Artificial intelligence is reshaping biological research through an increasingly integrated digital‑to‑physical workflow. General‑purpose large language models can retrieve and synthesize scientific knowledge, aid experimental planning and computational analysis; biological foundation models can predict, optimise and generate proteins, genes and genome‑scale sequences; agentic systems can orchestrate multi‑step research tasks; and automated laboratories can partially close the design‑build‑test‑learn loop. These capabilities promise major advances for medicine, public health and biotechnology.\ \ The biosecurity risk, however, depends not only on what AI can do but also on who wields it, their expertise and intent, access to laboratory tools and materials, and existing safeguards. Current evidence shows that AI uplift is mainly confined to digital tasks, while physical execution remains constrained. Frontier systems have surpassed expert baselines on in‑silico analyses and screening‑evasion benchmarks, yet controlled wet‑lab studies reveal that tacit knowledge and hands‑on execution still pose substantial barriers.\ \ This review outlines the various threat stages associated with AI tool use: information gathering, biological design, procurement, synthesis, testing, scale‑up and potential release. We examine why alignment techniques that work for general‑purpose models transfer poorly to biological models, and how emerging interpretability methods can audit whether hazardous capabilities have truly been removed. We advocate a defense‑in‑depth governance approach that ties capability thresholds to proportionate responsibilities across the biological AI ecosystem, reducing high‑consequence risk while preserving beneficial applications.\ \ Review