This work was a joint undertaking of RAND Europe and The Centre for Long-Term Resilience and is cross-posted on the RAND website here.
Artificial intelligence is transforming the life sciences, accelerating breakthroughs in medical research, drug discovery, and biotechnology. However, some of the AI tools that drive innovation can also be misused, posing significant dual-use risks. Ensuring that these technologies are developed and deployed responsibly requires a clear, structured understanding of the capabilities of individual AI-enabled biological tools and their potential misuse applications.
This report introduces the first Global Risk Index for AI-enabled Biological Tools, which provides a structured and scalable framework for assessing these tools based on their capabilities, potential for misuse, accessibility, and technological maturity. Our methodology builds upon previous work by the Centre for Long-Term Resilience and RAND Corporation, with significant updates and expansions that together deliver a more comprehensive evaluation approach.
Developers can use the Index to better understand the broader implications of the tools they’re building—not just their benefits, but also their risks—and to design these, and other related AI models, with safety and responsibility in mind. Policymakers can use the Index to navigate a rapidly evolving landscape, identify misuse-relevant tools or capabilities, and prioritise areas for governance, risk assessment and mitigation.
Recommendations
Based on our findings, we recommend five key actions for different stakeholders:
| 1. Developers and funders should use the Global Risk Index rubrics to assess tools for misuse-relevant capabilities before funding and developing tools, and before publication and model release. |
| The Global Risk Index rubrics can inform developers of potential misuse concerns before a tool is built. This allows funders to engage in responsible innovation and prioritise investment for safer defensive applications. Pre-deployment assessments also help identify safeguards and inform decisions on whether a tool should have mitigations embedded and be open-sourced or released with managed access. |
| 2. Developers and funders should implement managed access for tools with significant misuse-relevant capabilities using Know Your Customer (KYC) principles to differentially prioritise development of medical countermeasures and other defences. |
| Managed access programmes using KYC checks can provide legitimate researchers with early access to powerful AI capabilities, accelerating the development of medical countermeasures and other defences. This approach, already established in several other industries and fields, helps deny access to threat actors who might misuse these tools while fostering faster, safer innovation within a trusted community. |
| 3. Funders should enable developers to embed safeguards into tools ‘by design’, piloting promising approaches as soon as possible, while ensuring non-safeguarded model private accessibility for legitimate defensive researchers where necessary. |
| Additional funding is urgently needed to develop and test technical safeguards that can be built into AI-enabled biological tools from the start. Funders and developers should also carefully manage the generation and publication of sensitive dual-use data. Where necessary for defensive research, access to non-safeguarded versions of tools should be provided securely to legitimate researchers. |
| 4. Developers, funders and governments should promote a culture of responsible innovation by convening regularly and sharing information. |
| Acknowledging the risks of dual-use tools can attract more experts to work on safeguards and responsible innovation. We recommend that developers, funders, and government experts convene regularly to coordinate capability assessments, establish best practices, and foster international collaboration across the global developer community to reduce misuse risks and share benefits. |
| 5. Governments and independent experts should conduct ongoing tool assessment and monitoring, with input from developers and their funders. |
| Given the rapid pace of development, governments and independent experts should refresh the Global Risk Index regularly—ideally every six months—to avoid strategic surprises. This process should be done in consultation with tool developers and funders, who can help identify emerging capabilities and improve assessment methods. Piloting AI-enabled automation could significantly improve the efficiency of these ongoing assessments. |
To read the full report, please click ‘Download’ below.
For queries related to this report, please contact the corresponding authors, Dr Cassidy Nelson (cassidy@longtermresilience.org) and Dr Sana Zakaria (szakaria@randeurope.org).
Suggested citation: Webster et al. 2025. “Global Risk Index for AI-Enabled Biological Tools”. The Centre for Long-Term Resilience & RAND Europe. https://doi.org/10.71172/wjyw-6dyc
This publication is a shortened version of an April 2025 private report, adapted in line with our commitments to transparency and responsible disclosure of potentially hazardous information. This public report describes the methodology that underlies the Global Risk Index in detail, provides an overview of our results and offers recommendations to help both promote the benefits of AI-enabled biological tools and mitigate emerging risks they pose. Additional results and recommendations relevant only to government colleagues are omitted from this report—you are welcome to contact the corresponding authors for further information.