Deterrence by Resilience: A New Framework for Securing the US Against AI-Enabled Biological Threats
核心洞察
The Belfer Center's IB3 initiative proposes "deterrence by resilience," a new strategic framework to manage risks from the convergence of biology, AI, and bioengineering known as bioconvergence.
The framework combines prevention, detection, attribution, readiness, response, and resilience into a mutually reinforcing cycle that raises the costs of biological misuse while reducing its consequences.
Key recommendations include AI-biosecurity guardrails for frontier models, a nationwide biological monitoring system, and a National Strategic Bio Readiness Reserve for surge capacity.
The accelerating convergence of biology, artificial intelligence (AI), bioengineering, and digital infrastructure—a process the report terms "bioconvergence"—is reshaping the biological threat landscape in ways that challenge traditional national security frameworks and create potentially catastrophic risks to the United States and its allies. This is the central finding of a new report from the Initiative on Bioconvergence, Biosecurity, and Bioresilience (IB3), housed within the Program on Emerging Technology, Scientific Advancement, and Global Policy at the Harvard Kennedy School's Belfer Center for Science and International Affairs (搜索).
Led by Dr. Elizabeth Sherwood-Randall (搜索), the report advances a new strategic framework—"deterrence by resilience"—designed to balance the opportunities and risks of bioconvergence while sustaining American leadership in innovation.
A Transformational Threat Landscape
The report describes bioconvergence as generating a more distributed, broadly accessible, and rapidly evolving threat environment. Capabilities once limited to state-sponsored programs are increasingly available to new actors through advances in AI uplift for biological knowledge, AI-enabled biological design, declining costs of DNA synthesis and sequencing, and laboratory automation.
"These developments not only lower barriers to innovation but also lower barriers to entry and misuse," the report states. It concludes that traditional approaches to deterrence, including deterrence by denial and deterrence by punishment, are increasingly insufficient, and that biological risks increasingly resemble a hybrid of the nuclear and cyber domains while remaining distinct from both.
The Deterrence by Resilience Framework
Deterrence by resilience seeks to reduce adversaries' confidence that biological misuse will succeed, scale, or produce a strategic advantage. It combines steps across the full lifecycle of biological threats—prevention, detection, attribution, readiness, response, and long-term resilience—into a mutually reinforcing, virtuous cycle that raises the expected costs of misuse while reducing the damaging consequences of biological incidents.
A defining feature of the framework is that innovation and security are treated not as competing objectives but as complementary ones. "The infrastructure that enables American leadership in biotechnology and AI also enables national biosecurity," the report argues. While acknowledging that regulation often carries compliance costs, it contends that increased safety also generates benefits for both the public and the private AI-enabled biotechnology ecosystem.
Prevention: Guardrails for Frontier Models and Biological Data
The report's prevention recommendations center on establishing AI-biosecurity guardrails for frontier models and laboratory systems. It calls for a federal regulatory framework for advanced AI models and autonomous laboratory capabilities that—independently or when combined—exceed defined compute and biological capability thresholds, with requirements tailored to biological design, synthesis, and dual-use research risks.
Additional prevention measures include mandating pre-deployment biosecurity evaluations, post-deployment misuse monitoring, and incident reporting for high-risk AI systems, with a federal entity such as the Center for AI Standards and Innovation (CAISI) empowered to set standards for risk assessment, red teaming, and model evaluation. The report also recommends strengthening DNA synthesis screening through function-based criteria, know-your-customer requirements for benchtop DNA synthesizers, and technical safeguards that block sequences of concern.
Detection and Attribution: Building National Monitoring Infrastructure
Recognizing that prevention alone will not eliminate bioconvergence risks, the report emphasizes the need for a persistent national biological monitoring architecture capable of identifying both known and novel biological threats. It recommends establishing statutory requirements for biomonitoring coverage, detection timelines, and interoperable data standards, while scaling wastewater surveillance and pathogen-agnostic metagenomic sequencing.
On attribution, the report calls for operationalizing advanced bio-attribution technologies, including accelerating the Intelligence Advanced Research Projects Activity (IARPA) Finding Engineering-Linked Indicators (FELIX) program into a standing operational capability. This would include development of a national reference library of engineering-signatures and expansion of AI-based attribution tools capable of identifying biological agents designed entirely or substantially using AI systems.
Readiness and Response: Surge Capacity and Clinical Trials
To ensure rapid response to biological emergencies, the report proposes creating a National Strategic Bio Readiness Reserve (NSBRR)—a public-private surge capacity reserve modeled on the Civil Reserve Air Fleet—to ensure rapid access to critical biotechnology capabilities during emergencies, including discovery and design, compute power, advanced development, and biomanufacturing.
The report also recommends streamlining federal clinical trials through a National Clinical Trials Emergency Authority, requiring major hospitals to maintain standing clinical trial infrastructure with pre-negotiated Indefinite Delivery, Indefinite Quantity (IDIQ)-style contracts, and creating an emergency NIH research reserve fund. It further calls for investment in capacity to rapidly field personal protective equipment (PPE), tests, therapeutics, and prototype vaccines and adaptable platform technologies, targeting prioritized viral families with significant epidemic or national security risk potential, with sustained funding for programs led by the Department of Defense (搜索) (DOD), Biomedical Advanced Research and Development Authority (搜索) (BARDA), and Coalition for Epidemic Preparedness Innovations (搜索) (CEPI).
Resilience: Supply Chains and Strategic Competition
The report's resilience chapter tackles the intertwined challenges posed by China's growing strength in select areas of biotechnology research and its increasing dominance in components of the pharmaceutical supply chain, including active pharmaceutical ingredients, key starting materials, and drug manufacturing. It recommends reducing pharmaceutical supply-chain vulnerabilities, expanding domestic manufacturing, and building support for a "Boost American Bio Manufacturing Act" modeled on the CHIPS and Science Act.
The report also proposes creating a public-private National Institute for Bioresilience (NIBR) to integrate AI, biological data, and national security missions, and launching a Senior Leaders Biosecurity Network to lead international cooperation on biotechnology security and resilience.
The report was authored by Elizabeth Sherwood-Randall (搜索) and J. Michael McQuade, with contributing authors including Beth Cameron, Ashish Jha, and others, and is dated August 18, 2026.
