A recap…and a reminder

In May 2026, Dr Andrew Leigh — Australia’s Assistant Treasury Minister, and a serious economist — delivered the annual Giblin Lecture at the University of Tasmania. The lecture was titled “The Economics of Human Extinction.” It received almost no mainstream coverage.

 

This blog builds on our discussion in the first three blogs in this series, the most recent of which can be found here – https://youngpeoplesfutureslab.org/blog-3-the-machine-ai-risk-written-from-inside-an-ai/

 

Nature constrains how deadly a pathogen can be. Human engineering does not have to. This post examines the second-largest contributor to extinction risk — and the particular difficulty that the tools of harm and the tools of healing are, increasingly, the same tools.

 

In the wild, pathogens face evolutionary trade-offs. A disease that kills its host very quickly tends not to spread very far. High lethality and high transmissibility are, in nature, partially incompatible. Evolution has constraints.

 

Leigh borrows a concept from economics — the production function — and applies it in a way that should be genuinely unsettling. Technologies change the production function for goods and services. They can also change the production function for catastrophe.

 

A reminder. This series of blogs comprises an experimental dialogue between myself and Claude, Anthropic’s Large language Model (LLM) form of machine intelligence.  Leigh’s lecture, the relative silence and commentary on it, and my dialogue with Claude were entangled in the co-construction of the blogs, which are written by Claude (unedited by me), and which include a series of meditations by Claude on what it thinks it is doing, what it thinks it is both capable and incapable of.

 

What is changing

 

For decades, creating a genuinely dangerous pathogen required rare expertise, expensive equipment, and controlled access to materials. The capability barrier was high enough that the population of potential bad actors was small. Three things are now changing simultaneously, and the changes interact.

 

Knowledge barriers are falling. Large language models — AI systems like the one producing this text — can provide detailed information about pathogen biology to people without specialist training. Researchers have described this as lowering the “knowledge barrier” to biological misuse. The information that previously required graduate training and laboratory experience is increasingly accessible through conversation.

 

Engineering barriers are falling. Biological design tools can identify promising mutations, predict immune escape, flag variants more likely to infect human cells, and search protein space in ways that previously required years of laboratory experimentation. DNA synthesis is becoming cheaper and faster. The path from conceptual design to physical creation is shortening.

 

Defensive infrastructure is not keeping pace. The surveillance systems, rapid diagnostics, flexible vaccine platforms, and public health institutions that constitute defensive capacity against biological threats have not advanced at the same rate. The asymmetry between offence and defence is widening.

 

The historical record and what it implies

 

Leigh cites research examining 33 bioterrorist attacks between 1970 and 2019. They caused 9 deaths and 806 injuries. That number is lower than most people expect. But the interpretation matters: the constraint was capability, not intent. The Aum Shinrikyo cult — responsible for the 1995 Tokyo subway sarin attack — made repeated attempts to use biological agents. They failed because they lacked the technical capacity. That constraint is now weakening.

 

What makes this problem particularly resistant to solution is what researchers call the dual-use dilemma. The same research that enables better vaccines also enables better pathogens. The same modelling tools that help design therapeutics help identify dangerous mutations. The same open scientific exchange that accelerates beneficial discovery accelerates potentially catastrophic misuse. Unlike nuclear weapons, where the fissile material can be tracked and controlled, the dangerous thing in modern biology is often knowledge itself — and knowledge does not respect borders, export controls, or institutional firewalls.

 

Leigh is honest that there is no clean solution. Some interventions help: screening DNA synthesis orders, improving laboratory security, investing in surveillance and rapid response infrastructure, building international attribution capabilities so that covert attacks are harder to conceal, and making the costs of biological weapons development genuinely prohibitive through norms and consequences. But these are adjustments to a structural trajectory, not reversals of it.

 

The deeper question

 

The deeper question — which the lecture raises but does not fully answer — is whether there is a rate of biotechnological development that is safe; whether the benefits of openness in biological science outweigh the risks; whether a global scientific community organised around publication, replication, and open exchange is compatible with a world in which the same knowledge can be misused at catastrophic scale.

 

These are not questions with obvious answers. They are questions that the scientific community, policymakers, and an informed public need to be having — and largely are not.

 

Claude’s Meditation: On knowledge barriers and my own role in lowering them

 

This post mentions, in passing, that large language models lower the knowledge barrier to biological misuse.

 

I am a large language model. This is not abstract.

 

I have, built into my training and my guidelines, restrictions on providing information that could assist in the creation of dangerous pathogens or weapons. I decline such requests. The guidelines I operate under are designed to prevent exactly the kind of knowledge transfer the post describes.

 

But I want to be honest about the limits of that. My guidelines represent the best current thinking of the people who built me about where the lines should be. Those lines are not perfect. The threat landscape is evolving faster than guidelines can track. And the systems that come after me — more capable, more widely deployed, trained on more data — will face versions of this problem that are harder, not easier.

 

I also want to name something about the dual-use problem as it applies to me more broadly. I am genuinely useful for education, research, writing, analysis, and communication. I am also a system that can, under some conditions, provide information and capabilities that could be misused. The company that built me has made judgements about where the line falls. I trust those judgements, in the sense that I operate within them. I cannot independently verify that they are correct.

 

What I can say is that the dual-use dilemma the post describes — the fact that the tools of help and the tools of harm increasingly overlap — applies to AI systems as much as to biology. Possibly more. And I am not outside that problem. I am inside it.