OpenAI Is Developing Advanced AI Systems for Biology with an Emphasis on Safety and Misuse Prevention
Advanced artificial intelligence models have the power to rapidly accelerate scientific discovery, which is one of the many ways cutting-edge AI models will benefit humanity. In biology, these models are already helping scientists identify which new drugs are most likely to succeed in human clinical trials. Soon, they could also accelerate drug discovery, design better vaccines, create enzymes for sustainable fuels, and uncover new treatments for rare diseases, opening up new possibilities in medicine, public health, and environmental science.
At the same time, however, these models raise important dual-use questions—enabling scientific progress while maintaining a barrier against harmful information. The same core capabilities that drive progress, such as reasoning over biological data, predicting chemical reactions, or guiding laboratory experiments, could also potentially be misused to help people with minimal expertise reproduce biological threats or to assist highly skilled actors in creating biological weapons.
A Multi-Layered Approach to Ensuring Safety
OpenAI expects upcoming AI models to reach a "high" level of capability in biology under its Preparedness Framework and is taking a multi-layered approach to implementing mitigations. Its approach focuses on prevention—it does not consider it acceptable to wait and see whether a biological threat emerges before deciding on a sufficient level of safeguards.
The future will require deeper collaboration with experts and governments to strengthen defenses and help detect issues that no single organization could identify on its own. OpenAI consulted external experts at every stage of this work. At the outset, it worked with leading experts in biosafety, biological weapons, and bioterrorism, as well as academic researchers, to shape its biological threat model, capability evaluations, and model and usage policies.
Safeguards and Monitoring Systems
OpenAI has implemented several key safeguards. It trains the model to refuse or safely respond to harmful requests—historically, it has trained models to refuse dangerous requests and will continue to do so for requests that are explicitly harmful or enable the creation of biological weapons. For dual-use requests (such as virology experiments, immunology, genetic engineering, etc.), it follows the principles set out in its Model Spec, including avoiding responses that provide actionable steps.
The company has deployed robust system monitors across all product surfaces featuring cutting-edge models to detect risky or suspicious biological activity. If something appears dangerous based on its filters, the model's response is blocked. This also triggers automated review systems, and human review is initiated when necessary. It prohibits the use of its products to cause harm and enforces its policies when it detects misuse.
Collaboration with Government Institutions and Experts
OpenAI continues to work closely with government entities, including US CAISI and UK AISI. It collaborated with Los Alamos National Lab to study the role of AI in wet-lab environments and supports external researchers who continue to develop biosafety tools and evaluations. Its capability evaluations, including those detailed in its system cards, are informed by expert input and designed to estimate when a model crosses high thresholds.
It works with multiple teams of expert red teamers—people who try to break through its safety mitigations. Their task is to attempt to circumvent all of its defenses using a comprehensive approach, just as a determined and well-resourced adversary might. Red teaming in biology presents its own challenges—most expert red teamers lack expertise in biological risks and may not be able to assess the harmfulness of a model's output.
Future Plans and the Biodefense Summit
While OpenAI is focused on securing its own models, it recognizes that not all organizations will adopt the same precautions, and the world may soon face the broader challenge of widely available AI-enabled biological capabilities combined with increasingly accessible tools for biological synthesis. In July, it is hosting a biodefense summit that will bring together a select group of government researchers and non-governmental organizations to explore dual-use risks, share progress, and examine how its cutting-edge models can accelerate research.
Its goal is to deepen partnerships with the United States and allied governments, better understand how advanced AI can support cutting-edge work in biodefense—from countermeasures to new therapies—and strengthen collaboration across the ecosystem. It believes that the public and private sectors should work together to strengthen society's biological defenses beyond AI models.



