On July 2, 2026, a team at a public university posted a preprint describing the first chemically defined synthetic cell that feeds, grows, divides, and undergoes selection. It was built with published methods, released openly, and paired with a new nonprofit created to spread the tools worldwide. The lead scientist on that work also put her name first on the 2024 Science paper warning that a related line of synthetic biology could end life on Earth. That is the paradox this series confronts: the people most capable of building synthetic life are often the same people warning us about it, and there is no security architecture around any of it.
This assessment reaches three judgments. First, prescriptive regulation of synthetic biology, as currently attempted, is failing in real time and will not close the gap. Second, the United States cannot answer that failure by retreat; ceding this field to authoritarian competitors is the worse outcome by a wide margin. Third, the current operating model, in which catastrophic-capability work proceeds in uncleared university labs and inside private companies that set their own rules, is a national security liability we would tolerate in no other domain of comparable consequence. The recommendation is not more rules. It is a security architecture: compete to win, vet the people doing the most dangerous work, and impose enforceable controls on the private sector at the points that actually matter.
I hold these judgments with moderate to high confidence. Where the evidence is thin, I say so.
Kate Adamala’s laboratory at the University of Minnesota calls them spudcells. The formal title is drier: “A Chemically Defined Synthetic Cell Capable of Growth and Replication,” authored by Nathaniel Gaut, Christopher Deich, Brock Cash, Tanner Hoog, Aaron Engelhart, and Adamala [1]. The achievement is real and it is significant. The team encapsulated a roughly 90,000 base-pair genome, carried across seven plasmids, inside a lipid membrane, together with a protein-synthesis system. The cell reads its own DNA, replicates that DNA using a viral polymerase, feeds by fusing with supply vesicles under the control of a gene it expresses, and divides without the cytoskeleton that every natural cell uses to split. Over five generations, cells carrying a beneficial mutation produced more offspring and spread through the population. That last point matters most: this is not just a cell that copies itself, it is a synthetic system that undergoes selection [1].
Do not overstate what this is. The spudcell is not alive by any standard definition. It cannot manufacture its own ribosomes, its metabolism is minimal, and it dies without constant external feeding [1]. Jack Szostak, Adamala’s own doctoral adviser, made the point plainly in Quanta’s coverage: a system that cannot generate its own machinery is far from a bacterium [2]. This is a Wright Flyer, in Adamala’s words, not a Dreamliner [2].
But the Wright Flyer mattered, and so does this. The builders themselves frame the spudcell as a chassis “that could be adapted for a variety of purposes” and a “foundation for fully artificial organisms” [1]. Alongside the preprint, the team launched a nonprofit, Biotic, to distribute the tools to laboratories everywhere [2]. That is the entire national security problem in a sentence: a general-purpose, open, distributable toolkit for constructing life from defined parts, advancing fast, with no security controls attached to it whatsoever.
Any honest assessment must start by conceding that the upside is enormous and that it is a matter of national power, not merely commerce.
Synthetic biology already saved American lives on a scale that dwarfs its risks to date. The mRNA vaccine that anchored the COVID-19 response was designed on paper within days of the virus’s genetic sequence being posted, and reached a Phase I trial just 66 days after that sequence was released, work described by Kizzmekia Corbett and colleagues at the NIH Vaccine Research Center in Nature [3]. That speed is a strategic asset. In a deliberate biological attack or a natural pandemic, the interval between pathogen identification and countermeasure is the interval in which people die. Synthetic biology compresses it.
The 2024 Nobel Prize in Chemistry went to David Baker for computational protein design and to Demis Hassabis and John Jumper for AlphaFold’s structure prediction [4]. These are the tools of a coming era of designed enzymes, antibodies, and vaccine antigens. Metagenomic surveillance, championed by Kevin Esvelt and operationalized through efforts like the Nucleic Acid Observatory, offers something we have never had: the ability to detect a novel or engineered pathogen in wastewater or clinical samples before an outbreak announces itself [5]. And the spudcell platform points toward programmable biomanufacturing of fuels, materials, and drugs without fossil inputs [2].
