Every argument about synthetic biology risk eventually arrives at the same physical fact. A dangerous sequence is only information until someone turns it into DNA, and almost everyone who needs DNA orders it from a company. That step, the synthesis of nucleic acids, is the narrowest and most enforceable control point in the entire field. Screen there, and you catch a large fraction of misuse before it becomes biology. This is not my framing. It is the framing of the government’s own policy, which calls nucleic acid synthesis “a critical control point.”
The chokepoint works only if it is universal, and it is not. Companies that screen represent roughly 80 percent of global synthesis capacity, which means a fifth of the market screens little or nothing. Short DNA fragments are frequently waved through. Benchtop synthesizers now let a lab make its own DNA with no order to screen at all. And in October 2025, a team at Microsoft showed in Science that artificial intelligence can redesign a toxic protein to keep its function while changing its sequence enough to slip past the screening software meant to catch it. The chokepoint is leaking, the leak is widening, and the pressure on it is now automated.
Against that, American policy is moving backward. Three executive orders in eighteen months mandated screening, revoked the mandate, and then ordered a replacement that has not arrived. Today, screening is genuinely required only inside the National Institutes of Health’s own laboratories. Everywhere else it is voluntary.
I reach four judgments, stated with confidence levels, and I flag where the evidence is thin.
Begin with the event that should have changed the conversation and mostly did not.
On October 2, 2025, a team led by Eric Horvitz at Microsoft published a study in Science with an uncomfortable finding [1]. Using open-source artificial intelligence tools built to design proteins, the group took known toxic proteins and computationally redesigned them, producing variants predicted to keep their harmful function while carrying sequences different enough to evade detection. They generated a large library of these variants, more than 70,000 sequences, and ran them against the biosecurity screening software used by commercial DNA providers. A meaningful fraction of the potentially functional variants, on the order of 3 percent, slipped through the initial screening [1].
Read the response, not just the result, because the response is the point. The team did not publish and walk away. Over roughly ten months, working confidentially with the screening developers, they built and deployed patches worldwide before the paper appeared, and they framed the whole exercise in the language of computer security: a biosecurity “zero day,” found and closed before disclosure [1][19]. That is responsible science, and it is the model for how this should be done.
It is also a warning that cannot be patched away. The work was entirely computational. No proteins were made, and whether every AI-redesigned toxin would actually fold and function in a laboratory is an estimate, not a measured fact. The authors said as much, and one outside researcher, Michael Cohen at Berkeley, argued the challenge may have been weaker than presented. Those caveats are real, and I give them weight. But the structural lesson survives all of them. Screening that matches sequences against a list of known hazards is vulnerable to a system that can generate unlimited novel sequences that are functionally equivalent and textually unfamiliar. The patch closed one hole. The capability that found it is getting cheaper and better. Assessed with high confidence, about 80 out of 100: the era in which a static sequence blocklist is sufficient is ending.
To see why this matters so much, follow the path from idea to organism.
Designing a dangerous biological agent is, increasingly, an information problem, and information is hard to control. Sequences are published. Knowledge diffuses. The tools of design, as I argued in Part I, are spreading and improving. But between the digital design and the physical threat sits one stubborn requirement: you need actual DNA. As the field’s own analysts put it, biological information must pass through synthesis to become biological reality [2]. Most researchers, legitimate or otherwise, do not make DNA themselves. They order it. That order is the chokepoint.
Screening at that point has two parts, and both matter. The first is sequence screening: comparing each ordered sequence against databases of sequences of concern, the genetic signatures of known pathogens and toxins. The second, less discussed and more important, is customer screening: verifying who is ordering, confirming a legitimate institution and use, the know-your-customer discipline that banking has had for decades [3]. Sequence screening catches the recognizably dangerous molecule. Customer screening catches the unqualified or deceptive buyer even when the sequence looks benign. A serious regime needs both.
The appeal of the chokepoint is that it is narrow, physical, and already partly built. You do not have to surveil every scientist or ban every capability. You have to make one industrial step trustworthy. And here is the part that critics of regulation miss: universal screening is not a tax on the biotechnology industry, it is what keeps that industry legitimate and trusted. A sector that cannot demonstrate it refuses to print pandemic pathogens on demand is a sector waiting for the incident that invites heavy-handed control. Screening is how the industry protects its own license to operate [4]. That is the benefit case, and it is strong. I hold at about 82 out of 100 that synthesis screening is the single most leveraged, most enforceable control point available, precisely because it asks so little of everyone else.
A control point is only as good as its coverage, and this one has four widening holes.
The first is the unscreened fifth. The International Gene Synthesis Consortium, whose members follow a harmonized screening protocol, represents roughly 80 percent of global commercial synthesis capacity [5][2]. The remaining fifth includes smaller providers, academic core facilities, companies in jurisdictions without biosecurity frameworks, and grey-market sellers [2]. A buyer refused by a screening company can look for one that does not screen. A chokepoint with a documented bypass is a slower chokepoint, not a closed one.
The second is fragments. Screening has historically focused on longer sequences, while short pieces of DNA, the oligonucleotides below a couple hundred base pairs, are often minimally screened or not screened at all, even though fragments can be assembled into longer sequences of concern [2]. The consequence is not theoretical. A red-team study demonstrated that short DNA segments falling below screening thresholds could be ordered from numerous providers and assembled into a sequence of concern, using fragments of the 1918 pandemic influenza virus as its test case [21]. The gene synthesis industry contests that study’s framing, arguing it overstated the failure because each individual fragment was, on its own, unremarkable [22]. That dispute is the point rather than a rebuttal to it: the threshold is the gap, which is why the study’s authors call for regulating fragments directly [21].
The third, and structurally the worst, is the benchtop synthesizer. These desktop machines let a laboratory make its own DNA in-house, which means there is no order sent to any company and therefore nothing to screen per transaction. The device is screened, at most, once, at the point of sale. Everything it makes afterward is unobserved [6]. Analysts increasingly regard this as the most serious long-term threat to the entire model, because it removes the chokepoint rather than evading it [6][2]. As the machines spread, the control point that depends on centralized ordering simply ceases to exist for whoever owns one.
The fourth hole is the one from Section I. Even where sequence screening operates perfectly against its database, artificial intelligence can now generate functional variants that the database does not recognize [1]. The first three holes are gaps in coverage. This one is a gap in the method itself.
None of this means screening is useless. It means screening as currently built is a fence with a measured number of gaps, and the number is growing. Assessed with high confidence, about 80 out of 100.
Now set that widening leak against what the United States is actually doing about it, which is less than it did two years ago.
The sequence is a case study in how not to govern a fast technology. Executive Order 14110, in October 2023, directed a nucleic acid synthesis screening framework and moved to require it as a condition of federal research funding, a genuine mandate with reach [7]. The resulting Framework for Nucleic Acid Synthesis Screening followed in 2024, with a procurement requirement set to take effect in April 2025 [8]. Then, in January 2025, Executive Order 14148 revoked 14110 outright [9]. In May 2025, Executive Order 14292 ordered the framework revised or replaced within 90 days [10]. That deadline passed without a replacement.
What remains is a patchwork that a determined adversary would find encouraging. The National Institutes of Health kept a version alive for its own house: as of April 26, 2025, NIH intramural researchers may order synthetic nucleic acids only from providers, and benchtop equipment only from manufacturers, that attest to following the OSTP Framework [11]. That is a real requirement, and it is the right model. But it binds only NIH’s own internal laboratories. It does not bind the far larger universe of extramural, grant-funded research, and it does not bind the private market at all. The peer-reviewed history of these policies describes the trajectory bluntly: the funding-linked requirement of 2023 was countermanded in 2025, leaving the path forward uncertain [12].
So the honest status, as of mid-2026, is this. Universal synthesis screening in the United States is mandatory inside one agency’s own labs and voluntary everywhere else. Benchtop devices are largely outside any per-sequence regime. And the framework meant to fix this is officially under revision, with nothing delivered. Assessed with high confidence, about 85 out of 100, because the documentary record is clear and public. We have made the one control point that matters optional, at the exact moment the pressure on it went automated.
Here is the part that should embarrass the policy world, and it is why I end on it.
In December 2024, thirty-eight scientists published a paper in Science titled “Confronting risks of mirror life,” led by Katarzyna Adamala, the same researcher whose laboratory later built the synthetic cell I opened Part I with [13]. Their subject was mirror life: organisms built from mirror-image versions of the molecules that make up all known life. The appeal is real, and I will not pretend otherwise, because mirror molecules could yield drugs that resist degradation and research tools of genuine value. But the group concluded that a mirror bacterium, if ever created, could become an unprecedented danger, potentially acting as an invasive species across ecosystems and causing lethal infections that natural immune defenses are not built to recognize [13]. Alongside the paper, they published a technical report running to hundreds of pages [14]. The debate has continued into 2025, and the scientific caution has largely held [20].
Their recommendation was not a warning label. It was a stop. Research aimed at creating mirror bacteria should not proceed, they wrote, and funders should decline to support it [13]. These were not outside critics. They were the field’s own leaders, including some who had worked toward the very capability they now asked the world to forgo, choosing to draw a hard line around their own science before anyone was forced to.
