Biology
Bioresilience: The Month AI Labs Stopped Apologising for Biology
For about three years, the standard frontier-lab position on biology was defensive. Biology was the scary quadrant of the risk matrix.
For about three years, the standard frontier-lab position on biology was defensive. Biology was the scary quadrant of the risk matrix.
July 2026 has been the month the verb changed. Google DeepMind and Isomorphic Labs published a joint programme built on the opposite premise — that frontier models are not merely a biosecurity liability to be fenced off but the biosecurity infrastructure itself. Two weeks later, the US Bipartisan Commission on Biodefense made AI the sixteenth technology priority in its Apollo Program for Biodefense, the first addition since the programme was created in 2021. And OpenAI shipped its most biology-capable model to date through a government-gated preview, then opened it to everyone.
Three announcements, one argument: the same systems that make the threat model worse are now being positioned as the response to it. That argument deserves more scrutiny than it has received.
What happened#
16 July — DeepMind and Isomorphic Labs publish "Our approach to bioresilience." The blog post and accompanying report describe a programme organised into three buckets: prevent, detect, respond.
Under prevent, the companies describe a four-step safety process — threat modelling, evaluations, mitigations, monitoring — and disclose that they are "working on adapting our SynthID watermarking technology to biology, which could help DNA synthesis providers screen for potentially risky, AI-generated biological sequences." SynthID is Google's watermarking system for AI-generated images, audio and text. Extending it to nucleic acid sequences is a genuinely interesting idea and, per the post's own framing, exploratory work rather than a shipped product.
Under detect, DeepMind says its Gemini-powered coding agent AlphaEvolve "can optimise algorithms used for producing and analysing metagenomic sequencing data, helping detect new outbreaks faster," and that AlphaGenome and protein-function annotation could help characterise pathogens directly from sequence data.
Under respond, DeepMind is granting trusted researchers access to its latest systems for vaccine and countermeasure design, and Isomorphic Labs has stood up a dedicated unit to deploy its Drug Design Engine during novel outbreaks — explicitly including outbreaks "arising from the misuse of advanced AI."
The companies say they have advanced more than 15 partnerships with government bodies, biosecurity organisations and research groups over the past twelve months.
Speaking to Axios on the day of publication, Helen King, DeepMind's VP of responsibility, put the release condition plainly: "If we were to find that we were reaching a critical capability level and we didn't have the appropriate mitigations, then we would not be launching." She said that threshold has not been reached. Owen Larter, the lab's senior director of frontier AI policy, said frontier labs are "in agreement" on the need for rigorous pre-release testing. The announcement landed two days after DeepMind CEO Demis Hassabis told the same outlet that governments should stand up a standards body for frontier AI.
8 July — the Bipartisan Commission on Biodefense adds AI to the Apollo Program. The Commission, housed at the Atlantic Council, designated AI its sixteenth technology priority following a public meeting with OpenAI, Anthropic, Microsoft and AI/bio experts. The original fifteen priorities, set in the Commission's 2021 report, run from prototype-pathogen vaccine candidates to next-generation PPE.
Commission co-chair and former HHS Secretary Donna Shalala framed the stakes as a race between two curves: "Artificial intelligence has the potential to transform how we develop vaccines, diagnostics, and treatments… But without deliberate investment and clear policy, AI could benefit the attacker before it benefits the defender."
Late June into July — GPT-5.6 ships through a government gate. OpenAI's preview post for the GPT-5.6 series (Sol, Terra, Luna) reports improved biology performance on GeneBench v1, a long-horizon genomics and quantitative-biology benchmark. More relevant to this beat is the deployment machinery: real-time biology and cyber misuse classifiers that evaluate output as it is generated and can pause generation for review by a larger reasoning model; account-level review across conversations; differentiated access tiers; and over 700,000 A100-equivalent GPU hours spent on automated red-teaming for universal jailbreaks.
OpenAI also confirms it previewed the models to the US government ahead of launch and, at the government's request, began with a limited preview for partners whose participation was disclosed to the government. The company is notably unenthusiastic about the precedent: "We don't believe this kind of government access process should become the long-term default."
Why it matters#
The choke point has moved, and everyone knows it. The biosecurity community has spent years arguing that nucleic acid synthesis is the narrowest place to intervene in an AI-assisted protein engineering pipeline — you can't do much with a designed sequence you cannot order. That argument got sharper in October 2025, when Wittmann and colleagues published in Science that open-source protein design tools could generate variants of proteins of concern that current commercial screening software failed to reliably flag. The team worked with four DNA synthesis companies to develop and deploy patches.
DeepMind's SynthID-for-DNA line is best read as a response to exactly that finding. If AI-designed sequences can slip past homology-based screening, one option is watermarking at the point of generation rather than detection at the point of order. That is a meaningfully different governance model — and one that only works if the labs doing the designing agree to participate.
"Bioresilience" is a positioning move as much as a technical one. Framing frontier AI as biosecurity infrastructure rather than biosecurity risk changes who gets to sit at the table when rules are written. Axios read it correctly: Google is "increasingly arguing that frontier AI itself will become a critical biosecurity tool." That argument may well be true. It is also extremely convenient for a company that would prefer industry-funded, technically staffed standards bodies over statutory regulation — the model Hassabis proposed the same week.