This is why “ban it” is the wrong answer and a dangerous one. The benefits are dual-use with the risks because they are the same capability. You cannot have rapid vaccine design without rapid pathogen design. The question is never whether to develop synthetic biology. It is who develops it, under what controls, and whether we or our adversaries set the terms.
The National Academies laid out the credible threat model in 2018 in Biodefense in the Age of Synthetic Biology, and it holds up [6]. The three capabilities of greatest concern: recreating known pathogens from scratch, such as synthesizing a poliovirus or a 1918 influenza genome; re-engineering existing pathogens to be more transmissible, more lethal, or able to evade immunity; and engineering microbes to produce toxins or other harmful biochemicals [6]. Bacteria, the report judged, are in some respects a graver concern than viruses because their genomes are more stable and more tractable [6].
Layer artificial intelligence onto that model and the picture sharpens, but not in the way the headlines suggest. The critical distinction, articulated early by Jonas Sandbrink, is between large language models and biological design tools [7]. Language models like Claude or GPT primarily lower the floor: they repackage existing knowledge and could, in principle, help a novice past a hurdle. Biological design tools raise the ceiling: they can engineer proteins and genetic systems that do not exist in nature. These are different risks and they demand different responses [7]. The National Threat Initiative’s biosecurity team, including Sarah Carter, Nicole Wheeler, and Jaime Yassif, reached a compatible conclusion and has since proposed governing the most capable design tools through managed access rather than open release [8].
The evidence on language-model uplift is, so far, reassuring, and I want to be precise about it because it cuts against alarmism. The RAND Corporation’s 2024 controlled red-team study, by Christopher Mouton and colleagues, found no statistically significant difference in the viability of bioweapon attack plans produced with versus without language-model assistance [9]. OpenAI’s own study that same year found at most a mild uplift that did not reach significance [10]. The largest independent trial to date, a preregistered randomized controlled trial of 153 novices running real wet-lab procedures, published by Hong and colleagues in early 2026, found no substantial increase in task completion from mid-2025 models; the point estimate was a modest 1.4-fold effect whose credible interval crossed one [11].
The evidence is not unanimous, and integrity requires acknowledging the conflict. A 2025 RAND working paper by Roger Brent and Greg McKelvey argued that current models can meaningfully contribute to bioweapons development and that earlier red teams underestimated the risk [12]. That paper is not peer-reviewed and rests on qualitative dialogue rather than controlled trials [12]. The most rigorous, peer-reviewed demonstration of concrete AI-enabled danger points not at chatbots but at design tools: in October 2025, a team led by Eric Horvitz at Microsoft showed in Science that open-source protein design models could redesign toxic proteins to preserve function while evading the DNA synthesis screening that is supposed to catch them [13]. Roughly 3 percent of potentially functional toxin variants slipped past commercial screening software before the team quietly patched the tools over ten months [13]. The work was computational, the proteins were never made, and the patch is admittedly incomplete [13]. It is still the clearest signal we have, and it confirms the thesis: the danger lives in the design tools and at the synthesis chokepoint, not in the search-engine layer.
Here is the strongest case against my own thesis, stated first, as it should be. Regulation has worked before. The Select Agent Program, the Biological Weapons Convention, and nuclear nonproliferation controls have all constrained dangerous work. Voluntary DNA synthesis screening, coordinated through the International Biosecurity and Biosafety Initiative for Science and the SecureDNA project, already covers most commercial gene synthesis capacity [8][13]. One could argue the machinery exists and needs only to be strengthened.
The record of the last three years refutes the optimistic case. Consider the whipsaw. In October 2023, Executive Order 14110 directed a nucleic acid synthesis screening framework and, crucially, moved to make screening a condition of federal research funding: a de facto mandate with teeth [14]. In January 2025, Executive Order 14148 revoked 14110 outright [15]. In May 2025, Executive Order 14292 ordered the framework rewritten within 90 days [16]. That deadline passed with no replacement delivered. The net effect: synthesis screening in the United States remains voluntary, benchtop DNA synthesizers remain largely outside any screening regime, and the policy reverses itself with each change of administration.
