SecureBio AI

This stream will work on projects that empirically assess national security threats of AI misuse (CBRN terrorism and cyberattacks) and improve dangerous capability evaluations. Threat modeling applicants should have a skeptical mindset, enjoy case study work, and be strong written communicators. Eval applicants should be able and excited to help demonstrate concepts like sandbagging elicitation gaps in an AI misuse context.

Stream overview

This stream is primarily interested in mentoring projects in biosecurity that either (1) create rigorous threat models of AI biological misuse or (2) create benchmarks and tools that allow us to evaluate and mitigate these risks, as well as verifying that companies are taking suitable precautions.

Potential example projects include:

  • Threat Model: What do inference compute trends imply for how fast dangerous biological capabilities may proliferate and become harder to monitor?
  • Evaluations: Formalizing "scientific ideation in an empirical field" in a manner that allows one to assess human and LLM-generated hypotheses for novelty, plausibility, etc.
  • Mitigations: Developing a way to more richly assess and describe the "blast radius" or "collateral damage" of efforts to remove-in-pretraining or unlearn material from LLMs
  • Verification: How are we better able to standardize and compare the effectiveness of classifiers from different AI companies and assess how much they reduce misuse risk?

Mentors

Nelly Mak
SecureBio
,
Senior Research Scientist
No items found.

Nelly Mak is a research scientist on SecureBio's AI team, working on AIxBio evaluations and safeguards against AI-enabled biorisks. Mak previously completed a postdoc in the Jolly lab on HIV induction of tissue residency, and holds a PhD on the natural hosts of zoonotic viruses.

Read more
Peter Peneder
SecureBio
,
Senior Research Scientist
No items found.

Peter Peneder is a research scientist on SecureBio's AI & Biotechnology Risks team, where his work focuses on building evaluations that assess the biorisk posed by frontier AI models. Peneder previously developed multimodal deep learning approaches for biomedical data during a PhD in bioinformatics.

Read more
Coleman Breen
SecureBio
,
Head of AI Policy
No items found.

Coleman Breen works at SecureBio on technical evaluations of coding agents, EU AI Act implementation, and policymaker engagement. Before SecureBio, Breen was a fellow at the Johns Hopkins Center for Health Security working on AIxBio policy.

Read more
Bryce Cai
SecureBio
,
Senior Research Engineer
No items found.

Bryce Cai works on bio evaluations as part of SecureBio's AI team. Cai is a co-author of ABC-Bench, a suite of tasks measuring the biosecurity-relevant capabilities of AI agents on DNA design and laboratory automation.

Read more

Mentorship style

Typically, this would include weekly meetings, detailed comments on drafts, and asynchronous messaging.

Fellows we are looking for

For threat modeling work:

  • Skeptical mindset
  • Transparent reasoning
  • Analytical

For evaluations, mitigations, and verification work:

  • LLM engineering skills (e.g., agent orchestration)
  • Biosecurity knowledge

Project selection

Mentor(s) will talk through project ideas with scholar

Streams

The Winter 2027 cohort offers a wide range of research streams led by experts across AI alignment, interpretability, governance, and safety. Each stream provides its own research agenda, methodology, and mentorship focus.

London
Empirical
SF Bay Area
London
Control, Monitoring, Red-Teaming, Scalable Oversight, Scheming & Deception
SF Bay Area
Agent Foundations
SF Bay Area
Interpretability
SF Bay Area
Interpretability, Monitoring, Dangerous Capability Evals
SF Bay Area
Interpretability, Model Organisms, Red-Teaming, Safeguards, Scheming & Deception
SF Bay Area
Interpretability
Grand Rapids
Agent Foundations
Washington, D.C.
Compute Infrastructure, Policy & Governance, Security
London
Dangerous Capability Evals, Compute Infrastructure, Policy & Governance, Strategy & Forecasting
Washington, D.C.
Compute Infrastructure, Security
London
Control, Monitoring
London
Control, Scheming & Deception, Dangerous Capability Evals, Model Organisms, Monitoring