Detection is where the near-term public health payoff actually lives. Strip away the framing and the least speculative claim in the DeepMind announcement is the metagenomic one. Untargeted metagenomic sequencing can in principle detect pathogens nobody has characterised yet, which is the whole ballgame for a pathogen-agnostic early warning system. Its adoption has been throttled by cost per sample and analysis throughput. Anything that makes the bioinformatics meaningfully cheaper widens deployment — and unlike countermeasure design, it does not have to clear a regulator to matter.
Governments are now inside the release loop, and nobody is comfortable. A twelve-day government-gated preview of a commercial model is not how software has historically shipped. OpenAI accepted it while explicitly objecting to it becoming permanent. DeepMind is lobbying for a standards body. The Biodefense Commission's Tom Ridge said flatly that "the federal government is simply not equipped to address these rapid advances in technology." Everyone involved agrees the current arrangement is a placeholder. Nobody agrees on what replaces it.
The Limitations#
Almost none of this is independently verified. The DeepMind bioresilience post is a company blog and accompanying report, not a peer-reviewed paper. The claim that AlphaEvolve speeds up metagenomic analysis comes with no published benchmark, no baseline, no error rates. "Can optimise algorithms" is doing considerable work in that sentence. Treat it as a statement of intent until numbers appear.
SynthID for DNA is not a product. DeepMind describes it as work in progress. The technical challenge is real: watermarking a biological sequence means embedding a detectable signal in something that must remain functional, that is short relative to an image, that a determined actor can trivially mutate, and that arises identically in nature. Whether a robust scheme exists is an open research question.
The Science screening paper is peer-reviewed; the patches are not a fix. That study demonstrated a vulnerability and a partial remedy, tested against four commercial providers. It does not cover providers outside that cooperation, benchtop synthesisers, or actors who never place an order at all. Screening only binds the compliant.
Benchmark scores are not wet-lab capability. GeneBench and similar evaluations measure performance on curated tasks. The distance between answering genomics questions well and doing anything consequential at a bench remains large, poorly characterised, and heavily dependent on tacit skill and physical access. Both alarm and reassurance are frequently overstated on the basis of these numbers.
Preprint and non-peer-reviewed status, flagged: the DeepMind/Isomorphic report, the Atlantic Council issue brief, and the OpenAI system card are all self-published by interested parties. Only the Science paper in this post has been through peer review.
Access asymmetry is the ethics question nobody has answered. "Trusted partners" and "restricted releases" mean somebody is deciding who counts as trusted. On current form, that will skew toward well-resourced institutions in a small number of countries — while the surveillance gaps that matter most for pandemic detection are largely elsewhere.
FAQs#
Is AI making a pandemic more likely? The honest answer is that nobody knows, and the evidence is contested. What is documented is that AI protein design tools could produce sequences that evaded specific screening software, and that this was patched (Science, peer-reviewed). Claims beyond that — about end-to-end uplift for a real actor — rest on evaluations that measure knowledge, not capability at a bench.
What is "bioresilience," exactly? It's DeepMind and Isomorphic Labs' term for pairing misuse prevention with active investment in detection and response capacity. The implied contrast is with a purely restrictive posture. It is not an established term of art in the biosecurity literature.
Does watermarking DNA actually work? Unknown. Watermarking text and images is itself imperfect and defeatable. Biological sequences add constraints — functional integrity, short length, natural occurrence of the same subsequences, trivial mutability — that make the problem harder, not easier.
Is metagenomic surveillance already deployed? Partially and unevenly. Wastewater and clinical metagenomic programmes exist in several countries, but coverage is patchy, and cost remains the binding constraint. Cheaper analysis expands what is affordable; it does not by itself build the sampling network.
Should I change anything about my own health behaviour based on this? No. Nothing here concerns any current outbreak, treatment or personal risk. This post is not medical advice. For outbreak information, use WHO Disease Outbreak News and your national public health agency.
Why did all of this land in the same month? Partly coincidence, partly not. The US executive order process created a forcing function on release timelines, and the Biodefense Commission meeting in early July put the major labs in the same room. Announcements cluster around policy windows.
Primary sources#
- Google DeepMind & Isomorphic Labs, "Our approach to bioresilience," 16 July 2026 — https://deepmind.google/blog/our-approach-to-bioresilience/ (company blog; full report linked therein)
- Madison Mills, "Exclusive: Google bets that AI can stop bioweapons," Axios, 16 July 2026 — https://www.axios.com/2026/07/16/google-deepmind-biosecurity-safety (contains direct quotes from DeepMind executives)
- OpenAI, "Previewing GPT‑5.6 Sol: a next-generation model," 26 June 2026 — https://openai.com/index/previewing-gpt-5-6-sol/ (company post; safeguards and government preview process)
- Bipartisan Commission on Biodefense / Atlantic Council, "AI is the Next Major Biodefense Tech Priority," reported 8 July 2026 — https://www.hstoday.us/subject-matter-areas/pandemic-biohazard/biodefense-commission-adds-ai-as-new-technology-priority-in-preparedness-effort/
- Wittmann BJ, Alexanian T, Horvitz E, et al., "Strengthening nucleic acid biosecurity screening against generative protein design tools," Science, October 2025 — https://www.science.org/doi/10.1126/science.adu8578 (peer-reviewed)