Biology

The New Gain-of-Function Ban Stops at the Lab Door — and AI Is on the Other Side

The US government's July 28 policy prohibits dangerous gain-of-function research outright. But purely computational design of novel biological agents is explicitly not prohibited — it gets an interagency monitoring group instead. Here's what the policy says, why the split matters, and what it doesn't tell us.

Twelve pages of federal policy landed on July 28 did something biosecurity advocates have wanted for a decade: it flatly prohibits federal support for dangerous gain-of-function research, in the United States and abroad, with enforcement teeth attached.

Then, on the way past, it made a much quieter decision. Designing a novel biological agent on a computer — including with AI — is "not prohibited by this policy." That work gets an interagency committee to watch it.

One of those two sentences will get written about for years. It isn't the first one.

What happened#

On July 28, 2026, the White House released the United States Government Policy for Stopping High-Risk Life Sciences Research, issued under Section 4 of Executive Order 14292, the May 2025 order on improving the safety and security of biological research (NIH Guide Notice NOT-OD-26-101). The US Department of Health and Human Services (HHS) announced it the same day, calling it a framework that "prohibits federally supported dangerous gain-of-function (DGOF) research while establishing stronger oversight for life sciences research that could pose significant risks to public health, biosecurity, or national security" (HHS, July 28, 2026).

The policy targets two categories. Dangerous gain-of-function research is defined as research with a biological agent that "seeks, achieves, or has a substantial risk of achieving" one or more listed outcomes and could produce significant negative societal consequences; the guidance describes DGOF as work that "enhances a property or properties of a biological agent in ways that make it more dangerous" (NIH; policy text quoted in Nextgov/FCW). International research of concern (IROC) covers work conducted in a country of concern, or by institutions of concern, or in countries with inadequate oversight (NIH).

The mechanics matter more than the rhetoric. Agencies have 120 days to publish implementation guidance and 90 days to stand up a single independent third-party review body. Until then, every project already flagged as potential DGOF under the 2025 pause notices stays paused (NIH). The Center for Infectious Disease Research & Policy (CIDRAP) reports implementation is slated for mid-November (CIDRAP, July 29, 2026). Principal investigators carry a continuing obligation to evaluate their own work for DGOF and IROC status and to disclose non-US collaborators (CIDRAP). Counsel reviewing the document report that penalties for noncompliance run to immediate revocation of funding and up to five years of ineligibility for federal life sciences support (Butler Snow analysis).

HHS Secretary Robert F. Kennedy Jr. framed it as "ending federal support for dangerous gain-of-function research and replacing weak oversight with clear, enforceable safeguards." NIH Director Jay Bhattacharya said the framework rests on the principle that "the pursuit of knowledge must be matched by a commitment to responsibility" (HHS). In a same-day Wall Street Journal op-ed, Bhattacharya set out three principles: some categories of research are too risky to pursue; the whole biomedical enterprise must assess and monitor risk; and researchers, institutions and funders will be held accountable for evaluating and reporting high-risk work (quoted in Nextgov/FCW).

The timing was not subtle. The next day, Anthony Fauci invoked the Fifth Amendment before the Senate Homeland Security and Governmental Affairs Committee in a hearing about federal funding of research at the Wuhan Institute of Virology (Pandora Report, July 30, 2026; NBC News).

The in-silico carve-out#

Here is the language that deserves more attention than it has received. From the policy, as quoted by Nextgov/FCW:

"When a proposal includes plans to create or modify a biological agent that would meet the definition of DGOF research or potential DGOF research and is the result of in silico research, this policy applies. However, purely computational (i.e., in silico) research that may include development of computational models and software, or may use such means to design novel forms of biological agents, is not prohibited by this policy unless it involves an entity of concern."

And the oversight substitute:

"The White House Office of Science and Technology Policy (OSTP) will convene an interagency group to monitor advancements at the intersection of biological sciences and artificial intelligence, including in silico life sciences research."

(Nextgov/FCW, July 29, 2026)

Read plainly, the trigger is synthesis, not design. Draft a sequence for a more dangerous agent on a GPU cluster and the prohibition doesn't reach you. Propose to build it and it does. Nextgov's Edward Graham put it accurately: the policy "alludes to the risks of artificial intelligence but does not outright call for banning the use of the emerging capabilities in hazardous projects."

Why it matters#

There is a defensible case for that line. Computational virology is how vaccine strain selection, antiviral screening, and variant forecasting get done. A rule that swept in any model capable of proposing a more transmissible sequence would capture a large fraction of legitimate structural biology — and the same administration is spending real money to accelerate exactly that work through the Genesis Mission, launched in November 2025 to apply AI to national research priorities including biotechnology (Nextgov/FCW). A design that stays on a hard drive also cannot infect anyone. Regulating the physical step is the enforceable step.

