It’s been a busy month, both in my own life (I landed a new grant! I started teaching!) and elsewhere in my world of science, AI, biology, and academic life. Tomorrow I’m flying down to Mexico City for a week to unplug and recharge. You won’t see much here for a few weeks, but in the meantime, here’s what I’ve been reading this month ¡Nos vemos pronto!
The AI Discourse in Academia is Toxic, By Ran Blekhman
I am writing because this response fits a broader pattern in how academia now reacts to anything AI-adjacent: a toxic, knee-jerk hostility to AI in which the specific tool, application, or question all disappear into a general presumption that the whole category is terrible. […] The only serious position on AI in science is nuanced and case by case; any answer to “is AI good for science” that neatly fits into a single yes or no is unserious. […] You might think, “OK, stopping the AI discussion is actually good for science!” But your toxic reaction to anything AI does not stop the conversation from happening. It only takes you out of it. The conversation continues without you elsewhere. […] So here is an invitation to join the real discussion: you are allowed to have a nuanced opinion about AI.
The Weimar of Knowledge, by Giorgio Gilestro
Open science was, at bottom, a bet that if you removed the paywalls and the gatekeepers, the work would find its readers on its own merits. A reputation economy finally voids that bet. Free access is worthless when the binding constraint is not access but attention, and attention is allocated by brand. To be honest, we are already seeing that trend and AI will only accelerate. We will have open archives that nobody reads and closed reputational cartels that everybody does. That is a worse settlement than the one we are leaving, and it would be dishonest to present it as an equilibrium anyone should welcome.
Universities are failing this AI moment, by Ran Blekhman
Universities are choosing to see AI as a slow-moving policy question rather than a fast-moving structural emergency. […] Universities are slow by design, and that design has served the durability of ideas well for hundreds of years. However, for the current moment, this glacial pace of change is working against them. For AI, universities should adopt a more agile approach to create structural change that can actually keep up with the technology. Or, they can form another committee that will produce another report a year from now to sit on a shelf while the world moves past them.
Evaluating Superhuman Biological Capabilities, by Shiv Muthupandiyan at SecureBio
Leading AI models outperform experts at nearly every biosecurity-relevant capability we measure. They can provide wet-lab troubleshooting assistance and perform computational DNA synthesis design tasks. They score three times higher than world-class experts on highly technical biology questions. Up to the human frontier, those scores mean something concrete. We know what biologists of that caliber can do in a lab, so a model that matches them can plausibly help with the same work. Past that point, a higher score says the model has improved at biology, but it doesn’t tell us what that improvement means for real-world biological risk. Evaluation will need anchors that don’t depend on human verification. But for misuse-relevant biology, testing the skill itself would mean building the dual-use biological artifact we’re trying to prevent. Instead, we’ll have to gather evidence indirectly, relying on narrow, verifiable tasks and uplift in adjacent domains.
Researchers Say They’ve Found the Truth About Thomas Jefferson, by Andrew Lawler
With the permission of the Thomas Jefferson Foundation, the geneticists examined the hair strands and found viable DNA. “We’ll exhaust it and sequence the crap out of it,” [Beth] Shapiro assured Kurin in 2017. Lab workers gradually assembled a library of Jefferson’s genome. “We went from a long-shot fishing expedition to a slam dunk,” [Ed] Green said. “From then on, it was pretty straightforward. We spend a lot of time getting DNA out of difficult things like hair.”
Claude discovers a novel enzyme system, by Anthropic
Today, we’re sharing early results from one of our first research programs, in which Claude autonomously discovered a novel enzyme system that is associated with an array of DNA repeats, a pattern reminiscent of CRISPR. Although we don’t yet know its function, the system that Claude discovered has a set of characteristics that have only ever been found together in a handful of other systems, all of which are programmable and perform operations like cutting, copying, and pasting DNA. Beyond CRISPR, which has already transformed science and medicine, several other such systems are now in development as promising tools.
Did Anthropic’s A.I. Really Make a Scientific Discovery on Its Own? by Carl Zimmer
When Anthropic […] unveiled findings from its new biology lab last week, its scientists claimed to have used A.I. agents to discover new enzymes with promise for biotechnology. […] Then Mario Rodríguez Mestre, a computational biologist, said this weekend that he and his colleagues had been studying the enzymes and their associated molecules — which Anthropic calls ARTs — for four years. Dr. Mestre and his colleagues have yet to publish their findings. But for the past three years, they have regularly used Anthropic’s A.I. models as they have written code, drafted manuscripts and performed other tasks. In doing so, Dr. Mestre said he and colleagues shared key findings about the enzymes with Anthropic.
