OpenAI Preparing for Future AI Risks in Biology
OpenAI has announced a a comprehensive strategy to mitigate biological risks associated with frontier AI models. As these models approach "High" levels of capability in biology—as defined by OpenAI's Preparedness Framework—the company is implementing a multi-layered defense system to prevent the misuse of AI in creating bioweapons or recreating biological threats while continuing to support legitimate scientific discovery.
Proactive Mitigation and Expert Collaboration
OpenAI is adopting a prevention-first approach to biological risk, focusing on limiting access to harmful capabilities before a threat event occurs. This strategy relies heavily on collaboration with external domain experts and government entities to identify vulnerabilities and strengthen they system.
- Expert Consultation: OpenAI has worked with biosecurity, bioweapons, and bioterrorism experts, as well as academic researchers, to shape its threat models, capability assessments, and usage policies.
- Government Partnerships: The company is partnering with the US CAISI and UK AISI, and has collaborated with Los Alamos National Laboratory to study AI's role in wet lab settings.
- Validation: Human trainers with PhDs and master's degrees in biology are used to create and validate evaluation data to ensure the accuracy of safety assessments.
Technical Safety Measures for Biological Risks
To prevent the misuse of AI for biological weaponization, OpenAI has deployed several technical controls across its product surfaces:
Model Training and Response Filtering
OpenAI trains its models to refuse explicitly harmful requests or those that enable bioweaponization. For dual-use requests—such as those involving genetic engineering, immunology, or virology—the models follow the Model Spec, which avoids providing actionable, step-by-step instructions or wet lab troubleshooting guidance. The goal is to provide high-level insights for experts while withholding details that would allow a novice to misuse the system.
Detection and Enforcement
Always-on Monitoring: System-wide monitors detect risky or suspicious bio-related activity. If a request is flagged as unsafe, the response is blocked and an automated review is triggered, which may lead to human review.
Policy Enforcement: OpenAI prohibits the use of its products to cause harm. Misuse can result in account suspension and, in egregious cases, notification of law enforcement.
Red Teaming and Security Controls
End-to-End Red Teaming: OpenAI pairs biological domain experts with experienced red teamers to simulate sophisticated adversaries and identify gaps in the safety system.
Weight Protection: A defense-in-depth approach is used to protect model weights from exfiltration, combining access controls, infrastructure hardening, egress controls, and monitoring, supported by an Insider-Risk program.
Future Biosecurity Initiatives
OpenAI recognizes that securing individual models is insufficient and is advocating for a broader ecosystem of biological defenses.
Biodefense and Vetted Access
In July, OpenAI will host a biodefense summit with government researchers and NGOs to explore how frontier models can accelerate the development of countermeasures and novel therapies. Additionally, the company is developing protocols to grant vetted institutions access to more capable models to advance biological sciences.
Systemic Biological Defenses
OpenAI suggests that the public and private sectors collaborate to strengthen biological defenses outside of AI models, including:
Strengthened nucleic acid synthesis screening.
More robust early detection systems for novel pathogens.
Hardening infrastructure against biothreats.
Investment in biosecurity innovations and mission-driven startups to ensure long-term resilience.