Safety3 min read

Google DeepMind Builds Program to Stop AI Biology Misuse

July 16, 2026Synthesized from 1 source: AI News

Google DeepMind and Isomorphic Labs have published details of a joint effort to prevent AI tools from being used to design biological threats, while using the same tools to speed up outbreak response, and the underlying problem they are trying to solve is more serious than the announcement makes it sound.

Google DeepMind and its drug-discovery sister company Isomorphic Labs published details this week of a joint biosecurity program they have been building for about a year. More than 15 partnerships with government bodies, research institutes, and biosecurity organisations are now part of the structure.

The program is built around three goals: prevent AI tools from being used to design biological threats, detect outbreaks faster, and accelerate the response once something is identified. That framing sounds tidy, but the underlying problem is considerably messier.

AI systems trained on biology data are very good at biology. The same model that helps a pharmaceutical researcher identify how a virus protein is shaped can, in principle, help someone with harmful intentions close gaps in their knowledge. This is not a theoretical concern. A study published in Science in late 2025 tested whether AI-designed toxin variants could get past the screening checks that DNA synthesis companies use before shipping out genetic material. The screening software missed more than 75% of the AI-designed variants, because those variants did not resemble the known dangerous sequences in the company databases closely enough to trigger an alert.

DeepMind points to this exact problem in its announcement and says it is working on adapting SynthID, its existing technology for marking AI-generated content, to work on biological sequences. That work is described as exploratory, not something available today. A longer-term goal involves screening that assesses what a DNA sequence does, rather than just what it looks like, which would close the gap the 2025 study exposed. That kind of screening does not yet exist at scale.

The detection side of the program leans on a technique called metagenomic sequencing, which identifies every microorganism in a sample rather than checking for a preset list of known threats. Think of it as a full sweep rather than a targeted search. The barrier is cost, and the regions where outbreaks tend to start are often the regions least able to afford the equipment.

On outbreak response, the program's most concrete piece is a new dedicated unit inside Isomorphic Labs. That unit is designed to deploy Isomorphic's drug design engine quickly when a new pathogen emerges, working with government labs to develop potential treatments and diagnostics faster than traditional timelines allow. Isomorphic raised $600 million in external funding in 2025 and has pharmaceutical partnerships with companies including Novartis and Eli Lilly, so this is not a startup running on paper commitments.

AlphaFold, the protein-mapping tool DeepMind released several years ago, has already been cited in more than 10,000 research publications on infectious disease, covering work on tuberculosis, malaria, Mpox, and Nipah. A partnership with Lawrence Livermore National Laboratory will use the newest version of AlphaFold for broad-spectrum antibody design, including work on a class of viruses that includes Ebola.

The honest part of DeepMind's announcement is what it does not claim. The safety filters, the classifiers that flag suspicious queries in real time, the controls built into Gemini to refuse harmful biology questions: DeepMind describes all of these as ongoing work, not solved problems. A filter trained against known attack patterns in a controlled test is not guaranteed to catch new attack methods in the real world, and the company does not pretend otherwise.

That matters for any organisation in a regulated sector, from insurance to pharmaceuticals to government procurement, that is evaluating AI tools and being told the safety measures are in place. Safety measures in AI biology are real but incomplete, and the gap between a controlled evaluation and live adversarial use is not small.

The policy picture in the United States adds another layer of uncertainty. DeepMind has put forward recommendations to US lawmakers, tied to specific pending legislation on biosecurity and DNA screening standards. None of that legislation has passed. The regulatory framework for AI and biology in most countries is behind the technology by a meaningful distance, and the companies building the tools are, for now, also the ones setting most of the standards.

Stay informed

Get AI intelligence like this delivered to your inbox.


You May Also Find Valuable