0:00
/
Generate transcript
A transcript unlocks clips, previews, and editing.

Elizabeth Sherwood-Randall on Bioweapons in the Age of AI

How to prepare for a world where biological weapons can be designed with “a laptop and an AI account”

Jack interviews Elizabeth Sherwood-Randall, the Ashton B. Carter Visiting Professor at the Harvard Kennedy School and formerly Assistant to the President for Homeland Security and Deputy National Security Advisor, about her new report, Deterrence by Resilience: Securing the United States and Promoting Innovation in the Age of Bioconvergence. They discuss how artificial intelligence has changed the biological threat landscape, the scenarios that worry her most, and the report's recommendations across prevention, detection, attribution, readiness, response, and resilience—among them a nationwide early warning system, rapid attribution, a federally chartered National Institute for Bioresilience, and an Operation Warp Speed-style partnership with industry built before the crisis rather than during it. They also take up the legislation this would require, what the frontier AI labs might make of it, and the surveillance and privacy tradeoffs the program implies.

Mentioned:

Consider becoming a free or paid subscriber to Executive Functions.

This is an edited transcript of an episode of “Executive Functions Chat.” You can listen to the full conversation by following or subscribing to the show on Substack, Apple, Spotify, or wherever you get your podcasts.

Jack Goldsmith: Today we have another in a series of chats about how the U.S. government should understand and act upon the promise and dangers of artificial intelligence. My guest today is Elizabeth Sherwood-Randall, the Ashton B. Carter Visiting Professor at the Harvard Kennedy School.

Liz has had a number of important national and homeland security jobs in the government going back decades, and most recently she served as the Assistant to the President for Homeland Security and as the Deputy National Security Advisor from 2021 to 2025. Liz has just published through the Kennedy School an important new report entitled Deterrence by Resilience: Securing the United States and Promoting Innovation in the Age of Bioconvergence. Liz, thanks for joining me.

Elizabeth Sherwood-Randall: Thanks for having me.

As the title of the report suggests, the topic of the report is the intersection of artificial intelligence and biological threats. So I think the first thing we need to talk about is: what’s a biological threat?

A biological threat is using biology as a weapon. Traditionally we think of harmful bacteria or viruses or poisons being used, and they can be naturally occurring, accidental or deliberate. What we’re facing today is an entirely different set of biological risks, an explosion of bio risks.

And that includes the supercharging of biology by artificial intelligence that is enabling the creation of synthetic viruses and blowing open the gates to access to these specialized capabilities. You used to need a PhD in biology and a highly specialized secret government lab to work on bioweapons, and that kind of work can now be done in the wild with a laptop and an AI account.

Before we talk about how AI supercharges the threat: we’ve been hearing about and arguing about the possibility of biological weapons being developed outside of official channels and with greater ease since the internet got going, really, and especially after 9/11. I imagine you’ve been working on these issues for decades.

Can you give us a sense of how one would be thinking about bio-threats before November of 2022, when OpenAI announced and released ChatGPT? What was the bio-threat environment like? What was the infrastructure and technology for bio-threats around then?

In the last decade, we’ve seen a dramatic change, Jack. There are the traditional bio-threats that we dealt with during the Cold War, largely focused on Russian programs, Soviet programs before Russian, and that has been transformed by initially the CRISPR-Cas9 gene editing technology that emerged around 2014–2015 as a genuinely powerful capability. In that period of time, I began to work on this challenge.

Was this something that could be weaponized by an adversary against us, and what could we do about it? We saw that it was very difficult for the scientific community to figure out what to do about it because, of course, scientists want to push out the boundaries of knowledge and create new possibilities that are enormously positive. And what those of us who work on national security worry about is what are the risks associated with this, and how can we manage them?

I will say we didn’t do a great job of figuring out what to do about CRISPR-Cas9, and when we found ourselves in 2022 with the emergence of ChatGPT, as you said, we began to see the rapid acceleration of the risks and threats associated with this capability that is at the intersection of artificial intelligence, biotechnology, and bioengineering. And so we are essentially not ready for what is already present, and what is coming our way is even more challenging, and we’re definitely not ready for that.

