Building a Defense-in-Depth Biosecurity Strategy for the AI Era

Steph Guerra, Aurelia Attal-Juncqua, John P. Tarangelo, Casey Aveggio, Katie Dammer, David Glickstein

ResearchPublished Aug 18, 2026

Cover: Building a Defense-in-Depth Biosecurity Strategy for the AI Era

The convergence of artificial intelligence (AI) and biology offers great promise for medicine and public health, including the potential to yield transformative societal benefits. Yet this same convergence could introduce serious global health and national security risks. As capabilities continue to advance, AI-enabled biotechnology might lower the technical, operational, and motivational barriers to creating biological weapons. It might also enable high-consequence attacks involving enhanced or novel pathogens. The dual-use nature of biotechnology requires proactive mitigation measures to counter these threats.

In this report, the authors develop a defense-in-depth mitigation strategy that is robust, complementary, and deployable across a wide variety of threat scenarios. To create the strategy, the authors assessed the capabilities of various actor types across different steps of the bioweapon-development pathway prior to an attack, from ideation to weaponization. They also examined how different mitigations could add friction to primary milestones that nefarious actors must bypass to successfully execute an attack using AI-enabled biological weapons.

The authors describe a network of nine mitigations, each with their own strengths and weaknesses and areas of mutual reinforcement, and propose next steps for how decisionmakers in the public and private sectors can work collaboratively to advance this strategy.

Key Takeaways

  • Different threat actors require different prevention mechanisms. Resource-constrained individuals might be thwarted at material or information access chokepoints. However, technologically sophisticated or well-resourced groups, such as state actors, might be immune to access controls and therefore require deterrence through elevated perceived costs and a degraded expected utility of attack.
  • Prevention must evolve beyond access controls alone. Although restricting dual-use information and materials remains necessary, determined actors with sufficient resources can circumvent these barriers. An effective strategy, therefore, requires a complementary detection architecture that identifies and disrupts misuse patterns in digital and physical domains before they culminate in harm, shifting the paradigm from denial to integrated monitoring and early response.
  • Aggregate signals matter. Threat actors operating across multiple nodes of the AI-biology ecosystem—probing different models, querying multiple synthesis providers, sourcing materials from separate vendors—produce signals that appear ambiguous when observed individually but form identifiable patterns of concern when analyzed collectively. Realizing this aggregate value requires centralized information-sharing infrastructure that no entity can provide alone.
  • Invest early. Implementing this strategy’s mitigations will require investments in new research, institutional adaptation, legal clarification, and international coordination. Waiting until more-advanced biological threats are undeniable will be waiting too long.

Topics

Document Details

Citation

Chicago Manual of Style

Guerra, Steph, Aurelia Attal-Juncqua, John P. Tarangelo, Casey Aveggio, Katie Dammer, and David Glickstein, Building a Defense-in-Depth Biosecurity Strategy for the AI Era. Santa Monica, CA: RAND Corporation, 2026. https://www.rand.org/pubs/research_reports/RRA4999-1.html.
BibTeX RIS

Research conducted by

This publication is part of the RAND research report series. Research reports present research findings and objective analysis that address the challenges facing the public and private sectors. All RAND research reports undergo rigorous peer review to ensure high standards for research quality and objectivity.

This document and trademark(s) contained herein are protected by law. This representation of RAND intellectual property is provided for noncommercial use only. Unauthorized posting of this publication online is prohibited; linking directly to this product page is encouraged. Permission is required from RAND to reproduce, or reuse in another form, any of its research documents for commercial purposes. For information on reprint and reuse permissions, please visit www.rand.org/pubs/permissions.

RAND is a nonprofit institution that helps improve policy and decisionmaking through research and analysis. RAND's publications do not necessarily reflect the opinions of its research clients and sponsors.