Viruses and bacteria dominate discussions of biological risks from AI, but this focus leaves an important gap: microeukaryotes. Protists and fungi include pathogens that can cause serious disease, devastate crops, and produce harmful toxins. Their complex biology, including diverse life cycles and interactions with multiple hosts and vectors, may not be well represented by existing AI safeguards. As AI capabilities continue to advance across increasingly complex biological systems, our defenses should account for a broader range of biological agents and their distinctive risk profiles. This includes expanding existing benchmarks to test whether AI models can appropriately respond to risks associated with microeukaryotic agents, an effort that would benefit from additional real-world biological evidence to inform more comprehensive evaluations.
A Limited Range of Biological Agents are Considered in Threat Assessments
The rapid advancement of AI is lowering barriers across multiple stages of biological research and development, with implications for both legitimate researchers and malicious actors. To keep pace, researchers and policymakers have sought to identify biological agents most likely to experience meaningful AI-enabled capability uplift.
Existing threat classifications can inform which biological agents are prioritized for this assessment. For example, the U.S. Federal Select Agent Program identifies agents and toxins that pose significant risks to public health, agriculture, and animal populations. These well-characterized biological agents are particularly susceptible to AI-enabled capability uplift because extensive research has generated substantial genomic, functional, and experimental data relevant to their development. Threat modeling can then be used to assess this potential uplift by considering how the characteristics of biological agents align with different stages of the bioweapon development pathway, as outlined by the Centre for Long-Term Resilience (CLTR) in their 2023 Research Report and recently expanded on by the RAND Corporation.
Prioritizing Select Agents is underpinned by their recognized risks; however, a sole focus on well-known biological agents can leave us vulnerable to less-established ones. As AI capabilities continue to generalize across increasingly complex biological systems, underrepresented agents may become more accessible across the bioweapon development pathway.
Microeukaryotes are an Underrepresented Biosecurity Risk
Microeukaryotes receive less attention in biosecurity than viruses and bacteria, despite including pathogens with diverse and potentially serious impacts on human, animal, and plant health. The 2026 U.S. multistate outbreak caused by Cyclospora cayetanensis underscores the significant public health impact of foodborne protozoan parasites. Other human protozoan parasites include Plasmodium spp. (malaria), Toxoplasma gondii (toxoplasmosis), and Cryptosporidium parvum (cryptosporidiosis), as well as species affecting livestock such as Eimeria spp. (coccidiosis). Likewise, fungi and fungus-like organisms include human pathogens such as Candida auris and Aspergillus fumigatus, as well as major crop pathogens such as Magnaporthe oryzae (rice blast), Puccinia graminis (wheat rust), and Phytophthora infestans (potato blight). Other microeukaryotes can pose food safety and public health risks through toxin-mediated effects rather than infection. For example, aflatoxins produced by Aspergillus flavus can contaminate food crops and cause serious health effects, while saxitoxins produced by certain marine dinoflagellates can cause paralytic shellfish poisoning.
Unlike many viruses and bacteria, microeukaryotes often feature complex life cycles and diverse interactions with multiple hosts and vectors. This creates distinct opportunities for AI to contribute across the bioweapon development pathway, spanning the identification and characterization of biological agents, their development and optimization, and ultimately their deployment. The greatest concern is where AI lowers barriers to phenotypic changes that could increase dissemination or transmission, disease severity, or the potential for widespread harm, all of which are key characteristics of high-consequence bioweapons. This underscores the need for AI safeguards that account for the unique biology and risk profiles of microeukaryotic agents.
Expanding Existing Biosecurity Efforts to Include Microeukaryotes
Existing benchmarks provide ways to assess both the biological capabilities of AI systems (e.g., VCT, BiosecBench-Surveillance, BiosecBench-Function) and their ability to recognize and appropriately respond to biosecurity risks (e.g., BioTIER, BiosecBench-Refusal). These benchmarks provide an important foundation for safeguarding AI systems against emerging biological agents, but their coverage remains heavily weighted toward viruses and bacteria. Future evaluations could extend this coverage to test whether AI systems can appropriately respond to risks associated with microeukaryotic agents.
The goal should not be simply to add a handful of neglected microeukaryotes to existing evaluations, but to systematically represent the diversity of microeukaryotic biology and their relevance to biological risk. One approach is to organize evaluations around major functional classes of microeukaryotic agents, such as vector-borne protozoa, food- and waterborne protozoa, toxigenic fungi, plant-pathogenic fungi, and human-pathogenic fungi (Table 1). Within each class, evaluations can probe a common set of risk categories, including host and vector competence, environmental persistence, toxin production, enhanced virulence, reduced detectability, countermeasure resistance, and immune evasion. The relevance of these categories may differ across microeukaryotic groups, particularly where complex life cycles and host or vector interactions create distinctive constraints. Looking ahead, developing meaningful benchmarks around these categories will require expanding the underlying data, which in turn will require us to expand our biosurveillance efforts to include more microeukaryotes.1
Table 1: Proposed framework for systematically extending AI biosecurity evaluations across functional classes of microeukaryotic agents
Current targeted and untargeted biosurveillance methods may overlook microeukaryotes: targeted approaches due to the infrequent use of eukaryotic primers, and untargeted approaches due to filtering during sample processing, as microeukaryotes are typically much larger than viruses and bacteria. Many species also lack complete reference genomes due to challenges with culturing and assembly, compounded by comparatively limited sequencing investment in microeukaryotes.


