Governing Dual-Use Biotechnology Risks Without Slowing Responsible Life Sciences Innovation

Governing Dual-Use Biotechnology Risks Without Slowing Responsible Life Sciences Innovation
Modern biotechnology can produce vaccines, improve diagnostics, support food security, reduce industrial waste, and deepen understanding of disease. Some of the same knowledge and tools can also be misapplied, whether deliberately or through inadequate safety practices. This dual-use character is not unusual in science, but biology presents distinctive governance challenges because living systems can reproduce, methods can spread rapidly, and harmful consequences may cross institutional and national boundaries.
The central policy question is not whether biotechnology should be controlled. Laboratories already operate under layers of safety, ethics, security, funding, and professional requirements. The harder question is how to identify the activities that warrant additional scrutiny without treating broad areas of legitimate research as inherently suspect.
Effective governance must be selective, technically informed, and adaptable. It should focus on credible pathways to harm while preserving the openness, collaboration, and experimentation that make life sciences research productive.
What dual use means in biotechnology
Dual-use research has both beneficial applications and a plausible capacity for harmful use. The category covers a broad range of activities. Research might reveal how a pathogen interacts with a host, make biological production more efficient, identify vulnerabilities in immune defenses, or enable organisms to be engineered with greater precision.
Most such work is not dangerous merely because it involves advanced methods or pathogens. Its risk depends on the organism, experimental objective, resulting capability, accessibility of materials, skill required for replication, and potential consequences of misuse. Context matters as much as technical content.
A narrower category, often called dual-use research of concern, refers to work that could reasonably be expected to provide knowledge, products, or technologies with significant potential for harmful application. This concept is useful, but it should not be treated as a simple label. Reasonable experts may disagree about whether an experiment crosses that threshold, especially when evidence is incomplete.
Terms such as “gain of function” are even less precise. Many ordinary experiments give an organism a new or enhanced property. Using that broad description as a regulatory category can capture routine research while failing to isolate the specific characteristics that create serious risk. Governance is more effective when it asks what capability is being created, how accessible it will be, and what consequences could follow.
Different risks require different controls
Biological risk is not a single problem. Accidental exposure, laboratory escape, insider misuse, deliberate weapon development, insecure data, and poorly screened commercial synthesis orders have different causes. They also require different interventions.
Biosafety focuses primarily on preventing accidental exposure and unintentional release. It includes facility design, containment practices, protective equipment, training, waste management, and incident response. Biosecurity addresses deliberate loss, theft, diversion, or misuse of biological materials, information, and technology. Research integrity supports both by promoting accurate records, responsible supervision, and a culture in which concerns can be raised.
These areas overlap, but they should not be conflated. A laboratory may have excellent physical containment while paying insufficient attention to data access or insider threats. Conversely, stringent security procedures cannot compensate for poor experimental practice. Governance needs to examine the full research system rather than relying on a single review form or containment designation.
The international legal foundation includes the Biological Weapons Convention, which prohibits the development, production, acquisition, transfer, stockpiling, and use of biological and toxin weapons. The convention establishes a clear norm, but national implementation, research oversight, and enforcement remain the responsibility of individual states. Scientific collaboration and commercial supply chains make coordination across jurisdictions increasingly important.
Why overly broad restrictions can increase risk
Heavy controls may appear precautionary, but poorly targeted restrictions carry costs of their own. Lengthy or unpredictable reviews can discourage important work on emerging infections, antimicrobial resistance, vaccine platforms, and environmental monitoring. Compliance burdens may fall especially heavily on smaller institutions, early career researchers, and laboratories in countries with limited administrative capacity.
Restrictions can also push research into less visible settings. If oversight is seen as arbitrary or punitive, scientists may avoid discussing ambiguous findings, reporting mistakes, or seeking advice. That weakens the information flow on which effective risk management depends.
Secrecy can create additional vulnerabilities. Open scientific exchange supports replication, correction, surveillance, and the development of countermeasures. Restricting access to a method may reduce misuse in some circumstances, but it can also slow the work of public health laboratories and defensive researchers. Publication controls therefore require a concrete analysis of likely harm, not a presumption that less information is always safer.
The appropriate goal is not zero risk, which is unattainable. It is a proportionate reduction of serious and plausible risks while retaining the health, economic, and scientific benefits of responsible research.
