Opinion | This is how AI kills us all
Annie Jacobsen is the author of “Biological War: A Scenario.”
A week-and-a-half ago, AI researcher Jacob Coxon quit his job at Anthropic and warned the public that the people building the world’s most powerful AI systems genuinely believe the technology could “kill us all.” His alarm exploded across X, drawing some 170 million views and counting, as other AI researchers echoed his concern. But what especially interests me is more concrete: How, exactly, does AI kill everyone — or, at least, many millions of us?
I’ve spent decades investigating biological weapons, most recently for my book “Biological War: A Scenario,” which draws on interviews with microbiologists, epidemiologists, and high-ranking government officials to sketch out what a real-world attack might look like. Though the killer pathogen I imagine in my new book is created by a human scientist and not an AI, many of my post-publication conversations have converged on the AI-enabled bio threat.
The real danger, I’ve come to learn, is not that AI will develop some new deadly virus. There are plenty of lethal viruses in existence already. The danger is simpler — and therefore scarier.
Recently, I traveled to Fort Detrick, the military base in Maryland, to visit a laboratory where the US government confronts this threat and others. Behind high gates and armed security checkpoints (I went through four) sits a federal facility most Americans have never heard of. It’s called the National Biodefense Analysis and Countermeasures Center, or NBACC (“N-back”). After 9/11 and the anthrax attacks that followed, the government recognized that it needed a laboratory devoted to understanding biology as a weapon.
Fort Detrick is better known as the home of the US Army Medical Research Institute of Infectious Diseases, a division of the Department of Defense that focuses on protecting warfighters from biological threats. It conducts research and develops medical countermeasures: vaccines, diagnostics, and therapeutics to be used against biological agents in the event of an outbreak or an attack. NBACC asks a different set of questions: What could an adversary do with a biological agent? How dangerous could it be? And if a biological attack actually occurs, it will tackle the forensics: What is the agent involved, how was it made, and where did it come from?
To understand the AI-enabled threat that NBACC is weighing, it helps to start with a pre-AI example of how one scientist tried to make a biological weapon but failed: the case of Aafia Siddiqui, a Pakistani scientist educated in the United States. The FBI investigated her for her suspected ties to Al Qaeda, and she is now serving an 86-year federal sentence for attempting to murder US personnel in Afghanistan.
First listed on the FBI’s Seeking Information - Terrorism list in 2003, Siddiqui was captured five years later in Ghazni, Afghanistan. According to the Department of Justice indictment against her, a search of her handbag found documents describing a planned “mass casualty attack” involving various locations in the United States using biological and other weapons. According to an earlier DOJ complaint, “substances in gel and liquid form that were sealed in bottles and glass jars” were also found in her handbag, as well as a list of targets she intended to attack.
I spoke with Jim Lawler, the former chief of the CIA’s Counterproliferation Division, Special Activities Unit, about the Siddiqui case and the materials she developed.
“Siddiqui is a true believer,” Lawler told me, saying she was plotting an attack against the United States designed to deliver “staggering horror.”
“There were thousands of pages on a thumb drive” in her possession, says Dr. David Relman, a Stanford microbiologist, physician, and biosecurity expert who advises the White House on threat intelligence and infectious diseases. Relman briefed the intelligence community after reviewing the Siddiqui documents. “It was a wake-up call,” Relman says. “In ways that you wouldn’t have imagined.”
Siddiqui was working on a novel biological weapon to deploy inside the United States, Lawler said, “a chimera,” or hybrid that aimed “to combine the lethality of rabies with the infectiousness of chickenpox.” Rabies, he explained, “is 99.99 percent lethal, and chickenpox is one of the most contagious of all the pox viruses.” Siddiqui “had that on her computer,” Lawler said. “So the ideas are there.”
But Siddiqui’s scientific training did not give her the wide-ranging expertise required to turn such an idea into a working biological weapon. Understanding biology and neuroscience is one thing; knowing how to genetically engineer a pathogen, make it behave as intended, troubleshoot failed experiments, and turn it into something capable of spreading is another. As a young woman, Siddiqui had studied at MIT and Brandeis University, where she would have had routine access to university laboratories and other scientists, but by the time the FBI was after her, she’d long since left academia.
