The Case for ESM3 as a General-Purpose AI Model with Systemic Risk Under the EU AI Act
This paper argues that while biological foundation models like ESM3 should ideally be regulated as general-purpose AI models with systemic risk under the EU AI Act to mitigate dual-use biorisks, current ambiguities in the legislation mean they are not meaningfully covered, prompting the authors to propose specific remedies to close this regulatory gap.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
The Big Picture: A Safety Net with a Hole
Imagine the European Union (EU) built a massive, high-tech safety net called the EU AI Act. The goal of this net is to catch powerful AI systems that could cause serious harm to society (like those that might help create biological weapons) and force their creators to put safety measures in place.
The authors of this paper are pointing out a hole in the net. They argue that a very powerful new AI tool called ESM3 is slipping right through the cracks. Even though ESM3 could theoretically make it easier for bad actors to design dangerous biological agents, the current rules don't seem to catch it.
Meet ESM3: The "Master Chef" of Proteins
To understand the problem, you first need to understand the tool.
- What is ESM3? Think of proteins as the "ingredients" or "machines" that make life work. ESM3 is an AI that acts like a Master Chef who can look at a recipe (a protein's sequence), the shape of the dish (its structure), and what the dish does (its function).
- What can it do? If you give ESM3 a partial recipe or a description of a meal you want to cook, it can "fill in the blanks" and invent a brand new, working protein. It can do this incredibly fast, testing thousands of variations in a computer in the time it would take a human lab to test one.
- The Risk: Just as a Master Chef could accidentally create a poisonous dish, a bad actor could use ESM3 to design a new, dangerous virus or bacteria. The paper argues that ESM3 makes the steps to create such a weapon much easier and faster.
The Regulatory "Blind Spot"
The EU AI Act has a specific rule: if an AI is a "General-Purpose AI" (GPAI) with "Systemic Risk," the creators must follow strict safety rules.
However, the authors found that ESM3 is currently invisible to these rules because of two confusing things:
1. The "Language" Trap (The Act's Wording)
The law defines a "General-Purpose AI" as something that is very smart and can do many different tasks. The supporting guidelines (the "instruction manual" for the law) give examples of these tasks: writing text, making images from text, or speaking.
- The Problem: The guidelines seem to imply that to be "General-Purpose," the AI must speak human language (like English or French).
- The Loophole: ESM3 doesn't speak human language. It speaks "protein language" (sequences of amino acids). Because it doesn't chat with you or write essays, the current rules say, "Oh, this isn't a General-Purpose AI. It's just a specialized tool." Therefore, it doesn't have to follow the strict safety rules.
2. The "Compute" Threshold (The Size Limit)
The law also says that if an AI is trained with a massive amount of computer power (specifically, over operations), it is automatically considered dangerous.
- The Problem: ESM3 is huge, but it was trained with slightly less power than that magic number (). So, it doesn't get caught by the automatic "danger" trigger either.
The "Biorisk Chain" Analogy
The paper uses a concept called the Biorisk Chain. Imagine a bad actor trying to build a biological weapon is like a thief trying to break into a high-security bank. They have to complete a long list of steps:
- Decide to rob the bank.
- Plan the route.
- Pick the lock.
- Open the safe.
- Escape.
The paper argues that ESM3 acts like a super-tool that makes several of these steps (like picking the lock or opening the safe) much easier. Even if it doesn't do every step, making just a few steps easier increases the chance that the thief will succeed. Because ESM3 is open-source (free to download), even small groups with limited resources could use it.
Why This Matters
The authors are worried that because ESM3 doesn't fit the strict definition of "General-Purpose AI" (because it doesn't talk human language), it is unregulated. This means the company that made it doesn't have to prove they have safety measures to stop bad people from using it to make weapons.
The Proposed Fixes
The paper suggests four ways to patch the hole in the safety net:
- Redefine "General": The EU could officially say that "General-Purpose" includes AI that is a master at any complex field (like biology), not just human language.
- Update the Guidelines: The people who write the "instruction manual" for the law could change the rules to include biological models.
- Change the Law: They could rewrite the law to remove the requirement that an AI must be "General-Purpose" to be regulated for systemic risk.
- Export Controls: Treat the AI software itself like a dangerous physical weapon that cannot be exported or shared freely.
The Bottom Line
The paper concludes that ESM3 is currently flying under the radar. It has the power to cause significant harm (by lowering the barrier to creating biological weapons), but the current EU rules are too focused on "human language" AI to catch it. The authors urge the EU to fix these definitions so that powerful biological tools are held to the same safety standards as other dangerous AI systems.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.