Appendix B — Glossary of Biosecurity Terms
A glossary of terms used throughout The Biosecurity Handbook, organized alphabetically.
A
Aerosolization: The process of converting a liquid or solid into fine airborne particles, relevant to pathogen transmission and weaponization.
AI Safety Level (ASL): Risk classification framework developed by Anthropic for AI systems, modeled on biosafety levels (BSL). ASL-1 represents minimal risk; higher levels require additional safeguards.
Amerithrax: The FBI investigation into the 2001 anthrax letter attacks in the United States that killed five people and infected 17 others.
Anthrax: Disease caused by Bacillus anthracis, a spore-forming bacterium. Category A bioterrorism agent due to ease of production and environmental stability.
Attribution: The process of identifying the source and perpetrator of a biological event, whether natural, accidental, or deliberate.
Australia Group: Informal forum of countries established in 1985 to harmonize export controls on dual-use chemicals, biological agents, and related equipment.
Africa Pathogen Genomics Initiative (Africa PGI): $100 million partnership launched in 2020, led by Africa CDC, to expand genomic sequencing capacity across the African continent. Established 13 sequencing centers of excellence and expanded sequencing capability from 7 to 46 African countries by 2024.
B
Benefit-sharing: Principle that countries providing pathogen samples or genomic data should receive fair access to resulting benefits such as vaccines, diagnostics, and treatments. Formalized in the WHO Pandemic Influenza Preparedness (PIP) Framework.
Bacillus anthracis: The bacterium that causes anthrax. Notable for its ability to form hardy spores that can persist in the environment for decades.
BARDA (Biomedical Advanced Research and Development Authority): U.S. government agency responsible for developing and procuring medical countermeasures against CBRN threats and pandemic influenza.
Biorisk: The probability that a biological agent will cause harm, combining considerations of hazard and exposure.
Biological AI Models: AI models trained on or capable of meaningfully manipulating substantial quantities of biological data, including genetic sequences, protein structures, or complex biomolecular systems (Bloomfield et al., 2024). Distinguished from general-purpose LLMs by their specialized biological training data and capabilities.
Biosafety: Protection of people and the environment from unintentional exposure to biological agents through containment and safe laboratory practices.
Biosafety Level (BSL): Classification system (BSL-1 through BSL-4) defining physical containment requirements for work with biological agents, based on agent characteristics and procedures performed. See Laboratory Biosafety and Biosecurity for full discussion.
Biosecurity: Protection of biological agents, materials, and sensitive information from theft, misuse, diversion, or deliberate release. See What Is Biosecurity? for full discussion.
Benchtop DNA Synthesizer: Laboratory instrument that enables on-site synthesis of DNA sequences without ordering from commercial providers. Platforms from companies like DNA Script, Ansa Biotechnologies, and Nuclera bypass centralized screening infrastructure, creating biosecurity governance challenges.
Bioterrorism: The deliberate release of biological agents to cause illness, death, or fear for ideological, political, or religious purposes.
Bioweapon: A biological agent (pathogen or toxin) that has been weaponized for use against humans, animals, or plants.
Biological Weapons Convention (BWC): The 1972 international treaty prohibiting the development, production, stockpiling, and use of biological weapons. Entered into force in 1975.
Biopreparat: The Soviet Union’s clandestine biological weapons program that operated from 1973 to 1992, violating the BWC. At its peak, employed over 50,000 scientists.
Botulinum toxin: The most poisonous naturally occurring substance known, produced by Clostridium botulinum. Both a bioterrorism concern and medical therapeutic.
BSL-4: The highest biosafety level, required for work with agents that pose high risk of life-threatening disease with no available vaccines or treatments (e.g., Ebola, Marburg).
C
Case Fatality Rate (CFR): The proportion of people diagnosed with a disease who die from it, expressed as a percentage.
CBRN: Acronym for Chemical, Biological, Radiological, and Nuclear threats, often addressed together in security frameworks.
CDC (Centers for Disease Control and Prevention): U.S. federal agency responsible for protecting public health and safety, including oversight of select agents and biosafety.
Chain of Custody: Documentation tracking the handling and transfer of samples or evidence, critical for forensic attribution.
Classifier Cascade: A two-stage defense architecture where a lightweight first-stage classifier screens all traffic and escalates only suspicious exchanges to a more expensive second-stage classifier. Used in Constitutional Classifiers++ to reduce computational overhead while maintaining robustness against jailbreak attacks.
