The Uncleared Lab
We Vet the People Who Touch Nuclear Secrets and the People Who Guard Cash. We Do Not Vet the People Building the Tools of the Next Pandemic. Full Synthetic Biology: Risks and Benefits. Part III.
Bottom Line Up Front
In 2025 the United States put into effect a new framework for overseeing the most dangerous biological research. It is a serious document, and it does something important. It also reveals, by omission, the hole this piece is about. The policy scrutinizes the experiment. It says almost nothing about the experimenter.
We have decided, as a matter of national practice, that a person who handles Restricted Data about nuclear weapons must pass a Single Scope Background Investigation and submit to continuous evaluation for the rest of their career. A person who drives an armored truck full of cash is bonded and screened. A person who can now, with a modest budget and a benchtop machine, work at the frontier of engineering biology needs, in the overwhelming majority of cases, no security vetting of any kind. The one federal program that does vet people, the Select Agent Program, covers a fixed list of roughly sixty-five already-known agents and screens against a criminal and terrorism checklist, not the deeper investigation a clearance requires. Everything novel, everything synthetic, everything an artificial intelligence might design tomorrow, falls outside it.
This is the argument no one in academia wants to have, so I will make it plainly, and I will make the case against myself first and at full strength. My judgments, with confidence levels:
I. The Experiment We Vet, and the Experimenter We Do Not
Start with what the government actually built, because it is instructive.
The 2024 United States Government Policy for Oversight of Dual Use Research of Concern and Pathogens with Enhanced Pandemic Potential, which took effect in 2025, consolidated a patchwork of earlier rules into a single system [1]. Institutions that take federal research money must now stand up an Institutional Review Entity, identify research that meets the definitions of dual-use concern or enhanced pandemic potential, and obtain federal approval of a risk-benefit assessment and mitigation plan before the work proceeds [1][2]. This is real oversight, and it is a genuine improvement.
Read it closely and the design choice is unmistakable. The policy reviews activities. It asks whether a proposed experiment crosses a line, and if so, how to mitigate it. It does not vet the individuals who will do the work [1]. The same is true across the landscape. The dual-use framework governs the research. Institutional biosafety committees govern the protocol. Synthesis screening, the subject of Part II, governs the DNA. Nowhere in that stack is there a systematic answer to a simpler question: should this particular person be trusted with this particular capability. Assessed with high confidence, about 85 out of 100, because it is a matter of public record: the United States has no personnel-security regime for high-consequence life-science work outside one narrow program.
II. What We Already Do, and How Little It Covers
We are not starting from nothing, and honesty requires saying so.
The Federal Select Agent Program does vet people. Anyone seeking access to a select agent, the enumerated pathogens and toxins the government deems most dangerous, must undergo a Security Risk Assessment conducted by the FBI’s Bioterrorism Risk Assessment Group [3]. The assessment identifies “restricted persons” barred from access under the statute that grew out of the USA PATRIOT Act: felons, fugitives, unlawful drug users, certain aliens, people adjudicated mentally defective, nationals of designated state sponsors of terrorism, the dishonorably discharged, and members of designated terrorist organizations [3][4]. It is a real gate, and it has value.
But look at what it is and what it is not. It is keyed to a list. The select-agent list enumerates roughly sixty-five specific, already-known agents [3]. A researcher building a novel construct that is not on the list, assembling a pathogen from synthetic fragments, engineering a benign-looking organism toward harm, or training the next protein-design model, is very often not working with a select agent at all, and the vetting never triggers. And even where it does trigger, it is a background check against a criminal and terrorism checklist, not the financial history, foreign-contact review, and lifelong continuous evaluation that a Department of Energy Q clearance entails under its personnel-security rules [5]. We have, in other words, a shallow gate around a small and static yard, while the capability has walked out into the open field. Meanwhile the field itself is scaling: there are now sixty-nine maximum-containment BSL-4 laboratories operating, under construction, or planned across twenty-seven countries, up from fifty-nine in 2021, and the Global BioLabs survey found that biosecurity governance lags well behind biosafety, with oversight of dual-use research the single weakest component [6]. The yard is growing. The gate is not.