Hold the two stories side by side. When the danger was concrete and catastrophic, a group of scientists imposed a control that no statute required of them. Meanwhile the government, facing a control point it already understood, that its own documents call critical, let the requirement lapse. The scientists drew a line the state would not. That contrast is the argument of this piece. The capacity for responsible restraint exists in this field. What is missing is the public architecture to make it dependable rather than voluntary, general rather than heroic. I hold at about 78 out of 100 that the mirror-life episode is the clearest available proof that meaningful lines can be drawn without ending the science.
The strongest objection to everything that follows deserves the first word. Screening can be called security theater. A sufficiently capable and determined actor, especially a state, can acquire benchtop equipment, use an offshore provider, or design around a sequence filter, so why burden the legitimate 99 percent to inconvenience the dangerous fraction. The objection has force, and any honest advocate must concede that screening stops the opportunist and the mid-capability actor far more reliably than it stops a well-resourced state program. But the conclusion does not follow. We screen airline passengers knowing a determined adversary can still cause harm, because raising the floor across the whole system prevents the larger number of lower-sophistication attempts and buys detection, attribution, and time. Screening is a floor, not a ceiling, and a floor is worth having.
With that conceded, the requirements are not mysterious. They are four, matched to the four holes.
Make screening universal and mandatory, not voluntary, as a condition of both federal funding and market access. The 2023 approach linked screening to funding and was the right instinct; it should be restored and widened beyond a single agency’s internal labs to all federally supported research and to providers selling into the United States. Coverage is the whole game, because the unscreened fifth is where refused buyers go.
Close the fragment and customer gaps, not just the long-sequence one. Screening standards should cover short oligonucleotides and treat assembly as the threat it is, and customer verification should be given equal weight to sequence matching, because knowing the buyer catches what the sequence filter misses.
Move screening onto the benchtop. A device that manufactures DNA outside any per-order system must carry screening inside the machine, checking each synthesis against the hazard databases and logging as a condition of sale and operation. This is the single most important structural fix, because benchtop devices otherwise abolish the chokepoint rather than leak through it.
Fund and adopt the tools that already exist, and keep improving them against the AI problem. Two nonprofit systems, the IBBIS Common Mechanism and SecureDNA, already offer free screening, the latter built to preserve customer privacy through cryptography so that screening does not require exposing proprietary orders [15][16]. The barrier to universal adoption is not technology or cost. It is the absence of a requirement to use them. And because artificial intelligence can now generate sequences that evade static databases, screening must shift from matching known hazards toward predicting function, the harder problem the Science team’s work points toward.
None of this bans a single beneficial application. It asks one industrial step to be trustworthy and universal, which is the least intrusive serious intervention available in the whole domain. I hold the design of this fix at about 74 out of 100, lower than my confidence in the problem, because the implementation details, above all the international coordination required so that mandatory screening does not simply relocate demand offshore, are genuinely hard and only partly solved.
I subjected this to the obvious attacks. A hostile reviewer says the AI-evasion result was computational and already patched, so I am inflating a closed hole into a crisis. I have conceded the caveats; my claim is about the method’s trajectory, not that specific paper, and the trajectory is not patchable. A second says mandatory screening will drive synthesis offshore and cost the United States its lead. This is the strongest objection, and it is why the recommendation insists on international harmonization and on market-access conditions rather than a domestic-only rule; a mandate that ignores the global market fails. A third says benchtop on-device screening is technically hard and evadable by anyone who modifies the hardware. True, and it still raises the floor for the overwhelming majority who will not, which is what a floor is for. A fourth notes I lean in places on the industry’s own coverage figures; correct, and I have flagged it. Where I cite the fragment red-team I give both the published study and the industry’s rebuttal, and the primary policy documents, the executive orders, the framework, and the NIH rule, are quoted from source.
The unknowns are real. I do not know how many of the AI-redesigned toxins would actually function, because they were never made. I do not know the true size of the unscreened market with precision, only that it is a substantial minority. And I do not know whether the political will exists to restore a mandate that was just dismantled. What I do know is that we have identified the one place where a modest, universal, minimally intrusive control would do the most good, we built much of the machinery to do it, and we are now choosing not to require it. That is not a technical failure. It is a governance failure, and unlike the technical problems, it is one we could fix this year.
The chokepoint is still there. For now, we are simply declining to guard it.
Wittmann B, et al. (senior author Horvitz E). “Strengthening nucleic acid biosecurity screening against generative protein design tools.” Science, October 2, 2025, doi:10.1126/science.adu8578. https://www.science.org/doi/10.1126/science.adu8578
“DNA Synthesis Screening: The Critical Chokepoint.” The Biosecurity Handbook. https://biosecurityhandbook.com/biotechnology/dna-synthesis-screening.html
Nuclear Threat Initiative. “Preventing the Misuse of DNA Synthesis Technology.” https://www.nti.org/about/programs-projects/project/preventing-the-misuse-of-dna-synthesis-technology/
American Enterprise Institute. “Why Universal Gene Synthesis Screening Protects American Biotech.” https://www.aei.org/op-eds/why-universal-gene-synthesis-screening-protects-american-biotech/
International Gene Synthesis Consortium. “Harmonized Screening Protocol v3.0,” September 3, 2024. https://genesynthesisconsortium.org/wp-content/uploads/IGSC-Harmonized-Screening-Protocol-v3.0-1.pdf
Arms Control Association. “Regulatory Gaps in Benchtop Nucleic Acid Synthesis Create Biosecurity Vulnerabilities,” November 24, 2025. https://www.armscontrol.org/blog/2025-11-24/regulatory-gaps-benchtop-nucleic-acid-synthesis-create-biosecurity-vulnerabilities
Executive Order 14110, “Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence,” October 30, 2023. https://www.federalregister.gov/documents/2023/11/01/2023-24283/safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence
Office of Science and Technology Policy. “Framework for Nucleic Acid Synthesis Screening,” 2024 (HHS/ASPR). https://aspr.hhs.gov/S3/Pages/OSTP-Framework-for-Nucleic-Acid-Synthesis-Screening.aspx
Executive Order 14148, “Initial Rescissions of Harmful Executive Orders and Actions,” January 20, 2025. https://www.federalregister.gov/documents/2025/01/28/2025-01901/initial-rescissions-of-harmful-executive-orders-and-actions
Executive Order 14292, “Improving the Safety and Security of Biological Research,” May 5, 2025. https://www.federalregister.gov/documents/2025/05/08/2025-08266/improving-the-safety-and-security-of-biological-research
NIH Office of Intramural Research. “Policy on the Ordering or Provision of Synthetic Nucleic Acids in the IRP,” effective April 26, 2025. https://oir.nih.gov/sourcebook/ethical-conduct/special-research-considerations/policy-ordering-or-provision-synthetic-nucleic-acids-irp
Epstein GL, Williams KM, Sharkey PT. “The evolution of the United States nucleic acid screening policies.” Frontiers in Bioengineering and Biotechnology, 2026. https://www.frontiersin.org/journals/bioengineering-and-biotechnology/articles/10.3389/fbioe.2026.1827740/full
Adamala KP, et al. “Confronting risks of mirror life.” Science, December 12, 2024. https://doi.org/10.1126/science.ads9158
Adamala KP, et al. “Technical Report on Mirror Bacteria: Feasibility and Risks,” December 2024. https://stacks.stanford.edu/file/druid:cv716pj4036/Technical%20Report%20on%20Mirror%20Bacteria%20Feasibility%20and%20Risks.pdf
International Biosecurity and Biosafety Initiative for Science. “The Common Mechanism for DNA Synthesis Screening.” https://ibbis.bio/our-work/common-mechanism/
SecureDNA. “SecureDNA and the OSTP Framework.” https://securedna.org/securedna-and-the-ostp-framework/
National Academies of Sciences, Engineering, and Medicine. Biodefense in the Age of Synthetic Biology. 2018. https://doi.org/10.17226/24890
Sandbrink JB. “Artificial intelligence and biological misuse: Differentiating risks of language models and biological design tools.” arXiv:2306.13952, 2023. https://arxiv.org/abs/2306.13952
“Microsoft says AI can create zero-day threats in biology.” MIT Technology Review, October 2, 2025. https://www.technologyreview.com/2025/10/02/1124767/microsoft-says-ai-can-create-zero-day-threats-in-biology/
“Meet the scientists sounding the alarm about the doomsday risks of mirror life.” CNN, October 17, 2025. https://www.cnn.com/2025/10/17/science/mirror-cell-life-dangers
“Assembling unregulated DNA segments bypasses synthesis screening: regulate fragments as select agents.” Nature Communications, 2025. https://www.nature.com/articles/s41467-025-67955-3
“Why a misleading ‘red team’ study of the gene synthesis industry wrongly casts doubt on industry safety.” Bulletin of the Atomic Scientists, June 2024. https://thebulletin.org/2024/06/why-a-misleading-red-team-study-of-the-gene-synthesis-industry-wrongly-casts-doubt-on-industry-safety/
Next in this series: the uncleared laboratory, and the argument for personnel security in the life sciences that no one in academia wants to have.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.