Chirality: A molecular property where a structure is not superimposable on its mirror image, like left and right hands. In biology, DNA is right-handed and amino acids are left-handed. This universal orientation enables immune recognition of pathogens. Mirror organisms would use reversed chirality, potentially evading immune defenses.
Cloud Laboratory: Remotely accessible laboratory facility where experiments are conducted by robotic systems based on digital instructions, raising novel biosecurity oversight challenges.
Constitutional Classifier: AI safety system developed by Anthropic that monitors exchanges between users and AI models in real-time, using classifiers trained on synthetic data generated from natural language rules (a “constitution”) specifying permitted and restricted content. Constitutional Classifiers++ (2026) introduced exchange classifiers that evaluate outputs in context of inputs, achieving production-grade CBRN defense with 0.05% false positive rates. See Red-Teaming AI Systems for full discussion.
Codon Optimization: Modifying the nucleotide sequence of a gene to improve expression in a target organism without changing the amino acid sequence.
Containment: Physical and procedural measures to prevent the release of biological agents from laboratory or production facilities.
CRISPR (Clustered Regularly Interspaced Short Palindromic Repeats): Gene editing technology enabling precise modifications to DNA sequences, with significant dual-use implications.
CRISPR-Cas9: First-generation CRISPR gene editing system using Cas9 nuclease to create double-strand breaks at targeted genomic locations, enabling gene knockout or insertion through cellular repair mechanisms.
CRISPR Base Editing: Second-generation CRISPR technology enabling single-nucleotide changes (A→G, C→T conversions) without creating double-strand breaks, reducing unwanted insertions or deletions.
CRISPR Prime Editing: Third-generation CRISPR system enabling precise insertions, deletions, and all 12 possible base-to-base conversions without requiring double-strand breaks or donor DNA templates, offering enhanced precision and fewer off-target effects.
D
Decontamination: The process of removing or neutralizing biological agents from surfaces, equipment, or environments.
Deliberate Release: Intentional dissemination of biological agents, whether for terrorism, warfare, or other malicious purposes.
Democratization (of Biology): The trend toward making biological techniques and tools more accessible to non-specialists, raising concerns about misuse.
Digital Biomarkers: Physiological and behavioral data collected from digital devices (wearables, smartphones) that can indicate health status. In biosurveillance, aggregated digital biomarkers like resting heart rate and sleep patterns may detect population-level illness signals before traditional surveillance systems.
DNA Synthesis Screening: Process by which gene synthesis companies check orders against databases of dangerous sequences to prevent misuse. See DNA Synthesis Screening: The Critical Chokepoint for full discussion.
Dual-Use Research: Scientific research that can be used for both beneficial and harmful purposes.
Dual-Use Research of Concern (DURC): Life sciences research that, based on current understanding, can be reasonably anticipated to provide knowledge, information, products, or technologies that could be directly misapplied to pose a significant threat to public health, agriculture, or national security. See Dual-Use Research of Concern for full discussion.
E
Ebola Virus Disease (EVD): Severe, often fatal hemorrhagic fever caused by Ebola virus. CFR ranges from 25-90% depending on strain and healthcare quality.
Emerging Infectious Disease: A disease that has newly appeared in a population or has existed but is rapidly increasing in incidence or geographic range.
Endemic: A disease or pathogen that is constantly present within a given geographic area or population.
Epidemic: An increase in disease incidence above the expected baseline within a specific community or region.
Epidemiology: The study of distribution, patterns, and determinants of disease in populations.
Exchange Classifier: A type of Constitutional Classifier that evaluates AI model outputs in the context of their corresponding inputs, rather than examining inputs and outputs separately. This approach addresses reconstruction attacks (fragmenting harmful requests across benign segments) and output obfuscation attacks (disguising responses with metaphors or substitutions). Introduced in Constitutional Classifiers++ (2026).
Export Controls: Government regulations restricting the transfer of sensitive materials, technologies, or information across national borders.
F
Filamentous Phage: A type of bacteriophage (virus that infects bacteria) with a long, thin shape, sometimes used in biological research.
Fomite: An inanimate object that can carry and transmit infectious agents (e.g., doorknobs, medical equipment).
Foot-and-Mouth Disease (FMD): Highly contagious viral disease affecting cloven-hoofed animals. The 2001 UK outbreak resulted in the culling of over 6 million animals.
Forensic Microbiology: The application of microbiology to legal investigations, particularly attribution of biological incidents.
Functional Assay: Laboratory test that measures the biological activity of an agent or molecule.
Fink Report: The 2004 National Research Council publication Biotechnology Research in an Age of Terrorism that introduced the concept of dual-use research of concern (DURC) and defined seven categories of “experiments of concern.” Named after committee chair Gerald Fink.