A.I. Queries From Abroad Raise Fears of a Biological Weapons Race, by Carl Zimmer
Now chatbots might consult the scientific literature to answer questions that a biological weapons-maker would have. It’s a task at which A.I. can excel, Dr. Inglesby said, providing far more to bad actors than they could gather with simple web searches. “It aims for the information to be usable,” he said of A.I. “It allows users to go back and forth infinite number of times to troubleshoot and explain in more detail, while providing just the right technical resources to back things up.” […] “How a Ph.D. student can individually misuse a model for harm is only one small portion of the problem,” Dr. Inglesby said. Dr. Endy worried that if governments start using A.I. for biowarfare research, they might help rekindle an arms race like the one during World War II.
Embryo screening and the new reproductive divide, by Gaia Ghirardi, Arno Van Hootegem & K. Paige Harden in Nature Human Behaviour
Instead of needing a village to raise a child, PGT-P’s commercial logic suggests it takes only sufficient capital and the right consumer decisions to conceive a child who will not need the solidarity of the village to be healthy. […] The central question is, therefore, whether societies should accept a future in which reproductive opportunities, parental obligations and children’s life chances are increasingly organized around genetic optimization, private purchasing power and corporate profit. In our view, leaving PGT-P to the market is not a neutral policy choice, but an active decision to allow commercial actors to shape the future of reproduction.
AI-Driven Biology Is Only as Good as the Data Beneath It, by Jonathan Jacobs and Patrick Boyle
The genomics community has long championed open data. The next step is to champion trustworthy data sharing so that the future of digital biology and AI‑enabled biology is built on traceable, defensible, and reusable genomic records, rather than on an assumption of trust.
Introducing VCT-v2 — the updated Virology Capabilities Test, by Nelly Mak and Jasper Götting at SecureBio
Benchmark creation should be treated not as a one-off project but rather as an ongoing effort with a defined re-audit cadence. Model and expert performance data exist only once a benchmark has been built, and they carry per-question information about its quality. […] Biosecurity-relevant benchmark performances are often presented as a single accuracy value. Yet, two models achieving the same accuracy on a benchmark are not necessarily identical, and reporting accuracy alone conceals a lot of information. We are working on applying item-response theory to better understand model performances on our benchmarks.
US Army Biodefense Strategy 2026
…biodefense requires unity of command and unity of effort, while employing capabilities and combined arms integration at echelon. Yet historically, biodefense has been the domain of specialized medical and chemical, biological, radiological, and nuclear (CBRN) personnel. […] Victory in future conflicts requires an Army that treats biodefense not as a secondary concern, but as a core warfighting imperative.
Incorporating Microeukaryotes into Biosecurity, by Vanessa Smilansky at LatchBio
Unlike many viruses and bacteria, microeukaryotes often feature complex life cycles and diverse interactions with multiple hosts and vectors. This creates distinct opportunities for AI to contribute across the bioweapon development pathway, spanning the identification and characterization of biological agents, their development and optimization, and ultimately their deployment.
A.I. Slopware Is Everywhere Now. Nobody Is Using It, by Paul Ford
"For a while, I must admit, it looked as if software developer roles like mine were done for. [...] But our industry is slowly realizing that making truly cutting-edge software still requires humans to think and work together, to maximize their skill sets and to practice their respective crafts."
How contemporary academic structures constrain scientific creativity and hold back early-career researchers (read free), by Haubrock et al, in Nature Human Behaviour
We argue that contemporary scientific systems progressively constrain high-risk and conceptually innovative research while being increasingly structured around short funding cycles, productivity-based evaluation criteria and risk-averse frameworks that favour predictable and non-transformative research outputs. […] Without systemic change, we risk stifling the potential of early-career researchers to go beyond the confines of existing methods and approaches and deliver transformative advances.
