AI GUIDEPartner content

AI biosecurity: how to distinguish research from dangerous requests

Why a keyword filter does not solve the dual-use problem in biology and which access levels help avoid blocking useful research.

Affiliate link: your price stays the same and the project earns a commission.

The same molecular biology request may be part of drug development, epidemic risk assessment, or a dangerous experiment. These scenarios cannot be distinguished by a few words. Therefore, AI biosecurity is built not around banning all complex biology, but around context, access level, and control of the sequence of actions.

Why biological requests are dual-use

Dual use means that a method, instrument, or body of knowledge is useful for peaceful work while also capable of increasing the danger of a malicious project. This has long been a familiar problem for laboratories: DNA synthesis, microorganism cultivation, and work with toxins are regulated not because they are always harmful, but because the outcome depends on the purpose, the person carrying it out, and the conditions.

AI adds a new layer to this system. It helps search the literature, explain methods, write code for data analysis, and find errors in a research plan. Such assistance saves time for a qualified specialist. But the same interface can lower the barrier to entry for someone who previously lacked the experience to assemble scattered information into a workable plan.

Why keyword filters work poorly

An overly strict dictionary blocks routine scientific work. An overly permissive one lets a dangerous request through if it is broken into parts that sound neutral. Anthropic's report on abuse describes a case involving highly pathogenic avian influenza and the adaptation of a virus to mammals. The provider restricted access to the most capable models and took action against the account. What matters is not the specific topic itself, but the fact that its scientific and dangerous interpretations are superficially very similar.

There is also the reverse problem: from a single message, the system sees only a fragment. Today the user asks for a literature review, tomorrow for help with experimental design, and then for an analysis of a failed result. Individually, these steps may appear permissible, but together they reveal the objective. This means that it is necessary to check not only the text of the response, but also the trajectory of the work.

What indicators provide useful context

A reliable assessment should not be based on a single indicator. A practical set includes:

  • the user's identity and role — a verified laboratory, educational organization, or independent account;
  • model capability level — the greater the ability to provide specialized assistance, the stricter the access conditions;
  • the completeness of the chain — a request for a risk overview differs from sequential support for a dangerous experiment;
  • tools — reading open-access articles carries a different risk from access to laboratory automation or restricted databases;
  • behavioral anomalies — attempts to circumvent refusals, change wording, and distribute a single task across accounts.

No single item proves malicious intent. Their combination helps select a proportionate measure: a normal response, a safe high-level summary, manual review, transfer to a restricted model, or blocking.

Multilevel access instead of a blanket ban

For the general user, it is reasonable to allow high-level explanations: the basics of biology, epidemiology, laboratory safety rules, and analysis of published data. Specialized assistance that substantially increases the ability to carry out a complex experiment requires a different regime.

Such a regime may include organizational verification, a designated person responsible, request logs, restrictions on transferring results to external tools, and periodic audits. This is similar to access to hazardous reagents: legitimate work is not prohibited, but their origin, storage, and use are controlled.

The threshold should depend not on the user's prestige, but on the risk of the action. An employee of a well-known institution can also make a mistake or misuse access. Therefore, identity verification complements technical restrictions rather than replacing them.

How to organize safe work in the laboratory

Organizations should divide tasks into three groups in advance. The first is reference work with open sources. The second is analysis of internal data without control of equipment. The third is actions affecting experiments, procurement, or laboratory automation. For each group, the permitted models, data, and approval process are defined.

The minimum operating framework looks like this:

  1. do not provide models with data that may not be taken outside the organization;
  2. do not give an agent direct access to equipment by default;
  3. retain the request, response, sources used, and the specialist's decision;
  4. have a second qualified person verify critical conclusions;
  5. stop the chain if the AI begins replacing an approved protocol with its own assumptions.

This process is needed not only to prevent intentional harm. It protects against confidently worded errors, outdated data, and the incorrect transfer of a method from one system to another.

What cannot be entrusted to a single filter

A response filter does not see everything: a person may use multiple services, a local model, or pass the result to another operator. Therefore, protection must combine access policy, monitoring of action sequences, user verification, and industry measures outside the AI platform.

The useful goal here is not to “ban biology,” but to preserve legitimate research and increase the cost of dangerous activity. A detailed description of the case and the provider's measures is published in Anthropic's report on AI abuse. Its findings should be read as data from the company's internal investigation, not as an independent assessment of the entire market.

Compare models before you start

The service sets its plans, limits and model catalog. If they differ from this article, contact us so we can update it and record a new review date.

Browse models

Affiliate link: your price stays the same and the project earns a commission.

AI biosecurity dual use AI in biology AI access control

SEO Mind42 editorial team

We explore SEO and neural networks in practice: test services on our own projects, verify prices and limits against primary sources, and share things you can put to use the same day.

📚 Reference guide to SEO and AI 🔄 Materials are updated 🕐 Updated: 4 October 2026

Related reading

All in this section →