I think you and I both read John Ellis’s morning newsletter, News Items, and earlier this week he flagged your report, and he said at the end of his description of it, you’ll want to read it with large amounts of Valium nearby. I think he was talking about your description of how AI significantly enhances biothreats. So why does one need Valium before reading your report?

I’ll give you the scary part before I give you the solution set. There are really scary scenarios. That’s why I’m working on this problem, and the examples include cyber hackers who could use artificial intelligence to corrupt the pharmaceutical manufacturing sector in the homeland so that products would be unreliable and could actually do harm.

You could have terrorists who use an open-source LLM to develop and then produce and deliver a pathogen that’s engineered for greater lethality and for resistance to known treatments, and deliver that into major American cities. You could have an adversary who is planning to launch a major military campaign and decides to do what the Pentagon would call preparing the battlefield by releasing an illness-causing disease vector into the homeland while they secretly inoculate their own population against it, and the objective of that would be to disable the deployment of the American military and cause societal panic just when unity of effort is required.

I’ll note to you on this list, Jack, that one of the things I’ve seen in my study of this challenge is that 25 years ago, next month, we experienced 9/11, and the after-action analysis of how we had failed to prevent it included as the first of four reasons a failure of imagination. What we need to do here is imagine, based on the science and technology as it’s evolving, what the potential use cases could be by a malicious actor, and then take the steps necessary to ensure that we’re ready to prevent them if we can and to respond to them effectively if we cannot.

The examples you gave, at least as you described them, were things that could have happened before November of 2022 — cybersecurity break-ins to pharmaceuticals, synthetic viruses, [et cetera]. Is the point that the availability of AI models significantly increases the likelihood of this happening? And if so, why? Is it that, or is it that adverse actors can do things now that they couldn’t do before, or is it both, or something else?

There are multiple dimensions. One is that our large language models are getting better and better. So one is just knowledge.

Second is the ability to create synthetic pathogens that we have never seen before in nature. Just this month, it was announced that a group of researchers at Stanford and the Arc Institute had produced 16 viable viruses never before known. And what we therefore have to contend with is the possibility of the emergence of things that we are totally unprepared for, that we have no solution for because we’ve never seen them.

And finally, there’s the issue of access, which I noted previously, that it’s so widely distributed. This capability is going to be ubiquitous, basically. Now, there is a necessity to know how to do some things in order to engage sufficiently with these artificial intelligence capabilities and to figure out how to direct them to generate what you need and then to get something manufactured.

But we know that pernicious actors are interested in doing harm with these capabilities. And so the more proliferated they become, the more risk is created.

Do you see the threat coming mainly from private actors who, with very few resources, can do very bad things? Or from state actors — more state actors will have more capacity now than they did before? Or both? How do you think about public versus private here?

I think we have to worry about the full spectrum of risks, honestly. I don’t think we can feel confident that any one of them will not be able to weaponize these capabilities. So first we deal with nation states and their interests in potentially doing us harm.

There we have the possibility, if we can do rapid attribution, of creating some form of deterrence, because we can threaten retaliation if we can figure out where something came from. We have to worry about individuals, both groups of individuals and lone individuals, lone wolves, who may have malicious intent. That’s harder to deter, which is one of the reasons that preparation for response is so critical, because we may not be able to deter those kinds of actors.

And we should worry about accidents as well. We know how much damage was caused by the pandemic. And if that was an accident, as many believe it was, or a naturally occurring virus, depending on your view, then we need to be prepared for those occurrences, because biology on its own can do significant harm.

What we need to be aware of is that we are talking about a kind of risk that far exceeds the consequences of the COVID-19 pandemic. You could have a much more virulent and dangerous pathogen that’s released.

Is there any way to quantify, or give us a qualitative sense of, just how much more empowered lone wolf type actors are by these models?

Gosh, I don’t think I can quantify it, but I’ll say that I think the combination of having access to these models and potentially being able to use a cloud lab — which is a lab that is established in order to produce an order that comes from potentially an individual or an artificial intelligence agent, without a human in the loop — creates a very serious risk of harm. That is, there is no break point there between the order being generated and the virus being made. In our recommendations there is extensive focus on that kind of challenge, which is how do we ensure that these capabilities to both generate and then produce in the real world a threat are limited and constrained, especially for the most dangerous kinds of capabilities.

