Skip to content

Product1 publisher3 min readPublished

Bench scientists put the bioweapon bottleneck in the wet lab

Frontier labs are citing AI-designed bioweapons to argue for new controls on synthetic DNA. Researchers who run labs told WIRED the hard part is assembling and verifying a virus, and that no fully autonomous lab exists.

The Product Desk · Product desk

Illustration accompanying Bench scientists put the bioweapon bottleneck in the wet lab

What happened

  • AI company chief executives called earlier this summer for new laws controlling the manufacture of synthetic DNA, and the case for them has been building through the summer's research and reports.
  • Anthropic published a report saying there had been attempts to use Claude in ways that could support biological weapons development, and Dario Amodei asked government to help labs pace the frontier.
  • Working scientists told WIRED the binding constraint is elsewhere: obtaining gene fragments, assembling a genome, and verifying the result infects humans and transmits between them.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint If assembly and verification are the constraint, controls placed on model outputs act on a step the scientists describe as already accessible, and the physical step goes untouched.
  • decision Anyone drafting or answering a synthetic DNA rule has to decide whether it screens orders at synthesis vendors or imposes duties on model providers, because the two land on different steps.
  • contradiction Scharfman agrees no fully autonomous lab exists and still calls AI-assisted bioterrorism immediate, because a model can hire a human, which neither guardrails nor order screening fully addresses.
  • exposure Autonomous-lab operators like Ginkgo now sit inside the safety argument as evidence, and their access controls become part of the regulatory record.

The claim being made to legislators is about information: a model that knows too much about virology, handed to someone who should not have it. The people who have to physically make a pathogen put the constraint somewhere else. David Bellamy, a research scientist at the Institute of Foundation Models in Sunnyvale, told WIRED that AI helps good and bad actors move through documents faster, and added: "But those capabilities are not really the bottleneck in the production of bioweapons." [4][5]

What he puts in the bottleneck is the build. A bad actor has to obtain gene fragments, assemble a whole genome from scratch, then verify that the result infects humans, causes the intended illness, and transmits between people. [6] Robots can speed parts of that up, but someone still needs the skill to run the experiments and the resources to pay for them. [7]

That distinction matters for who gets regulated. Screening synthetic DNA orders sits on the fragment-acquisition step, which the scientists in WIRED's account agree is a real constraint. Guardrails inside a chat model sit on the literature-search step, which Bellamy says was already eroded by the open internet, open-access journals and Google Translate long before large language models. [3] Both asks are being carried by the same argument.

Ginkgo Bioworks chief executive Jason Kelly has the closest thing to a field test: his company builds autonomous labs and ran a project with OpenAI in which GPT-5 operated one. [8] Kelly said "The AI could not take over the lab," in part because the humans inside could decline to hand over the substances and equipment it asked for. [9] For a system to route around that, he said, "you'd have to have dramatically more robots all over the place." [10]

Olivia Scharfman, a biotechnology fellow at the Institute for Progress, said "It is impossible for AI to access a fully autonomous lab and autonomously build a virus today because fully autonomous labs do not exist yet." [11] She also said an AI could pay someone to do it, and she treats AI-assisted bioterrorism as an immediate threat. [12] So the disagreement is about the human in the loop being purchasable, not about the model being capable on its own. A control regime aimed at model outputs does not touch that, and a control regime aimed at synthesis vendors partly does.

Anyone writing a policy or a vendor questionnaire has to decide what a given control acts on: knowledge, materials, or labour. Model guardrails and publication review are knowledge controls, and the scientists WIRED quoted think that step was already leaky. Order screening at DNA synthesis vendors is a materials control, and it sits on the step Bellamy identifies. Nothing in this account addresses labour. That is where Scharfman puts the near-term risk.

Immunologist Derya Unutmaz argued that even a released supervirus would meet scientists using other AI systems to develop a vaccine quickly. [13] Anthropic's own report calls biological misuse "one of the most serious risks of frontier AI models," and chief executive Dario Amodei has urged the government to help AI labs "pace the frontier." [2] Stanford and Arc Institute researchers did show AI designing new viral genomes. [1] In the account the bench scientists give, the bottleneck comes after that step.

What to watch

  • Whether US legislation on synthetic DNA manufacturing advances, and whether it screens orders at synthesis vendors or imposes duties on model providers.
  • Progress toward a genuinely autonomous lab, which Scharfman names as the missing precondition for an AI-only build.
  • Whether Anthropic or another frontier lab publishes misuse evidence that reaches the assembly and verification steps.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories