
The next frontier AI safety fight may not be about chatbots saying the wrong thing. It may be about whether powerful models can help people design or obtain dangerous biological materials.
The Financial Times reports that AI companies including OpenAI, Anthropic and Google DeepMind are racing to tighten safeguards around biological risk. The fear is not that today’s public chatbots can casually create a bioweapon, but that increasingly capable scientific models could lower the barrier for people with harmful intent.
OpenAI has already published work on biosecurity evaluations for AI systems, including efforts to test whether models can meaningfully assist with dangerous biological workflows. Anthropic has also discussed frontier threat red-teaming, while Google DeepMind has outlined its approach to frontier AI and biosecurity.
This is a difficult area because AI can do enormous good in biology. The same systems that help scientists understand proteins, search literature, design experiments or speed drug discovery can also make certain dangerous knowledge easier to find and combine.
That is why the safety question is not simply whether a model mentions a harmful topic. It is whether the model can help a user move through a sequence of steps that makes a dangerous project more practical. A refusal at the final answer is not enough if the system has already helped with planning, sourcing, troubleshooting or experiment design.
The problem also shows why open and closed AI systems create different tradeoffs. Open models can democratise access and reduce dependence on a few companies, a point we explored in our open-weight AI explainer. But once powerful models are widely available, it becomes much harder to control how they are modified or used.
Closed labs have more control over access, logging and policy enforcement. But closed labs also concentrate power and require users to trust private companies to define safety rules. Neither approach is perfect.
The likely answer will be a mix of evaluations, access controls, model safeguards, expert red-teaming, government standards and stronger rules around biological materials themselves. AI companies cannot solve biosecurity alone because dangerous biology does not begin and end inside a chatbot.
This also connects to the broader pattern of AI risk moving from theoretical debate into product decisions. Cybersecurity restrictions, agent containment and now biological safeguards all point in the same direction. Frontier AI is becoming powerful enough that release decisions are becoming public-safety decisions.
For readers, the important point is that AI safety is not only about whether a model is polite, balanced or politically neutral. The bigger issue is whether it can materially increase someone’s ability to cause harm. That is why the biosecurity race deserves attention before the worst-case scenario becomes less hypothetical.