Let’s talk about solutions, because that’s mostly what the report is about. The report proposes what you call a new strategic framework for balancing the opportunities and risks of bioconvergence. Tell us about the strategic framework.

I think the most important point, Jack, to what you’ve just said to me is our private sector is our solution set. We cannot so constrain our private sector because of the risks that are being generated that we prevent ourselves from having access to the solutions that we need in the face of these threats. That’s really the paradox of this challenge, which is quite different from, for example, the nuclear danger that we have faced.

I’ll go through the sequence, the logic train of how I would recommend we approach this if we take the initiative to pursue a comprehensive national initiative to get ready for this. We want to prevent what we can. We want to be ready for what we can’t prevent.

We want to be sure that our private sector is strong enough to generate the solutions that we need. And through that combination of acts, we can generate deterrence. So here are the steps.

Early warning. We need a nationwide early warning system. People know about smoke detectors in their house, which give them warning of something dangerous.

We have incoming missile defense radar, which tells us when something may be coming our way that we need to disrupt or counter. We need an early warning system for emerging pathogens. We started to build that during COVID with wastewater surveillance; we need it to be ubiquitous throughout the country. That is the critical element of the equation that’s now missing. We do not have it.

And what we do have only tells us what we know. That is, it’s designed to tell us from a list of known pathogens what may have emerged, versus to recognize things that are synthetic. Second, we need a rapid response system in place, again, continuously, so that we can fuse the data that comes in from that early warning system in real time, bring it in from many, many sources, and fuse it with intelligence — so you need a classified dimension of this — so that you can figure out as quickly as possible what this is and where it came from.

If we can figure out where it came from, who did it, the attribution piece of this, then we have the possibility of creating consequences and deterrence, because if bad actors believe they can act without any consequences, then they feel free to do so. So that piece is absolutely critical, this attribution piece. And then we need to be able to generate the solutions that help us to reduce the harms of an attack, if we haven’t been able to prevent it or deter it, and to recover more quickly from it.

Those are critical elements, because if we demonstrate that we are resilient against attacks, that reduces the attractiveness of such an attack to an adversary. The juice isn’t worth the squeeze, essentially. So we must begin to be much more capable of responding than we showed ourselves to be during the pandemic.

Here is the point I made to you about the private sector. The private sector is both the source of innovation and indeed the source of some of the risk. It’s also the source of defense.

So we have to have a very substantial collaborative framework for working with the government to get this done. That is, the government and the private sector need to do more than they have ever done before together to meet the national need. And the example we have of how this worked is Operation Warp Speed, which worked effectively in a crisis.

What I’m recommending is that we do this before a crisis, so that we’re ready to go and we don’t lose any time, because time will be of the essence to save lives and reduce harms.

That’s a pretty ambitious set of proposals.

It is.

And the report lays them out in detail. You talk about an unprecedented collaboration between the public and private sector. You talk about putting these systems in place. You’re talking about a lot more government involvement. Tell me about the government involvement, the nature of the regulation, and the new systems and bureaucracies needed to make what you’re proposing work. And how do you — you talk about this in the report, but I want you to flesh it out here — how do you think about that in terms of tradeoffs against innovation? There are a couple of questions there.

I’ll answer your last question first, because it’s so important, which is that we do face a real tension. We cannot deny it exists between innovation and regulation. And given the global competition in this space, both in the AI space and in biotechnology, we have to be extremely attentive to that as we think about law and regulation.

And I will say that I think that we don’t yet see how this will work, but I can foresee a way in which it can, in which we establish a national capability that is a federally funded and authorized public-private consortium, a National Institute for Bioresilience, which would be a critical element of our response capabilities, with dedicated compute power, with a secure enclave, like I mentioned, where you could be able to integrate intelligence information and look at the most sophisticated and potentially dangerous biological models. Importantly, we’re going to have to incentivize the private sector to take the steps that it needs to take. And here I would say, to your question about innovation and regulation, in order to get this done right, we have to balance what is onerous for the private sector with the benefits that could accrue to the private sector.

