AI Scientist Agents and Biosecurity: Capabilities, Risks, and Governance for Autonomous Labs
Abstract
The transition from conversational large language models to tool-using AI scientist agents has increased both the capabilities and the risks of AI-driven science. This position paper argues that current biosecurity debates often conflate informational assistance with executable scientific agency. That distinction matters: today's AI scientist agents are increasingly effective at structured orchestration, long-horizon planning, and interaction with robotic or software-mediated workflows, but they still struggle with tacit wet-lab manipulation, ambiguous physical feedback, and open-ended troubleshooting. As a result, they do not reduce barriers uniformly across actors. This perspective shifts near-term concern away from generic “LLMs enable bioterrorism” narratives and toward actor–infrastructure pairings that can combine agentic systems with structured execution environments, especially well-funded non-state groups and some agricultural misuse pathways. We use this argument to offer a structured critique of prevailing threat narratives, a prioritization of near-term biosecurity risks under current AI scientist capabilities, and recommendations for governing the execution layer of AI-driven science through stronger synthesis screening, better biosurveillance, and greater investment in AI-assisted defensive response.