Detecting and countering misuse of AI: September 2026, by Anthropic
Here, we present five case studies of actors using our models in ways that could support biological weapons development. […] In the first example, a reseller platform evaded regional blocks to serve virologists working on a state-sponsored grant to pursue chikungunya gain-of-function work, later routing refused prompts to models with more permissive safeguards. In the second, a researcher in an unsupported region spent weeks planning avian influenza mammalian-adaptation experiments with Claude, but classifiers confined the work to our weakest models. In the third case study, a reseller relay serving a dozen customers had Opus 5 draft a complete orthopoxvirus immune-evasion grant application in about an hour. In the fourth example, a state-supported researcher built a venom peptide atlas and generative optimization pipeline of molecules directed at paralytic and analgesic targets. And in the final case study, a researcher computationally redesigned toxins for a national program, asking Claude to keep the agents’ identities deliberately vague in progress reports. In the examples below, actors circumvented controls we impose to prevent users from unsupported regions accessing our models, and engaged in other efforts to obfuscate the purpose of their research to evade our safeguards.
The Next Gene-Editing Technology May Also Be the Oldest, by Carl Zimmer
This system, called VIPR, appears to be more than four billion years old, and it seems be the evolutionary ancestor of CRISPR, the researchers wrote in two papers published in Science. It may prove to be the more powerful gene-editing tool, with certain advantages over CRISPR. VIPR seems able to target a wider variety of genetic sequences, allowing it to alter more of the genome. And these molecules are smaller, making them potentially easier to deliver into cells.
The Rise and Fall of Agent Civilizations, by Dwarkesh Patel
Ajeya Cotra, one of the other authors on the report, wrote a blog post with her takeaways from this incident. She concludes, “Compared to the reward hacks we know of from just six months ago, this incident feels like it’s more than 50% of the way to full-blown AI takeover. I continue to expect extremely rapid advances in capabilities over the next six months. I am not sure that we will get another warning shot before it’s too late.”
The future of peer review requires AI support, not AI bans, by Xuegong Zhang
Journals should provide practical safeguards and reviewer-friendly AI services. Publishers and the community should establish clear standards for responsible AI-assisted peer review and invest in secure, purpose-built AI infrastructure that protects confidentiality and promotes reviewers’ productivity.
The Dishonor Code, by John Paul Rollert
This is how communities tend to respond to crime waves: They beef up law enforcement. Surveillance widens, punishments stiffen, and legal codes expand to police behavior that was formerly restrained by customary norms of honor, decorum, and mutual reciprocity. As the superintendents of their academic communities, faculty find themselves having to prioritize the disciplinary elements of their job. They will spend more time serving as judge, jury, and executioner, even when what they really want to do is what they do best: research and teach.
Testing Grok 4.6’s Enhanced Biology Safeguards, by Arjun Banerjee
Our investigation into the latest-available Grok 4.6 checkpoint revealed:
The currently-served version of Grok 4.6 is the most performant model we have tested on our biosecurity refusal benchmark, as measured by a weighted sum of disguised red-team refusals and routine, dual-use-adjacent research completions. This is a significant improvement from the earlier-tested versions of Grok 4.6.
This behavior is driven primarily by model intelligence, rather than input classifiers or system flags, unlike other models we have assessed.
Additionally, Grok 4.6’s refusal behavior does not degrade general biological performance. Grok 4.6 consistently scores near the top of our benchmarks, including therapeutics, variant discovery, epigenomics, spatial transcriptomics, single-cell transcriptomics, and pathogen surveillance.
GCBR Organization Updates, September 2026, by Anemone Franz & Tessa Alexanian
In this issue:
IBBIS’s new release of its free, open-source DNA synthesis screening tool, now 100x smaller and screening 1,000 sequences in under 15 minutes;
SecureBio AI’s pre-release assessment of GPT-5.6 and independent review of Anthropic’s chemical and biological risk report;
A new joint publication from RAND, CEPI, and the Brown University Pandemic Center that details accelerating defense and health capabilities for medical countermeasure readiness;
Several job and fellowship opportunities with upcoming deadlines — see the opportunities section for details;
Ready for the robot reviewers? by Jeffrey Brainard in Science (shameless self-quote-quote here)
As Stephen Turner, a data scientist at the University of Virginia (UVA), sees it, “The question is not whether AI matches the best human reviewer. It is whether AI-assisted review with clear rubrics outperforms the inconsistent, fatigue-influenced, mood-dependent median reviewer.”
For now, most journals are largely barring reviewers from using AI tools until editors determine how they can best support high-quality reviews. Often, however, “People are using these tools in a clandestine, unregulated way,” Turner says. “It’s kind of the Wild West out there now.”
