Extinction Bounties

Policy-based deterrence for the 21st century.

So Was Navier-Stokes

On "it's hard" as a load-bearing argument in biosecurity.

11 September 2026 · alpha

Claus Wilke has written a piece arguing that you are not going to die from an AI-engineered supervirus. It is a good piece by someone who actually knows the subject, aimed at a target that deserves hitting, and I agree with more of it than I disagree with.

I still think it proves less than it sets out to. Three things, after the concessions, which come first because they are not decorative.

What he gets right

He has domain expertise and I do not. He has computationally designed biological systems; his lab put well over a hundred mutations into a bacteriophage at once and showed the attenuation held up under replication, which is a harder thing to do than it sounds and is the opposite of the armchair. His day job is building and evaluating AI systems for protein and peptide design. I have designed nothing. When he says that PhD students with state-of-the-art tooling spend months failing to make a peptide binder express without being toxic, that is information from inside the room, and it is worth more than my priors.

His target deserves attacking. A teenager in 2029 asking a model for a virus and killing most of humanity is not a scenario I would defend either. And the line he quotes — that the author has yet to hear a halfway-convincing argument for why this is far-fetched — is, as Wilke says, a sentence that should make you check whether you have been talking to anyone who would know.

He is right about opportunity cost, and this is the part I agree with hardest. There is a live Ebola outbreak. Measles is surging in a country that had eliminated it. Vaccine coverage is falling. The unglamorous work — surveillance, vaccination, antivirals, indoor air quality — is underfunded, and attention paid to a designed pathogen is substantially attention taken from pathogens that are currently in circulation and killing people. If you asked me where the marginal biosecurity dollar should go, I would not say AI.

And note what he does not claim. He says not now, and not for a few decades, and he explicitly allows that the world may look different by mid-century. So the disagreement between us is about a schedule, not about a possibility. That is worth naming, because a schedule argument and an impossibility argument are different animals and only one of them is a reason to stop thinking about something.

One: “hard” is a present-tense claim

The load-bearing move in the piece is that computational design of biological systems is unfathomably difficult, that experts hit walls constantly, and that the distance between here and the scenario is enormous.

All true. The question is what it licenses.

Protein structure prediction was hard. It was hard for fifty years, and the people who said it was hard were right about why, and they were describing real obstacles rather than a failure of nerve. Navier–Stokes existence and smoothness is hard, and has been hard since before anyone reading this was born, and may stay hard forever — or may fall next year to a technique nobody has thought of. The set of problems that are hard and stay hard and the set of problems that are hard and then abruptly are not look identical from inside the period when they are hard.

I want to be fair about what this does and does not get me. Wilke is not claiming permanence; he is claiming the gap is enormous, and an enormous gap genuinely is evidence about timelines. My objection is narrower than it might sound: “hard for experts in 2026” is compatible with a very wide distribution over when it stops being hard, and nothing in the piece gives us purchase on the shape of that distribution. Reporting the current difficulty accurately, which he does, is not the same as bounding the future, which is what the reassurance requires.

Two: the tradeoff is a fact about what evolution sampled

This is the argument I actually care about.

The reassuring structure of the piece is the tradeoff. Lethality trades against transmissibility: to spread well a virus needs a host who is ambulatory and shedding, and a host who is dying in bed is not spreading anything. The receptor story is a clean illustration — the seasonal flu subtype binding in the upper respiratory tract spreads easily, the avian subtype binding deep in the lungs causes worse disease and spreads badly. Extremely lethal viruses are either not contagious, not airborne, or not silently transmissible, and the one pathogen with a long asymptomatic infectious period and near-total lethality untreated is also one of the hardest to catch.

Every data point behind that generalization comes from a pathogen shaped by natural selection, and natural selection was optimizing reproductive fitness.

Fitness is not lethality. It is not lethality times transmissibility either. A pathogen that kills its host too efficiently loses transmission opportunities, which means selection has been actively pushing away from the region we are frightened of, for as long as there have been pathogens. The observed tradeoff is therefore a description of the sampled distribution. Treating it as a constraint on the attainable set requires an additional argument, and I do not think the piece makes one.