The case against is that the physical step keeps getting cheaper, and the people closest to the models keep saying so. On June 4, 2026, an open letter signed by OpenAI's Sam Altman, Anthropic's Dario Amodei, Google DeepMind's Demis Hassabis and Microsoft AI's Mustafa Suleyman urged Congress to make screening and recordkeeping mandatory for orders of synthetic nucleic acids and the equipment used to make them. Their stated reason: "AI systems are improving rapidly, and alongside incredible benefits to science and medicine, there is a real possibility that the knowledge barriers which have historically prevented bad actors from obtaining biological weapons will meaningfully erode" (screendna.org, organized by the Foundation for American Innovation and the Institute for Progress; reported by Fortune and GEN). The administration's own July 2025 AI Action Plan warned that AI could open "new pathways for malicious actors to synthesize harmful pathogens and other biomolecules" (quoted in Nextgov/FCW).

So: the executive branch tightened the rules on the wet lab, and the bottleneck the AI industry itself keeps pointing at — the synthesis order, the DNA that turns a file into an organism — remains outside this policy. That's a job for Congress, and the bill is still a bill.

Meanwhile, the design layer is largely unsupervised in practice. Epoch AI's February 2026 database of biological AI models catalogued 1,196 models released after September 2024 and found that fewer than 3% carry any documented safeguards; roughly 2.5% have documented risk assessments and 2.3% report risk-related evaluations (Epoch AI, commissioned by Sentinel Bio). Frontier general-purpose LLMs are the exception, not the rule — and even there, verification is young. SecureBio's review of Anthropic's unredacted chemical and biological risk report for Claude Opus 4.6 concurred with the developer's own assessment that catastrophic-outcome risk was "very low but not negligible" for non-novel CB weapons and "low risk, but with substantial uncertainty" for novel ones, and found the refusal classifiers blocked 94.2% of hazardous prompts in SecureBio's benchmark. SecureBio noted it received no funding from Anthropic for the work (SecureBio). That is one lab, one model, one voluntary review.

An OSTP monitoring group is a reasonable first move into that gap. It is also, for now, a group that monitors.

The limitations#

Nobody has read the implementation guidance, because it doesn't exist. Agencies have 120 days and the independent review body has 90 (NIH). Everything about how DGOF gets adjudicated in practice — who sits on the board, what evidentiary standard applies, how appeals work — is unwritten. Judgments about how this policy behaves are provisional until roughly mid-November.

"Dangerous" is doing enormous work, and the field is not agreed on it. The ASM, formerly the American Society for Microbiology, said the policy "broadly defines several categories of research that, if shut down, will impede our ability as a nation to address infectious disease threats and respond to future outbreaks." ASM chief strategy officer Allen Segal told CIDRAP that pushing global standards upward is worthwhile, but that domestically "we should be investing in facilities and training to ensure that it is being done safely, rather than taking the risk of prohibiting research to detect, prevent, and treat illness" (CIDRAP; ASM statement). Prohibition has a risk profile of its own, and it is not zero.

The scope is federal funding. Private DGOF-potential research is not covered today. The policy says an interagency working group will "explore" additional regulatory or legislative action to reach privately funded work (CIDRAP).

This is a US policy in a networked world. The US is calling on international partners to adopt matching standards (HHS joint statement), which is a request, not a regime. And the domestic backdrop is not reassuring: measles at a 35-year high, an Ebola outbreak in the DRC approaching the second-largest on record, and roughly 80% of senior CDC leadership positions without permanent officials (Pandora Report, citing The Guardian, Bloomberg and CIDRAP). Rules about research are one input to preparedness. They are not the binding one right now.

FAQs#

Does this ban all gain-of-function research? No. It prohibits federal support for research meeting the policy's DGOF definition, and restricts international research of concern. HHS states the policy preserves development of vaccines, therapeutics, diagnostics and other medical countermeasures under safeguards (HHS).

Is my lab's AI protein-design work now illegal? Not under this policy. Purely computational work, including using computational means to design novel forms of biological agents, is not prohibited unless an entity of concern is involved. If a proposal includes plans to create or modify an agent meeting the DGOF definition based on that computational work, the policy applies (policy text quoted in Nextgov/FCW). Nothing here is legal advice; institutions should wait for agency implementation guidance.

When does it take effect? Agencies have 120 days for implementation guidance and 90 days to establish the review body; already-flagged potential DGOF projects remain paused in the interim (NIH). CIDRAP reports mid-November implementation (CIDRAP).

Does it require screening of synthetic DNA orders? Not this policy. Mandatory nucleic acid synthesis screening is the subject of the June 2026 open letter to Congress and pending legislation (screendna.org).

What is the OSTP group actually empowered to do? The policy says it will convene to monitor advances at the biology–AI intersection, including in-silico research (Nextgov/FCW). Membership, authorities and reporting obligations are not specified in the material available so far.


Sources#

Related observations

Adjacent work from the same lines of enquiry.

Two Doors Into Biology

OpenAI is giving 100,000 academic researchers free frontier model access with 75+ life science skills. Anthropic's newest flagship refuses to explain mitochondria. Both companies claim to be managing the same biosecurity risk — and the gap between their answers tells you how unsettled AI-for-biology governance really is.

The Test Said No, The Sequencing Said Yes

Genome sequencing published this week places the virus behind Central Africa's fastest-growing Ebola outbreak on a distinct branch of the Bundibugyo family tree — with an evolutionary signal nobody expected. Here is what that means for diagnostics built on the wrong prior, and where AI-assisted sequencing genuinely helps.