<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.3 20070202//EN" "journalpublishing.dtd">
<article article-type="review-article" dtd-version="2.3" xml:lang="EN" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">Front. Bioeng. Biotechnol.</journal-id>
<journal-title>Frontiers in Bioengineering and Biotechnology</journal-title>
<abbrev-journal-title abbrev-type="pubmed">Front. Bioeng. Biotechnol.</abbrev-journal-title>
<issn pub-type="epub">2296-4185</issn>
<publisher>
<publisher-name>Frontiers Media S.A.</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">1537471</article-id>
<article-id pub-id-type="doi">10.3389/fbioe.2025.1537471</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Bioengineering and Biotechnology</subject>
<subj-group>
<subject>Review</subject>
</subj-group>
</subj-group>
</article-categories>
<title-group>
<article-title>Responsible AI in biotechnology: balancing discovery, innovation and biosecurity risks</article-title>
<alt-title alt-title-type="left-running-head">Wheeler</alt-title>
<alt-title alt-title-type="right-running-head">
<ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3389/fbioe.2025.1537471">10.3389/fbioe.2025.1537471</ext-link>
</alt-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" corresp="yes">
<name>
<surname>Wheeler</surname>
<given-names>Nicole E.</given-names>
</name>
<xref ref-type="corresp" rid="c001">&#x2a;</xref>
<uri xlink:href="https://loop.frontiersin.org/people/2910409/overview"/>
<role content-type="https://credit.niso.org/contributor-roles/conceptualization/"/>
<role content-type="https://credit.niso.org/contributor-roles/investigation/"/>
<role content-type="https://credit.niso.org/contributor-roles/writing-original-draft/"/>
<role content-type="https://credit.niso.org/contributor-roles/Writing - review &#x26; editing/"/>
</contrib>
</contrib-group>
<aff>
<institution>Department of Microbes</institution>, <institution>Infection and Microbiomes</institution>, <institution>School of Infection</institution>, <institution>Inflammation and Immunology</institution>, <institution>College of Medicine and Health</institution>, <institution>University of Birmingham</institution>, <addr-line>Birmingham</addr-line>, <country>United Kingdom</country>
</aff>
<author-notes>
<fn fn-type="edited-by">
<p>
<bold>Edited by:</bold> <ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/174419/overview">Segaran P. Pillai</ext-link>, United States Department of Health and Human Services, United States</p>
</fn>
<fn fn-type="edited-by">
<p>
<bold>Reviewed by:</bold> <ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/170546/overview">Gerald Epstein</ext-link>, RAND Corporation, United States</p>
<p>
<ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/2893165/overview">Matt Sharkey</ext-link>, United States Department of Health and Human Services, United States</p>
</fn>
<corresp id="c001">&#x2a;Correspondence: Nicole E. Wheeler, <email>n.wheeler@bham.ac.uk</email>
</corresp>
</author-notes>
<pub-date pub-type="epub">
<day>05</day>
<month>02</month>
<year>2025</year>
</pub-date>
<pub-date pub-type="collection">
<year>2025</year>
</pub-date>
<volume>13</volume>
<elocation-id>1537471</elocation-id>
<history>
<date date-type="received">
<day>30</day>
<month>11</month>
<year>2024</year>
</date>
<date date-type="accepted">
<day>03</day>
<month>01</month>
<year>2025</year>
</date>
</history>
<permissions>
<copyright-statement>Copyright &#xa9; 2025 Wheeler.</copyright-statement>
<copyright-year>2025</copyright-year>
<copyright-holder>Wheeler</copyright-holder>
<license xlink:href="http://creativecommons.org/licenses/by/4.0/">
<p>This is an open-access article distributed under the terms of the Creative Commons Attribution License (CC BY). The use, distribution or reproduction in other forums is permitted, provided the original author(s) and the copyright owner(s) are credited and that the original publication in this journal is cited, in accordance with accepted academic practice. No use, distribution or reproduction is permitted which does not comply with these terms.</p>
</license>
</permissions>
<abstract>
<p>The integration of artificial intelligence (AI) in protein design presents unparalleled opportunities for innovation in bioengineering and biotechnology. However, it also raises significant biosecurity concerns. This review examines the changing landscape of bioweapon risks, the dual-use potential of AI-driven bioengineering tools, and the necessary safeguards to prevent misuse while fostering innovation. It highlights emerging policy frameworks, technical safeguards, and community responses aimed at mitigating risks and enabling responsible development and application of AI in protein design.</p>
</abstract>
<kwd-group>
<kwd>artificial intellegence</kwd>
<kwd>biotechnology</kwd>
<kwd>AI safety</kwd>
<kwd>protein design and engineering</kwd>
<kwd>synthetic biology</kwd>
</kwd-group>
<custom-meta-wrap>
<custom-meta>
<meta-name>section-at-acceptance</meta-name>
<meta-value>Biosafety and Biosecurity</meta-value>
</custom-meta>
</custom-meta-wrap>
</article-meta>
</front>
<body>
<sec id="s1">
<title>Introduction</title>
<p>The convergence of artificial intelligence (AI) and biotechnology is rapidly transforming the landscape of scientific research, promising groundbreaking advancements in medicine, agriculture, and environmental science (<xref ref-type="bibr" rid="B55">OECD, 2023</xref>; <xref ref-type="bibr" rid="B4">AI Policy Perspectives, 2024</xref>). However, these same tools also present unique biosecurity challenges. The ability of AI to accelerate drug discovery and design novel proteins can, if misused, lower the barriers to developing biological weapons with unprecedented precision and potency (<xref ref-type="bibr" rid="B17">Carter et al., 2023</xref>; <xref ref-type="bibr" rid="B66">Sandbrink, 2023</xref>; <xref ref-type="bibr" rid="B25">Drexel and Withers, 2024</xref>).</p>
<p>This dual-use potential&#x2014;where innovations designed for beneficial purposes may also enable harm&#x2014;demands urgent attention from the biotechnology community. This review explores the history and evolving threat model of bioweapons development, outlines specific concerns raised in the light of AI, highlights key mitigations and safeguards already in place, and outlines actionable pathways for biotechnologists to engage with this critical issue. By addressing these risks, the field can ensure that the transformative power of AI is harnessed responsibly, minimising dangers while maximising its potential for good.</p>
<sec id="s1-1">
<title>Overview of AI applications in bioscience</title>
<p>AI has driven remarkable advancements in discovery science and deepened our understanding of biological systems, particularly the proteins that underpin essential biological functions. For instance, tools like DeepVariant (<xref ref-type="bibr" rid="B61">Poplin et al., 2018</xref>) use AI to identify genetic variants with unprecedented accuracy, aiding genomics research. EVE (<xref ref-type="bibr" rid="B27">Frazer et al., 2021</xref>) and AlphaMissense (<xref ref-type="bibr" rid="B19">Cheng et al., 2023</xref>) provide valuable insights into the likely impacts of genetic mutations, illuminating the genetic mechanisms underlying disease. Beyond genetic analysis, AlphaFold (<xref ref-type="bibr" rid="B44">Jumper et al., 2021</xref>) and RosettaFold (<xref ref-type="bibr" rid="B47">Krishna et al., 2024</xref>) have significantly contributed to structural biology by accurately predicting protein 3D structures and complementing experimental methods. Similarly, ESM3 has excelled in protein sequence analysis, helping to bridge the gap between sequence, structure and function (<xref ref-type="bibr" rid="B39">Hayes et al., 2024</xref>), and other deep learning models have made further progress helping to address the major scientific challenge of protein function prediction (<xref ref-type="bibr" rid="B13">Bileschi et al., 2022</xref>). These tools collectively address one of the central challenges of modern biology: understanding DNA and protein functions and their roles in biological life, marking a new era of AI-enabled scientific discovery.</p>
<p>The integration of artificial intelligence (AI) into bioengineering is helping to transform biological design into a systematic engineering discipline, sparking rapid progress and innovation. AI-driven tools are revolutionising protein design, unlocking opportunities in therapeutics, diagnostics, and synthetic biology. For instance, tools like RFDiffusion (<xref ref-type="bibr" rid="B86">Watson et al., 2023</xref>) and Chroma (<xref ref-type="bibr" rid="B42">Ingraham et al., 2023</xref>) allow the creation of proteins with desired structures and properties, while DiffDock (<xref ref-type="bibr" rid="B22">Corso et al., 2022</xref>) significantly improves the prediction of protein-ligand binding interactions. Tools like DeepBind (<xref ref-type="bibr" rid="B7">Alipanahi et al., 2015</xref>) accurately predict protein binding to DNA and RNA, AlphaProteo (<xref ref-type="bibr" rid="B93">Zambaldi et al., 2024</xref>) allows the design of novel binders, and AI tools are being used to engineer proteins with greater stability and functionality (<xref ref-type="bibr" rid="B70">Sumida et al., 2024</xref>). These innovations tackle long-standing challenges such as engineering enzymes for industrial applications and combating antimicrobial resistance, while also paving the way for transformative advancements in personalised medicine, biomanufacturing, and environmental sustainability. By harnessing the power of AI, bioengineering can strive to achieve levels of precision and reproducibility akin to traditional engineering disciplines, heralding a new era of scientific discovery and application.</p>
<p>AI and robotic scientists represent a cutting-edge application of AI in biotechnology and other scientific fields (<xref ref-type="bibr" rid="B55">OECD, 2023</xref>). These systems automate and accelerate the scientific discovery process, from hypothesis generation to experimentation and data analysis. One notable example is Adam, a robot scientist designed to autonomously identify gene functions in yeast, pioneering the integration of AI with laboratory automation (<xref ref-type="bibr" rid="B69">Sparkes et al., 2010</xref>). Building on Adam&#x2019;s success, Eve was developed to accelerate drug discovery and has identified existing compounds with potential applications for treating neglected tropical diseases (<xref ref-type="bibr" rid="B91">Williams et al., 2015</xref>). In metabolic engineering, automated systems have shown significant promise in optimizing biological processes. For instance, a study by <xref ref-type="bibr" rid="B38">HamediRad et al. (2019)</xref> demonstrated the use of automated tools to enhance experimental success rates and improve yields in the production of valuable biomolecules. Additionally, digital AI systems like the data-to-paper platform (<xref ref-type="bibr" rid="B40">Ifargan et al., 2024</xref>), independently analyze large datasets to identify priority findings, providing researchers with actionable insights and reducing time spent on data interpretation.</p>
<p>AI is revolutionizing how scientists generate, process, and disseminate knowledge, fundamentally transforming the research landscape. Its applications span the entire scientific workflow, from gathering and annotating data to modeling complex systems and devising solutions to some of humanity&#x2019;s most pressing challenges (<xref ref-type="bibr" rid="B4">AI Policy Perspectives, 2024</xref>). One striking example of the transformative impact of AI is the recognition of its contributions to protein science through the Nobel Prize in Chemistry. The developers of AlphaFold and Rosetta were awarded the prize for their groundbreaking work in understanding and designing proteins, highlighting how AI tools are enabling researchers to solve problems previously thought insurmountable (<xref ref-type="bibr" rid="B54">Nature, 2024</xref>). This recognition underscores the pivotal role AI is playing across disciplines, driving progress not only in protein science but also in areas like climate modeling, materials science, and personalised medicine. By enhancing the speed, scale, and precision of scientific inquiry, AI is unlocking new frontiers of knowledge and reshaping the future of innovation.</p>
</sec>
<sec id="s1-2">
<title>The dual-use dilemma: risks in AI-driven bioengineering</title>
<p>The transformative power of AI in bioengineering comes with inherent risks, particularly due to the dual-use nature of biotechnology&#x2014;where tools intended for beneficial purposes can also be exploited for malicious ends (<xref ref-type="bibr" rid="B51">National Research Council US, 2007</xref>). The incorporation of AI amplifies these concerns by lowering some technical barriers to advanced bioengineering, potentially enabling misuse by malicious actors (<xref ref-type="bibr" rid="B17">Carter et al., 2023</xref>; <xref ref-type="bibr" rid="B25">Drexel and Withers, 2024</xref>). Historical precedents, such as the development and deployment of biological weapons during the 20th century, underscore the potentially catastrophic consequences of biotechnological misuse.</p>
<p>Recognising these risks, the international community has initiated frameworks such as the Biological Weapons Convention (BWC) (<xref ref-type="bibr" rid="B80">UNODA, 2024</xref>) to establish norms against the misuse of biotechnology. Recent efforts, including global AI safety summits, have sought to extend these principles to the intersection of AI and biosecurity. However, these initiatives face significant challenges, including inadequate funding, weak enforcement mechanisms, and the rapid pace of technological advancements (<xref ref-type="bibr" rid="B23">Cropper et al., 2023</xref>).</p>
<p>This review delves into the evolving landscape of biosecurity risks associated with AI-powered protein design. It examines the dual-use potential of these tools, evaluates existing and proposed safeguards, and highlights actionable roles for scientists. By addressing these challenges head-on, we can build a secure and resilient ecosystem that maximises the benefits of AI-driven bioengineering while safeguarding against its misuse.</p>
</sec>
</sec>
<sec id="s2">
<title>The changing biorisk landscape</title>
<p>The landscape of biological risks has transformed dramatically over the past century, driven by scientific advancements, changing geopolitical contexts, and the emergence of disruptive technologies like artificial intelligence (AI). Historically, the development and deployment of biological weapons were constrained by significant technical and logistical barriers (<xref ref-type="bibr" rid="B11">Ben Ouagrham-Gormley, 2014</xref>; <xref ref-type="bibr" rid="B65">Revill and Jefferson, 2014</xref>). However, there are concerns that the growing accessibility of cutting-edge biotechnological tools, particularly those powered by AI, has begun to erode these barriers (<xref ref-type="bibr" rid="B17">Carter et al., 2023</xref>; <xref ref-type="bibr" rid="B66">Sandbrink, 2023</xref>; <xref ref-type="bibr" rid="B25">Drexel and Withers, 2024</xref>). AI-driven applications in synthetic biology, protein design, and genetic engineering have not only accelerated legitimate scientific progress but also expanded the potential for misuse, enabling actors with limited expertise to pursue sophisticated biological capabilities.</p>
<p>This section examines the evolution of biological risks, beginning with the historical context of bioweapons development and the global responses to these threats. It then explores the contemporary challenges posed by the convergence of AI and biotechnology, focusing on how these technologies are reshaping the threat landscape. Finally, it assesses the implications of AI-driven advancements for biosecurity, highlighting the need for proactive measures to address the dual-use nature of these powerful tools.</p>
<sec id="s2-1">
<title>Historical context: bioweapons development and challenges</title>
<p>Biological weapons have posed a persistent threat since their initial development in the 20th century. During World War II, several nations invested substantial resources into bioweapons programs, but technical and logistical hurdles often precluded successful deployment. These challenges included the selection of pathogenic strains, difficulties in scaling up production, and ensuring properties such as heat stability and effective dispersal under operational conditions (<xref ref-type="bibr" rid="B11">Ben Ouagrham-Gormley, 2014</xref>).</p>
<p>While large-scale bioweapons programs have become less common, sporadic incidents highlight the enduring risks associated with these technologies. Notable examples include the Amerithrax attacks of 2001, where anthrax spores were mailed to targets in the United States, causing public panic and five deaths (<xref ref-type="bibr" rid="B63">Rasko et al., 2011</xref>). Another instance occurred in 1984, when a religious commune deliberately contaminated salad bars with <italic>Salmonella</italic> in an Oregon town, resulting in 751 cases of food poisoning (<xref ref-type="bibr" rid="B78">T&#xf6;r&#xf6;k et al., 1997</xref>).</p>
<p>These incidents underscore the challenges of identifying and attributing bioweapon use, as well as the widespread public fear such attacks can provoke. Notably, they have primarily involved naturally occurring agents or those subjected to relatively minor modifications, such as engineering drug resistance. However, the future of biological and toxin weapons may deviate significantly from these historical patterns. Advances in biotechnology and artificial intelligence raise concerns that future threats could involve entirely novel agents designed for specific characteristics, such as enhanced transmissibility or pathogenicity, targeted effects on particular populations, or resistance to existing detection and countermeasure systems or existing immunity (<xref ref-type="bibr" rid="B66">Sandbrink, 2023</xref>; <xref ref-type="bibr" rid="B25">Drexel and Withers, 2024</xref>; <xref ref-type="bibr" rid="B58">Pannu et al., 2024</xref>). Such developments could render traditional preparedness strategies insufficient, highlighting the urgent need for proactive measures and adaptable biosecurity frameworks to address these emerging risks.</p>
</sec>
<sec id="s2-2">
<title>Emerging challenges in the contemporary landscape</title>
<p>The modern era is witnessing a renewed awareness of the possibilities of biological warfare in light of rapid advancements in biotechnology, artificial intelligence, and shifting geopolitical dynamics (<xref ref-type="bibr" rid="B43">Juling, 2023</xref>; <xref ref-type="bibr" rid="B15">Brent et al., 2024</xref>; <xref ref-type="bibr" rid="B12">Berg and Kappler, 2024</xref>). These developments expand the potential scope and sophistication of potential threats, elevating biological weapons to a central concern in contemporary security discussions.</p>
<p>The rise of hybrid warfare&#x2014;characterised by the integration of conventional military tactics with unconventional methods&#x2014;further complicates the biological risk landscape. A biological weapons attack, for example, could be coordinated with cyberattacks targeting health infrastructure, undermining emergency response efforts, or paired with disinformation campaigns to sow public panic and distrust (<xref ref-type="bibr" rid="B72">Smith, 2019</xref>; <xref ref-type="bibr" rid="B18">Chatham House&#x2013;International Affairs Think Tank, 2024</xref>). These strategies could amplify the impact of a biological assault, rendering traditional mitigation measures inadequate and necessitating more comprehensive, integrated security frameworks.</p>
</sec>
<sec id="s2-3">
<title>Challenges in detecting and attributing malicious use</title>
<p>Detecting malicious intent in the development of biological weapons presents unique challenges, particularly when compared to other weapons of mass destruction. The raw materials and technologies required for bioweapons often overlap substantially with those used in legitimate fields, such as medical research, public health, and agriculture, complicating efforts to distinguish misuse from beneficial applications (<xref ref-type="bibr" rid="B46">Koblentz, 2009</xref>). AI is also likely to enable the design of novel sequences with pathogenic or toxic functions, challenging existing frameworks for detecting threats based on similarity to historical hazards (<xref ref-type="bibr" rid="B83">US National Science and Technology Council, 2024</xref>; <xref ref-type="bibr" rid="B82">U.S. HHS, 2023</xref>). Advances in laboratory automation and the self-replicating nature of biological agents further exacerbate these challenges, enabling rapid scale-up with minimal infrastructure. Additionally, the democratisation of synthetic biology tools, which are increasingly accessible to a global audience, reduces the technical and logistical barriers to bioweapon development (<xref ref-type="bibr" rid="B48">Lee et al., 2023</xref>). Together, these factors underscore the need for robust biosecurity frameworks to mitigate the dual-use risks of biotechnology (<xref ref-type="bibr" rid="B89">WHO, 2022a</xref>).</p>
</sec>
<sec id="s2-4">
<title>The role of AI in shaping the biorisk landscape</title>
<p>AI has emerged as a potentially transformative factor reshaping the scope and sophistication of biological threats (<xref ref-type="bibr" rid="B17">Carter et al., 2023</xref>; <xref ref-type="bibr" rid="B66">Sandbrink, 2023</xref>; <xref ref-type="bibr" rid="B25">Drexel and Withers, 2024</xref>). In protein design and bioengineering, AI-driven tools could streamline the creation of bioweapons by enabling the design of proteins with tailored properties, such as enhanced heat stability, solubility, or binding specificity&#x2014;traits that could increase their efficacy as weapons (<xref ref-type="bibr" rid="B25">Drexel and Withers, 2024</xref>; <xref ref-type="bibr" rid="B86">Watson et al., 2023</xref>; <xref ref-type="bibr" rid="B70">Sumida et al., 2024</xref>). For instance, AI can be used to develop novel proteins capable of binding to specific targets (<xref ref-type="bibr" rid="B93">Zambaldi et al., 2024</xref>), a capability with potential applications for toxins and biologics in military contexts. Beyond biological design, AI-powered systems like chatbots can enhance logistical aspects of bioweapons development, including planning, acquisition of materials, operational coordination, and delivery strategies (<xref ref-type="bibr" rid="B68">Soice et al., 2023</xref>; <xref ref-type="bibr" rid="B56">OpenAI, 2024</xref>).</p>
<p>AI systems can automate complex scientific tasks, reducing the need for advanced training or deep domain knowledge. For instance, AI can design experiments, optimise chemical or biological designs and synthesis pathways, and predict the efficacy of biological agents with reduced human oversight. This de-skilling effect democratises access to capabilities that were once restricted to well-funded state actors or specialised institutions, which may empower non-state actors or small groups to credibly develop sophisticated bioweapons (<xref ref-type="bibr" rid="B20">CLTR, 2024</xref>). For highly resourced actors, the possibilities are even more alarming, with AI opening avenues for designing novel toxins with more targeted and tunable effects, or the development of pathogens with impacts far exceeding those seen in nature. However, toxins without an effective self-replicating delivery tool function more similarly to chemical weapons, limiting their potential for mass harm, and experts remain divided on the feasibility of effective pandemic pathogen design (<xref ref-type="bibr" rid="B17">Carter et al., 2023</xref>; <xref ref-type="bibr" rid="B58">Pannu et al., 2024</xref>). As AI continues to advance, its dual-use potential underscores the urgent need for robust safeguards to prevent misuse while enabling beneficial scientific progress.</p>
<p>The credibility of the threat posed by AI-enabled bioweapons remains a contentious issue, with expert opinions varying widely across disciplines, including historical biological weapons (BW) programs, biotechnology, security, and artificial intelligence (<xref ref-type="bibr" rid="B17">Carter et al., 2023</xref>). Substantial testing has been conducted on large language models (LLMs) (<xref ref-type="bibr" rid="B56">OpenAI, 2024</xref>; <xref ref-type="bibr" rid="B50">Mouton et al., 2024</xref>; <xref ref-type="bibr" rid="B60">Phuong et al., 2024</xref>), and has yielded mixed findings. Early evaluations suggested minimal uplift compared to information readily available on the internet (<xref ref-type="bibr" rid="B50">Mouton et al., 2024</xref>). However, OpenAI&#x2019;s o1 model demonstrated measurable benefits for experts, particularly in synthesising existing threat information and enhancing access to previously obscure knowledge (<xref ref-type="bibr" rid="B56">OpenAI, 2024</xref>).</p>
<p>No direct testing of the misuse potential of AI tools used in biological design (biological design tools, or BDTs) has been publicly reported. The most advanced of these capabilities is protein design tools, but this class of tools also includes those for designing DNA, biological circuits and cells (<xref ref-type="bibr" rid="B17">Carter et al., 2023</xref>). Key risks identified for protein tools include the design of novel toxins and effectors, the design of novel viral pathogens and vectors, and the alteration of existing pathogen proteins to change their properties in ways that increase their utility as weapons, such as host range, binding to target cells, and evasion of natural immunity. Indicators of emerging risks include advancements in targeted therapeutics, which reduce the number of iterations required to achieve successful designs, improvements in automation processes, and the increasing efficiency of mass production systems. These developments collectively suggest that BDTs could enable more rapid and scalable approaches to bioweapons design in the future. Addressing these gaps requires a focused effort to evaluate BDT risks rigorously, using realistic yet ethically sound testing methods. This includes incorporating benign use cases that reflect the operational challenges of weaponisation, as well as investing in the development of frameworks to detect and mitigate emerging threats.</p>
</sec>
<sec id="s2-5">
<title>Implications for biosecurity</title>
<p>The changing biorisk landscape underscores the urgency of addressing the dual-use potential of AI in biotechnology. Policymakers, scientists, and industry leaders must recognise that traditional biosecurity frameworks are insufficient to counter emerging threats. Without proactive measures, the risk of AI exacerbating bioweapons development will continue to grow, posing serious threats to global security and public health. This evolving context necessitates a reimagining of biosecurity approaches, with discussions focusing not only on restricting access but also on promoting transparency, accountability, and innovation for defensive and beneficial purposes.</p>
</sec>
</sec>
<sec id="s3">
<title>Collaborative responses to AI risks in biotechnology</title>
<p>As the potential for misuse of AI in biotechnology becomes an increasing concern, policymakers, private sector stakeholders, and the scientific community have begun taking steps to address the associated risks. These efforts focus on fostering collaboration, developing safeguards, and implementing frameworks that balance innovation with biosecurity. This section examines the initiatives led by these groups and highlights the challenges and opportunities they present.</p>
<sec id="s3-1">
<title>Policy efforts</title>
<p>Policymakers across the globe are increasingly prioritising the risks posed by AI in biotechnology, particularly the potential for these technologies to lower barriers to developing bioweapons (<xref ref-type="bibr" rid="B5">AI Safety Summit, 2023</xref>; <xref ref-type="bibr" rid="B81">U.S. Department of Homeland Security, 2024</xref>). Recent high-profile events, such as the AI Safety Summit 2023, have brought biosecurity concerns to the forefront, highlighting the need for international collaboration and education (<xref ref-type="bibr" rid="B34">GOV.UK, 2023</xref>; <xref ref-type="bibr" rid="B32">GOV.UK, 2024a</xref>). These initiatives aim to inform policymakers about the technical complexities of AI-driven advancements in biotechnology and their dual-use implications. AI Safety Institutes are also forming in countries around the world to evaluate risks and inform policymaking (<xref ref-type="bibr" rid="B3">AISI, 2024</xref>; <xref ref-type="bibr" rid="B14">NIST, 2023</xref>; <xref ref-type="bibr" rid="B6">AISI Japan, 2024</xref>; <xref ref-type="bibr" rid="B67">Shaping Europe&#x2019;s digital future, 2024</xref>).</p>
<p>Governments and international organisations are advancing frameworks to assess and mitigate the misuse potential of biotechnology tools. Efforts to improve DNA synthesis screening are a vital component of these efforts (<xref ref-type="bibr" rid="B10">Baker and Church, 2024</xref>). In the United States, a new policy mandates that nucleic acids purchased with federal research funding must come from providers that screen orders for potential misuse (<xref ref-type="bibr" rid="B83">US National Science and Technology Council, 2024</xref>; <xref ref-type="bibr" rid="B76">The White House, 2023</xref>). Similarly, the United Kingdom has introduced its first-ever guidance for domestic nucleic acid providers, outlining best practices for screening synthetic nucleic acid orders (<xref ref-type="bibr" rid="B35">GOV.UK, 2024b</xref>). The recent U.S. Executive Order on AI (<xref ref-type="bibr" rid="B76">The White House, 2023</xref>) established additional specific measures to evaluate and mitigate risks from AI-driven biotechnologies. Among these measures is a requirement for reporting on biological foundation models with a lower floating-point operations per second (FLOP) threshold compared to other AI applications, reflecting their heightened dual-use concerns. These initiatives mark significant progress in balancing the opportunities of AI-enabled biotechnology with the critical need for global biosecurity.</p>
</sec>
<sec id="s3-2">
<title>Industry-led initiatives</title>
<p>Major AI companies are taking proactive steps to assess and mitigate the risks associated with their technologies. Participation in collaborative platforms like the Frontier Model Forum (<xref ref-type="bibr" rid="B30">Frontier Model Forum, 2024c</xref>) and AIxBio Global Forum (<xref ref-type="bibr" rid="B53">NTIbio, 2024</xref>) which bring together key stakeholders to share best practices, develop guidelines, and promote the safe deployment of tools has become a critical process for AI companies to share learnings and best practices and inform their internal policies (<xref ref-type="bibr" rid="B28">Frontier Model Forum, 2024a</xref>; <xref ref-type="bibr" rid="B29">Frontier Model Forum, 2024b</xref>). Companies like OpenAI (<xref ref-type="bibr" rid="B56">OpenAI, 2024</xref>), Meta (<xref ref-type="bibr" rid="B26">Dubey et al., 2024</xref>; <xref ref-type="bibr" rid="B1">Anthropic, 2024</xref>) and DeepMind (<xref ref-type="bibr" rid="B37">Grin et al., 2024</xref>) have also commissioned comprehensive safety evaluations for their models, often including red-teaming exercises designed to uncover vulnerabilities and identify potential misuse. However, these efforts demand careful oversight to prevent accidental disclosure of sensitive findings or unintended misuse. Some companies have placed their models behind an interface that allows them to control and monitor access, but others have released their models fully in the public domain, precluding the implementation of robust governance mechanisms. A new industry is forming around providing risk assessments and safety evaluations for AI and biotechnology applications. While best practices for this sector are still being developed, there is growing demand for experts in biotechnology to design robust safety protocols and capability benchmarks.</p>
</sec>
<sec id="s3-3">
<title>Academic and research community efforts</title>
<p>The academic community has increasingly recognised its responsibility to mitigate biosecurity risks while continuing to advance scientific discovery. One significant step has been the protein design community&#x2019;s issuance of a statement on the responsible use of AI in biodesign, which underscores the importance of ethical considerations in deploying these powerful tools (<xref ref-type="bibr" rid="B64">Responsible AI x Biodesign, 2024</xref>). In parallel, some research funders now require applicants to submit statements detailing how potential dual-use applications of their work, including bioweapons risks, will be mitigated (<xref ref-type="bibr" rid="B87">Wellcome, 2024</xref>). The Biofunders Compact has further encouraged bioscience and biotechnology funders to make public commitments to integrating biosecurity and biosafety into their funding decisions, promoting accountability and transparency (<xref ref-type="bibr" rid="B75">The Nuclear Threat Initiative. NTI, 2024b</xref>). Academic contributions to defensive measures have also been notable. Research into methods for detecting genetic engineering (<xref ref-type="bibr" rid="B84">Wang et al., 2019</xref>; <xref ref-type="bibr" rid="B8">Alley et al., 2020</xref>) and attributing the origins of engineered organisms (<xref ref-type="bibr" rid="B85">Wang et al., 2021</xref>), has advanced significantly. Progress in DNA synthesis screening technologies (<xref ref-type="bibr" rid="B31">Godbold et al., 2021</xref>; <xref ref-type="bibr" rid="B88">Wheeler et al., 2024</xref>), and microbial forensics (<xref ref-type="bibr" rid="B41">Inglis, 2024</xref>; <xref ref-type="bibr" rid="B79">Tripathi et al., 2024</xref>) further illustrates the research community&#x2019;s proactive role in addressing dual-use risks. The academic community faces particular challenges in securely sharing sensitive results on the safety and security of AI capabilities without the inappropriate proliferation of dual-use information. Collectively, these efforts exemplify how the academic community is balancing the imperative of innovation with the need to ensure global biosecurity.</p>
</sec>
<sec id="s3-4">
<title>Challenges and opportunities</title>
<p>While significant progress has been made in addressing the risks associated with AI in biotechnology, notable challenges remain. The demand for scientific expertise to support policymakers and international bodies, such as the Biological Weapons Convention (BWC) (<xref ref-type="bibr" rid="B73">The InterAcademy Partnership, 2024</xref>), continues to grow, placing pressure on the availability of knowledgeable advisors. Policymakers and the scientific community must also navigate the delicate balance between fostering innovation and implementing necessary regulations. Despite these challenges, the current landscape offers significant opportunities. Strengthening the biosecurity framework can foster interdisciplinary collaboration between AI developers, biologists, and policymakers, creating a more unified approach to managing dual-use risks.</p>
</sec>
</sec>
<sec id="s4">
<title>Safeguards for mitigating risks: current state, opportunities and challenges</title>
<p>Safeguards to mitigate risks in AI and biotechnology are evolving, yet significant gaps persist. While a range of potential safeguards have been proposed, such as refusal mechanisms, tiered access controls, and enhanced monitoring systems (<xref ref-type="bibr" rid="B74">The Nuclear Threat Initiative. NTI, 2024a</xref>), their application in AI tools specific to biotechnology remains largely uncharted. Many of these tools operate in a dual-use space, where their capabilities can advance both beneficial applications, like therapeutic development, and potential misuse, such as bioweapon design, creating substantial challenges in mitigating risks of misuse while harnessing their benefits.</p>
<sec id="s4-1">
<title>Data controls</title>
<p>Some model developers have taken proactive steps to withhold data they deem risky, such as certain pathogen genomes, from AI models. Examples include the exclusion of sensitive datasets in tools like ESM3 (<xref ref-type="bibr" rid="B39">Hayes et al., 2024</xref>) and Evo (<xref ref-type="bibr" rid="B52">Nguyen et al., 2024</xref>). However, the open nature of many AI models has allowed fine-tuning with restricted data, potentially undermining these precautions (<xref ref-type="bibr" rid="B59">PathoLM, 2024</xref>; <xref ref-type="bibr" rid="B92">Workman and LatchBio, 2024</xref>). Policy proposals to limit access to future pathogen genome data have also emerged (<xref ref-type="bibr" rid="B17">Carter et al., 2023</xref>; <xref ref-type="bibr" rid="B49">Maxmen, 2021</xref>), aiming to preempt misuse. These proposals are not entirely new (<xref ref-type="bibr" rid="B21">Committee on Genomics Databases for Bioterrorism Threat Agents and Board on Life Sciences, 2004</xref>), but have gained renewed urgency in the context of AI&#x2019;s rapid development and the increasing democratisation of biotechnology. While these proposals have garnered support in some policy circles, they have been met with criticism from experts who warn that restrictions could impede scientific progress and global collaboration (<xref ref-type="bibr" rid="B21">Committee on Genomics Databases for Bioterrorism Threat Agents and Board on Life Sciences, 2004</xref>). The World Health Organization (WHO) emphasises that sharing pathogen genome data is crucial for preventing, detecting, and responding to epidemics and pandemics, as well as for monitoring endemic diseases and tracking antimicrobial resistance (<xref ref-type="bibr" rid="B90">WHO, 2022b</xref>). Moreover, some experts question whether excluding pathogen data from AI training would significantly limit the development of concerning capabilities, noting that design methodologies often rely on unrelated or widely accessible data (<xref ref-type="bibr" rid="B74">The Nuclear Threat Initiative. NTI, 2024a</xref>). This ongoing debate reflects the complex balance between biosecurity and the need for scientific openness.</p>
</sec>
<sec id="s4-2">
<title>Built-in safeguards in AI tools</title>
<p>Built-in safeguards are a critical component of risk mitigation strategies for general-purpose AI tools, designed to prevent misuse and ensure responsible deployment. These safeguards include mechanisms such as refusal systems that block harmful or unethical requests and hard-coded constraints to limit specific high-risk functionalities. However, the implementation and effectiveness of these measures vary significantly across AI domains. For large language models (LLMs), extensive safeguards have been adopted. Systems such as ChatGPT (<xref ref-type="bibr" rid="B56">OpenAI, 2024</xref>) and Gemini (<xref ref-type="bibr" rid="B33">Google Cloud, 2024</xref>) feature refusal mechanisms that prevent responses to potentially harmful queries, including instructions for creating weapons or performing unsafe chemical reactions. Yet even these safeguards can be stripped out if sufficiently open access is provided to the models, such as through the open release of model weights.</p>
