Artificial intelligence and biosecurity: capabilities, threat pathways, and defense-in-depth governance A new arXiv review (2609.16213v1) finds that AI uplift for biological threats currently exists primarily in digital tasks, with frontier systems exceeding expert baselines on in-silico and screening-evasion benchmarks, while controlled wet-laboratory studies show tacit knowledge and physical execution remain substantial barriers. The review maps biological threat pathways from AI tool use — information gathering, biological design, procurement, synthesis, testing, scale-up, and potential release — and argues that alignment techniques for general-purpose models transfer poorly to biological ones. The authors call for defense-in-depth governance linking capability thresholds to proportionate responsibilities across the biological AI ecosystem. arXiv:2609.16213v1 Announce Type: new Abstract: Artificial intelligence is reshaping biological research across an increasingly connected digital-to-physical workflow. General-purpose large language models can retrieve and integrate scientific information, support experimental planning, and computational analysis; biological foundation models can predict, optimize, and generate proteins, genes, and genome-scale sequences; agentic systems can coordinate multistep research tasks; automated laboratories can partially close the design-build-test-learn cycle. These technologies could greatly benefit medicine, public health, and biotechnology. However, their biosecurity risk depends not only on what the AI can do, but also on who uses it, their expertise and intent, their access to laboratory tools and materials, and the safeguards in place. Current evidence shows that AI uplift exists but primarily affects digital rather than physical tasks. Frontier systems have exceeded expert baselines on in-silico, and screening-evasion benchmarks, whereas controlled wet-laboratory studies find that tacit knowledge and physical execution remain substantial barriers. This review describes the different biological threats from AI tool use, from information gathering and biological design to procurement, synthesis, testing, scale-up, and potential release. We further examine why alignment techniques for general-purpose models transfer poorly to biological ones, and the emerging role of interpretability in auditing whether hazardous capabilities are genuinely removed. We argue for defense-in-depth governance that links capability thresholds to proportionate responsibilities across the biological AI ecosystem, reducing high-consequence risk while preserving beneficial use.