This is not an argument that rules are useless. It is an argument about structure. Synthetic biology has four features that defeat prescriptive, jurisdiction-bound regulation: it is dual-use to the core, so you cannot ban the capability without banning the cure; it is cheap and getting cheaper, so cost no longer gates access; it is global, so a rule in Washington relocates the work to Shenzhen or a garage; and it is information, so the dangerous part travels as a file, not a shipment. Chinese and European scholars reach similar conclusions from the other direction: Liao Bohua and colleagues, writing in the Journal of Biosafety and Biosecurity, concede that overly restrictive rules simply push synthetic biology into covert laboratories, worsening oversight [17]. A regime that assumes compliance from the very actors most likely to defect is not a security regime. It is a hope.
If the government cannot regulate this into safety, what does responsible practice look like? The most developed private-sector model belongs to Anthropic, the AI company behind Claude, and it is worth examining precisely because it is voluntary, imperfect, and instructive.
Anthropic’s Responsible Scaling Policy commits the company to defined capability thresholds and matching safeguards [18]. In May 2025, it activated its ASL-3 protections for its Claude Opus 4 model. The important detail, routinely misreported, is that Anthropic did not claim the model was confirmed dangerous; it activated the protections precautionarily because it could not rule out that the model provided meaningful uplift on chemical and biological weapons tasks [18]. Those protections include real-time classifiers trained to block CBRN content, a bug-bounty program to stress-test them, and over a hundred security controls to prevent theft of the model weights [18].
The company has gone further than its own products. In August 2025, Anthropic and the Department of Energy’s National Nuclear Security Administration announced a jointly developed classifier that distinguishes concerning nuclear-weapons conversations from benign ones, reporting 96 percent overall accuracy and deploying it on live traffic [19]. Anthropic’s chief executive, Dario Amodei, testified to the Senate Judiciary Committee as early as 2023 that a straightforward extrapolation of AI capabilities could, within a few years, widen the pool of actors able to conduct a large-scale biological attack [20]. For classified government use, the company built Claude Gov, a model set access-limited to personnel operating in classified environments [21], and it is a signatory, alongside OpenAI and Google DeepMind leaders, to the June 2026 open letter calling for mandatory synthesis screening [13].
I present this as a template, not an endorsement. Every figure above is Anthropic’s own self-report. I found no independent, peer-reviewed reproduction of its uplift or classifier results, and the security world knows the difference between a control that is claimed and a control that is audited. That caution noted, the model is real: capability thresholds, weight security, personnel-gated access, and an external chokepoint partnership. It is closer to a security architecture than anything the regulatory process has produced.
It also exposes the deeper problem. In early 2026, the Department of Defense demanded that Anthropic remove two of its red lines: prohibitions on fully autonomous weapons and on mass domestic surveillance. Anthropic refused. The dispute escalated to a Defense Production Act threat, a supply-chain-risk designation, and federal litigation that, as of mid-2026, had divided a federal appeals court [22]. Amodei’s public position was that frontier systems are not reliable enough for autonomous weapons and that AI-enabled mass surveillance is incompatible with a free society [22]. One can respect those lines and still see the hazard clearly: a single private company was setting national security policy through its terms of service, and the government’s only tools were coercion or capitulation. That is not a stable arrangement, and it is the argument for public standards rather than corporate discretion.
The counterargument to everything that follows deserves to be stated at full strength. Security controls on science are a tax on discovery. Clearances are slow, exclusionary, and often keep out the foreign-born talent that built American biotechnology. Openness is not a bug in the American system; it is the source of our lead. Impose a security state on the life sciences and you may hand the future to competitors willing to move faster with fewer scruples. I take this seriously. It is why the recommendation is targeted rather than total.
Three pillars.
First, compete to win, because leadership is itself a security control. The United States must out-build and out-fund this field, maintain export controls on the compute and equipment that give us an edge, as Amodei argued in his analysis of chip controls [23], and treat biomanufacturing capacity as strategic infrastructure. A world in which the best synthetic biology is done here, under our norms, is safer than one in which it is done elsewhere under none. Retreat is the highest-risk option on the table.