Lawler suggested in my conversation with him that Al Qaeda’s extreme prejudice against women may have contributed to Siddiqui’s apparent inability to acquire the additional expertise she needed. As a woman, he explained, she would almost certainly have had limited access to male colleagues and their laboratories, limiting her ability to develop new know-how.
If the Siddiqui case points to a pre-AI gap between having an idea and making it real, though, it seems clear that the gap is now closing.
Capable AI systems function as expertise multipliers. They can read and synthesize vast amounts of scientific literature, connect findings from different fields that a researcher might never think to put together, identify why an experiment failed, suggest what to investigate next, interpret results, and shorten the time between question and answer. A bad actor does not need AI to invent an entirely new apocalyptic weapon; AI does not have to make the impossible possible. It only has to make difficult things much easier. It only has to enhance expertise.
And while the top AI labs have made efforts to cut off chatbot conversations about biological weapons, we have seen evidence — in plenty of realms — of clever users working their way around this kind of prohibition.
Of course, even a would-be terrorist who has the requisite expertise needs the ingredients required to build a weapon. And this is what makes biology uniquely troubling. Much of the raw material for a terrorist attack already exists in nature. Yes, some dangerous pathogens are extraordinarily difficult to obtain. Possess variola virus, which causes smallpox, without authorization and you can face a $2 million fine and 25 years to life in federal prison. But other dangerous pathogens exist outside secure government repositories.
Rabies, for example, circulates naturally in animal populations. In the United States alone, thousands of animals test positive for the disease each year. The point is not that turning a naturally occurring pathogen into a weapon is easy; it is not. The point is that unlike the fissile material required to build a nuclear weapon, biology’s raw material is readily available.
And because an outbreak can initially look natural even if it is not, determining where a biological event came from is becoming a national-security problem of the first order.
At Fort Detrick, I raised the Siddiqui scenario directly with the NBACC lab director, Dr. Nicholas Bergman. He couldn’t tell me whether NBACC had ever examined Siddiqui’s plans, nor could he discuss the classified threat scenarios that his scientists work on. But speaking hypothetically, he explained how a proposal like hers is precisely the kind of problem NBACC was designed to investigate. Scientists there can take an enemy’s or adversary’s idea apart, test its underlying assumptions, and determine whether something that exists on paper could actually work in the physical world.
And in the age of AI, it seems that more could actually work in the physical world.
Within 24 hours of Coxon, the AI researcher, warning that the technology could “kill us all,” naysayers began pushing back. Elon Musk called it “the groundwork” for a “psy op.” Bill Ackman, the outspoken investor and founder of Pershing Square Capital Management, amplified a post calling it “a well-funded PR operation to get support for Democrats to regulate AI into oblivion.” The Atlantic ran an article headlined “The AI Pandemic Isn’t on Its Way.”
But after my visit to Fort Detrick, this much is clear to me: Artificial intelligence and biology are not two distant technological revolutions moving along parallel tracks. They have already begun to intersect. And that is dangerous. The question is: What are we going to do about it?
Related Stories
AI News
Artificial Intelligence, Jobs and Ghana’s Young People
12 minutes ago
AI News
The Majority of Americans Are Now Terrified of AI
13 minutes ago
AI News
A world of difference in 10 days: the changing course of AI
13 minutes ago
AI News
N.Korean leader Kim inspects munitions factories
41 minutes ago
AI News
‘Just ask Grok’: How ISIL is using Big Tech’s AI to build bombs
43 minutes ago
Amazon tests an Artificial Intelligence that adapts actors' lips to dubbing: repercussions in the Industry
1 hour ago
AI News
Artificial Intelligence policies in Lee schools | Opinion letters
1 hour ago
AI News
China bogeyman looms large over American firms’ AI doomsday scenario
1 hour ago