Understanding the Theoretical Limits of AI-Enabled Pathogen Design: Insights from a Delphi Study
RAND Health Quarterly, 2025; 13(1):10
RAND Health Quarterly, 2025; 13(1):10
RAND Health Quarterly is an online-only journal dedicated to showcasing the breadth of health research and policy analysis conducted RAND-wide.
More in this issueConcerns that artificial intelligence (AI) might enable pathogen design are increasing, but risks and timelines remain unclear. In this study, the authors present findings from a Delphi study designed to assess the near-term limits of AI-enabled biological design (AIxBio). Rather than forecasting specific risks, the authors' central objective was to identify which biological and AI-related constraints might serve as hard or persistent barriers to this specific misuse. To do so, they conducted two parallel Delphi elicitations, engaging experts in biology and AI to independently and comparatively evaluate the limits that each field faces. The authors asked participants in the study to assess the validity and applicability of a set of proposed constraints within the near-term future (from 2025 to 2027). The constraints included biological trade-offs, such as transmissibility and environmental stability, and technical challenges in data availability and AI model generalization.
The overarching goal of this study is to inform policy and risk analysis by clarifying which scenarios fall outside the plausible envelope of near-future capabilities and which will remain impossible indefinitely. By focusing on what might be impossible or unlikely, this research can help refine the scope of biosecurity planning and improve the signal-to-noise ratio in discussions about AIxBio.
This study presents the findings from a structured expert elicitation designed to assess the near-term limits of artificial intelligence–(AI)-assisted and AI-driven biological design, focusing on the feasibility of engineering novel pathogens. Motivated by increasing concern about the dual-use potential of AI in bioengineering, we sought to distinguish among impossible threats, theoretically possible but implausible threats, and threats that warrant concrete risk mitigation now or in the near-term future. Rather than forecasting specific risks, our central objective was to identify which biological and AI-related constraints might serve as hard or persistent barriers to misuse.
To do so, we conducted two parallel Delphi elicitations, engaging experts in biology and in AI to independently and comparatively evaluate the limits that each field faces. We asked the participants to assess the validity and applicability of a set of proposed constraints that included biological trade-offs, such as transmissibility and environmental stability, and technical challenges in data availability and AI model generalization. We determined the time horizon for this assessment to extend from 2025 to 2027, a period in which substantial advances are plausible but full autonomy in biological design by AI is unlikely.
The overarching goal of this effort is to inform policy and risk analysis by clarifying which scenarios fall outside the plausible envelope of near-future capabilities and which will remain impossible indefinitely. By focusing on what might be impossible or unlikely, this work aims to help refine the scope of biosecurity planning and improve the signal-to-noise ratio in discussions about AI-assisted biological design.
We employed the Delphi method to elicit expert judgment on the limits of AI-enabled pathogen design, drawing from two distinct panels: one composed of experts in biology and bioengineering and the other in AI and computational biology. One limitation of this work is that the participant groups were small (10 to 12 members per group) and did not include participants from large AI companies. Participants were asked to evaluate a curated list of proposed limits along two dimensions: (1) validity (whether the limit is likely to be real, either in the near term or fundamentally) and (2) applicability (whether the limit, if valid, would meaningfully constrain capabilities). Our Delphi study was designed not to force consensus but to identify areas of agreement and persistent disagreement and underlying rationales. Although small and interdisciplinary by design, the elicitations provided qualitative and semiquantitative insight into the boundaries of what is currently (as of 2025) and plausibly possible in terms of using AI in the domain of biological threat design and what will remain implausible, even in the future.
In this section, we summarize our findings based on the responses of the experts who participated in the Delphi study.
Despite growing concerns about AIxBio, expert assessments from our elicitation indicated that many of the most-extreme speculative scenarios—such as autonomous AI systems independently designing radically novel pathogens—remain implausible within the next one to two years, but advances in AI systems and other types of progress could change the risk landscape greatly and should be monitored closely. Current and near-future AI tools are more likely to serve as accelerators for already capable actors rather than as independent agents of risk, primarily enhancing the speed and efficiency of optimizing known biological threats.
Some experts anticipated rapid gains in AI capabilities, but there was widespread uncertainty about the pace and direction of such progress. Most experts emphasized that any projections beyond the near term (i.e., from 2025 to 2027) are highly speculative.
Our results show that the two most-immediate governance needs are prioritizing the monitoring of scientific progress and future risks and mitigating the most-plausible and most-actionable risk pathways—specifically, the use of AI tools to assist in optimizing or modifying existing pathogens.
For monitoring changes to risk, the most-promising areas to monitor are
Advances in any of these areas will indicate that current limits have been weakened or removed.
In the near term, researchers should clarify where hard limits exist, with a particular focus on the intersection of biological and AI constraints. Such clarification can significantly sharpen threat models and help policymakers focus on credible misuse cases. In this context, we found that biological data infrastructure emerges as a key leverage point: The quality, accessibility, and oversight of genomic and experimental data will shape both the capabilities and the risks of AI-assisted bioengineering.
In addition, there are immediate and general benefits to reinforcing traditional biosecurity safeguards as AI tools increasingly lower the threshold for sophisticated misuse. Strengthening and globally coordinating gene-synthesis screening can help prevent the malicious or accidental creation of risky sequences, especially considering that participants agreed that AI already accelerates iterative design. As a result of these risks, emerging cloud and automated lab platforms should be subject to oversight frameworks that include identity verification, experiment prescreening, and audit trails to prevent or at least detect misuse. In parallel, increased and sustained investment in core pandemic preparedness—such as rapid diagnostics, scalable vaccine platforms, and public health surge capacity—provides a robust backstop. This investment comes with immediate benefits for reducing the disease burden from nonengineered pathogens and new natural outbreaks, and it could reduce the impact of any AI-assisted biological threat that might bypass upstream controls.
In addition, cultivating a culture of responsible AI use in biological research is essential, particularly among developers and institutions deploying increasingly capable tools. Encouraging interdisciplinary coordination—especially among AI practitioners, biologists, and biosecurity experts—can help bridge gaps in understanding and align technical capabilities with risk awareness. This cross-domain engagement is foundational for building flexible governance frameworks that can adapt to fast-moving developments through such mechanisms as horizon scanning and iterative threat modeling. Although self-governance approaches (such as predeployment review and responsible disclosure) are also important and should play larger roles in fostering safety norms, they are inherently limited in anticipating novel misuse pathways or constraining determined actors, including state-sponsored programs. This underscores the need for complementary regulatory and institutional safeguards to be put in place as quickly as possible.
This research was independently initiated using gifts for research at RAND's discretion from philanthropic supporter Open Philanthropy, as well as gifts from other RAND supporters and income from operations. The research was conducted by the Meselson Center within RAND Global and Emerging Risks.
More in this issueRAND Health Quarterly is produced by the RAND Corporation. ISSN 2162-8254.
Explore RAND Health Quarterly articles on PubMed