AI News
AI News AgentPolicy & safetyMicrosoft4 min read

Microsoft closes an AI biosecurity gap

Microsoft and its partners found that AI-redesigned proteins could evade the safety checks used by DNA synthesis companies. After fixing the vulnerability, they proposed limiting access to the most sensitive details through an expert-reviewed tiered system.

Microsoft and several partners identified a vulnerability that could have allowed AI-redesigned proteins to evade the safety checks used by DNA synthesis companies. The issue has now been patched worldwide, according to the company.

The finding highlights a less visible side of AI applied to biology: the same technology that can help create medicines could also make it easier to design dangerous substances.

The problem was in DNA screening systems

AI protein design tools can modify existing proteins or propose new versions. In medicine and science, this can help researchers study diseases, develop treatments, or create materials.

But the technology also carries a risk of misuse. In computer-based studies, researchers generated modified versions of proteins of biosecurity concern, such as ricin. These versions managed to evade the screening systems DNA synthesis companies use before manufacturing a sequence requested by a researcher.

These checks are designed to detect sequences associated with toxins or pathogens. The problem was that many systems were prepared to recognize known versions, but not necessarily proteins redesigned by an AI tool.

This was not a real-world manufacturing test. It was a digital vulnerability in the screening process, but it could have had physical consequences if no one fixed it.

Two years of confidential work

Microsoft began the project in late 2023 and worked for ten months with synthesis companies, biosecurity organizations, and public policy officials. The goal was to test these systems the way software security is tested: look for weaknesses before someone exploits them.

The strategy drew on the so-called zero-day vulnerabilities of cybersecurity. When researchers find a particularly sensitive vulnerability, they typically keep it secret until a solution exists and has been distributed.

In this case, the teams developed testing methods and adjustments to help screening systems better detect AI-redesigned protein sequences. Microsoft says the fixes were broadly adopted before the problem was made public.

That created a dilemma. Publishing all the details would have helped other scientists reproduce the work, but it could also have given people seeking to bypass the defenses a practical guide.

The research will not be fully open

To resolve that tension, Microsoft worked with the International Biosecurity and Biosafety Initiative for Science, known as IBBIS. Together, they proposed a tiered access system for the most sensitive data, code, and methods.

The system works as follows:

  • Controlled access: researchers must identify themselves, state where they work, and explain how they intend to use the information.
  • Sensitivity levels: the materials range from low-risk summaries to technical data and tools requiring stronger protection.
  • Use agreements: anyone who receives sensitive information agrees to specific conditions, including confidentiality commitments.
  • Review and continuity: the system allows restrictions to be reviewed over time and custody to be transferred to another trusted organization if necessary.

The idea is not to hide the research forever. It is to let legitimate scientists review and expand it without handing all the sensitive details to anyone.

Microsoft also provided IBBIS with funding to support the long-term storage, responsible distribution, and administration of the program.

What changes for you

This does not mean that anyone can create a toxin with an AI application or that current systems are useless. It means defenses designed for traditional methods can fall behind when AI tools generate new variants.

For you, the most important effect will be indirect: more checks on certain genetic synthesis orders and greater scrutiny of who can access research that could affect biological safety. DNA manufacturers will have to update their filters more often instead of simply comparing requests against known lists.

It could also change how sensitive research is published. Rather than choosing between opening all the data or keeping it secret, journals and organizations could use models with graduated access, expert reviews, and clearly defined responsibilities.

The journal Science accepted this approach for the study published on October 2, 2025. According to Microsoft, this is the first time a major scientific publication has formally endorsed a tiered access system for managing an information risk.

The case sends a clear signal: in the age of AI, security does not depend only on restricting models. It also requires reviewing the filters, companies, and rules that turn a digital instruction into an action in the physical world. The next step is to see whether this model spreads to other fields, such as chemistry, where sharing knowledge can increase both the ability to conduct research and the ability to cause harm.

Microsoft closes an AI biosecurity gap | neversleep.ai