<p>In contrast, the adoption of built-in safeguards for biotechnology-focused AI tools remains underdeveloped, despite their dual-use potential (<xref ref-type="bibr" rid="B74">The Nuclear Threat Initiative. NTI, 2024a</xref>). For example, AlphaFold3 were early adopters of experimental refusal mechanisms to block misuse, but these efforts were preliminary and highlighted the challenges of balancing functionality with security (<xref ref-type="bibr" rid="B37">Grin et al., 2024</xref>). The appropriateness of implementing refusal mechanisms in biological design tools remains a complex and underexplored issue. Unlike in large language models, where refusals can effectively block queries with clear malicious intent, biological design often resides in a dual-use space. Many therapeutic and diagnostic efforts inherently involve predictions and designs that overlap with weaponisation potential. For instance, the development of treatments for infectious diseases may require modelling pathogenic structures or engineering highly specific proteins, which could also be repurposed for harmful applications (<xref ref-type="bibr" rid="B71">Thadani et al., 2023</xref>). This overlap makes it challenging to delineate legitimate use cases from misuse solely through automated refusal systems (<xref ref-type="bibr" rid="B74">The Nuclear Threat Initiative. NTI, 2024a</xref>). Therefore, refusal mechanisms, if overly restrictive, could impede critical research, such as designing countermeasures for bioterrorism or creating synthetic vaccines. Balancing the need for accuracy and functionality in therapeutic and diagnostic efforts with biosecurity safeguards will require a nuanced approach, combining automated mechanisms with human oversight and contextual analysis, which will inevitably raise difficult trade-offs in promoting beneficial science, preventing harm, and financing the resources required for safety measures. This highlights the importance of further investigation into refusal mechanisms tailored to the unique challenges of biological design tools.</p>
</sec>
<sec id="s4-3">
<title>Managed access frameworks</title>
<p>Open-weight models are highly valued by academic and research communities for their ability to foster transparency, reproducibility, and innovation. By allowing researchers to replicate studies, extend existing work, and democratise advanced technologies, these models have become indispensable tools in scientific progress. However, their open-access nature introduces significant risks of misuse, particularly in fields like biotechnology where dual-use applications can enable harmful purposes (<xref ref-type="bibr" rid="B74">The Nuclear Threat Initiative. NTI, 2024a</xref>).</p>
<p>Efforts to restrict access to open-weight models frequently encounter resistance from the academic and open-source communities. Advocates of open access argue that transparency is essential for scientific integrity, promoting collaboration, and accelerating innovation (<xref ref-type="bibr" rid="B9">Anonymous, 2024</xref>). This tension is further compounded by the rapid emergence of open-source versions of closed models, driven by demand for their functionality (<xref ref-type="bibr" rid="B16">Callaway, 2024</xref>). As a result, restricting access often proves challenging, as it may lead to the proliferation of unofficial and less-regulated alternatives.</p>
<p>Managed access frameworks offer a potential solution to these challenges by enabling the controlled distribution of AI tools while maintaining some degree of accessibility. Platforms like <xref ref-type="bibr" rid="B77">Together AI (2024)</xref> and <xref ref-type="bibr" rid="B2">Huggingface (2024)</xref> provide repositories and APIs that balance openness with accountability by requiring users to comply with ethical guidelines or community standards. <xref ref-type="bibr" rid="B45">Kaggle (2024)</xref>, a popular platform for data science competitions, exemplifies another managed-access approach by providing datasets, models and computational resources in a controlled environment. These frameworks promote responsible use while still democratising AI tools. However, managed-access frameworks come with caveats. They would demand substantial resources for implementation and oversight, including providing cloud computing resources, monitoring usage, vetting users, and enforcing compliance. A key component of managed-access frameworks for biosecurity may involve Know Your Customer (KYC) processes, which are widely used in industries like finance to verify user identities. Applying KYC principles to AI access might include identity verification, institutional affiliation checks, and risk assessments of intended use. Such measures could leverage existing frameworks and technologies to enhance security while preserving accessibility. Using ORCIDs (Open Researcher and Contributor IDs) (<xref ref-type="bibr" rid="B57">ORCID, 2024</xref>) as part of a managed-access framework offers an efficient and scalable way to implement KYC principles in the life sciences. ORCIDs provide a persistent, unique identifier for researchers, allowing platforms to verify users&#x27; identities and affiliations while minimising administrative burdens. By integrating ORCIDs into access protocols, AI developers and data providers could ensure that only authenticated researchers with credible affiliations gain access to sensitive tools or datasets. This approach leverages an existing, widely adopted system, reducing barriers to implementation while enhancing accountability and traceability in the use of dual-use technologies.</p>
<p>Without adequate resources, these managed access systems risk being bypassed or failing to address security concerns comprehensively, and even with sufficient resources, they cannot eliminate the possibility of an &#x201c;inside threat&#x201d; who passes the various vetting requirements but still has nefarious intent.</p>
</sec>
<sec id="s4-4">
<title>Evaluations and red teaming</title>
<p>Effective evaluations and red-teaming efforts are vital for advancing AI applications in biotechnology responsibly, yet the current landscape is hindered by inconsistent benchmarks, making it challenging to measure progress or compare capabilities across tools. Treaty commitments (<xref ref-type="bibr" rid="B80">UNODA, 2024</xref>) and ethical considerations often restrict direct assessments of harmful applications, leaving a critical gap in standardised testing protocols and evidence-based evaluations. Benign proxy tasks can shine light on capabilities of concern and the effectiveness of safeguards while avoiding the creation of harmful products (<xref ref-type="bibr" rid="B62">RAND, 2024</xref>). However, there is still ongoing debate about which proxy tasks are most effective for assessing risks related to biological weapons.</p>
<p>
<xref ref-type="bibr" rid="B24">DiEuliis et al. (2024)</xref> highlight the need for robust and multifaceted approaches to evaluating biosecurity risks. Experts in biotechnology are needed to engage in red-teaming exercises, where participants simulate misuse scenarios to uncover vulnerabilities and inform mitigation strategies. They are also needed to feed in to ongoing, dynamic assessments of factors like technological readiness, accessibility, and the expertise required for potential exploitation of a tool. A particularly pressing need exists for benchmarks to evaluate design capabilities. Reliable metrics for assessing the efficacy and safety of AI-driven design tools are scarce, leaving gaps in understanding how these systems might be leveraged for dual-use purposes and presenting opportunities for research and engagement from the biotechnology community.</p>
</sec>
<sec id="s4-5">
<title>Capture of design metadata</title>
<p>Capturing and standardising activity from DNA and protein sequence design tools offers a significant opportunity to enhance both the traceability and accountability of biological work. By cataloging the design process, including the steps taken and decisions made, researchers can create a transparent audit trail that not only strengthens biosecurity but also fosters trust and collaboration within the scientific community (<xref ref-type="bibr" rid="B74">The Nuclear Threat Initiative. NTI, 2024a</xref>). Such audit trails would be invaluable for DNA synthesis providers, enabling them to better assess the intent behind novel sequences submitted for synthesis. By understanding the design process, providers could more effectively evaluate potential risks and ensure compliance with biosecurity standards. Additionally, these records could serve as an important resource for publishing the methods used in scientific research, offering reproducibility and clarity in peer-reviewed studies. Moreover, sharing standardised data on sequence design could promote best practices in DNA and protein engineering, creating a foundation for collaborative innovation while mitigating risks of misuse. This approach aligns with efforts to balance the need for transparency and openness in research with the imperative of safeguarding against the dual-use potential of emerging biotechnologies.</p>
</sec>
<sec id="s4-6">
<title>Current limitations and pathways for enhancement</title>
<p>The dual-use nature of AI in biotechnology raises urgent and complex questions about the effectiveness and consequences of proposed safeguards. For instance, could refusal mechanisms effectively block harmful applications without obstructing critical research? Might managed access models balance the need for security with the imperative of fostering open collaboration? Furthermore, what are the logistical and financial implications of implementing these safeguards at scale, especially for smaller institutions or researchers in resource-constrained settings?</p>
<p>Addressing these challenges will require a concerted effort involving rigorous testing of safeguard mechanisms, broad stakeholder engagement, and the creation of context-specific frameworks tailored to the unique risks and opportunities in biotechnology. Central to these efforts is the active participation of the biotechnology research community. Researchers must help to ground risk assessments in demonstrated and realistic future capabilities, ensuring that mitigation strategies are both effective at reducing risks and compatible with enabling beneficial research. By striking this balance, the community can help ensure that AI in biotechnology advances responsibly, maximising its potential for global good while minimising the risk of misuse.</p>
</sec>
</sec>
<sec sec-type="discussion" id="s5">
<title>Discussion</title>
<p>The dual-use nature of AI in biotechnology underscores the delicate balance between fostering innovation and implementing safeguards. Over-regulation risks stifling progress, particularly in areas like therapeutic discovery and synthetic biology, where access to advanced tools can drive breakthroughs. On the other hand, insufficient safeguards leave the door open to potential misuse, from bioweapon development to accidental creation of harmful agents. Striking this balance requires policies that are flexible enough to adapt to evolving technologies while robust enough to address emerging threats. A proactive, interdisciplinary approach is essential to address the challenges posed by AI in biotechnology. Engagement between AI researchers, bioengineers, and security experts can foster a deeper understanding of dual-use risks and enable the development of practical safeguards.</p>
<p>A proactive approach, modelled on the success of the Asilomar Conference on recombinant DNA (<xref ref-type="bibr" rid="B36">Grace, 2015</xref>), can set the stage for responsible innovation in AI-powered biotechnology. Involving diverse stakeholders early in the conversation ensures that safety and ethical concerns are addressed without stifling progress. Unlike early genetic engineering efforts, current AI applications must prioritise addressing dual-use risks, including potential misuse for bioweapons or harmful applications. Effectively communicating the risks and benefits of AI in biotechnology is critical to building public trust. Simplifying complex issues without oversimplifying their implications can bridge the gap between experts and non-experts. By learning from the successes and challenges of regulating genetic engineering, stakeholders in AI-powered biotechnology can develop more effective and balanced governance frameworks, fostering innovation while minimising risks.</p>
<p>The biotechnology community must recognise its responsibility in this shared effort. Developing skills in public engagement, policy advocacy, and risk assessment is more critical than ever. If biotechnology is regulated entirely from the outside&#x2014;without input from those who understand its complexities&#x2014;it risks being shaped by poorly informed policies that hinder progress. At the same time, the community must take its responsibility seriously, prioritising safety and ethical considerations in every stage of research and development. The consequences of failing to act responsibly could jeopardise both public trust and the future of innovation in this transformative field.</p>
</sec>
</body>
<back>
<sec sec-type="author-contributions" id="s6">
<title>Author contributions</title>
<p>NW: Conceptualization, Investigation, Writing&#x2013;original draft, Writing&#x2013;review and editing.</p>
</sec>
<sec sec-type="funding-information" id="s7">
<title>Funding</title>
<p>The author(s) declare that no financial support was received for the research, authorship, and/or publication of this article.</p>
</sec>
<sec sec-type="COI-statement" id="s8">
<title>Conflict of interest</title>
<p>NW was a consultant in AI safety and biosecurity for the Nuclear Threat Initiative, Google DeepMind, Frontier, Faculty and RAND.</p>
</sec>
<sec sec-type="ai-statement" id="s9">
<title>Generative AI statement</title>
<p>The author(s) declare that Generative AI was used in the creation of this manuscript. To enhance clarity and coherence.</p>
</sec>
<sec sec-type="disclaimer" id="s10">
<title>Publisher&#x2019;s note</title>
<p>All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article, or claim that may be made by its manufacturer, is not guaranteed or endorsed by the publisher.</p>