G
Gain-of-Function (GOF) Research: Research that modifies a biological agent to confer new or enhanced capabilities, such as increased transmissibility or virulence. See Gain-of-Function Research: Science, Risk, and Governance for full discussion.
Gene Drive: Genetic engineering technology designed to spread a particular gene through a population faster than normal inheritance would allow. See Gene Drives and Environmental Biosecurity for full discussion.
Gene Synthesis: The artificial construction of DNA sequences from chemical building blocks, without requiring a template organism.
Genetic Engineering: Direct manipulation of an organism’s genome using biotechnology.
Genomic Surveillance: Systematic sequencing and analysis of pathogen genomes to track evolution, transmission, and origins.
GISAID: Global Initiative on Sharing All Influenza Data, a platform for rapid sharing of pathogen genomic data.
H
H5N1: A subtype of influenza A virus that causes highly pathogenic avian influenza (bird flu) with pandemic potential.
Hemorrhagic Fever: Class of diseases characterized by fever and bleeding disorders, including Ebola, Marburg, and Lassa fever.
High-Consequence Pathogen: Biological agent capable of causing severe disease or death, often with limited treatment options.
HEPR (Health Emergency Preparedness, Response and Resilience): WHO framework launched in 2023 defining five core capacity areas for pandemic preparedness: surveillance, clinical care, protecting communities, access to medical countermeasures, and emergency operations. Provides evidence-based guidance while emphasizing that preparedness must be operationalized at the national level.
Host Range: The spectrum of species that a pathogen can infect.
I
IARPA (Intelligence Advanced Research Projects Activity): U.S. intelligence agency that funds high-risk, high-reward research, including biosurveillance technologies.
Incubation Period: The time between infection and the appearance of symptoms.
Index Case: The first documented case in an outbreak (also called “patient zero”).
Information Hazard: Risk arising from the dissemination of true information that could enable harm if misused. See LLMs and Information Hazards for full discussion.
Insider Threat: Risk posed by individuals with authorized access to sensitive materials, facilities, or information who may misuse that access.
International Health Regulations (IHR): WHO framework requiring member states to detect, assess, report, and respond to public health emergencies of international concern.
J
Jailbreak Attack: Technique used to bypass safety measures in AI systems through adversarial prompting or other methods.
Joint External Evaluation (JEE): Voluntary WHO assessment tool measuring country capacity across 19 technical areas relevant to International Health Regulations (IHR) compliance, including laboratory diagnostics, surveillance, and emergency response capabilities.
K
Koch’s Postulates: Criteria for establishing a causal relationship between a microorganism and a disease, developed by Robert Koch in the 19th century.
L
Laboratory Accident: Unintended release or exposure involving biological agents within a laboratory setting.
Laboratory-Acquired Infection (LAI): Infection resulting from work in a laboratory environment.
Large Language Model (LLM): AI system trained on large text datasets capable of generating human-like text, with potential dual-use implications for biosecurity.
Lethality: The capacity of a pathogen or agent to cause death.
LNT (Lethal and Non-Transmissible): Category of biological agents that can kill but do not spread person-to-person (e.g., anthrax, botulinum toxin).
M
Marburg Virus: Filovirus closely related to Ebola, causing severe hemorrhagic fever with high fatality rates.
Medical Countermeasures (MCM): FDA-regulated products (biologics, drugs, devices) used to prevent, diagnose, or treat conditions associated with CBRN threats or emerging infectious diseases. See Medical Countermeasures and Biodefense for full discussion.
Metagenomic Sequencing: Approach that sequences all genetic material in a sample, enabling detection of known and unknown pathogens.
Mirror Life (Mirror Bacteria): Hypothetical organisms built from mirror-image versions of biological molecules, using left-handed DNA and right-handed amino acids instead of the natural orientations. A December 2024 Science report by 38 researchers warned that mirror bacteria could evade immune systems, face no natural predators, and spread irreversibly if released. Creating complete mirror organisms is not yet possible but may become feasible within a decade. No international governance framework currently addresses this technology.
Morphotype: A distinct variant of a microorganism distinguishable by its physical characteristics, important in forensic attribution.
mRNA Vaccine: Vaccine technology using messenger RNA to instruct cells to produce an antigen, enabling rapid development (e.g., COVID-19 vaccines).