It is not that the government cannot build screening infrastructure around research. It already has. Under a national security memorandum issued in 2021, federally funded institutions must run research-security programs that screen for undisclosed foreign affiliations and participation in foreign talent-recruitment programs [18]. The machinery exists. It is simply aimed at foreign interference and financial disclosure, not at whether a given individual should be trusted with catastrophic biological capability. We built the apparatus and pointed it elsewhere.
III. The Insider Is Not Hypothetical
The objection forms immediately: this is a solution in search of a problem, because the threat is foreign and external, not the vetted researcher at the bench. The historical record does not support that comfort.
The worst biological attack in American history came from inside. The FBI concluded that the 2001 anthrax letters, which killed five people and shut down parts of the federal government, were sent by Bruce Ivins, a vaccine researcher at the Army’s own biodefense laboratory at Fort Detrick, a man with legitimate access to the material and the trust of his institution [7]. I state the FBI’s conclusion as exactly that. Ivins died in 2008 before charges were filed, a subsequent National Academies review found the scientific evidence did not definitively establish that his flask was the source, and the case remains contested [8]. Personally, I do not believe that Dr. Ivins was involved in the Anthrax attacks and agree with the National Academies findings. That uncertainty does not weaken the lesson. It sharpens it. The person the entire system was built to trust was, on the government’s own finding, the threat, and the vetting he had already passed did not stop the domestic terrorists.
That cuts against my argument as much as for it, and I will not hide from it. If Ivins was cleared and still did it, vetting is no guarantee. Correct. The conclusion is not that personnel security is futile. It is that a one-time entry check is the wrong model. What catches the insider is continuous evaluation, behavioral monitoring, and a culture that treats warning signs as reportable rather than private, which is precisely what the nuclear complex learned to build after its own failures and what the life sciences have never had. Aum Shinrikyo, which pursued biological weapons before turning to sarin, is the external-actor reminder that the intent is real. Amerithrax is the reminder that the dangerous person can already be inside the building, holding a badge.
IV. The Strongest Case Against Me
Now the argument I respect most, stated without a straw man, because if I cannot beat it honestly I should not be making the case at all.
Openness is not a weakness of American science. It is the source of its supremacy.
The United States leads biology because talent flows here from everywhere, because results are published rather than buried, and because a graduate student with an idea can pursue it without asking permission from a security officer. A large share of the researchers who built American biotechnology were foreign-born, and a personnel-security regime is, unavoidably, a mechanism that treats the foreign-born with suspicion. Clearances are slow, expensive, and exclusionary. They are often abused for political ends, as the history of loyalty investigations in this country shows in ugly detail. Impose them on the life sciences and you risk three separate harms at once: driving the best work to more permissive countries, deterring the immigrant talent that is a national asset, and building an apparatus that a future administration could turn against dissenting scientists. Add to this that the field has a proud tradition of governing itself. At Asilomar in 1975, molecular biologists voluntarily paused recombinant DNA work and wrote their own safety rules [12], and the mirror-life scientists did the same in our own decade [9]. Perhaps self-governance, not clearance, is the American way to handle this.
I hold this counterargument at real weight. It is why the recommendation that follows is a scalpel and not a hammer.
V. Why the Counterargument Narrows the Case Rather Than Defeating It
Here is where I think the openness argument, powerful as it is, proves less than it claims.
It proves that a blanket clearance regime for the life sciences would be a catastrophe. It does not prove that the status quo, in which almost no one doing frontier work is vetted at all, is correct. Those are different claims, and the space between them is exactly where policy should live. The openness case was formed in a world where the barrier to catastrophic biology was tacit skill, scarce materials, and years of institutional apprenticeship. That world is ending. The design tools are diffusing, the synthesis of physical DNA is cheap and global, and the capability that once required a state program is migrating toward a well-resourced individual. When the barrier was high, openness was nearly free, because most people simply could not do the dangerous thing. As the barrier falls, the same openness carries a rising cost, and pretending otherwise is not principled, it is nostalgic.
The mirror-life episode, which I keep returning to, is the tell. When the stakes became existential, the field’s own leaders concluded that some work should not be done and asked funders to refuse it [9]. They drew a line around an activity. My claim is only that the same logic extends from the activity to the person: for the narrow set of work whose misuse would be catastrophic, it is not enough to approve the experiment, you must also be able to trust the hand that runs it. That is not McCarthyism. It is the same judgment we make, without controversy, for the people who guard warheads and the people who audit banks. The life sciences have been treated as an exception, and the exception is expiring. Assessed with moderate to high confidence, about 80 out of 100.
VI. What a Tiered Regime Would Actually Look Like
The counterargument dictates the design. The goal is to secure the narrow top of the risk distribution while leaving the broad base untouched, and to do it in a way that is hard to abuse.
Key the vetting to capability, not to a static list. The select-agent model fails because it enumerates yesterday’s agents. A modern regime should trigger on the consequence of the work, using thresholds the field can already articulate: research that would enhance the transmissibility or lethality of a pandemic-capable pathogen, that would reconstitute or construct a self-propagating agent from synthetic parts, or that would build or operate the most capable biological design tools. The National Academies named these categories of concern years ago, extending the Fink report’s original list of experiments of concern [10][11]. Most research touches none of them and should see no security officer at all.
For that narrow set, and only for it, require a personnel-security tier modeled on what already works elsewhere: an investigation deeper than the select-agent checklist, continuous evaluation rather than a one-time gate, insider-threat awareness of the kind the nuclear complex runs, and a foreign-influence review that is about specific hostile-state ties rather than national origin as such. Make it a condition of federal funding and of operating the highest-containment work, which is the same lever the dual-use policy and the synthesis-screening framework already use. And because this apparatus is genuinely dangerous to civil liberties, build the safeguards in from the start: narrow and published triggers, due-process rights to see and rebut adverse information, an appeals channel, sunset and reauthorization so it cannot quietly metastasize, and a firewall against using it to police the content of anyone’s science or speech. A regime that cannot be abused is impossible. A regime designed to make abuse difficult and visible is not.
There is a benefit here that the openness camp undersells. A credible personnel-security floor is what would let the United States keep doing the most sensitive work at home, under trust, rather than banning it outright or watching it migrate. Security is not only a restriction on ambitious science. For the most consequential experiments, it is the precondition for being allowed to do them at all. I hold the design at about 65 out of 100, lower than my confidence in the problem, because the implementation is hard and the potential for abuse is real, and both deserve more humility than advocates usually grant.
VII. Red Team
The attacks worth taking seriously. First, this will offshore the work, and a determined actor will simply operate from a jurisdiction with no vetting. Partly true, which is why personnel security is worthless without the international coordination and leadership arguments from earlier in this series; it is one layer, not a wall. Second, it will discriminate against foreign-born scientists and reads as xenophobia. This is the gravest risk, and the only honest answer is that the design must target specific hostile-state relationships and behavior, not nationality, and must be audited for disparate impact, because a regime that becomes a loyalty test for immigrants would deserve to fail. Third, Amerithrax proves vetting does not work. It proves entry checks do not work, which is why the model here is continuous evaluation, not a single gate. Fourth, this chills the openness that is our advantage. It would, if applied broadly, which is why it must be applied narrowly, to a set of experiments small enough that the median biologist never encounters it.
The unknowns are substantial and I will not paper over them. I do not know whether a capability-keyed trigger can be written precisely enough to avoid both over- and under-inclusion, though the dual-use policy suggests it is possible. I do not know whether the political system can build an intrusive security apparatus and keep it narrow, given how rarely it has. And I do not know the true insider base rate, because the sample is mercifully small. What I do know is that we have built our biosecurity around the experiment and the material while leaving the person unexamined, that the capability which made that acceptable is eroding, and that we vet the guard at the bank more carefully than the scientist who could seed a pandemic. That asymmetry is not a principle. It is an accident of history that we have not yet had the discomfort to correct.
I expect disagreement, much of it sincere and some of it from people I respect. Bring it. This is the argument the field has been avoiding, and avoidance is not a strategy.
References
1. Office of Science and Technology Policy. “United States Government Policy for Oversight of Dual Use Research of Concern and Pathogens with Enhanced Pandemic Potential,” May 2024 (effective 2025). https://aspr.hhs.gov/S3/Documents/USG-Policy-for-Oversight-of-DURC-and-PEPP-May2024-508.pdf
2. “Implementation Guidance for the United States Government Policy for Oversight of DURC and PEPP,” 2024. https://osp.od.nih.gov/policies/biosafety-and-biosecurity-policy/
3. Federal Select Agent Program. “Security Risk Assessments.” https://www.selectagents.gov/compliance/risk.htm
4. Federal Bureau of Investigation. “Bioterrorism Risk Assessment Group” (restricted persons under 18 U.S.C. 175b). https://www.fbi.gov/investigate/terrorism/bioterrorism-risk-assessment-group
5. U.S. Department of Energy. “Personnel Security” (10 CFR Part 710; Q and L access authorizations). https://www.energy.gov/ehss/personnel-security
6. Global BioLabs. “Global BioLabs Report 2023” (Koblentz and Kaunert, King’s College London). https://www.kcl.ac.uk/warstudies/assets/global-biolabs-report-2023.pdf
7. U.S. Department of Justice. “Amerithrax Investigative Summary,” February 19, 2010. https://www.justice.gov/archive/amerithrax/docs/amx-investigative-summary.pdf
8. National Research Council. “Review of the Scientific Approaches Used During the FBI’s Investigation of the 2001 Anthrax Letters,” 2011. https://www.nationalacademies.org/our-work/review-of-the-scientific-approaches-used-during-the-fbis-investigation-of-the-2001-anthrax-letters
9. Adamala KP, et al. “Confronting risks of mirror life.” Science, December 12, 2024. https://doi.org/10.1126/science.ads9158
10. National Academies of Sciences, Engineering, and Medicine. Biodefense in the Age of Synthetic Biology. 2018. https://doi.org/10.17226/24890
11. National Research Council. Biotechnology Research in an Age of Terrorism (the Fink Report). 2004. https://doi.org/10.17226/10827
12. Berg P, et al. “Summary statement of the Asilomar Conference on Recombinant DNA Molecules.” PNAS, 1975. https://www.pnas.org/doi/10.1073/pnas.72.6.1981
13. Sandbrink JB. “Artificial intelligence and biological misuse: Differentiating risks of language models and biological design tools.” arXiv:2306.13952, 2023. https://arxiv.org/abs/2306.13952
14. Executive Order 14292, “Improving the Safety and Security of Biological Research,” May 5, 2025. https://www.federalregister.gov/documents/2025/05/08/2025-08266/improving-the-safety-and-security-of-biological-research
15. Wittmann B, et al. (senior author Horvitz E). “Strengthening nucleic acid biosecurity screening against generative protein design tools.” Science, October 2, 2025. https://www.microsoft.com/en-us/research/publication/strengthening-nucleic-acid-biosecurity-screening-against-generative-protein-design-tools/
16. Carter SR, Wheeler N, et al. “The Convergence of Artificial Intelligence and the Life Sciences.” NTI, 2023. https://www.nti.org/analysis/articles/the-convergence-of-artificial-intelligence-and-the-life-sciences/
17. Tucker JB (ed.). Innovation, Dual Use, and Security. MIT Press, 2012. https://mitpress.mit.edu/9780262516952/innovation-dual-use-and-security/
18. National Science and Technology Council. “Guidance for Implementing National Security Presidential Memorandum 33 (NSPM-33) on National Security Strategy for United States Government-Supported Research and Development,” January 2022. https://bidenwhitehouse.archives.gov/wp-content/uploads/2022/01/010422-NSPM-33-Implementation-Guidance.pdf
Next in this series: the race we cannot afford to lose. Adversary capability, export controls, and what it actually means for the United States to lead.






Shalom Dr. Huff,
Respect to true whistleblowers vs pleaing the thers. I think it's an honor your na m e is attached @ #17 to the upcoming audit peace accords in Geneva at this time. We don't anticipate any former EcoHealth personnel having to go to Congress like Fauci. Keep praying the admissions are enough.
https://WHOtoSTOP.org
Nice paper
Thank you