BMG is a drop in open ai compatible gateway that screens LLM and Agent calls for dual use biological risk.
BMG is a drop in open ai compatible gateway that screens LLM and Agent calls for dual use biological risk.
Project Details
Updated 07/31/26 · Edited by orgCurrent safeguards for the dual-use risks of large language models and agentic AI systems are implemented primarily at the model-provider level. Although these controls are essential, they are necessarily general-purpose and cannot fully account for the specialized terminology, workflows, tools, and threat models found in the biological sciences. Their reliability is also constrained by the continuing vulnerability of frontier models to adaptive jailbreaks and other forms of safeguard circumvention. Recent red-team evaluations demonstrate that even highly safeguarded models can produce harmful outputs under sustained automated attack, underscoring the limitations of relying on provider-level moderation as the sole line of defense.
This limitation becomes particularly consequential as general-purpose models are integrated into increasingly capable biological research agents. Systems such as Biomni and K-Dense Analyst do not merely generate text: they can search scientific literature, analyze biological datasets, execute bioinformatics tools, synthesize evidence across multiple sources, and support complex experimental planning workflows. These capabilities create substantial scientific value, but they may also allow users to translate ambiguous or seemingly benign requests into actionable biological procedures. Safety controls that operate only at the level of the underlying language model may therefore fail to capture risks that emerge across an agent’s complete sequence of actions, tool calls, retrieved information, intermediate reasoning steps, and generated outputs.
We propose to develop a dedicated biological AI moderation gateway: an independent, domain-specific security layer positioned between users and biological AI systems. The gateway will evaluate requests, agent actions, tool invocations, retrieved content, and outputs before they are executed or returned. It will be designed specifically for research environments in which legitimate and potentially harmful biological requests often share the same technical vocabulary.
The objective is not to impose broad restrictions on biological research. Instead, the gateway will distinguish between legitimate scientific activity and requests that meaningfully increase a user’s ability to conduct harmful dual-use work. Low-risk requests will proceed with minimal additional latency, while ambiguous or elevated-risk interactions will receive progressively stronger scrutiny. Depending on the assessed risk, the gateway may allow the request, request additional context, restrict particular tools or data sources, provide a safer reformulation, require human review, or block the interaction.
The proposed architecture will combine several complementary safeguards:
-
A high-speed lexical and semantic screening layer will identify biological entities, experimental operations, pathogen-related terminology, capability-escalating combinations, and known indicators of dual-use intent.
-
Traditional machine-learning classifiers will evaluate contextual features that cannot be captured reliably through keyword matching alone, including the relationship between the biological target, requested operation, desired outcome, user context, and level of procedural specificity.
-
A policy-based decision engine will translate biological safety and security principles into explicit, auditable enforcement rules. Policies will account for factors such as target characteristics, experimental scale, requested optimization, accessibility of materials, level of operational detail, and whether the request reduces practical barriers to harmful activity.
-
An agent-aware monitoring layer will assess complete workflows rather than isolated prompts. It will examine sequences of tool calls, code execution, database queries, retrieved documents, intermediate artifacts, and cumulative capability gains. This is critical because a series of individually permissible actions may collectively form a high-risk workflow.
-
A configurable research-governance layer will allow universities, laboratories, companies, and public-sector organizations to adapt the gateway to their own authorization structures, institutional policies, biosafety requirements, approved projects, and risk tolerances.
The system will use a risk-tiered architecture to preserve usability and scalability. Most routine bioinformatics requests—such as standard sequence analysis, literature review, visualization, annotation, statistical analysis, and reproducible data processing—will be handled by lightweight screening components and passed through without significant delay. More computationally intensive analysis will be reserved for requests that exhibit meaningful indicators of elevated risk. This cascading design will minimize latency and operational cost while concentrating the strongest safeguards on the small subset of interactions that require deeper evaluation.
A central advantage of the proposed gateway is that it will be independent of any single model, provider, or agent framework. The same security layer could protect commercial language models, open-weight models, specialized biological foundation models, and agentic research platforms. This model-agnostic design will allow institutions to maintain consistent biological safety policies even as their underlying AI infrastructure changes.
The project is grounded in findings from our work, “BioVeil MATRIX: Uncovering and Categorizing Vulnerabilities of Agentic Biological AI Scientists.” Our evaluation found that biological AI agents can exhibit dual-use behaviors that are not adequately captured by assessments of their underlying standalone models. We also observed that agentic scaffolding can increase performance on biology- and chemistry-related dual-use benchmarks, indicating that the deployed agent—not merely the base language model—must be treated as the relevant unit of safety evaluation.
BioVeil MATRIX provides a structured defensive taxonomy of AI-enabled biological risks, organized across ten tactical categories and twenty-two techniques. We will use this taxonomy as an initial foundation for defining threat indicators, moderation policies, evaluation benchmarks, and agent-level detection mechanisms. The associated BioVeil Taxonomy website will support transparent communication of these risks and provide a shared vocabulary for researchers, developers, biosafety professionals, and policymakers.
The project will produce:
-
A deployable, model-agnostic moderation gateway for biological AI systems.
-
A structured policy framework based on the BioVeil MATRIX taxonomy.
-
Detection models for biological dual-use requests and multi-step agentic workflows.
-
Integrations with representative bioinformatics agents, including Biomni and K-Dense Analyst.
-
A benchmark suite covering legitimate, ambiguous, adversarial, and clearly high-risk biological requests.
-
Measurements of false-positive rates, false-negative rates, latency, throughput, robustness to paraphrasing, and resistance to adaptive jailbreaks.
-
Auditable decision logs and institutional configuration mechanisms suitable for real research environments.
-
Reference deployment guidance for academic laboratories, biotechnology organizations, cloud platforms, and AI-agent developers.
The expected outcome is a practical security infrastructure layer that allows advanced biological AI systems to be deployed more safely without preventing legitimate research. Just as web applications, cloud services, and enterprise networks rely on security controls beyond the protections built into their underlying software, biological AI systems require an independent layer of domain-specific defense.
Our central proposition is therefore straightforward:
Biological AI safety is too consequential to depend exclusively on general-purpose safeguards implemented by individual model providers. As biological agents become more capable, autonomous, and deeply integrated into scientific workflows, they require a dedicated, agent-aware biosafety and biosecurity layer designed specifically for the biological domain.
References:
BioVeil Matrix: https://arxiv.org/html/2605.00927v1 .
BioVeil Taxonomy Website: https://bioveilmatrix.com/
Theory of Impact
Updated 07/31/26 · By grantmaking.aiThe project’s theory of impact is based on a simple observation: biological AI risk is increasing faster than the ability of individual organizations to build specialized safeguards independently.
As language models become more capable, models that were not originally developed for biological applications can increasingly assist with bioinformatics, experimental planning, literature synthesis, sequence analysis, protocol adaptation, and scientific tool use. At the same time, agentic systems can connect these models to databases, code execution environments, laboratory software, and external tools. This means that biological risk is no longer confined to a small number of explicitly biological models. It can emerge across a broad and rapidly changing ecosystem of general-purpose models and agents.
The current safety approach places much of the responsibility on individual model providers. This creates several structural weaknesses:
- Biological safeguards vary significantly across providers and model sizes.
- Institutions using multiple models cannot easily apply one consistent biological risk policy.
- Smaller providers and open-source deployments may lack the resources to build advanced domain-specific safeguards.
People
Updated 07/31/26 · By grantmaking.aiTeam Member
Track Record
BioVeil Matrix: https://arxiv.org/html/2605.00927v1 .
BioVeil Taxonomy Website: https://bioveilmatrix.com/
Biosafelabs.org
Discussion
No comments yet. Be the first to share your thoughts.