</sec>
<ref-list>
<title>References</title>
<ref id="B1">
<citation citation-type="web">
<collab>Anthropic</collab> (<year>2024</year>). <article-title>A new initiative for developing third-party model evaluations</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.anthropic.com/news/a-new-initiative-for-developing-third-party-model-evaluations">https://www.anthropic.com/news/a-new-initiative-for-developing-third-party-model-evaluations</ext-link> (Accessed November 30, 2024)</comment>
</citation>
</ref>
<ref id="B2">
<citation citation-type="web">
<collab>Huggingface</collab> (<year>2024</year>). <article-title>The AI community building the future</article-title> <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://huggingface.co/">https://huggingface.co/</ext-link> (Accessed November 30, 2024)</comment>
</citation>
</ref>
<ref id="B3">
<citation citation-type="web">
<collab>AISI</collab> (<year>2024</year>). <article-title>The AI Safety Institute (AISI)</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.aisi.gov.uk/">https://www.aisi.gov.uk/</ext-link> (Accessed November 30, 2024)</comment>
</citation>
</ref>
<ref id="B4">
<citation citation-type="web">
<collab>AI Policy Perspectives</collab> (<year>2024</year>). <article-title>A new golden age of discovery</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.aipolicyperspectives.com/p/a-new-golden-age-of-discovery">https://www.aipolicyperspectives.com/p/a-new-golden-age-of-discovery</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B5">
<citation citation-type="book">
<collab>AI Safety Summit</collab> (<year>2023</year>). <source>Capabilities and risks from frontier AI</source>. <publisher-loc>United Kingdom</publisher-loc>: <publisher-name>DSIT</publisher-name>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://assets.publishing.service.gov.uk/media/65395abae6c968000daa9b25/frontier-ai-capabilities-risks-report.pdf">https://assets.publishing.service.gov.uk/media/65395abae6c968000daa9b25/frontier-ai-capabilities-risks-report.pdf</ext-link>.</comment>
</citation>
</ref>
<ref id="B6">
<citation citation-type="web">
<collab>AISI Japan</collab> (<year>2024</year>). <article-title>AISI Japan - AI safety Institute</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://aisi.go.jp/">https://aisi.go.jp/</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B7">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Alipanahi</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Delong</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Weirauch</surname>
<given-names>M. T.</given-names>
</name>
<name>
<surname>Frey</surname>
<given-names>B. J.</given-names>
</name>
</person-group> (<year>2015</year>). <article-title>Predicting the sequence specificities of DNA- and RNA-binding proteins by deep learning</article-title>. <source>Nat. Biotechnol.</source> <volume>33</volume> (<issue>8</issue>), <fpage>831</fpage>&#x2013;<lpage>838</lpage>. <pub-id pub-id-type="doi">10.1038/nbt.3300</pub-id>
</citation>
</ref>
<ref id="B8">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Alley</surname>
<given-names>E. C.</given-names>
</name>
<name>
<surname>Turpin</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Liu</surname>
<given-names>A. B.</given-names>
</name>
<name>
<surname>Kulp-McDowall</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Swett</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Edison</surname>
<given-names>R.</given-names>
</name>
<etal/>
</person-group> (<year>2020</year>). <article-title>A machine learning toolkit for genetic engineering attribution to facilitate biosecurity</article-title>. <source>Nat. Commun.</source> <volume>11</volume> (<issue>1</issue>), <fpage>6293</fpage>. <pub-id pub-id-type="doi">10.1038/s41467-020-19612-0</pub-id>
</citation>
</ref>
<ref id="B9">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Anonymous</surname>
</name>
</person-group> (<year>2024</year>). <article-title>AlphaFold3 - why did Nature publish it without its code?</article-title>. <source>Nature</source>. <volume>629</volume> (<issue>8013</issue>), <fpage>728</fpage>. <pub-id pub-id-type="doi">10.1038/d41586-024-01463-0</pub-id>
</citation>
</ref>
<ref id="B10">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Baker</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Church</surname>
<given-names>G.</given-names>
</name>
</person-group> (<year>2024</year>). <article-title>Protein design meets biosecurity</article-title>. <source>Science</source> <volume>383</volume> (<issue>6681</issue>), <fpage>349</fpage>. <pub-id pub-id-type="doi">10.1126/science.ado1671</pub-id>
</citation>
</ref>
<ref id="B11">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Ben Ouagrham-Gormley</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2014</year>). <source>Barriers to bioweapons: the challenges of expertise and organization for weapons development</source>. <publisher-loc>Ithaca, NY</publisher-loc>: <publisher-name>Cornell University Press</publisher-name>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://academic.oup.com/cornell-scholarship-online/book/16600">https://academic.oup.com/cornell-scholarship-online/book/16600</ext-link> (Accessed September 29, 2024)</comment>.</citation>
</ref>
<ref id="B12">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Berg</surname>
<given-names>F.</given-names>
</name>
<name>
<surname>Kappler</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2024</year>). &#x201c;<article-title>Future biological and chemical weapons</article-title>,&#x201d; in <source>Ciottone&#x2019;s disaster medicine</source> (<publisher-name>Elsevier</publisher-name>), <fpage>520</fpage>&#x2013;<lpage>530</lpage>. <pub-id pub-id-type="doi">10.1016/B978-0-323-80932-0.00083-5</pub-id>
</citation>
</ref>
<ref id="B13">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Bileschi</surname>
<given-names>M. L.</given-names>
</name>
<name>
<surname>Belanger</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Bryant</surname>
<given-names>D. H.</given-names>
</name>
<name>
<surname>Sanderson</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Carter</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Sculley</surname>
<given-names>D.</given-names>
</name>
<etal/>
</person-group> (<year>2022</year>). <article-title>Using deep learning to annotate the protein universe</article-title>. <source>Nat. Biotechnol.</source> <volume>40</volume> (<issue>6</issue>), <fpage>932</fpage>&#x2013;<lpage>937</lpage>. <pub-id pub-id-type="doi">10.1038/s41587-021-01179-w</pub-id>
</citation>
</ref>
<ref id="B15">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Brent</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Greg McKelvey</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Matheny</surname>
<given-names>A. J.</given-names>
</name>
</person-group> (<year>2024</year>). <source>The new bioweapons: how synthetic biology could destabilize the world essays</source> <volume>103</volume>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.foreignaffairs.com/world/new-bioweapons-covid-biology">https://www.foreignaffairs.com/world/new-bioweapons-covid-biology</ext-link>.</comment>
</citation>
</ref>
<ref id="B16">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Callaway</surname>
<given-names>E.</given-names>
</name>
</person-group> (<year>2024</year>). <article-title>Who will make AlphaFold3 open source? Scientists race to crack AI model</article-title>. <source>Nature</source> <volume>630</volume> (<issue>8015</issue>), <fpage>14</fpage>&#x2013;<lpage>15</lpage>. <pub-id pub-id-type="doi">10.1038/d41586-024-01555-x</pub-id>
</citation>
</ref>
<ref id="B17">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Carter</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Wheeler</surname>
<given-names>N. E.</given-names>
</name>
<name>
<surname>Chwalek</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Isaac</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Yassif</surname>
<given-names>J. M.</given-names>
</name>
</person-group> (<year>2023</year>). <source>The convergence of artificial intelligence and the life sciences</source>. <publisher-loc>United States</publisher-loc>: <publisher-name>NTI &#x7c; bio</publisher-name>.</citation>
</ref>
<ref id="B18">
<citation citation-type="web">
<collab>Chatham House &#x2013; International Affairs Think Tank</collab> (<year>2024</year>). <article-title>Russian cyber and information warfare in practice</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.chathamhouse.org/2023/12/russian-cyber-and-information-warfare-practice/04-information-confrontation-human-effects">https://www.chathamhouse.org/2023/12/russian-cyber-and-information-warfare-practice/04-information-confrontation-human-effects</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B19">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Cheng</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Novati</surname>
<given-names>G.</given-names>
</name>
<name>
<surname>Pan</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Bycroft</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>&#x17d;emgulyt&#x117;</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Applebaum</surname>
<given-names>T.</given-names>
</name>
<etal/>
</person-group> (<year>2023</year>). <article-title>Accurate proteome-wide missense variant effect prediction with AlphaMissense</article-title>. <source>Science</source> <volume>381</volume> (<issue>6664</issue>), <fpage>eadg7492</fpage>. <pub-id pub-id-type="doi">10.1126/science.adg7492</pub-id>
</citation>
</ref>
<ref id="B20">
<citation citation-type="web">
<collab>CLTR</collab> (<year>2024</year>). <article-title>The near-term impact of AI on biological misuse</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.longtermresilience.org/reports/the-near-term-impact-of-ai-on-biological-misuse/">https://www.longtermresilience.org/reports/the-near-term-impact-of-ai-on-biological-misuse/</ext-link> (Accessed October 14, 2024)</comment>.</citation>
</ref>
<ref id="B21">
<citation citation-type="book">
<collab>Committee on Genomics Databases for Bioterrorism Threat Agents, Board on Life Sciences</collab> (<year>2004</year>). <source>Division on earth and life studies, national research Council, national academy of sciences. Seeking security: pathogens, open access, and genome databases</source>. <publisher-loc>Washington, DC</publisher-loc>: <publisher-name>National Academies Press</publisher-name>, <fpage>88</fpage>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://nap.nationalacademies.org/download/11087">https://nap.nationalacademies.org/download/11087</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B22">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Corso</surname>
<given-names>G.</given-names>
</name>
<name>
<surname>St&#xe4;rk</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Jing</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Barzilay</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Jaakkola</surname>
<given-names>T.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>DiffDock: diffusion steps, twists, and turns for molecular docking</article-title>. <source>arXiv [q-bio.BM]</source>. <pub-id pub-id-type="doi">10.48550/arXiv.2210.01776</pub-id>
</citation>
</ref>
<ref id="B23">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Cropper</surname>
<given-names>N. R.</given-names>
</name>
<name>
<surname>Rath</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Teo</surname>
<given-names>R. J. C.</given-names>
</name>
<name>
<surname>Warmbrod</surname>
<given-names>K. L.</given-names>
</name>
<name>
<surname>Lancaster</surname>
<given-names>M. J.</given-names>
</name>
</person-group> (<year>2023</year>). <article-title>A modular-incremental approach to improving compliance verification with the biological weapons convention</article-title>. <source>Health Secur.</source> <volume>21</volume> (<issue>5</issue>), <fpage>421</fpage>&#x2013;<lpage>427</lpage>. <pub-id pub-id-type="doi">10.1089/hs.2023.0078</pub-id>
</citation>
</ref>
<ref id="B24">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>DiEuliis</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Imperiale</surname>
<given-names>M. J.</given-names>
</name>
<name>
<surname>Berger</surname>
<given-names>K. M.</given-names>
</name>
</person-group> (<year>2024</year>). <article-title>Biosecurity assessments for emerging transdisciplinary biotechnologies: revisiting biodefense in an age of synthetic biology</article-title>. <source>Appl. Biosaf.</source> <volume>29</volume> (<issue>3</issue>), <fpage>123</fpage>&#x2013;<lpage>132</lpage>. <pub-id pub-id-type="doi">10.1089/apb.2024.0005</pub-id>
</citation>
</ref>
<ref id="B25">
<citation citation-type="web">
<person-group person-group-type="author">
<name>
<surname>Drexel</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Withers</surname>
<given-names>C.</given-names>
</name>
</person-group> (<year>2024</year>). <article-title>AI and the evolution of biological national security risks: capabilities, thresholds, and interventions</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://s3.us-east-1.amazonaws.com/files.cnas.org/documents/AIBiologicalRisk_2024_Final.pdf">https://s3.us-east-1.amazonaws.com/files.cnas.org/documents/AIBiologicalRisk_2024_Final.pdf</ext-link>.</comment>
</citation>
</ref>