Multimodal AI: AI systems capable of processing and integrating multiple types of input (text, images, video, audio). In biosecurity contexts, multimodal capabilities enable vision-based laboratory coaching, real-time technique correction via video observation, and potentially erode the tacit knowledge barrier that has historically limited biological threats.
N
National Select Agent Registry: U.S. program regulating possession, use, and transfer of biological agents and toxins that pose severe threats.
Natural Spillover: Transmission of a pathogen from an animal reservoir to humans without human intervention.
Nextstrain: Open-source platform for real-time tracking of pathogen evolution through phylogenetic analysis and visualization. Developed by Trevor Bedford and Richard Neher, Nextstrain integrates genomic data with epidemiological information to enable outbreak tracking, variant surveillance, and evolutionary analysis.
Nucleic Acid Observatory (NAO): Concept for continuous, pathogen-agnostic environmental metagenomic surveillance. Proposes sequencing all genetic material in wastewater or other environmental samples to detect novel pathogens before clinical presentation, regardless of prior knowledge about the threat.
Nipah Virus: Emerging zoonotic virus with high fatality rate (40-75%), transmitted from fruit bats and causing encephalitis.
Normalization of Deviance: Gradual process by which unacceptable practices become acceptable within an organization, often preceding accidents.
Novichok: Class of nerve agents developed by the Soviet Union, used in the 2018 Salisbury poisoning.
O
One Health: Integrative approach recognizing that human, animal, and environmental health are fundamentally interconnected. Formally endorsed by WHO, FAO, UNEP, and WOAH (World Organisation for Animal Health) through the Quadripartite One Health Joint Plan of Action. Approximately 60-75% of emerging infectious diseases are zoonotic, highlighting the importance of cross-sector collaboration in biosecurity surveillance, outbreak response, and threat mitigation.
OPCW (Organisation for the Prohibition of Chemical Weapons): International organization implementing the Chemical Weapons Convention, with some overlapping concerns with biosecurity.
Outbreak: Occurrence of disease cases in excess of normal expectancy in a given community or region.
P
P3CO (Potential Pandemic Pathogen Care and Oversight) Policy: U.S. policy framework for oversight of research involving enhanced potential pandemic pathogens.
Pandemic: An epidemic that has spread across multiple countries or continents, affecting a substantial number of people.
Pandemic Fund: Multilateral financing mechanism established in 2022 by WHO and the World Bank to strengthen pandemic preparedness in low- and lower-middle-income countries. Through 2025, the fund has awarded approximately $885 million in grants across two funding rounds, mobilizing an additional $6 billion in co-financing to close critical capacity gaps in surveillance, laboratory systems, and emergency operations.
Pandemic Influenza Preparedness (PIP) Framework: WHO framework established in 2011 governing the sharing of influenza viruses with pandemic potential and access to resulting vaccines and benefits. Codifies benefit-sharing principles requiring that countries providing pathogen samples receive fair access to resulting medical countermeasures.
Pangolin (Phylogenetic Assignment of Named Global Outbreak Lineages): Machine learning-based software tool for assigning SARS-CoV-2 genomic sequences to named lineages within the Pango nomenclature system. Developed by Áine O’Toole and colleagues, Pangolin enabled standardized variant tracking during the COVID-19 pandemic.
Pathogen: A biological agent capable of causing disease in a host organism.
Pathogen-agnostic Detection: Surveillance approach designed to detect any pathogen without requiring prior knowledge or hypothesis about the specific threat. Contrasts with targeted diagnostics that test for specific known pathogens. Metagenomic sequencing exemplifies pathogen-agnostic methodology.
Pathogenicity: The ability of a pathogen to cause disease.
Personal Protective Equipment (PPE): Specialized clothing or equipment worn to minimize exposure to hazards.
Phylogenetic Analysis: Study of evolutionary relationships among organisms based on genetic sequence data, used in outbreak investigation.
Plague: Disease caused by Yersinia pestis, historically responsible for major pandemics including the Black Death.
Platform Technology: Adaptable technology that can be quickly modified for different applications, such as mRNA vaccine platforms.
Positive-Pressure Suit: Full-body protective garment with filtered air supply, used in BSL-4 laboratories.
ProMED (Program for Monitoring Emerging Diseases): International surveillance network for early detection of disease outbreaks.
Q
Quarantine: Separation and restriction of movement for individuals who may have been exposed to a contagious disease.
R
R0 (Basic Reproduction Number): The average number of secondary infections produced by a single infected individual in a fully susceptible population.
