The gaps in biosecurity law
A newcomer's overview of what DNA-synthesis rules cover, and what they miss.
Policy makers often find the current biosecurity laws most confusing. I'll break this down to make it clearer. This piece is aimed at newcomers who want an overview.
As you may expect, complete working viruses are already illegal to transfer. You can't send someone a vial of the ebola virus. The reason is simple: you need to check they have the appropriate lab conditions to handle this without infecting themselves. A range of laws put this in place, including the US Bioterrorism Act 2002 (response to 9/11).
Components of viruses present a different picture. Deactivated viruses, useful for vaccine production, are not covered by existing rules. DNA synthesis, which creates the virus's genetic code, is also unregulated anywhere. Established, well-documented methods exist for taking viral genetic material and reconstructing the virus around it. This is the primary concern of biosecurity experts. A malicious actor could use AI to design the DNA of a novel supervirus, order it, and turn it into a weapon. While they would need various lab materials, the most obvious chokepoint is the DNA synthesis service.
What rules already exist?
DNA synthesis companies are under scrutiny to check what's in an order before it is sent out. This is known as screening. There is voluntary participation of gene synthesis companies, who have agreed to screen orders through a body known as the International Gene Synthesis Consortium. But it's estimated that while 80% of orders are screened, this only makes up a minority of providers. There are many, many providers who are small and don't screen.
No country has laws requiring DNA synthesis companies to conduct proper screening. Both the UK and the US have issued voluntary guidance. In the US, labs that receive research funding may order only from DNA providers that screen, but this offers a weak incentive because it mainly affects academic customers, a small portion of gene-synthesis companies' revenue.
What would good regulation look like?
DNA synthesis companies should be directed to use a screening provider. There are a few levers for this. You could mandate that they have to screen, then you could require audits to check their biosecurity setup, similar to how ISO 27001 audits cybersecurity (voluntarily).
You could also require them to report suspicious orders to a helpline within 24 hours. This is good because it's easy to test, doesn't require much federal funding, and you can also audit this easily with red-teaming services. You could regulate benchtop synthesisers, the lab devices that affect this.
In summary, while there are rules about complete pathogens, there are still large gaps in prevention of future bioterrorism. Whether they get solved through regulation or other voluntary mechanisms is still unclear.