Assess capabilities rather than labels
A durable governance system should evaluate the capabilities produced by research. Relevant questions include whether a project could substantially alter pathogenicity, host range, transmissibility, immune evasion, resistance to medical countermeasures, environmental persistence, or detectability. Reviewers should also consider whether the work could facilitate reconstruction of a hazardous agent or lower practical barriers to causing harm.
Capability assessment avoids several weaknesses of list-based regulation. Lists of organisms and toxins can provide clarity, but they may become outdated as technology changes. They can also overlook work involving components, engineered systems, or combinations of methods that do not fit conventional taxonomies.
Lists still have a role. They are useful for setting baseline controls, defining reporting obligations, and identifying materials that require secure handling. They work best when supplemented by a process that can recognize new capabilities and unusual experimental contexts.
Risk assessment should also distinguish between intrinsic hazard and operational feasibility. A result may appear alarming in theory but require rare materials, exceptional expertise, specialized facilities, or a sequence of unreliable steps. Another result may seem less dramatic but be easily reproduced with widely available equipment. Both consequence and feasibility matter.
Review throughout the research lifecycle
A one-time review before funding or experimentation is insufficient. Projects change, unexpected results emerge, and initially benign data may become more consequential when combined with new tools.
Early review should begin during project design. Researchers can often modify an experiment, choose a safer model system, divide work into stages, or establish decision points before sensitive results are generated. This is generally less disruptive than imposing controls after substantial investment.
Review should continue when methods change, key findings emerge, collaborators are added, or data are prepared for release. Publication review should not function as a last-minute censorship mechanism. By that stage, the relevant information may already have circulated among researchers, contractors, funders, and digital systems.
Post-project responsibilities matter as well. Institutions need policies for retaining strains, destroying unneeded materials, preserving audit records, controlling data repositories, and managing access after staff leave. Governance that ends when a grant closes leaves avoidable gaps.
Place responsibility at several levels
Researchers are often best positioned to recognize the significance of their work, but they should not carry the full burden of deciding whether it poses a broader security risk. Individual judgment can be affected by disciplinary norms, career incentives, or incomplete knowledge of threat pathways.
Institutions should maintain review bodies with expertise in biosafety, biosecurity, ethics, relevant scientific fields, cybersecurity, and public health. Independent perspectives are valuable when a project has consequences beyond the host laboratory. Review bodies also need clear authority, documented procedures, and routes for appeal.
Funders can establish consistent expectations before projects begin and support the cost of compliance. Publishers and preprint platforms can create confidential processes for handling manuscripts that raise credible concerns. Commercial providers, including biological synthesis companies, can screen customers and orders while protecting legitimate research and confidential information.
Governments remain responsible for setting minimum standards, clarifying legal obligations, coordinating intelligence and public health expertise, and ensuring that decisions are not fragmented across agencies. International organizations can support common principles and capacity building. The World Health Organization’s global guidance framework emphasizes shared responsibility across the life sciences ecosystem rather than assigning the problem to laboratories alone.
No single layer is sufficient. Distributed responsibility is valuable only when roles are explicit and information can move between them.
Sequence synthesis and automated design need tailored oversight
The growth of commercial nucleic acid synthesis has changed access to biological materials. Screening orders can help identify requests involving regulated pathogens, toxins, or sequences of concern. Customer verification can add another layer by assessing whether an order is consistent with a legitimate organization and stated purpose.
Screening is technically and institutionally difficult. Short fragments may have many benign uses. Modified or functionally equivalent sequences may not match a reference list. Providers also differ in resources, legal obligations, and access to reliable customer information. If rigorous screening is voluntary and costly, customers may migrate toward suppliers with weaker practices.
Effective policy should promote interoperable standards, protect sensitive screening information, and avoid imposing requirements that only the largest companies can meet. Support for smaller providers may be necessary if screening is expected to become a reliable global safeguard.
Automated design tools add another concern. Artificial intelligence can assist with protein design, experimental planning, literature analysis, and optimization. These systems may accelerate beneficial research, but they can also reduce the expertise or time needed for some sensitive tasks. Governance should focus on demonstrated capabilities and credible misuse pathways rather than treating all biological artificial intelligence as equally risky.
Possible controls include access management for unusually capable systems, testing against defined biological misuse scenarios, monitoring for suspicious usage where lawful, and structured reporting when safeguards fail. Such measures should be evaluated for effectiveness. A safeguard that is easily bypassed or produces large numbers of false alarms may create reassurance without materially reducing risk.
Information controls should be narrow and reviewable
Some research outputs may justify limits on immediate or unrestricted release. Options include delaying publication, omitting specific operational details, sharing information with vetted researchers, or releasing findings alongside effective countermeasures. Complete suppression should be exceptional because it is difficult to reverse and may obstruct defensive work.
Any restriction should meet several conditions. The anticipated harm should be credible and serious. The restricted information should make a meaningful contribution to that harm. Less restrictive alternatives should have been considered. The decision should have a defined scope, accountable decision makers, and a date for reassessment.
Information hazards are also cumulative. A single paper may be innocuous, while several datasets, protocols, and software tools together create a more consequential capability. Review processes need enough technical breadth to recognize these combinations without assuming that all aggregation is dangerous.
Cybersecurity is increasingly part of biological security. Genomic data, laboratory automation systems, strain inventories, experimental records, and remote access credentials can all be sensitive. Basic controls such as role-based access, secure backups, authentication, logging, and timely removal of former users may prevent both malicious activity and accidental loss. These measures should be integrated into normal research operations rather than added only to projects carrying a special security label.
Build a culture that supports reporting
Formal compliance cannot anticipate every unusual result or procedural failure. Institutions need a culture in which researchers can report mistakes, near misses, and ambiguous concerns without expecting automatic punishment.
This does not mean abandoning accountability. Deliberate misconduct and reckless disregard require an appropriate response. Honest reporting, however, should be distinguished from concealment or repeated negligence. Confidential consultation channels and protected escalation routes can help researchers seek guidance before a concern becomes a crisis.
Training should use realistic cases rather than relying on abstract rules. Scientists need practice recognizing when a change in experimental design, an unexpected phenotype, a new collaborator, or a publication plan could alter risk. Training should also explain who makes decisions and what happens after a concern is raised. Vague instructions to “consider dual use” offer little practical value.
Leadership behavior is crucial. If principal investigators and senior administrators treat review as a bureaucratic obstacle, junior staff will learn to minimize disclosure. If leaders discuss uncertainty openly and reward responsible problem solving, oversight becomes part of good science.
Measure whether governance works
Biosecurity policies are often judged by the existence of committees, forms, and training records. These are easy to count but do not establish that risk has been reduced.
More meaningful evaluation asks whether high-risk projects are identified early, reviews are completed within predictable periods, mitigation measures are implemented, incidents and near misses are reported, and decisions are consistent across comparable cases. Authorities should also examine unintended effects, including abandoned public health research, duplicated review, prolonged delays, and movement toward less accountable providers.
Because serious biological incidents are rare, evaluation cannot rely only on event counts. Exercises, audits, anonymized case analysis, and structured testing can reveal weaknesses before an emergency occurs. Policies should include scheduled review so that ineffective requirements can be revised or removed.
Transparency supports legitimacy. Institutions and governments can publish aggregate information about review processes, decision criteria, and policy outcomes without exposing sensitive research. Clear explanations also help the public distinguish ordinary life sciences work from the small subset of activities requiring heightened controls.
A proportionate path forward
Responsible innovation and biosecurity are not opposing goals. High-quality science depends on careful methods, reliable institutions, and public trust, all of which also support risk reduction. Conflict arises when controls are vague, duplicative, or disconnected from actual capabilities.
A workable model combines clear baseline standards with enhanced review for research that could materially increase dangerous biological capabilities. It assesses risk throughout the research lifecycle, distributes responsibility across institutions, and creates confidential routes for expert consultation. It also subjects security measures to evidence, review, and revision.
The governing principle should be proportionality. Low-risk work should proceed without unnecessary friction. Uncertain cases should receive timely multidisciplinary assessment. Research with credible potential for severe harm should face stronger safeguards, and in rare circumstances it may need to be redesigned, restricted, or stopped.
Biotechnology will continue to become more accessible and computationally sophisticated. Governance will remain credible only if it adapts at a similar pace while preserving the scientific cooperation needed to detect disease, develop countermeasures, and solve difficult biological problems.