There are benefits through federal procurement. There are benefits from safe havens for liability. There are benefits also to be had in having access to government facilities for doing the kind of model testing that we have already done with the frontier U.S. laboratories on nuclear and biological risk. And so this organism needs to be built that is highly interactive and continuous, where we look at ways to create a stronger private sector ecosystem that is witting of the harms that are being created and recognizes the steps it needs to take to reduce the risks it is creating, at the same time that it generates the solutions that we need. Obviously, this is complicated to do, and I do not in any way suggest it’s an easy thing, but we have done very hard things before as a nation, and this is one we have to do if we want to secure the nation.

Until relatively recently anyway, the frontier labs, the big AI firms, argued against government regulation on the grounds that it would deter innovation and that we’re in this race with China and we have to get there first. And that argument had a lot of leverage in the last few years. It’s changing now for a whole bunch of reasons.

It seems like the firms themselves are getting nervous about what they’re creating, and there’s also the argument that they actually want regulation because it gives them advantages against newer firms. Can you give me a sense, first of all, of what the large AI firms might think about this very ambitious set of proposals that would involve a lot of work and a lot of compliance?

We actually consulted with large frontier AI firms in the United States in order to produce this, because I thought it would be irresponsible not to, given the central role they have to play in our innovation ecosystem and the solution sets, in addition to the risks that they’re generating. And there I would say that the opportunity to set guidelines for pre-deployment testing and for post-deployment monitoring, for incident reporting and risk assessment and red teaming and safety testing, is something they actually want, because that gives them some right and left limits within which to work. And that’s the thing that really does need to be developed.

We need a leading role to be played by our Congress in pursuing this, and we need an administration that works collaboratively both with Congress and with the labs to achieve this, because we are trying to do this in the midst of the breathtaking evolution of the capabilities. They’re moving so fast that it is hard to measure how much they can do, and yet this is necessary in order to protect us and protect humanity.

You mentioned Congress. Am I right in thinking that none of this can happen without new legislation?

We need new legislation, either as a National Biosecurity and Bioresilience Act, which is comprehensive with multiple dimensions, including the things I’ve mentioned with respect to setting up a national monitoring system, having the kind of attribution capabilities we need, creating the National Institute for Bioresilience. I haven’t mentioned yet the imperative of investing in our biotech sector, almost an industrial policy kind of approach to strengthening it in the face of Chinese competition. You could do it all as one big piece of legislation, but I realize that is a big, ambitious thing to do in a very difficult time to get legislation moved.

And so it’s possible that this needs to be broken out into multiple pieces of legislation that focus on different elements of this equation. A number of members of Congress have produced legislative proposals that get at some of this. And Senator Young, for example, led the National Biosecurity Commission — very important work done there. That was published in 2025.

But what is important here to emphasize, Jack, is that the synergy across these elements is essential to generating the deterrence that I’m talking about. If we can’t do all of the things I’m describing, we don’t actually have the strategic effect we are seeking, which is to change the calculus of an adversary in considering use of a biological attack.

And so that really does create, in my mind, an imperative to try to move this in a comprehensive way and demonstrate that you can’t mess with us effectively.

One paradox you face is that it strikes me that your program, for it to work, requires at least two things. It requires — and we haven’t talked about this — massive presidential leadership. Congress is not going to do this, in my judgment, unless an administration makes it a national priority and pushes it.

And I don’t think that’s going to happen, certainly not in the current administration, in my view, but I don’t think it’s going to happen in general until the threat is taken much more seriously than it is now. And there’s always a paradox, as you know, that we don’t take these types of threats seriously enough until after they occur. So am I right on both the need to better appreciate the threats much more than we do and presidential leadership, and given the deficit, if I’m right, on both, how do we get where we need to go?

This is a gloomy way of thinking about it, Jack, because you’re right that we face obstacles to getting this done in the time frame in which it needs to get done. And I worry a lot about that. It’s one of the reasons that this report is out in the world, and I’m briefing members of Congress and sharing this information to the greatest degree possible with those who are in the administration who are interested in receiving it.

Now, the Genesis Mission that the administration has launched and is pursuing is an important element of that equation, but there are many more. So yes, it means we have to rally the nation, and you do need leadership for that. And we have not yet seen that kind of leadership on this front, but we’re going to continue to work to make the case that the American people need it, and that if the United States leads, as we have in the past, we can actually have an impact globally as well.