<ref id="B26">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Dubey</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Jauhri</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Pandey</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Kadian</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Al-Dahle</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Letman</surname>
<given-names>A.</given-names>
</name>
<etal/>
</person-group> (<year>2024</year>). <article-title>The Llama 3 herd of models</article-title>. <source>arXiv [cs.AI]</source>. <pub-id pub-id-type="doi">10.48550/arXiv.2407.21783</pub-id>
</citation>
</ref>
<ref id="B27">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Frazer</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Notin</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Dias</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Gomez</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Min</surname>
<given-names>J. K.</given-names>
</name>
<name>
<surname>Brock</surname>
<given-names>K.</given-names>
</name>
<etal/>
</person-group> (<year>2021</year>). <article-title>Disease variant prediction with deep generative models of evolutionary data</article-title>. <source>Nature</source> <volume>599</volume> (<issue>7883</issue>), <fpage>91</fpage>&#x2013;<lpage>95</lpage>. <pub-id pub-id-type="doi">10.1038/s41586-021-04043-8</pub-id>
</citation>
</ref>
<ref id="B28">
<citation citation-type="web">
<collab>Frontier Model Forum</collab> (<year>2024a</year>). <article-title>Issue brief: early best practices for frontier AI safety evaluations</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.frontiermodelforum.org/updates/early-best-practices-for-frontier-ai-safety-evaluations/">https://www.frontiermodelforum.org/updates/early-best-practices-for-frontier-ai-safety-evaluations/</ext-link>(Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B29">
<citation citation-type="web">
<collab>Frontier Model Forum</collab> (<year>2024b</year>). <article-title>Issue brief: foundational security practices</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.frontiermodelforum.org/updates/issue-brief-foundational-security-practices/">https://www.frontiermodelforum.org/updates/issue-brief-foundational-security-practices/</ext-link>(Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B30">
<citation citation-type="web">
<collab>Frontier Model Forum</collab> (<year>2024c</year>). <article-title>Progress update: advancing frontier AI safety in 2024 and beyond</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.frontiermodelforum.org/updates/progress-update-advancing-frontier-ai-safety-in-2024-and-beyond/">https://www.frontiermodelforum.org/updates/progress-update-advancing-frontier-ai-safety-in-2024-and-beyond/</ext-link>(Accessed October 15, 2024)</comment>.</citation>
</ref>
<ref id="B31">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Godbold</surname>
<given-names>G. D.</given-names>
</name>
<name>
<surname>Kappell</surname>
<given-names>A. D.</given-names>
</name>
<name>
<surname>LeSassier</surname>
<given-names>D. S.</given-names>
</name>
<name>
<surname>Treangen</surname>
<given-names>T. J.</given-names>
</name>
<name>
<surname>Ternus</surname>
<given-names>K. L.</given-names>
</name>
</person-group> (<year>2021</year>). <article-title>Categorizing sequences of concern by function to better assess mechanisms of microbial pathogenesis</article-title>. <source>Infect. Immun.</source> <volume>15</volume>, <fpage>e0033421</fpage>. <pub-id pub-id-type="doi">10.1128/IAI.00334-21</pub-id>
</citation>
</ref>
<ref id="B32">
<citation citation-type="book">
<collab>GOV.UK</collab> (<year>2024a</year>). <source>New commitment to deepen work on severe AI risks concludes AI Seoul Summit</source>. <publisher-name>Department for Science, Technology</publisher-name>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.gov.uk/government/news/new-commitmentto-deepen-work-on-severe-ai-risks-concludes-ai-seoul-summit">https://www.gov.uk/government/news/new-commitmentto-deepen-work-on-severe-ai-risks-concludes-ai-seoul-summit</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B33">
<citation citation-type="web">
<collab>Google Cloud</collab> (<year>2024</year>). <article-title>Gemini for google cloud and responsible AI</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://cloud.google.com/gemini/docs/discover/responsible-ai">https://cloud.google.com/gemini/docs/discover/responsible-ai</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B34">
<citation citation-type="web">
<collab>GOV.UK</collab> (<year>2023</year>). <article-title>About the AI safety summit 2023</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.gov.uk/government/topical-events/ai-safety-summit-2023/about">https://www.gov.uk/government/topical-events/ai-safety-summit-2023/about</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B35">
<citation citation-type="web">
<collab>GOV.UK</collab> (<year>2024b</year>). <article-title>UK screening guidance on synthetic nucleic acids for users and providers</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.gov.uk/government/publications/uk-screening-guidance-on-synthetic-nucleic-acids/uk-screening-guidance-on-synthetic-nucleic-acids-for-users-and-providers">https://www.gov.uk/government/publications/uk-screening-guidance-on-synthetic-nucleic-acids/uk-screening-guidance-on-synthetic-nucleic-acids-for-users-and-providers</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B36">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Grace</surname>
<given-names>K.</given-names>
</name>
</person-group> (<year>2015</year>). <source>The Asilomar conference: a case study in risk mitigation</source>. <publisher-loc>Berkeley, CA</publisher-loc>: <publisher-name>Machine Intelligence Research Institute</publisher-name>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://intelligence.org/files/TheAsilomarConference.pdf">https://intelligence.org/files/TheAsilomarConference.pdf</ext-link>.</comment>
</citation>
</ref>
<ref id="B37">
<citation citation-type="web">
<person-group person-group-type="author">
<name>
<surname>Grin</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Howard</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Paterson</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Swanson</surname>
<given-names>N.</given-names>
</name>
<name>
<surname>Bloxwich</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Jumper</surname>
<given-names>J.</given-names>
</name>
<etal/>
</person-group> (<year>2024</year>). <article-title>Our approach to biosecurity for AlphaFold 3</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://storage.googleapis.com/deepmind-media/DeepMind.com/Blog/alphafold-3-predicts-the-structure-and-interactions-of-all-lifes-molecules/Our-approach-to-biosecurity-for-AlphaFold-3-08052024">https://storage.googleapis.com/deepmind-media/DeepMind.com/Blog/alphafold-3-predicts-the-structure-and-interactions-of-all-lifes-molecules/Our-approach-to-biosecurity-for-AlphaFold-3-08052024</ext-link>.</comment>
</citation>
</ref>
<ref id="B38">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>HamediRad</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Chao</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Weisberg</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Lian</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Sinha</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Zhao</surname>
<given-names>H.</given-names>
</name>
</person-group> (<year>2019</year>). <article-title>Towards a fully automated algorithm driven platform for biosystems design</article-title>. <source>Nat. Commun.</source> <volume>10</volume> (<issue>1</issue>), <fpage>5150</fpage>. <pub-id pub-id-type="doi">10.1038/s41467-019-13189-z</pub-id>
</citation>
</ref>
<ref id="B39">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Hayes</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Rao</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Akin</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Sofroniew</surname>
<given-names>N. J.</given-names>
</name>
<name>
<surname>Oktay</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Lin</surname>
<given-names>Z.</given-names>
</name>
<etal/>
</person-group> (<year>2024</year>). <article-title>Simulating 500 million years of evolution with a language model</article-title>. <source>bioRxiv</source>. <pub-id pub-id-type="doi">10.1101/2024.07.01.600583</pub-id>
</citation>
</ref>
<ref id="B40">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Ifargan</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Hafner</surname>
<given-names>L.</given-names>
</name>
<name>
<surname>Kern</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Alcalay</surname>
<given-names>O.</given-names>
</name>
<name>
<surname>Kishony</surname>
<given-names>R.</given-names>
</name>
</person-group> (<year>2024</year>). <article-title>Autonomous LLM-driven research from data to human-verifiable research papers</article-title>. <source>arXiv [q-bio.OT]</source>. <pub-id pub-id-type="doi">10.48550/arXiv.2404.17605</pub-id>
</citation>
</ref>
<ref id="B41">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Inglis</surname>
<given-names>T. J. J.</given-names>
</name>
</person-group> (<year>2024</year>). <article-title>A systematic approach to microbial forensics</article-title>. <source>J. Med. Microbiol.</source> <volume>73</volume> (<issue>2</issue>), <fpage>001802</fpage>. <pub-id pub-id-type="doi">10.1099/jmm.0.001802</pub-id>
</citation>
</ref>
<ref id="B42">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Ingraham</surname>
<given-names>J. B.</given-names>
</name>
<name>
<surname>Baranov</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Costello</surname>
<given-names>Z.</given-names>
</name>
<name>
<surname>Barber</surname>
<given-names>K. W.</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>W.</given-names>
</name>
<name>
<surname>Ismail</surname>
<given-names>A.</given-names>
</name>
<etal/>
</person-group> (<year>2023</year>). <article-title>Illuminating protein space with a programmable generative model</article-title>. <source>Nature</source> <volume>623</volume> (<issue>7989</issue>), <fpage>1070</fpage>&#x2013;<lpage>1078</lpage>. <pub-id pub-id-type="doi">10.1038/s41586-023-06728-8</pub-id>
</citation>
</ref>
<ref id="B43">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Juling</surname>
<given-names>D.</given-names>
</name>
</person-group> (<year>2023</year>). <article-title>Future bioterror and biowarfare threats for NATO&#x2019;s armed forces until 2030</article-title>. <source>J. Adv. Mil. Stud.</source> <volume>14</volume> (<issue>1</issue>), <fpage>118</fpage>&#x2013;<lpage>143</lpage>. <pub-id pub-id-type="doi">10.21140/mcuj.20231401005</pub-id>
</citation>
</ref>
<ref id="B44">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Jumper</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Evans</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Pritzel</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Green</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Figurnov</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Ronneberger</surname>
<given-names>O.</given-names>
</name>
<etal/>
</person-group> (<year>2021</year>). <article-title>Highly accurate protein structure prediction with AlphaFold</article-title>. <source>Nature</source> <volume>596</volume> (<issue>7873</issue>), <fpage>583</fpage>&#x2013;<lpage>589</lpage>. <pub-id pub-id-type="doi">10.1038/s41586-021-03819-2</pub-id>
</citation>
</ref>
<ref id="B45">
<citation citation-type="web">
<collab>Kaggle</collab> (<year>2024</year>). <article-title>Your machine learning and data science community</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.kaggle.com/">https://www.kaggle.com/</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B46">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Koblentz</surname>
<given-names>G. D.</given-names>
</name>
</person-group> (<year>2009</year>). <source>Living weapons: biological warfare and international security</source>. <publisher-loc>Ithaca, NY</publisher-loc>: <publisher-name>Cornell University Press</publisher-name>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.jstor.org/stable/10.7591/j.ctt7z9s0">https://www.jstor.org/stable/10.7591/j.ctt7z9s0</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B47">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Krishna</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Ahern</surname>
<given-names>W.</given-names>
</name>
<name>
<surname>Sturmfels</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Venkatesh</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Kalvet</surname>
<given-names>I.</given-names>
</name>
<etal/>
</person-group> (<year>2024</year>). <article-title>Generalized biomolecular modeling and design with RoseTTAFold All-Atom</article-title>. <source>Science</source> <volume>384</volume> (<issue>6693</issue>), <fpage>eadl2528</fpage>. <pub-id pub-id-type="doi">10.1126/science.adl2528</pub-id>
</citation>
</ref>
<ref id="B48">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Lee</surname>
<given-names>D. H.</given-names>
</name>
<name>
<surname>Kim</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Sung</surname>
<given-names>B. H.</given-names>
</name>
<name>
<surname>Cho</surname>
<given-names>B. K.</given-names>
</name>
<name>
<surname>Lee</surname>
<given-names>S. G.</given-names>
</name>