Reconstruction Attack: A jailbreak technique where adversaries fragment harmful information across multiple benign-appearing segments within a larger context, then instruct the AI model to reassemble them. Example: embedding a dangerous query as scattered function return values in code, then asking the model to reconstruct and respond to the hidden message. Exchange classifiers address this by evaluating outputs in the context of inputs.
Red-Teaming: Adversarial testing methodology to identify vulnerabilities in systems, organizations, or AI models before malicious actors can exploit them.
Resilience and Sustainability Trust (RST): IMF financing mechanism providing affordable, long-term loans to low- and middle-income countries for climate adaptation and pandemic preparedness. Part of the $60 billion initiative launched with WHO and World Bank to embed preparedness conditions into international development financing.
Responsible Scaling Policy (RSP): Framework for developing AI systems with safety measures proportional to their capabilities, particularly for models with potential dual-use risks.
Ricin: Highly toxic protein derived from castor beans, classified as a Category B bioterrorism agent.
Rinderpest: Viral disease of cattle, sheep, and goats, eradicated in 2011 making it only the second disease (after smallpox) to be eliminated.
RMR-1029: The specific flask of anthrax spores identified as the source material in the 2001 anthrax letter attacks.
S
SARS (Severe Acute Respiratory Syndrome): Respiratory illness caused by SARS-CoV, which emerged in 2002-2003 and was contained through public health measures.
SARS-CoV-2: The coronavirus responsible for COVID-19, first identified in 2019.
Select Agent: Biological agent or toxin designated by U.S. regulations as posing a severe threat to public, animal, or plant health.
Sentinel Surveillance: Monitoring disease through a network of selected sites to detect trends or emerging threats.
Sequence Screening: Analysis of DNA/RNA sequences against databases of known pathogens and toxins to prevent synthesis of dangerous agents.
Smallpox: Disease caused by variola virus, eradicated in 1980. Samples retained in two WHO-authorized repositories.
Spillover Event: Transmission of a pathogen from its natural reservoir to a new host species.
Strain: A genetic variant or subtype of a microorganism.
Strategic National Stockpile (SNS): U.S. national repository of medical supplies for public health emergencies.
Sverdlovsk Incident: 1979 accidental release of anthrax spores from a Soviet bioweapons facility, killing at least 66 people.
Syndromic Surveillance: Monitoring of health indicators (symptoms, behaviors) to detect outbreaks before laboratory confirmation.
Synthetic Biology: Field combining biology and engineering to design and construct new biological parts, devices, and systems.
T
Tacit Knowledge: Knowledge that is difficult to transfer through written instructions, requiring hands-on training and experience.
Toxin: Poisonous substance produced by living organisms, including bacteria, plants, and animals.
Transmissibility: The ease with which a pathogen spreads from one host to another.
Tularemia: Disease caused by Francisella tularensis, also known as “rabbit fever.” Category A bioterrorism agent.
U
UNSGM (United Nations Secretary-General’s Mechanism): UN framework for investigating alleged use of biological or chemical weapons.
Uplift Study: Evaluation assessing whether AI systems increase an individual’s capability to perform tasks with dual-use potential.
V
Vaccine Platform: Technology framework that can be adapted to develop vaccines against multiple pathogens (e.g., mRNA, viral vector).
Variola Virus: The causative agent of smallpox, now eliminated from nature but retained in authorized laboratories.
Viral Hemorrhagic Fever (VHF): Group of illnesses caused by several families of viruses, characterized by fever and bleeding disorders.
Viral Sovereignty: The assertion that countries have sovereign rights over pathogens circulating within their territory, including control over sample sharing and access to resulting benefits. This concept emerged partly from concerns that high-income countries exploited pathogen samples from lower-income countries without reciprocal access to vaccines or treatments.
Virulence: The degree of pathogenicity or disease-causing ability of a microorganism.
Virus: Submicroscopic infectious agent that replicates only inside living cells.
W
Wastewater Surveillance: Monitoring sewage for pathogen genetic material to detect community-level infections.
Weaponization: The process of converting a biological agent into a form suitable for deliberate release as a weapon.
WHO (World Health Organization): United Nations agency responsible for international public health, including pandemic preparedness and response.
Window of Vulnerability: Period during which offensive biological capabilities may advance faster than defensive capabilities.
X
Xenotransplantation: Transplantation of organs or tissues between different species, with associated biosecurity considerations.
Y
Yersinia pestis: The bacterium that causes plague.
Z
Zoonosis (pl. Zoonoses): Infectious disease that has jumped from animals to humans.
Zoonotic Spillover: The process by which a pathogen in an animal population infects and establishes itself in humans.
This glossary is part of The Biosecurity Handbook.