The Line Nobody Agreed On: What AI and Pandemic Preparedness Have in Common

(SeaPRwire) – By: Julian Holbrooke
The hardest calls in the Situation Room were never obvious. They came when information was thin. The question wasn’t what to do. It was whether anything concerning was happening at all.
In 2023, my team assessed pandemic influenza plans when we learned H5N1 had killed a girl in a remote Cambodian village. The national security adviser wanted to brief President Biden immediately. I told him to wait. We had agreed beforehand on what would trigger escalation: sustained human-to-human transmission. The data didn’t show it. So I told the president we’d know if the ground truth changed.
That trigger did two jobs at once. It kept us from dismissing a real emergency and from escalating one that wasn’t. In almost every crisis, the decisive moment arrived before anyone agreed there was one. We are in that moment now.
On Tuesday, President Trump and leaders of some of the largest AI companies signed the White House Accord on Superintelligence. It asks firms to strengthen internal controls around risks including biosecurity. The accord calls for monitoring, independent assessments and board oversight. But it leaves companies to decide what safeguards should look like and when a risk is serious enough to act.
Bill Gates warned Americans that AI crossed thresholds this year. Bio-attack capability among them. The line he fears most is whether an AI can design a bioterrorism weapon capable of killing millions. Last week, Anthropic’s chief executive urged the U.N. Security Council to back a ban on AI-made biological weapons. This followed Anthropic’s disclosure of five cases of biological misuse. One researcher studied how H5N1 adapts to mammals and causes illness beyond the respiratory tract. The company banned the accounts.
There is almost no population immunity to H5N1. Roughly half of human cases are fatal. And the virus does not yet spread efficiently between people. Not yet. That last clause is the threshold I gave the national security adviser. It is the line between two infected relatives in a Cambodian village and a pandemic. Someone was asking an AI model how it gets crossed.
Gates is right that a line was crossed. But nothing followed because no one had decided in advance what measures should set it off. The more useful question is whether AI can carry a design from the digital world into the physical one. A model that can write a research protocol to create a pathogen is not a person who can create it. You need synthesized DNA, equipment and a lab with four walls to grow a virus. AI has not yet dissolved those barriers.
That’s not a reason to let up. It shows where we can mitigate risk while that is still possible.
We answered that question before the emergency arrived in 2023. A specific observable trigger, paired with a specific action, agreed in advance. We have not applied this trigger-action discipline to AI and biology risks. So here is what I am watching for and what each should set off.
I’m paying close attention to evidence that someone without advanced biological expertise used AI to overcome experimental problems that previously required expert judgment. Independent evaluators need to red-team AI models before deployment, not just rely on voluntary company disclosures.
I’m looking for an AI-generated sequence of concern being ordered from a synthesis provider or run through an automated laboratory. Watermarking and tracing tools for biological design systems are essential, as the Bipartisan Commission on Biodefense has recommended.
And I’m watching for proof that AI has substantially reduced the hands-on experience needed for dangerous biological work. DNA synthesis providers, cloud laboratories and benchtop synthesizers are where digital capability becomes physical. Screening there should be expanded. A bipartisan Senate bill has not moved since January.
None of these is “AI answered a dangerous biological question.” Each trigger would signal that the barrier separating AI-generated knowledge from the capability to use it in a physical lab is beginning to erode. Each has an action paired with it.
The White House accord is an important acknowledgment that biosecurity belongs at the center of the AI safety conversation. But internal controls are only part of the answer. The next step is settling two things: what evidence would show that AI has helped a dangerous capability cross into the physical world, and what we will do when it does. Without pre-defined thresholds, every ambiguous warning becomes something to panic about or one more thing we have already lived through. The calm response in Cambodia worked because we knew what signal we were looking for and what to do if we found it.
Author bio: Julian Holbrooke is an overseas international relations analyst who frequently contributes to major European daily newspapers on technology governance and biosecurity policy.