-world problems in biological research and wet lab environments.

What is tacit knowledge in biology?

Tacit knowledge refers to the hands-on, hard-to-Google skills acquired through years of physical laboratory experience, such as knowing why a specific chemical reaction failed.

Can an AI model physically create a virus?

No. AI models can only provide instructions and troubleshoot protocols. A user still needs access to physical laboratory equipment and synthetic DNA to create a pathogen.

What is novice uplift?

Novice uplift is the phenomenon where AI assistance allows individuals with limited scientific training to perform complex tasks at an expert level, potentially lowering the barrier to creating bioweapons.

Sources

Source coverage

7 outlets

3 viewpoints surfaced

AI Safety Researchers 40%Biosecurity Pragmatists 40%Open-Science Advocates 20%
  1. [1]arXivAI Safety Researchers

    Virology Capabilities Test (VCT): A Multimodal Virology Q&A Benchmark

    Read on arXiv
  2. [2]Fast CompanyOpen-Science Advocates

    Risk from bio AI

    Read on Fast Company
  3. [3]The GuardianBiosecurity Pragmatists

    Scientists use AI to design novel bacteriophage genomes

    Read on The Guardian
  4. [4]RAND CorporationBiosecurity Pragmatists

    Contemporary Foundation AI Models Increase Biological Weapons Risk

    Read on RAND Corporation
  5. [5]OECD AI Policy ObservatoryBiosecurity Pragmatists

    AI Outperforms Virologists, Raising Bioweapon Concerns

    Read on OECD AI Policy Observatory
  6. [6]Forecasting Research InstituteAI Safety Researchers

    Forecasting biological risks from large language models

    Read on Forecasting Research Institute
  7. [7]80,000 HoursOpen-Science Advocates

    AI already surpasses top virologists on troubleshooting tacit knowledge

    Read on 80,000 Hours

Comments

Stay informed

Every angle. Every day.

Get ai stories with full source coverage and perspective breakdowns delivered to your inbox.