Second, vet the people doing the most dangerous work, including in universities. It is indefensible that constructing self-replicating synthetic cells, engineering enhanced pathogens, or building the most capable biological design tools proceeds in academic laboratories with no personnel security whatsoever, when far less consequential work in the nuclear and classified spaces requires clearances, continuous evaluation, and insider-threat monitoring. I am not proposing to clear every graduate student pipetting buffer. I am proposing a tiered personnel-security standard, triggered by defined capability thresholds, for the narrow set of experiments that cross into catastrophic potential. The mirror-life episode proves the field can define such thresholds when it chooses: Adamala and thirty-odd co-authors, including George Church, Craig Venter, and Kevin Esvelt, concluded in Science that mirror bacteria research should not proceed and that funders should decline to support it [24]. If the scientists can draw that line, the government can build a personnel regime around it.
Third, impose enforceable controls on the private sector at the points that matter. Not a licensing bureaucracy for every startup. Specific chokepoints: mandatory, audited DNA synthesis screening for all providers and for benchtop synthesizers, closing the gap the executive-order whipsaw left open; security standards for model weights and for the most capable biological design tools, along the lines Anthropic built voluntarily but set by public authority and independently verified; and capability-threshold reporting so that no company decides alone, and in secret, when it has crossed a line that concerns the nation. Anthropic’s willingness to walk away from a defense contract to hold its red lines shows private conscience can work; the Pentagon dispute shows it cannot be the only safeguard.
I subjected this assessment to the obvious attacks. A hostile reviewer would say I am inflating a lab curiosity into a threat; the spudcell cannot make a ribosome, let alone a weapon, and the controlled evidence shows minimal AI uplift. That criticism has force, and I have conceded both points. My answer is that security architecture is built on trajectory, not on the current state, and the trajectory here is steep, open, and unmanaged. A second reviewer would say personnel security in universities is unworkable and un-American. My answer is that it is already the norm wherever consequences are grave enough, and that catastrophic biology now qualifies. A third would say mandatory controls will offshore the work. That is the strongest objection, and it is exactly why the first pillar is competitiveness: controls without leadership do fail, which is why we need both. A fourth would note that I rely heavily on Anthropic’s self-reported figures. Correct, and I have flagged it; independent verification is the missing ingredient, and it should be built.
The unknowns are substantial and I will not paper over them. We do not know the true uplift ceiling of the next generation of models, because it has not been tested. We do not know whether AI-designed toxins would actually fold and function, because they have not been synthesized. We do not know whether a personnel-security regime can be designed without strangling the openness that is our advantage. Those are the questions the rest of this series will pursue.
What I do know is this. We are building the capacity to construct life from defined parts, we are doing it in the open, we are doing it faster every year, and we are doing it with essentially no security around the people or the tools. Regulation as attempted will not fix that. Retreat would be a strategic blunder. The only serious path is to lead the field and secure it at the same time. That is harder than either banning it or ignoring it. It is also the only option that does not end with a preventable catastrophe and a commission asking why no one acted when the warning was this clear.