Put it this way. The claim that needs defending is that the frontier we observe in nature is the Pareto frontier — that there is no reachable combination of properties lying outside it. That might be true! There may be mechanistic reasons why silent transmissibility and high lethality cannot coexist, something about tissue tropism or immune evasion or viral load kinetics that makes the corner of the space genuinely empty rather than merely unvisited. Wilke gestures at some of this when he observes that viruses with long incubation periods tend to hide in compartments that do not shed. But gesturing is not showing, and “no such thing exists in nature” is precisely the observation we should expect in both the world where the corner is empty and the world where it is merely unselected.

I should be honest about the limits of my own argument. This is a selection-effects point, not a biological one. I am not telling a virologist that a mechanism exists; I am saying the evidence offered does not rule one out, which is a much weaker claim and one a virologist may be able to answer with facts I do not have. If someone can show me why the corner is mechanistically empty, I will take the update gladly and it will be the most reassuring thing I read this year.

It is worth noticing that this is the same shape of argument as page 05 of the sequence, in reverse. There I argue that the aligned region of a space is thin, and then attack my own argument on the grounds that nobody is sampling uniformly and engineers hit improbable targets on purpose. Here the same distinction runs the other way: the region looks empty because of how it was sampled, and a designer is not sampling the way evolution did. If I am going to insist on that distinction when it cuts against me, I should insist on it when it cuts for me.

Three: guardrails are a property of a deployment

The version of this conversation that happens on the internet usually includes someone pointing out that models refuse virology requests, which is true, and that they do so fairly aggressively — sometimes refusing figure generation if a virus is mentioned anywhere in the file.

This is a fact about hosted models. It is a temporary fact about open-weight ones. Removing refusal behavior from open weights is a solved engineering problem with off-the-shelf tooling , so any capability that exists in the weights is available to anyone who can run them, on a timescale set by publication rather than by policy. An argument that leans on refusal is leaning on something that is removed by a script.

The Hugging Face breach in July supplied an almost comic illustration. During incident response, their analysts found that commercial APIs would not process their requests, because the requests contained exploit payloads. They ran an open-weight model locally instead. The safety training did not inconvenience the attacker in the slightest. It inconvenienced the people cleaning up. I have written about that incident separately .

Where that leaves me

Not very far from him, which is the honest summary.

He has established that this is hard now. That is true, useful, and worth saying against people who are certain it is easy. What the piece does is slide from there to reassurance, and the slide is rhetorical rather than argued. Under the framing I use on the rest of this site, the question is never really “is this likely.” It is whether the failure is recoverable and whether we can check in advance. A difficulty argument from the present tense does not speak to either.

But he is right that this is a bad place to put the marginal dollar, and he is right that the fear-mongering version crowds out the boring work that would actually save lives, and he is right that the people writing the alarming version mostly cannot tell you what a receptor is. If the choice is between funding measles vaccination and funding worry about a synthetic pathogen, fund the vaccination. I do not think you have to believe the corner of the space is empty to get there.

To cite this page: Andrew Quinn, "So Was Navier-Stokes." Extinction Bounties, last revised 2026-09-11. https://extinction-bounties.com/writing/so-was-navier-stokes/

Policy-research disclaimer

Extinction Bounties publishes theoretical economic and legal mechanisms intended to stimulate scholarly and public debate on catastrophic-risk governance. The site offers policy analysis and advocacy only in the sense of outlining possible legislative or contractual frameworks.

No legal or financial advice

Nothing here should be treated as a substitute for qualified legal counsel, financial due diligence, or regulatory guidance. Readers remain responsible for ensuring their actions comply with the laws and professional standards of their own jurisdictions.

Exploratory and personal views

All scenarios, numerical examples and opinions are research hypotheses presented by the author in a personal capacity. They do not represent the views of the author's employer, funding bodies, or any governmental authority.

Implementation caveats

Any real-world adoption of these ideas would require democratic deliberation, statutory authority, and robust safeguards against misuse. References to enforcement, penalties, or "bounties" are illustrative models, not instructions or invitations to engage in private policing or unlawful conduct. Nothing here is directed at any identifiable individual — see non-targeting.

No warranty and limited liability

Content is provided "as is" without warranty of completeness or accuracy; the author disclaims liability for losses arising from reliance on this material.

By continuing beyond this notice you acknowledge that you have read, understood, and accepted these conditions.