</person-group> (<year>2023</year>). <article-title>Biofoundries: bridging automation and biomanufacturing in synthetic biology</article-title>. <source>Biotechnol. Bioprocess Eng.</source> <volume>28</volume> (<issue>6</issue>), <fpage>892</fpage>&#x2013;<lpage>904</lpage>. <pub-id pub-id-type="doi">10.1007/s12257-023-0226-x</pub-id>
</citation>
</ref>
<ref id="B49">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Maxmen</surname>
<given-names>A.</given-names>
</name>
</person-group> (<year>2021</year>). <article-title>Why some researchers oppose unrestricted sharing of coronavirus genome data</article-title>. <source>Nature</source> <volume>593</volume> (<issue>7858</issue>), <fpage>176</fpage>&#x2013;<lpage>177</lpage>. <pub-id pub-id-type="doi">10.1038/d41586-021-01194-6</pub-id>
</citation>
</ref>
<ref id="B50">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Mouton</surname>
<given-names>C. A.</given-names>
</name>
<name>
<surname>Lucas</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Guest</surname>
<given-names>E.</given-names>
</name>
</person-group> (<year>2024</year>). <source>The operational risks of AI in large-scale biological attacks A red-team approach</source>. <publisher-loc>United States</publisher-loc>: <publisher-name>RAND</publisher-name>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.rand.org/content/dam/rand/pubs/research_reports/RRA2900/RRA2977-2/RAND_RRA2977-2.pdf">https://www.rand.org/content/dam/rand/pubs/research_reports/RRA2900/RRA2977-2/RAND_RRA2977-2.pdf</ext-link>.</comment>
</citation>
</ref>
<ref id="B51">
<citation citation-type="book">
<collab>National Research Council (US)</collab> (<year>2007</year>). &#x201c;<article-title>Committee on a new government-university partnership for science, security. Biosecurity and dual-use research in the life sciences</article-title>,&#x201d; in <source>Science and security in a post 9/11 world: a report based on regional discussions between the science and security communities</source> (<publisher-loc>Washington, DC</publisher-loc>: <publisher-name>National Academies Press US</publisher-name>). <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.ncbi.nlm.nih.gov/books/NBK11496/">https://www.ncbi.nlm.nih.gov/books/NBK11496/</ext-link>(Accessed October 21, 2024)</comment>.</citation>
</ref>
<ref id="B52">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Nguyen</surname>
<given-names>E.</given-names>
</name>
<name>
<surname>Poli</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Durrant</surname>
<given-names>M. G.</given-names>
</name>
<name>
<surname>Thomas</surname>
<given-names>A. W.</given-names>
</name>
<name>
<surname>Kang</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Sullivan</surname>
<given-names>J.</given-names>
</name>
<etal/>
</person-group> (<year>2024</year>). <article-title>Sequence modeling and design from molecular to genome scale with Evo</article-title>. <source>bioRxiv</source>. <pub-id pub-id-type="doi">10.1101/2024.02.27.582234</pub-id>
</citation>
</ref>
<ref id="B14">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>NIST</surname>
<given-names>R. F.</given-names>
</name>
</person-group> (<year>2023</year>). <source>U.S. Artificial intelligence safety Institute</source>. <publisher-loc>United States</publisher-loc>: <publisher-name>NIST</publisher-name>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.nist.gov/aisi">https://www.nist.gov/aisi</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B53">
<citation citation-type="web">
<collab>NTIbio</collab> (<year>2024</year>). <article-title>AIxBio global Forum structure and goals</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.nti.org/wp-content/uploads/2024/07/AI_Bio-Global-Forum-Structure-and-Goals_White-Paper.pdf">https://www.nti.org/wp-content/uploads/2024/07/AI_Bio-Global-Forum-Structure-and-Goals_White-Paper.pdf</ext-link>.</comment>
</citation>
</ref>
<ref id="B54">
<citation citation-type="journal">
<collab>Nature</collab> (<year>2024</year>). <article-title>AI pioneers win 2024 Nobel prizes</article-title>. <source>Nat. Mach. Intell.</source> <volume>6</volume>(<issue>11</issue>), <fpage>1271</fpage>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.nature.com/articles/s42256-024-00945-0">https://www.nature.com/articles/s42256-024-00945-0</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B55">
<citation citation-type="book">
<collab>OECD</collab> (<year>2023</year>). <source>Artificial intelligence in science: challenges, opportunities and the future of research</source>. <publisher-loc>Paris</publisher-loc>: <publisher-name>OECD</publisher-name>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.oecd-ilibrary.org/science-and-technology/artificial-intelligence-in-science_a8d820bd-en%20(Accessed%20January%206,%202024).Refstyled.html">https://www.oecd-ilibrary.org/science-and-technology/artificial-intelligence-in-science_a8d820bd-en (Accessed January 6, 2024).Refstyled.html</ext-link>
</comment>
</citation>
</ref>
<ref id="B56">
<citation citation-type="web">
<collab>OpenAI</collab> (<year>2024</year>). <article-title>OpenAI o1 system card</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://assets.ctfassets.net/kftzwdyauwt9/67qJD51Aur3eIc96iOfeOP/71551c3d223cd97e591aa89567306912/o1_system_card.pdf">https://assets.ctfassets.net/kftzwdyauwt9/67qJD51Aur3eIc96iOfeOP/71551c3d223cd97e591aa89567306912/o1_system_card.pdf</ext-link>.</comment>
</citation>
</ref>
<ref id="B57">
<citation citation-type="web">
<collab>ORCID</collab> (<year>2024</year>). <article-title>ORCID&#x2019;s Global Participation Fund</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://orcid.org/">https://orcid.org/</ext-link> (Accessed October 21, 2024)</comment>.</citation>
</ref>
<ref id="B58">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Pannu</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Bloomfield</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Zhu</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>MacKnight</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Gomes</surname>
<given-names>G.</given-names>
</name>
<name>
<surname>Cicero</surname>
<given-names>A.</given-names>
</name>
<etal/>
</person-group> (<year>2024</year>). <article-title>Prioritizing high-consequence biological capabilities in evaluations of artificial intelligence models</article-title>. <source>arXiv [cs.CY]</source>. <pub-id pub-id-type="doi">10.48550/arXiv.2407.13059</pub-id>
</citation>
</ref>
<ref id="B59">
<citation citation-type="journal">
<collab>PathoLM</collab> (<year>2024</year>). <article-title>Identifying pathogenicity from the DNA sequence through the genome foundation</article-title>. <source>Model</source>. <pub-id pub-id-type="doi">10.48550/arXiv.2406.13133</pub-id>
</citation>
</ref>
<ref id="B60">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Phuong</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Aitchison</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Catt</surname>
<given-names>E.</given-names>
</name>
<name>
<surname>Cogan</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Kaskasoli</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Krakovna</surname>
<given-names>V.</given-names>
</name>
<etal/>
</person-group> (<year>2024</year>). <article-title>Evaluating frontier models for dangerous capabilities</article-title>. <source>arXiv [cs.LG]</source>. <pub-id pub-id-type="doi">10.48550/arXiv.2403.13793</pub-id>
</citation>
</ref>
<ref id="B61">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Poplin</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Chang</surname>
<given-names>P. C.</given-names>
</name>
<name>
<surname>Alexander</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Schwartz</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Colthurst</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Ku</surname>
<given-names>A.</given-names>
</name>
<etal/>
</person-group> (<year>2018</year>). <article-title>A universal SNP and small-indel variant caller using deep neural networks</article-title>. <source>Nat. Biotechnol.</source> <volume>36</volume> (<issue>10</issue>), <fpage>983</fpage>&#x2013;<lpage>987</lpage>. <pub-id pub-id-type="doi">10.1038/nbt.4235</pub-id>
</citation>
</ref>
<ref id="B62">
<citation citation-type="web">
<collab>RAND</collab> (<year>2024</year>). <article-title>On the responsible development and use of chem-bio AI models</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.rand.org/content/dam/rand/pubs/perspectives/PEA3600/PEA3674-1/RAND_PEA3674-1.pdf">https://www.rand.org/content/dam/rand/pubs/perspectives/PEA3600/PEA3674-1/RAND_PEA3674-1.pdf</ext-link>.</comment>
</citation>
</ref>
<ref id="B63">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Rasko</surname>
<given-names>D. A.</given-names>
</name>
<name>
<surname>Worsham</surname>
<given-names>P. L.</given-names>
</name>
<name>
<surname>Abshire</surname>
<given-names>T. G.</given-names>
</name>
<name>
<surname>Stanley</surname>
<given-names>S. T.</given-names>
</name>
<name>
<surname>Bannan</surname>
<given-names>J. D.</given-names>
</name>
<name>
<surname>Wilson</surname>
<given-names>M. R.</given-names>
</name>
<etal/>
</person-group> (<year>2011</year>). <article-title>Bacillus anthracis comparative genome analysis in support of the Amerithrax investigation</article-title>. <source>Proc. Natl. Acad. Sci. U. S. A.</source> <volume>108</volume> (<issue>12</issue>), <fpage>5027</fpage>&#x2013;<lpage>5032</lpage>. <pub-id pub-id-type="doi">10.1073/pnas.1016657108</pub-id>
</citation>
</ref>
<ref id="B64">
<citation citation-type="web">
<collab>Responsible AI x Biodesign</collab> (<year>2024</year>). <article-title>Community Values, Guiding Principles, and Commitments for the Responsible Development of AI for Protein Design</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://responsiblebiodesign.ai/">https://responsiblebiodesign.ai/</ext-link> (Accessed September 29, 2024)</comment>.</citation>
</ref>
<ref id="B65">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Revill</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Jefferson</surname>
<given-names>C.</given-names>
</name>
</person-group> (<year>2014</year>). <article-title>Tacit knowledge and the biological weapons regime</article-title>. <source>Sci. Public Policy</source> <volume>41</volume> (<issue>5</issue>), <fpage>597</fpage>&#x2013;<lpage>610</lpage>. <pub-id pub-id-type="doi">10.1093/scipol/sct090</pub-id>
</citation>
</ref>
<ref id="B66">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Sandbrink</surname>
<given-names>J. B.</given-names>
</name>
</person-group> (<year>2023</year>). <article-title>Artificial intelligence and biological misuse: differentiating risks of language models and biological design tools</article-title>. <source>arXiv [cs.CY]</source>. <pub-id pub-id-type="doi">10.48550/arXiv.2306.13952</pub-id>
</citation>
</ref>
<ref id="B67">
<citation citation-type="web">
<collab>Shaping Europe&#x2019;s digital future</collab> (<year>2024</year>). <article-title>European AI office</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://digital-strategy.ec.europa.eu/en/policies/ai-office#ecl-inpage-tasks-of-the-ai-office">https://digital-strategy.ec.europa.eu/en/policies/ai-office&#x23;ecl-inpage-tasks-of-the-ai-office</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B72">
<citation citation-type="web">
<person-group person-group-type="author">
<name>
<surname>Smith</surname>
<given-names>H.</given-names>
</name>
</person-group> (<year>2019</year>). <article-title>Countering hybrid threats</article-title>. <source>Democracy</source> <volume>95</volume> (<issue>2</issue>), <fpage>255</fpage>&#x2013;<lpage>77</lpage>.</citation>
</ref>
<ref id="B68">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Soice</surname>
<given-names>E. H.</given-names>
</name>
<name>
<surname>Rocha</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Cordova</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Specter</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Esvelt</surname>
<given-names>K. M.</given-names>
</name>
</person-group> (<year>2023</year>). <article-title>Can large language models democratize access to dual-use biotechnology?</article-title> <source>arXiv [cs.CY]</source>. <pub-id pub-id-type="doi">10.48550/arXiv.2306.03809</pub-id>
</citation>
</ref>
<ref id="B69">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Sparkes</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>King</surname>
<given-names>R. D.</given-names>
</name>
<name>
<surname>Aubrey</surname>
<given-names>W.</given-names>
</name>
<name>
<surname>Benway</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Byrne</surname>
<given-names>E.</given-names>
</name>
<name>
<surname>Clare</surname>
<given-names>A.</given-names>
</name>
<etal/>
</person-group> (<year>2010</year>). <article-title>An integrated laboratory robotic system for autonomous discovery of gene function</article-title>. <source>J. Lab. Autom.</source> <volume>15</volume> (<issue>1</issue>), <fpage>33</fpage>&#x2013;<lpage>40</lpage>. <pub-id pub-id-type="doi">10.1016/j.jala.2009.10.001</pub-id>
</citation>
</ref>
<ref id="B70">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Sumida</surname>
<given-names>K. H.</given-names>
</name>
<name>
<surname>N&#xfa;&#xf1;ez-Franco</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Kalvet</surname>
<given-names>I.</given-names>
</name>
<name>
<surname>Pellock</surname>
<given-names>S. J.</given-names>
</name>
<name>
