Risky Business

Trump-Xi Summit: Perception, Not Capability, May Drive AI-Bioweapons Risks

Earlier this month, Anthropic released its latest threat intelligence report, and for the first time showed documented incidents of misuse that could support bioweapons development. Google also issued a report on a single incident of a user trying to create a bioweapon development guide .

NTI | bio has thought about “why” a state would seek to develop or obtain a bioweapon. In a 2024 essay collection, we asked whether it is possible to determine a state’s biological weapons intent. We also asked what drives a state to pursue a bioweapon.

After all, it’s not obvious that biological weapons would prove useful. While they could be devastating and cheap to produce, they are operationally unpredictable and slow compared with other weapons.

Identifying intent is difficult: biological tools are a near-ideal example of dual-use technology. The use of a tool tells almost nothing about the user’s intent.

Anthropic tried to assess intent by combining technical characteristics (such as whether pandemic potential pathogens were involved and the model’s capability) with social context (country of origin, institutional credibility, research maturity, obscuring of user identity or location).

Anthropic’s technical safeguards did not stop all activity that could contribute to a bioweapon’s development. In one case, “Given the dual-use nature of this research and its explicit focus on attenuation, Claude supplied the user with information and thus was not blocked by our classifiers.”

It is hard to read and alter a state’s intent toward a bioweapon. Intent is shaped far upstream of the day-to-day work of creating a bioweapon. A state’s long-term strategy drives the technical means chosen for developing, manufacturing, and deploying the weapon, and the long-term strategy depends on the larger strategic environment.

“…bioweapons serve a larger goal of the state. A state’s pursuit of security, prestige, bureaucratic autonomy, regime stability, or electoral success could all affect the state’s offensive and defensive goals, which in turn affect the specific intent to obtain bioweapons. As a state’s goals change, one should expect that the intent for bioweapons also changes.” — Nathan A. Paxton, “Prospects for Assessing State Intent to Proliferate Biological Weapons” 

The intense AI competition between the United States and China affects each country’s perceptions (and misperceptions) of the other. Political scientist Robert Jervis argued that leaders’ perceptions and interpretation of ambiguous signals drive state actions more than objective facts.

In the United States right now, voices across the political spectrum (from Sen. Ted Cruz to Dario Amodei) are calling for maintaining our AI advantages and locking China out of those gains. Leading voices also argue that AI models continue to make progress toward a heretofore unknown power, one with a 10-25 percent chance of ending humanity.

The combination of rhetoric and capability could alter Chinese perception about what the United States might do with AI superiority. Jervis showed that state leaders generally assume the worst of each other’s actions, and suspicion in one area of rivalry spills over into others. China may interpret being locked out of a dual-use technology that could end humankind as a threat, all U.S. reassurances aside.

China may perceive strategic rivalry with the United States mostly in the economic or geopolitical realm, but China might also update its judgment about U.S. intent for a bioweapon, should the United States pursue AI superiority (absent appropriate and comprehensive safeguards and if China perceives those objectively). That spillover drives the “security dilemma,” where a country’s defensive actions appear threatening to another, lead to increased mutual distrust, and drive arms races.

While there has been much talk about the challenge that advanced AI poses, including in bioweapon nonproliferation, there has been little of what political scientists call “costly signals”— actions that a country takes that have real economic, political, or military costs to prove seriousness about threats or promises.

Both China and the United States will have to take verifiably costly actions if they want to “slow the pace” of AI development or prevent the multiplication of risk that will emerge as AI systems advance in abilities.

NTI | bio has several initiatives to assist the United States and China and identify paths away from increased risk of deliberate misuse.

  • We engage in multilateral dialogues to build cross-national understanding and identify cooperation opportunities to prevent non-state actor misuse. Expert input can increase communication about actions and motivations, reducing the potential for arms-racing dynamics.
  • In Disincentivizing Bioweapons, we explored strategies for increasing the monetary and political costs of bioweapons development and production, including increased transparency measures, new strategies of deterrence, increasing the bioweapons “taboo,” and the challenges of accountability.
  • We have studied political and technical options for increasing transparency. In “Enhancing Transparency for Bioscience Research and Development,” we developed comprehensive options in data collection and analysis, procedural support for data collection and analysis, and institutions that can support or house such processes.

To separate harmful intent from legitimate research, U.S. AI labs and government agencies must work beyond just technical safeguards and consider the strategic context shaping user actions. The United States and China need to recognize that each country’s actions—or lack—co-create the strategic security environment that increases the risks in AI development, including with respect to bioweapons. While neither side may be pursuing a bioweapon, either may believe that the other is.

The Trump and Xi summit today may offer an opportunity to begin filling the leadership vacuum on AI advances, especially with respect to bioweapons. If the reports from AI companies are correct, it’s imperative that Presidents Trump and Xi start this work now.

 

Stay Informed

Sign up for our newsletter to get the latest on nuclear and biological threats.

Sign Up

NTI at 25: Fostering Innovation Through Technology Governance

Risky Business

NTI at 25: Fostering Innovation Through Technology Governance

As NTI celebrates 25 years of impact, we remain committed to reducing the risks of accidental release and deliberate misuse of life science innovations, strengthening global biosecurity, and guiding efforts to govern emerging technologies.


People Are Trying to Misuse AI. That’s Exactly Why Safeguards Matter.

Risky Business

People Are Trying to Misuse AI. That’s Exactly Why Safeguards Matter.

The policy challenge ahead is ensuring that safeguards, governance frameworks, and security practices continue to responsibly scale alongside the technology. If they do, society can capture AI's enormous benefits while keeping emerging risks firmly under control. 


Biological Risks Are Growing. The BWC is Working to Keep Up.

Risky Business

Biological Risks Are Growing. The BWC is Working to Keep Up.

As scientific and technological advances accelerate, the Biological Weapons Convention (BWC) faces a defining test. The BWC’s future depends on whether the world can match the pace of biological innovation with equally ambitious efforts to prevent catastrophe.


See All

Close

My Resources

Subscribe to NTI

Sign up for regular updates on innovative, real-world solutions to existential threats.

Get Updates