Gaut N, Deich C, Cash B, Hoog T, Engelhart A, Adamala KP. “A Chemically Defined Synthetic Cell Capable of Growth and Replication.” bioRxiv preprint, posted July 2, 2026. https://doi.org/10.64898/2026.07.01.735724
Saplakoglu Y. “For the First Time, a Cell Built From Scratch Grows and Divides.” Quanta Magazine, July 1, 2026. https://www.quantamagazine.org/for-the-first-time-a-cell-built-from-scratch-grows-and-divides-20260701/
Corbett KS, et al. “SARS-CoV-2 mRNA vaccine design enabled by prototype pathogen preparedness.” Nature, August 5, 2020. https://www.nature.com/articles/s41586-020-2622-0
The Nobel Prize in Chemistry 2024 (David Baker; Demis Hassabis and John Jumper). Nobel Foundation, October 9, 2024. https://www.nobelprize.org/prizes/chemistry/2024/press-release/
The Nucleic Acid Observatory Consortium (Esvelt K, et al.). “A Global Nucleic Acid Observatory for Biodefense and Planetary Health.” arXiv:2108.02678, 2021. https://arxiv.org/abs/2108.02678
National Academies of Sciences, Engineering, and Medicine. Biodefense in the Age of Synthetic Biology. Washington, DC: The National Academies Press, 2018. https://doi.org/10.17226/24890
Sandbrink JB. “Artificial intelligence and biological misuse: Differentiating risks of language models and biological design tools.” arXiv:2306.13952, 2023. https://arxiv.org/abs/2306.13952
Carter SR, Wheeler N, Chwalek S, Isaac C, Yassif JM. “The Convergence of Artificial Intelligence and the Life Sciences.” Nuclear Threat Initiative (NTI bio), October 30, 2023. https://www.nti.org/analysis/articles/the-convergence-of-artificial-intelligence-and-the-life-sciences/
Mouton CA, Lucas C, Guest E. “The Operational Risks of AI in Large-Scale Biological Attacks.” RAND Corporation, January 25, 2024. https://www.rand.org/pubs/research_reports/RRA2977-2.html
OpenAI. “Building an early warning system for LLM-aided biological threat creation.” January 31, 2024. https://openai.com/index/building-an-early-warning-system-for-llm-aided-biological-threat-creation/
Hong S, et al. “A randomized controlled trial of LLM assistance for novice wet-lab task completion.” arXiv:2602.16703, February 18, 2026. https://arxiv.org/abs/2602.16703
Brent R, McKelvey TG. “Language models and biological weapons development” (RAND Meselson Center working paper WR-A3853-1). arXiv:2506.13798, June 2025. https://arxiv.org/abs/2506.13798
Wittmann B, et al. (senior author Horvitz E). “Strengthening nucleic acid biosecurity screening against generative protein design tools.” Science, October 2, 2025. https://www.microsoft.com/en-us/research/publication/strengthening-nucleic-acid-biosecurity-screening-against-generative-protein-design-tools/
Executive Order 14110, “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence.” October 30, 2023. https://www.federalregister.gov/documents/2023/11/01/2023-24283/safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence
Executive Order 14148, “Initial Rescissions of Harmful Executive Orders and Actions.” January 20, 2025. https://www.federalregister.gov/documents/2025/01/28/2025-01901/initial-rescissions-of-harmful-executive-orders-and-actions
Executive Order 14292, “Improving the Safety and Security of Biological Research.” May 5, 2025. https://www.federalregister.gov/documents/2025/05/08/2025-08266/improving-the-safety-and-security-of-biological-research
Liao B, Wang Y, Ou Y, Zuo K, Liu H, Lei R. “Ethical framework on risk governance of synthetic biology.” Journal of Biosafety and Biosecurity, June 2023. https://doi.org/10.1016/j.jobb.2023.03.002
Anthropic. “Activating AI Safety Level 3 Protections.” May 22, 2025. https://www.anthropic.com/news/activating-asl3-protections
Anthropic. “Developing nuclear safeguards for AI through public-private partnership” (with DOE/NNSA). August 21, 2025. https://www.anthropic.com/news/developing-nuclear-safeguards-for-ai-through-public-private-partnership
Amodei D. Written testimony, U.S. Senate Committee on the Judiciary, Subcommittee on Privacy, Technology, and the Law. July 25, 2023. https://www.judiciary.senate.gov/imo/media/doc/2023-07-26_-_testimony_-_amodei.pdf
Anthropic. “Claude Gov: Models for U.S. national security customers.” June 5, 2025. https://www.anthropic.com/news/claude-gov-models-for-u-s-national-security-customers
“Pentagon-Anthropic Dispute over Autonomous Weapon Systems: Potential Issues for Congress.” Congressional Research Service, IN12669, 2026. https://www.congress.gov/crs-product/IN12669 ; and Amodei D, “Statement on the Department of War,” Anthropic, February 26, 2026. https://www.anthropic.com/news/statement-department-of-war
Amodei D. “On DeepSeek and Export Controls.” January 2025. https://darioamodei.com/post/on-deepseek-and-export-controls
Adamala KP, et al. “Confronting risks of mirror life.” Science, December 12, 2024. https://doi.org/10.1126/science.ads9158
Next in this series: the biological design tools themselves, and the synthesis chokepoint that AI is learning to defeat.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.