<surname>Wicky</surname>
<given-names>B. I. M.</given-names>
</name>
<name>
<surname>Milles</surname>
<given-names>L. F.</given-names>
</name>
<etal/>
</person-group> (<year>2024</year>). <article-title>Improving protein expression, stability, and function with ProteinMPNN</article-title>. <source>J. Am. Chem. Soc.</source> <volume>146</volume> (<issue>3</issue>), <fpage>2054</fpage>&#x2013;<lpage>2061</lpage>. <pub-id pub-id-type="doi">10.1021/jacs.3c10941</pub-id>
</citation>
</ref>
<ref id="B71">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Thadani</surname>
<given-names>N. N.</given-names>
</name>
<name>
<surname>Gurev</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Notin</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Youssef</surname>
<given-names>N.</given-names>
</name>
<name>
<surname>Rollins</surname>
<given-names>N. J.</given-names>
</name>
<name>
<surname>Ritter</surname>
<given-names>D.</given-names>
</name>
<etal/>
</person-group> (<year>2023</year>). <article-title>Learning from prepandemic data to forecast viral escape</article-title>. <source>Nature</source> <volume>622</volume> (<issue>7984</issue>), <fpage>818</fpage>&#x2013;<lpage>825</lpage>. <pub-id pub-id-type="doi">10.1038/s41586-023-06617-0</pub-id>
</citation>
</ref>
<ref id="B73">
<citation citation-type="web">
<collab>The InterAcademy Partnership (IAP)</collab> (<year>2024</year>). <article-title>Proof of concept meeting on a BWC scientific advisory body procedural report</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.interacademies.org/publication/bwc-proof-concept-procedural-report">https://www.interacademies.org/publication/bwc-proof-concept-procedural-report</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B74">
<citation citation-type="web">
<collab>The Nuclear Threat Initiative. NTI</collab> (<year>2024a</year>). <article-title>Developing guardrails for AI biodesign tools</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.nti.org/analysis/articles/developing-guardrails-for-ai-biodesign-tools/">https://www.nti.org/analysis/articles/developing-guardrails-for-ai-biodesign-tools/</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B75">
<citation citation-type="web">
<collab>The Nuclear Threat Initiative. NTI</collab> (<year>2024b</year>). <article-title>International bio funders Compact</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.nti.org/about/programs-projects/project/bio-funders-compact/">https://www.nti.org/about/programs-projects/project/bio-funders-compact/</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B76">
<citation citation-type="web">
<collab>The White House</collab> (<year>2023</year>). <article-title>Executive order on the safe, secure, and trustworthy development and use of artificial intelligence</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.whitehouse.gov/briefing-room/presidential-actions/2023/10/30/executive-order-on-the-safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence/">https://www.whitehouse.gov/briefing-room/presidential-actions/2023/10/30/executive-order-on-the-safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence/</ext-link> (Accessed November 24, 2023)</comment>.</citation>
</ref>
<ref id="B77">
<citation citation-type="web">
<collab>Together AI</collab> (<year>2024</year>). <article-title>Together AI &#x2013; the AI acceleration cloud - fast inference, fine-tuning and training</article-title> <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.together.ai/">https://www.together.ai/</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B78">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>T&#xf6;r&#xf6;k</surname>
<given-names>T. J.</given-names>
</name>
<name>
<surname>Tauxe</surname>
<given-names>R. V.</given-names>
</name>
<name>
<surname>Wise</surname>
<given-names>R. P.</given-names>
</name>
<name>
<surname>Livengood</surname>
<given-names>J. R.</given-names>
</name>
<name>
<surname>Sokolow</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Mauvais</surname>
<given-names>S.</given-names>
</name>
<etal/>
</person-group> (<year>1997</year>). <article-title>A large community outbreak of salmonellosis caused by intentional contamination of restaurant salad bars</article-title>. <source>JAMA</source> <volume>278</volume> (<issue>5</issue>), <fpage>389</fpage>. <pub-id pub-id-type="doi">10.1001/jama.1997.03550050051033</pub-id>
</citation>
</ref>
<ref id="B79">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Tripathi</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Render</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Nidhi</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Tripathi</surname>
<given-names>V.</given-names>
</name>
</person-group> (<year>2024</year>). <article-title>Microbial genomics: a potential toolkit for forensic investigations</article-title>. <source>Forensic Sci. Med. Pathol.</source> <pub-id pub-id-type="doi">10.1007/s12024-024-00830-7</pub-id>
</citation>
</ref>
<ref id="B80">
<citation citation-type="web">
<collab>UNODA</collab> (<year>2024</year>). <article-title>Biological weapons &#x2013; UNODA</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://disarmament.unoda.org/biological-weapons/">https://disarmament.unoda.org/biological-weapons/</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B81">
<citation citation-type="web">
<collab>U.S. Department of Homeland Security</collab> (<year>2024</year>). <article-title>FACT sheet and report: DHS advances efforts to reduce the risks at the intersection of artificial intelligence and chemical, biological, radiological, and nuclear (CBRN) threats</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.dhs.gov/publication/fact-sheet-and-report-dhs-advances-efforts-reduce-risks-intersection-artificial">https://www.dhs.gov/publication/fact-sheet-and-report-dhs-advances-efforts-reduce-risks-intersection-artificial</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B82">
<citation citation-type="web">
<collab>U.S. HHS</collab> (<year>2023</year>). <article-title>Screening framework guidance for providers and users of synthetic nucleic acids</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://aspr.hhs.gov/legal/synna/Documents/SynNA-Guidance-2023.pdf">https://aspr.hhs.gov/legal/synna/Documents/SynNA-Guidance-2023.pdf</ext-link> (Accessed November 24, 2023)</comment>.</citation>
</ref>
<ref id="B83">
<citation citation-type="web">
<collab>US National Science and Technology Council</collab> (<year>2024</year>). <article-title>Framework for nucleic acid synthesis screening</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.whitehouse.gov/wp-content/uploads/2024/04/Nucleic-Acid_Synthesis_Screening_Framework.pdf">https://www.whitehouse.gov/wp-content/uploads/2024/04/Nucleic-Acid_Synthesis_Screening_Framework.pdf</ext-link>.</comment>
</citation>
</ref>
<ref id="B84">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Wang</surname>
<given-names>Q.</given-names>
</name>
<name>
<surname>Elworth</surname>
<given-names>R. A. L.</given-names>
</name>
<name>
<surname>Liu</surname>
<given-names>T. R.</given-names>
</name>
<name>
<surname>Treangen</surname>
<given-names>T. J.</given-names>
</name>
</person-group> (<year>2019</year>). <source>Faster pan-genome construction for efficient differentiation of naturally occurring and engineered plasmids with plaster</source>. <publisher-name>Schloss Dagstuhl - Leibniz-Zentrum f&#xfc;r Informatik</publisher-name>. <pub-id pub-id-type="doi">10.4230/LIPIcs.WABI.2019.19</pub-id>
</citation>
</ref>
<ref id="B85">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Wang</surname>
<given-names>Q.</given-names>
</name>
<name>
<surname>Kille</surname>
<given-names>B.</given-names>
</name>
<name>
<surname>Liu</surname>
<given-names>T. R.</given-names>
</name>
<name>
<surname>Elworth</surname>
<given-names>R. A. L.</given-names>
</name>
<name>
<surname>Treangen</surname>
<given-names>T. J.</given-names>
</name>
</person-group> (<year>2021</year>). <article-title>PlasmidHawk improves lab of origin prediction of engineered plasmids using sequence alignment</article-title>. <source>Nat. Commun.</source> <volume>12</volume> (<issue>1</issue>), <fpage>1167</fpage>. <pub-id pub-id-type="doi">10.1038/s41467-021-21180-w</pub-id>
</citation>
</ref>
<ref id="B86">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Watson</surname>
<given-names>J. L.</given-names>
</name>
<name>
<surname>Juergens</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Bennett</surname>
<given-names>N. R.</given-names>
</name>
<name>
<surname>Trippe</surname>
<given-names>B. L.</given-names>
</name>
<name>
<surname>Yim</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Eisenach</surname>
<given-names>H. E.</given-names>
</name>
<etal/>
</person-group> (<year>2023</year>). <article-title>
<italic>De novo</italic> design of protein structure and function with RFdiffusion</article-title>. <source>Nature</source> <volume>620</volume> (<issue>7976</issue>), <fpage>1089</fpage>&#x2013;<lpage>1100</lpage>. <pub-id pub-id-type="doi">10.1038/s41586-023-06415-8</pub-id>
</citation>
</ref>
<ref id="B87">
<citation citation-type="web">
<collab>Wellcome</collab> (<year>2024</year>). <article-title>Managing risks of research misuse</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://wellcome.org/grant-funding/guidance/policies-grant-conditions/managing-risks-research-misuse?utm_source=chatgpt.com">https://wellcome.org/grant-funding/guidance/policies-grant-conditions/managing-risks-research-misuse?utm_source&#x3d;chatgpt.com</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B88">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Wheeler</surname>
<given-names>N. E.</given-names>
</name>
<name>
<surname>Bartling</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Carter</surname>
<given-names>S. R.</given-names>
</name>
<name>
<surname>Clore</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Diggans</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Flyangolts</surname>
<given-names>K.</given-names>
</name>
<etal/>
</person-group> (<year>2024</year>). <article-title>Progress and prospects for a nucleic acid screening test set</article-title>. <source>Appl. Biosaf.</source> <volume>29</volume>, <fpage>133</fpage>&#x2013;<lpage>141</lpage>. <pub-id pub-id-type="doi">10.1089/apb.2023.0033</pub-id>
</citation>
</ref>
<ref id="B89">
<citation citation-type="book">
<collab>WHO</collab> (<year>2022a</year>). <source>Global guidance framework for the responsible use of the life sciences: mitigating biorisks and governing dual-use research</source>. <publisher-loc>Geneva</publisher-loc>: <publisher-name>WHO</publisher-name>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://play.google.com/store/books/details?id=vUiKEAAAQBAJ">https://play.google.com/store/books/details?id&#x3d;vUiKEAAAQBAJ</ext-link>.</comment>
</citation>
</ref>
<ref id="B90">
<citation citation-type="book">
<collab>WHO</collab> (<year>2022b</year>). <source>WHO guiding principles for pathogen genome data sharing</source>. <publisher-name>World Health Organization</publisher-name>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.who.int/publications/i/item/9789240061743?utm_source=chatgpt.com">https://www.who.int/publications/i/item/9789240061743?utm_source&#x3d;chatgpt.com</ext-link> (Accessed November 30, 2024)</comment>.</citation>
</ref>
<ref id="B91">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Williams</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Bilsland</surname>
<given-names>E.</given-names>
</name>
<name>
<surname>Sparkes</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Aubrey</surname>
<given-names>W.</given-names>
</name>
<name>
<surname>Young</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Soldatova</surname>
<given-names>L. N.</given-names>
</name>
<etal/>
</person-group> (<year>2015</year>). <article-title>Cheaper faster drug development validated by the repositioning of drugs against neglected tropical diseases</article-title>. <source>J. R. Soc. Interface</source> <volume>12</volume> (<issue>104</issue>), <fpage>20141289</fpage>. <pub-id pub-id-type="doi">10.1098/rsif.2014.1289</pub-id>
</citation>
</ref>
<ref id="B92">
<citation citation-type="web">
<person-group person-group-type="author">
<name>
<surname>Workman</surname>
<given-names>K.</given-names>
</name>
</person-group>
<collab>LatchBio.</collab> (<year>2024</year>). <article-title>Engineering AAVs with Evo and AlphaFold</article-title>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://blog.latch.bio/p/engineering-aavs-with-evo-and-alphafold">https://blog.latch.bio/p/engineering-aavs-with-evo-and-alphafold</ext-link> (Accessed October 14, 2024)</comment>.</citation>
</ref>
<ref id="B93">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Zambaldi</surname>
<given-names>V.</given-names>
</name>
<name>
<surname>La</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Chu</surname>
<given-names>A. E.</given-names>
</name>
<name>
<surname>Patani</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Danson</surname>
<given-names>A. E.</given-names>
</name>
<name>
<surname>Kwan</surname>
<given-names>T. O. C.</given-names>
</name>
<etal/>
</person-group> (<year>2024</year>). <article-title>
<italic>De novo</italic> design of high-affinity protein binders with AlphaProteo</article-title>. <source>arXiv [q-bio.BM]</source>. <pub-id pub-id-type="doi">10.48550/arXiv.2409.08022</pub-id>
</citation>
</ref>
</ref-list>
</back>
</article>