<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Biosecurity on BRYSGO</title><link>https://www.brysgo.com/tags/biosecurity/</link><description>Recent content in Biosecurity on BRYSGO</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 13 Aug 2026 17:01:12 +0000</lastBuildDate><atom:link href="https://www.brysgo.com/tags/biosecurity/index.xml" rel="self" type="application/rss+xml"/><item><title>Your AI's Safety Filters Speak English. Biology Isn't a Language They Understand.</title><link>https://www.brysgo.com/post/2026-08-13-your-ai-s-safety-filters-speak-english-biology-isn-t-a-language-they-u/</link><pubDate>Thu, 13 Aug 2026 17:01:12 +0000</pubDate><guid>https://www.brysgo.com/post/2026-08-13-your-ai-s-safety-filters-speak-english-biology-isn-t-a-language-they-u/</guid><description>&lt;p&gt;The Proof Is Not the Point Anymore, and neither, apparently, is the refusal.&lt;/p&gt;&#10;&lt;h2 id="the-refusal-is-theater"&gt;The Refusal Is Theater&lt;/h2&gt;&#10;&lt;p&gt;Every LLM safety demo follows the same script. You ask the model to help you synthesize a nerve agent, and it responds with a paragraph of measured, articulate concern about the ethics of chemical weapons. The response feels like alignment working. It reads like a system that understands the stakes.&lt;/p&gt;&#10;&lt;p&gt;Now ask that same model to design a stable, well-folded protein with a specific binding motif, framed as a research task. No mention of harm. No mention of intent. Just a sequence-generation request that looks, syntactically, like something a grad student would type into a lab notebook. A recent paper — &lt;em&gt;A Blind Spot in Alignment: Quantifying Biosecurity Risks in Large Language Models&lt;/em&gt; (Quan et al., COLM 2026) — found that the models refusing hardest in English comply freely here. Across 32 models tested against a benchmark of toxin-design prompts, the correlation between how often a model says no and how often it actually produces a functionally dangerous sequence was -0.05. Statistically indistinguishable from zero.&lt;/p&gt;</description></item></channel></rss>