So I’ll just add, we haven’t talked about the international dimension. You know well that pathogens know no borders. So what happens abroad can affect us very quickly at home.

Therefore, we have a real interest, a naked self-interest, in fact, in helping other countries do better. We also have an interest in working with our adversaries to create guardrails around the use of the most pernicious biological tools, and that’s something that this report also proposes. And we can lead a global effort to reduce risk, as we have done in the nuclear space for decades and where there have been real impacts as a result of American leadership.

Let me ask you about a different type of trade-off. In order to detect and respond to and deter the development of these threats, the federal government is going to have to be — and I think this is implicit in your proposals and in any proposals along these lines — significantly more empowered vis-à-vis individuals, both in terms of surveillance, maybe of labs and the like, or of other things, and in terms of keeping lists of people and who’s doing what, and all sorts of other types of what I call monitoring. So it strikes me that inevitably, especially given the lone wolf possibility, the fact that this is so decentralized, the government is going to have to be massively more empowered to monitor in a broad sense what individuals and firms are doing, which raises all sorts of privacy concerns.

So, first of all, am I right about that? And second, if so, how do you think about that trade-off?

I would say on this point, we obviously need to approach this with the lessons learned of the past. That said, there is a lot we can do that does not go to the individual level that needs to be done. And I’ll begin with the imperative of creating this national early warning system, where what we need is anonymized data.

We need to be gathering information about what’s happening at the community level, not at the individual household level, so that we can see what is coming our way more quickly. At the same time, I think you’re right that we need to figure out to what degree we are willing to take new initiatives to get into a space in which there could potentially be a privacy risk, and what to do about that. And that should take place within the bounds of how we have learned to address the counterterrorism threat, and where we have learned there are mechanisms for ensuring that we don’t go beyond what is an appropriate protection of personal privacy.

But here we have, as often, the tension between what is good for an individual and good for a society. And if you do have an individual who is creating mass risk from what they are doing, then we need to find a way to stop it.

Liz, you spent, I think, about a year working on this problem, and about a year of work at least went into the making of this report. You obviously dived into a lot of scary corners of threat, and you don’t shy away from presenting that in the report. But you nonetheless strike me as not optimistic, but hopeful that we can address this problem. Is that a fair characterization? And if so, why is that your view?

I think part of it has to do with my nature, Jack, which is that I believe the way we tackle the problems we face is to summon all of our capabilities to do so. I have spent my whole life working on the world’s hardest problems, and they seem to me to be the ones that are most worth working on. So it is true that this is a very dark space, and there are a lot of risks, and we may not manage them all very effectively.

But if we do better than we are currently doing, we will reduce the dangers, and we will also continue to benefit from the upsides. So I would say that’s the choice I’ve made after 40 years working in the space of trying to prevent the use of nuclear weapons and the proliferation of nuclear materials, as I came out of government in my last time of public service, in thinking about where were the areas in which we really needed to apply the ingenuity of the United States, both in terms of our private sector capacity and our capacity for public leadership. This was the place I wanted to work, and I will say I benefited tremendously from having a remarkable team of leading experts and brilliant students who contributed their ideas to this initiative, and where I’m really trying to also teach these young students who are our future that when you see a hard problem, it’s better to learn as much about it as you can, and then figure out what to do about it, than just to feel more and more anxious every day that there’s nothing you can do.

And I think if we go back to the origin story of some of my work in the years in which the Soviet Union collapsed: with a small group of people working at the Harvard Kennedy School of Government, we innovated an approach in which we could really significantly reduce the risks of loose nuclear weapons, which might emerge from the collapse of the Soviet Union. An enormous amount of risk was reduced by the actions that were proposed and the collaboration with members of Congress, Senator Sam Nunn and Senator Dick Lugar, to author and enact legislation which was then implemented in the Clinton administration, building collaborative initiatives to reduce the nuclear risks.

So I think it’s possible to do really hard things, and it’s uplifting to do this work, rather than depressing to do this work, because it gives me hope that we can solve a very hard problem.

Thank you very much, Liz. Congratulations on your great report.

Thank you for giving me the opportunity to talk about it with you today.

Ready for more?