What the 2001 Anthrax Attacks Teach Us About AI and Bioweapon Risks
As the world focuses on the risks of artificial intelligence, it is worth remembering the serious biological vulnerability the United States faced 25 years ago. In 2001, against the backdrop of the September 11 terrorist attacks, the country experienced the first major bioterrorism attack in decades.
Anthrax spores were mailed as a white powder to news organizations in Florida and New York and to government offices in Washington, DC.
AI can design viruses, toxins, and other biological weapons. How worried should I be?
It quickly became clear that the 22 confirmed pulmonary anthrax cases, including five deaths, were not naturally occurring but were the result of a deliberate attack.1 The FBI determined that the spores may have originated in a US military laboratory, although the perpetrator was never convicted. The main suspect, microbiologist Bruce Ivins, died before he could be charged.
Amid panic, poor communication, awkward coordination between government agencies and public calls for preventive medicine, the attack—codenamed “Amerithrax”—exposed a disconnect between years of bioterrorism preparation and what happens when a real crisis begins.
I worry that the United States is not more prepared today. Worse, focusing on one threat can come at the expense of others. Policymakers, researchers and the public risk overlooking the most pressing vulnerabilities by concentrating on overhyped biohazards, including AI-designed biological threats, even though all of these risks deserve attention.
Stronger and more agile safeguards for biological materials and equipment, supported by sustained and coordinated governance, should be the priority.
Biosafety risks are increasing
Since 2001, access to powerful analytical equipment has become more widespread and affordable. Benchtop DNA synthesizers allow researchers to generate arrays of DNA and RNA in their own laboratories rather than ordering them from commercial providers. Fully automated, remotely controlled wet laboratories—often called cloud labs—have also streamlined the development of biobased products.2
These technologies create opportunities for scientific breakthroughs and strengthen the bioeconomy. But they could also make abuse harder to detect in private research laboratories. Such facilities might bypass requirements applied to federally funded research and the biosecurity checks used by commercial genetic-sequence providers, including verification of a customer’s identity and the type of sequence being ordered.
Artificial intelligence could amplify these concerns by reducing the amount of tacit knowledge needed to produce biological weapons and by helping generate ideas for evading defensive measures. Potential risks include losing control of an AI system, producing unintended consequences or circumventing built-in limitations. Malicious actors could also use AI models to design new or enhanced pathogens. Such tools may expand the pool of people capable of posing a biological threat.

Research on pathogens, such as the virus that causes coronavirus disease (COVID-19), must be conducted in secure biosafety laboratories.
Credit: Michele Ursi/Getty
Many people see these concerns as the result of rapid technological progress outpacing slow governance processes. In reality, biology is complex, and understanding its risks is essential to getting ahead of them. Barbara del Castello, a biologist at RAND in Santa Monica, California, told me: “Although AI agents can optimize on-screen arrays in seconds, converting that digital design into a viable, functional biological product still requires overcoming severe physical and operational bottlenecks.”
The answer is effective government regulation, stronger oversight and robust safeguards. Voluntary industry action cannot replace independent oversight. At the same time, AI tools and their guardrails must be designed so that legitimate research can continue.
Even without AI, biological risks have long been difficult to regulate. Researchers still struggle to establish effective oversight and realistic governance for high-risk dual-use research, including work involving enhanced pathogens with pandemic potential.
US biologists also face regulatory whiplash. In 2025, President Donald Trump’s administration ordered federally funded agencies to suspend or review dangerous gain-of-function research on pathogens with pandemic potential.
In July, those instructions were replaced by new rules, causing further confusion. Seven types of research previously defined as dangerous gain-of-function and subject to review are now completely banned. Researchers are also being asked to assess studies involving pathogens that could put people at “significant risk”, not only those with pandemic potential.
AI could pose pandemic-sized biosecurity risks. Here’s how to make it more secure
There is also growing concern about the global expansion and management of high-containment laboratories for biological research. Research involving anthrax, Ebola and H5N1 avian influenza requires particularly strong safety measures. A 2023 analysis found that the number of biosafety level 4 laboratories—the highest-containment facilities—had doubled since 2001, reaching 51 laboratories in 27 countries. Further information is available at www.globalbiolabs.org.
Government-funded research is subject to substantial, although imperfect, oversight. However, worrying gaps remain, and the number of private research facilities is not fully known. In 2022 and 2026, authorities accidentally discovered unregulated biological testing spaces in Nevada and California, where they found biological samples and pathogens.
Responding to biological threats also requires the ability to investigate signs of deliberate activity and determine the origin of biological material, a process known as bioattribution. Pathogen early-warning systems have improved since 2001 through programs such as the US National Biosurveillance Integration Center and the expansion of the Department of Defense’s Global Emerging Infectious Disease Surveillance Program. However, investigations remain complex, fragmented and dependent on consensus.
Advances in bioinformatics and forensic genetics have improved investigations, but genetic engineering can also make it possible to alter existing pathogens to evade detection or to engineer pathogens that mimic important features of naturally occurring diseases. Geopolitical tensions, disinformation and the politicization of scientific knowledge further complicate the technical rigor and international cooperation required for bioattribution. These factors have, for example, complicated research into the origins of SARS-CoV-2.
The COVID-19 pandemic exposed many of the same weaknesses seen during the US anthrax attacks, even though COVID-19 was a natural rather than manufactured threat. These weaknesses included inadequate biosurveillance, poorly managed public fear and communication, and vulnerabilities in supply chains and the workforce.
Africa’s response to the Ebola outbreak shows how it will shape global health
I see a parallel between these events and today’s conversations about emerging risks. It is a cycle of panic and neglect: governments flood systems with money during outbreaks but fail to address the underlying problems of biological preparedness and resilience.3
Risk categories are also not weighted equally in public debate. AI-enabled biological risks have received significant attention, while the more subtle and fundamental vulnerabilities exposed by COVID-19 and the anthrax attacks remain largely unaddressed. That imbalance will shape how prepared societies are for future threats.
Fragmentation hinders biological resilience
Since 2001, the US government has invested billions of dollars in biodefense and established research programs and centers such as the National Center for Biodefense Analysis and Countermeasures. These efforts have produced important advances in biological-weapons deterrence, biosurveillance, medical-countermeasure development and pandemic prevention.4
Source: www.nature.com


