"CBRN uplift" is the threat model that frontier AI systems materially lower the barrier for non-state or under-resourced actors to acquire and deploy chemical, biological, radiological, or nuclear weapons. It is among the most operationalized catastrophic-risk categories in industry safety frameworks, with explicit thresholds, red-team protocols, and regulatory hooks, and it connects AI safety work to traditional national-security institutions. See AI Biosecurity for the biology-specific subset and AI and National Security for the broader national-security frame.
Definition
Uplift is the marginal increase in capability that an AI system provides to a threat actor compared to what they could achieve with pre-AI tools such as Google, textbooks, and specialist mentorship. The policy-relevant question is not whether AI could in principle describe a weapon, but whether it meaningfully compresses the barrier between a motivated novice and operational capability.
Uplift is commonly decomposed into knowledge uplift (retrieval, synthesis, and translation of specialist literature), troubleshooting uplift (interactive debugging of wet-lab or synthesis problems), planning uplift (acquisition pathways, procurement routing, and workflow design), and tacit-knowledge uplift (approximation of mentorship that would otherwise require PhD-level advisors). Biology is the most-studied subcategory because the barrier is lowest, given dual-use reagents and mail-order synthesis, and because tacit knowledge historically gated progress.
Industry thresholds
Every frontier lab now maintains an explicit CBRN red line, a state of affairs that did not hold in 2023 (Source: Frontier AI Safety Commitments (Seoul, 2024), Anthropic's Responsible Scaling Policy (Version 3.1), OpenAI Preparedness Framework V.2).
Anthropic's responsible scaling policy (Anthropic's Responsible Scaling Policy (Version 3.1)) defines two CBRN tiers. CBRN-3 covers a model that provides meaningful uplift to someone with a basic STEM background attempting to create a weapon capable of mass casualties, and triggers the ASL-3 deployment and security standards. CBRN-4 covers a model that provides uplift to state-level weapons-development programs, and triggers ASL-4. The RSP v2.2 and v3.1 make CBRN-3 the most salient near-term red line; Anthropic has publicly stated that recent Claude models have approached but not crossed it under its evaluation protocol.
The OpenAI Preparedness Framework (OpenAI Preparedness Framework V.2) defines a biological category with graded levels of Low, Medium, High, and Critical. Deployment and development are gated on category scores, and a "Critical" biology score triggers a halt. Google DeepMind's Frontier Safety Framework defines a CBR category (chemical, biological, radiological) with similar graded thresholds.
Uplift studies
Empirical work has converged on a cluster of methodologies. Task-based evaluations have red-teamers attempt CBRN-adjacent tasks with and without model access, measuring accuracy and time-to-completion. Expert-versus-novice panels compare uplift against a baseline of Google access. Lab-based biology uplift, the hardest tier, involves actual wet-lab troubleshooting conducted dry-run only and with IRB-equivalent oversight.
Specific studies include an OpenAI biology uplift study (2024), which reported modest but measurable uplift for GPT-4-class models on biology-relevant task suites without reaching a "Critical" threshold, and Anthropic red-team findings documented in RSP annexes, which showed a similar pattern. METR has expanded from autonomy evaluation into adjacent uplift measurement. SecureBio operates biology-specific evaluations for frontier labs and has co-designed evaluation protocols with OpenAI, Anthropic, and the UK and US AISIs. RAND produced dual-use biology studies in 2023–2024 on the biosecurity implications of large language models.
As of 2026 the prevailing reading is that measurable uplift exists while catastrophic thresholds have not been crossed on public evaluation protocols, although methodology debate remains active and the evaluations are acknowledged to be incomplete.
Dual-use research of concern
AI uplift intersects the long-running debate over dual-use research of concern (DURC) in biosecurity. That debate covers gain-of-function research that generates pathogens with enhanced traits, the tension between open publication norms and dual-use concerns inherited from the Asilomar legacy, and synthesis-screening by which DNA and RNA providers screen sequences against hazard lists. Industry CBRN evaluations effectively extend the DURC frame from experimental results to AI system capabilities.
Policy responses
In the United States, BIS biosecurity and synthesis-screening guidance establishes voluntary screening frameworks for nucleic-acid synthesis providers, led by OSTP. The Department of Defense has made biosurveillance investments, and the Chief Digital and Artificial Intelligence Office (CDAO) conducts dual-use AI work. EO 14110, rescinded under Executive Order 14365 — Ensuring a National Policy Framework for AI, previously required dual-use foundation-model reporting with CBRN risk framing. America's AI Action Plan (America's AI Action Plan) retains CBRN risk language while rolling back disclosure requirements.
Internationally, the International Biosecurity and Biosafety Initiative for Science (IBSA) provides multi-government coordination. The AISI network — the UK AISI, the US AISI (now CAISI), and partners — conducts CBRN evaluations in red-team partnerships with frontier labs. The Seoul and Paris summit commitments call out CBRN explicitly in voluntary frontier commitments (Frontier AI Safety Commitments (Seoul, 2024)).
For industry coordination, the Frontier Model Forum (Frontier Model Forum) runs working groups on biosecurity and shares red-team findings under confidentiality.
Debates and positions
Whether current uplift is catastrophic or marginal is contested: labs and AISIs argue that it is bounded and manageable, while some biosecurity researchers argue that the trajectory is fast enough that "not yet" is a weak answer. The adequacy of evaluations is also disputed, with critics noting that evaluations are designed around known hazards and that unknown-unknowns are by definition unmeasured. A further question is export-control overlap, namely whether CBRN model capability itself should be export-controlled; the EU AI Act treats systemic-risk GPAI specially, while the US has not. Finally, there is the open-source question of whether open-weight models should be held to the same CBRN thresholds, with industry labs arguing yes and open-source advocates arguing that the threat model is weaker than claimed.
Relationships
- depends-on: AI Safety Cases and Frameworks
- instance-of: catastrophic-risk threat model (with AI Autonomy Risk, cyber uplift, deceptive alignment)
- supports: Anthropic's Responsible Scaling Policy (Version 3.1), OpenAI Preparedness Framework V.2
- related: AI Biosecurity, AI and National Security, Executive Order 14110 — Safe, Secure, and Trustworthy AI, America's AI Action Plan, Frontier AI Safety Commitments (Seoul, 2024), Frontier Model Forum
See also
- Anthropic's Responsible Scaling Policy (Version 3.1) — CBRN-3/4 thresholds.
- OpenAI Preparedness Framework V.2 — biology category.
- AI Biosecurity — biology-specific detail.
- Frontier AI Safety Commitments (Seoul, 2024) — industry red-line commitments.
- International AI Safety Report 2025 — state-of-evidence survey.
- America's AI Action Plan — current US policy frame.