U.S. Biosecurity: Guarding the Wrong Door While Time is Running Out
In January 2026, three researchers at MIT went shopping. Rey Edison, Shay Toner, and Kevin Esvelt ordered DNA fragments from dozens of commercial gene-synthesis providers, and what arrived on the bench was collectively sufficient to fully reconstruct the 1918 influenza virus. Not one of those orders was illegal or even unusual, and no provider saw the whole picture. That was the point. American select-agent rules cover intact dangerous sequences, and say nothing about the pieces, so the apparent danger was legally disassembled across a market and every piece passed screening. No lab. No license. No flag.
The main screening safeguard on dangerous biology leaves more than one vulnerability. The other tactic is disguise. Reporting in Science, Bruce Wittmann and a Microsoft-led team worked with industry to run proteins of concern through open-source design software and got back redesigned synthetic homologs that kept the folded shape of the original but not its sequence, no longer a risk of setting off alarms during a screen that matches an order against a known list. Disassemble or disguise it, the screen fails either way.
The screening checkpoint is worth defending, and what is happening to it should alarm anyone still reading. The skill barrier to engineering a biothreat is at an all-time low. What took a career to learn now runs on software and ships as mail-order DNA. That is decentralized bioengineering. And counterintuitively, as that barrier lowers the federal money to meet it is falling too. The most recent budget cut biodefense again, even as the defense budget request rises by about a hundred and sixty billion dollars. Money is not the constraint, direction is. The request climbs while the line that would stop a biothreat in the supply chain shrinks, and that gap is a choice not an accident.
When the screen can be picked apart or disguised, the reflex is to harden the checkpoint or move the watch beyond the breach. Movements logged, private life turned into evidence while the pathogen is already in circulation. I have felt that pull. Underneath is the frame behind most security debates, liberty and security as two ends of one dial, every choice reduced to where the pointer should sit. That tradeoff is not a straw man, it is how many converse about hard choices in public policy, and the tension is real. I am convinced the dial is still the wrong instrument, and a dangerous one, because it teaches us to answer fear by turning it, offering our freedoms up as sacrificial lambs for a promise of security that downstream surveillance rarely keeps.
We had a phrase in my unit running route clearance and reconnaissance in Afghanistan. Complacency kills. I suspect most of the people setting U.S. policy have discarded that sentiment, or never needed to learn it entirely. Vigilance is not a posture, it is a skill in reading indicators. A bomb-maker is often missing a finger. The knowledge is gained by working with unforgiving material, the mark is the indicator left on the one who performed it. You do not need their name, their politics, or search history to recognize the work.
Let’s ask the same question of the biothreat and its maker. Where does the work bite back? Not at the bookshelf. Ordering piecewise DNA leaves an invisible footprint, clean and industrial. It bites back in the wet lab, where making the material fold, express, and function in a living cell is still a craft learned by failing. Decentralized bioengineering cuts both ways. None of what made the pieces easy to get makes the assembly any simpler. The toll comes in failed runs, ruined reagents, and accidents kept quiet. Keeping things quiet is work too, and it often perturbs through the same supply chain as everything else.
The detection apparatus already exists, on paper. Open the 2024 OSTP screening framework and turn to the provisions still set to take effect on October 13, 2026. Providers will have to shrink the screening window from 200 nucleotides to 50 by then. They should catch shorter sequences ordered by one customer over time that could be assembled into something dangerous. And the definition of a sequence of concern would widen to include anything pathogenic or toxic, regulated agent or not. Esvelt’s loophole, closed. Wittmann’s loophole, closed. The repair was drafted before either was published, and since spring 2025 the only thing that has moved toward October is the calendar.
That 2024 OSTP screening framework remains on the books, but revision was ordered and never delivered. Executive Order 14292, signed in May 2025, ordered the framework revised or replaced within ninety days. That deadline passed in the summer of 2025. Now fifteen months after the order, no replacement has appeared. We are guarding the wrong door while gene parts roll through the one left open. The upgrade advances on the calendar while the document that carries it waits for a revision that never came.
Further confounding matters, the Biosecurity Modernization and Innovation Act introduced in January 2026, stalled in the Senate Commerce Committee without a markup or vote. Cotton and Klobuchar sponsored it, with the biosecurity field and industry already having endorsed it. Nothing is blocking it. That is the strongest evidence for complacency in this piece, and the proposed bill got closer than anything before it. It would mandate screening by regulation, customer verification, and split-order detection across providers. That last part closes the fragment loophole directly. However, on sequences redesigned to evade a list-based screen, it only directs NIST to research and prototype function-based models, not to require their use in provider screening.
The fix is unglamorous and already drawn up, and its virtue is that it screens the people placing orders rather than the population. It is not free. Tighter screening will snag legitimate research and slow the supply chain in ways open science rightly resists. Marginal friction in the lab against a meaningful gain where the threat actually enters. Is that trade-off worth it? Put that question to the taxpayer and not the grant holder, the deliberation quickly becomes an exercise in futility. These are reasons to build it carefully, not to skip it. When the fix goes unbuilt, the pressure continues to build. It waits for the next scare and comes back as something far more expensive. U.S. biosecurity is bogged down in bureaucratic sludge. The fix is drawn up, and the calendar moves. The machinery does not.
There will be another serious biological scare, and it will produce enormous pressure to do something sweeping and visible such as increased monitoring of the population and opening our private lives to invasive government inspection, because surveillance feels like control. It costs the most freedom, catches the fewest real threats, and pulls money from the work that actually protects people. Install the framework before the date we ourselves set, and none of that is necessary. Miss it, and the next crisis will not come through the door we are watching. Remember, we are not the only ones keeping watch. Bad actors stare vigilantly at the holes in our defenses, regardless of why those vulnerabilities exist and which direction political blame will be hurled afterwards.
The deadline to fix all this lapsed last year. Researchers at RAND found that as general-purpose AI and biological design tools converge, the skill-barrier for pathogen construction continues to fall while actionable mitigations remain underdeveloped. As laid out here, little has changed since their 2025 assessment. Complacency is ultimately why we are deferring biothreat safeguards to private vendors in the hopes that they police themselves, as though shareholder interest and national security are always aligned. They are not. Give a gene-synthesis company door A and door B where A has reduced costs while B is safer for the public. We can no longer act surprised when a profit-maximization machine does exactly what it was built to do and walks through door A.