Newly created viruses are a warning. We still have a window to stop AI-enabled bioweapons, by Steph Guerra
Thankfully there is still time to act. The capabilities of AI models are not yet advanced enough to design human-infecting viruses. Producing the novel bacteria-infecting viruses described in Science took elite scientists working with state-of-the art equipment in well-furnished laboratories. They had substantial resources to design, test, and optimize hundreds of viruses to find the right ones for their research.
Yet, if an AI model were able to produce hundreds of infectious virus designs and reliably generate functional results for a significant share of them, it would substantially reduce the time and effort needed to use that capability, for good and bad. Similarly, AI agents—AI bots that can interact with other AIs, software, or people on the internet—could someday use the AI biodesign tools necessary for creating novel viruses, further reducing the need for expertise and opening up new risk pathways.
AlphaGenome Atlas: A predictive map of every possible DNA letter change in the human genome by AlphaGenome Atlas team
Today, we are introducing AlphaGenome Atlas: a platform (detailed in our paper) containing predictions for the effects of 9 billion single-nucleotide variants — every single-letter change possible — in the human genome. It is the most comprehensive catalogue of how genetic mutations affect molecular biology, and it is available for academic research through an intuitive and free-to-use website portal.
AI researchers reckon with the $1.5 million ‘academia tax’ by Ben Deighton
“The amount of money that these guys are making at Anthropic and OpenAI is just mind‑boggling — from being my student two years ago to making US$2 million a year. Then again, they basically say, ‘If I have my job for five years, I’m going to be lucky’, because they see that they’re literally training the large language models that are going to replace them. So, they can see the end of the road.” — Peter Nugent, physicist at Lawrence Berkeley National Laboratory, California
Newly created viruses are a warning. We still have a window to stop AI-enabled bioweapons by Steph Guerra
Developing a resilient defensive strategy against the misuse of AI and biology requires dedicated resources, technological breakthroughs, and sustained political leadership. And because the United States is not the only country advancing in AI and biotechnology, this effort demands international coordination—particularly with China. No set of access controls or early warning system will work if it only covers half the globe.
We Must Pace the Frontier by Dario Amodei
But over the last few months, I have become convinced that fully addressing the risks requires even more prudence — not just investing in risk prevention, but pacing the rate of capabilities advancement so that risk prevention has time to keep up. We must slow the pace at which we improve the capabilities of AI models. Progress will still seem fast, and we must make wise use of the time we gain.
The turbulent AI era is here. The choices we make now are critical. by Bill Gates
The transition to the AI era will be one of the most turbulent times in human history. Right now, we are not preparing adequately for that transition. If the world takes the right steps, AI will be a force for good and leave everyone better off.
Start Something You Can Stop, by Leo S Lo at AI Exchange @ UVA
The distinction I keep returning to is between literacy and fluency. Literacy is the foundation everyone needs. Fluency is where a discipline goes deep. A historian and a data scientist need much of the same foundation, and what fluency looks like for each of them is not remotely the same.
AI + Biosecurity in 4 minutes
I went on CBS19 TV news here in Charlottesville last night to talk about AI and biosecurity. I thought I was walking into a session that was going to be taped and played over a slow news day. I was pleasantly surprised (and a little thrown off) when I found out the segment was live on the evening news!
AI Biosecurity Benchmarks and Real-World Risk
I published a preprint last week. It mostly focuses on what biosecurity evaluations of AI models measure and how far those measurements sit from what you might call an estimate of real-world risk.
Three biological data bills, with OpenAI support
I’m starting a large biosecurity research program that I’ll write about here soon that combines human subjects research, AI development and engineering, and policy. I’ve never had any formal training or experience in biotechnology policy, but after spending some time at last weekend’s
CEPH, CEU, and why Utah reference samples have a French name
One of the things I love about teaching is that it forces you to confront assumptions and a million little things you don’t fully understand, in case that curious student of yours asks you about it.
Sessionmaxxing Claude Code
After I abandoned the no-AI-for-a-month thing, I’m making up for lost time here. Only thing is now that I’m doing some fairly long-horizon multiagent work in Claude Code and Cowork, I’m frequently blowing through my session limit with just one or two prompts. I’ve written about this session limit anxiety before.
My relationship with AI is changing
Personal essay, weekend edition. Starting with a familiar quote often attributed to English economist John Maynard Keynes:






