The knowledge and infrastructure needed to engineer a pandemic pathogen, once confined to a handful of elite military and civilian research institutions, are quietly becoming more accessible.
The gene genie has been out of the bottle for some time. In late 2023, two graduate students working under FBI supervision at the Massachusetts Institute of Technology (MIT) Media Lab ordered fragments of a virus from 38 commercial DNA synthesis companies. The virus in question was the 1918 "Spanish flu" variant of influenza—the pathogen responsible for one of history's most devastating pandemics, which killed an estimated fifty million people worldwide. The orders were placed on behalf of an organisation that conducts no laboratory experiments, and shipping was requested to an address with no laboratory facilities—both details that should have triggered scrutiny. The students used simple evasive strategies to disguise what they were ordering.
Of the 38 companies they contacted, 36 shipped the fragments anyway. Only one firm detected a potential hazard and asked for proof of biosafety approval. The rest—including twelve of thirteen members of the International Gene Synthesis Consortium, the industry's own voluntary biosecurity body—sent the material without question. The students then demonstrated that standard synthetic biology techniques could assemble the pieces into an infectious virus identical to the one that plagued combatants during the First World War and killed far more people than the fighting did.
That unsettling experiment, led by MIT biosecurity researcher Professor Kevin Esvelt and his students Rey Edison and Shay Toner, exemplifies a threat that is at once highly technical and urgently practical. The knowledge and infrastructure needed to engineer a pandemic pathogen, once confined to a handful of elite military and civilian research institutions, is quietly becoming more accessible. And artificial intelligence is accelerating the process in ways that policy has not yet addressed.
A Supply Chain Built for Science, Not Security
To understand the vulnerability, it helps to understand how modern biological research works. Scientists who need custom segments of DNA or RNA can order them online from commercial synthesis firms, much like ordering a part from an electronics supplier. Customers specify the genetic sequence they want, then the company's machines synthesise it chemically and ship it within days. This costs a few cents per base pair. The technology has been transformative for medicine, agriculture, and basic research.
It has also created what biosecurity experts call a "choke point"—a juncture at which dangerous sequences could be intercepted before reaching would-be bad actors. Genome sequences for pandemic-potential viruses, including the reconstructed 1918 influenza strain, are freely available in public databases. Step-by-step protocols for generating infectious virus from synthetic DNA are published in the scientific literature. The only practical barrier between that public knowledge and a working pathogen is whether the synthesis company filling the order is cognisant of the implications of what it is being asked to provide.
Since 2009, many of the largest synthesis providers have voluntarily screened orders against databases of dangerous sequences through the International Gene Synthesis Consortium. But the system has structural weaknesses that Professor Esvelt and others have documented for years: non-member companies—numbering in the dozens globally—face no obligation to screen at all. Also, member companies generally screen for complete dangerous sequences but are less reliable at catching orders split across multiple fragments or spread across multiple providers. And the screening tools in widest use compare ordered sequences against known dangerous sequences by simple similarity, an approach that increasingly sophisticated AI tools can circumvent.
AI Lowers the Bar
For most of the history of biosecurity, the knowledge required to engineer a dangerous pathogen served as its own barrier. Reconstructing a pandemic influenza virus, for example, demanded not just the genome sequence but also deep expertise in virology, reverse genetics, and biosafety protocols—skills that take years to acquire and that, practically speaking, limited the pool of potential bad actors to credentialed scientists working in equipped laboratories.
Artificial intelligence is eroding that barrier. AI systems now routinely outperform PhD-level virologists on highly technical laboratory questions. Research published in Science in 2025 by Microsoft's Eric Horvitz and colleagues demonstrated that AI-assisted protein-design tools could be used to redesign 72 biological molecules—including toxins and viral proteins—in ways that preserve their dangerous functions while evading the sequence-similarity screening that most synthesis companies rely upon. Working with four commercial DNA synthesis companies, the team stress-tested existing screening methods and helped develop patches to improve detection. Of concern, however, is that for every patch applied, someone with access to the same open-source AI tools could devise a new evasion strategy.
In June, the CEOs of the world's largest AI companies and others signed an open letter calling on Congress to act. Sam Altman of OpenAI, Dario Amodei of Anthropic, Demis Hassabis of Google DeepMind, and Mustafa Suleyman of Microsoft AI joined Nobel laureate David Baker, Esvelt himself, and former Secretary of the Army Christine Wormuth in warning that "there is a real possibility that the knowledge barriers which have historically prevented bad actors from obtaining biological weapons will meaningfully erode." The signatories were careful to note that the evidence on immediate risk remains "genuinely mixed." But their argument is about trajectory: as AI capabilities improve, the window for action narrows.
The Regulatory Patchwork
American biosecurity policy has moved, but haltingly. In October 2023, President Biden's Executive Order on artificial intelligence included a provision requiring federally funded researchers to purchase synthetic nucleic acids only from providers that conduct biosecurity screening. The White House Office of Science and Technology Policy (OSTP) followed in April 2024 with a formal Framework for Nucleic Acid Synthesis Screening. Both were meaningful steps, but they fell short of what biosecurity experts say is needed.
The Executive Order's screening requirements apply only to federally funded purchases, leaving the commercial market largely unaffected. This is a significant shortcoming. The framework's technical standards focus on sequence identity, the same approach that AI protein design tools can circumvent. In May 2025, the Trump administration ordered OSTP to revise or replace the Biden-era framework entirely, with a new version still awaited.
Legislative action has been equally tentative and insufficient. The Nucleic Acid Standards for Biosecurity Act, H.R. 3029, passed the U.S. House of Representatives in July 2026, but it targets voluntary standards rather than mandates. A more stringent Senate companion bill, S. 3741, the Biosecurity Modernization and Innovation Act of 2026, would require the Secretary of Commerce to issue binding regulations on synthesis security. The open letter from the AI executives calls for action "this session" and urges states not to fill the vacuum with inconsistent local laws.
The Dispute Within the Field
The Esvelt-MIT Spanish Flu virus experiment—and the broader debate about bioterrorism risk—is not without controversy. The International Gene Synthesis Consortium disputed the findings, arguing that member companies had in fact screened both the sequences and the ordering organisation, and determined the order to be legitimate. The name on the orders belonged to someone who had co-published with Esvelt and was associated with SecureBio, a nonprofit Esvelt cofounded to develop improved screening tools. "The system worked as designed," the consortium argued.
Esvelt and his co-authors do not deny that some companies flagged the orders. Their point is that the overall system, relying on voluntary participation and standards that can be gamed, is insufficient for the risk environment that AI is creating. There is a difference, they argue, between a system that catches a known researcher affiliated with a known biosecurity organisation and a system capable of catching a bad actor using AI tools to design novel sequences that bear no resemblance to anything in a screening database.
That distinction matters enormously for policy. If the relevant question is whether current screening catches known dangerous sequences ordered by identifiable people, the answer may be reassuring. If the question is whether or not it catches AI-designed variants ordered through shell organisations, the answer is far less clear.
What Could Actually Work
The biosecurity community has converged on several interventions that experts believe would substantially reduce the risks. The most important is mandatory, universal screening—not voluntary compliance by responsible industry members, but legal requirements extending to every provider, including the growing number of bench-top synthesis devices that let researchers produce custom DNA in their own laboratories without placing an external order at all.
Free-to-use screening platforms now exist. SecureDNA, developed in part by Esvelt's group, is available to all synthesis providers at no cost, and it can detect evasive strategies including split orders across multiple companies. The Nuclear Threat Initiative has developed its own platform in partnership with the World Economic Forum. The argument that screening imposes prohibitive costs on smaller providers no longer holds—the tools are there, and freely available. What's missing is the mandate.
Beyond sequence screening, biosecurity experts advocate for mandatory record-keeping—documentation that lets investigators trace suspicious orders even when individual fragments would not, in isolation, raise a flag. The AI executives' open letter endorses both measures. International coordination presents a harder problem. The Biological Weapons Convention—the global treaty banning biological and toxin weapons—lacks the verification mechanisms and enforcement capacity of comparable arms-control agreements. Most countries have no synthesis screening requirements at all. American and European mandates, however important, cannot close a supply chain that circles the globe.
The Clock Is Ticking
The 2001 anthrax-letter attacks—which killed five people and prompted what is thought to be the largest law-enforcement investigation in American history—were carried out with biological material available to a credentialed government scientist. No AI was required, and no commercial synthesis was needed. The barriers to catastrophic bioterrorism have never been absolute. The question that biosecurity researchers are now asking is whether or not rapidly progressing AI will lower them far enough and fast enough that the probability of a catastrophic event shifts from remote to foreseeable before policy catches up.
Professor Kevin Esvelt, who has spent years trying to sound this alarm, offers a concise formulation of the problem: the fault lies not with gene synthesis companies that screen voluntarily at their own expense, but with governments that have not required everyone to do so. The tools to build a better system exist. What is lacking is the political will to use them. After decades of voluntary good intentions, the gene-synthesis industry—and the governments that regulate it—may be running out of time to act before it's too late.
Henry I. Miller, a physician and molecular biologist, is the Glenn Swogger Distinguished Fellow at the Science Literacy Project. He was the founding director of the U.S. FDA's Office of Biotechnology.

