
In the White House Situation Room, the hardest calls were never the obvious emergencies. What kept me up were the nights when a fragment of information came in and the debate wasn’t about what to do. It was about whether anything concerning was happening at all.
In 2023, my team and I were assessing the nation’s pandemic influenza plans when the Situation Room notified me that H5N1 influenza had infected a father and killed his daughter in a remote Cambodian village. Was the virus spreading between people – the start of a pandemic that could kill millions? The national security adviser asked whether to brief President Biden immediately. If these cases were the first signs, we would need to commit billions of dollars to vaccines and treatments within days.
I told him to wait. Not because I thought it was nothing, but because we had already agreed, before the alert came, on what would tell us it was something: sustained human-to-human transmission. We worked with health officials to pull surveillance data from nearby emergency rooms and compared it against prior years. The cases were not unexpectedly high. The President did not need to be alerted, I told him, and I would let him know if the ground truth changed.
That trigger did two jobs at once. It kept us from dismissing a real emergency, and it kept us from escalating one that wasn’t. In almost every crisis I have worked, the decisive moment arrived before anyone agreed there was one. We are in one of those moments now.
On Tuesday, President Trump and leaders of some of the nation’s largest AI companies signed the White House Accord on Superintelligence, a voluntary agreement calling on companies to strengthen internal controls around risks including biosecurity. The accord calls for internal monitoring, independent assessments and board oversight. But it leaves companies largely responsible for determining what those safeguards should look like and when a risk has become serious enough to act.
Bill Gates is warning Americans that artificial intelligence crossed thresholds this year, bio-attack capability among them. The threshold of most concern, he said, is whether an AI can design a bioterrorism weapon capable of killing millions. Last week, Anthropic’s chief executive urged the U.N. Security Council to back a ban on the use of AI to make biological weapons. It followed Anthropic’s disclosure of five cases of biological misuse of its models, including a researcher studying how H5N1 influenza adapts to mammals and causes illness beyond the respiratory tract. The company banned the accounts. There is almost no population immunity to H5N1, roughly half of human cases are fatal, and the virus does not yet spread efficiently between people.
Not yet. The last clause is the threshold I gave the national security adviser in 2023. It is the line between two infected relatives in a Cambodian village and a pandemic. Someone was asking an AI model how it gets crossed.
Most people who read a disclosure like this come to one of two conclusions: AI has made biological weapons frighteningly accessible, or the safeguards worked and there is nothing to worry about. Neither tells us what we most need to know. Gates is right that a line was crossed, but nothing followed, because no one had decided in advance what measures crossing it should set off. The more useful question is: What could the AI help this person do, and what could it not do?
The threshold Gates described is about design. The one that matters next is whether AI can carry a design from the digital world into the physical one. A model that can write a research protocol to create a pathogen is not a person who can create it. You need synthesized DNA, equipment and a lab with four walls to grow a virus in. AI has not yet dissolved those barriers.
That’s not a reason to let up. It shows where we can mitigate risk, while that is still possible.
In the Situation Room, we answered that question before the emergency arrived: a specific observable trigger, paired with a specific action, agreed in advance. We have not applied this trigger-action discipline to the risks associated with AI and biology. So here is what I am watching for, and what each should set off.
I’m paying close attention to evidence that someone without advanced biological expertise used AI to overcome experimental problems that previously required expert judgment. That requires independent evaluators to red-team AI models before deployment, not voluntary company disclosures.
I’m looking for an AI-generated sequence of concern being ordered from a synthesis provider or run through an automated laboratory. That requires watermarking and tracing tools for biological design systems, as the Bipartisan Commission on Biodefense, on which I serve, has recommended.
And I’m watching for proof that AI has substantially reduced the hands-on experience needed for dangerous biological work. DNA synthesis providers, cloud laboratories and benchtop synthesizers are where a digital capability becomes a physical one. Screening there should be expanded; a bipartisan Senate bill has not moved since January.
None of these is “AI answered a dangerous biological question.” Each trigger would signal that the barrier separating AI-generated knowledge from the capability to use it in a physical lab is beginning to erode. Each has an action paired with it.
Faced with a frightening new risk, we tend to ask a question that is almost impossible to answer: how worried should I be? Pre-defined thresholds are not alarmism. That is what allowed us to respond calmly when two cases of H5N1 influenza appeared in one Cambodian family. We knew what signal we were looking for and what to do if we found it. Without one, every ambiguous warning becomes something to panic about or one more thing we have already lived through.
AI is getting better at helping people do advanced biological work, and without stronger safeguards, that raises the risk of bioterrorism. The White House accord is an important acknowledgment that biosecurity belongs at the center of the AI safety conversation. But internal controls are only part of the answer.
The next step is to settle two things: what evidence would show that AI has helped a dangerous capability cross into the physical world, and what we will do when it does. ‘Not yet’ is useful information. It is not a plan.
The opinions expressed in Fortune.com commentary pieces are solely the views of their authors and do not necessarily reflect the opinions and beliefs of Fortune.
#served #White #Houses #top #biosecurity #official #Heres #watching