Old version — revision 1
This is a fixed snapshot of Dual-use research of concern, saved by Import as part of the initial corpus import. It is not edited and it is not updated; the article may have changed since.
Edit summary: Initial import of content/dual-use-research.md — the filesystem corpus, unchanged. Not an edit.
Life-science research that produces knowledge or tools with legitimate purposes but foreseeable potential for catastrophic misuse, and the oversight regimes built around it.
Dual-use research of concern, or DURC, is life-science research conducted for legitimate purposes that could reasonably be anticipated to yield knowledge, methods, or materials directly applicable to causing large-scale harm. The category was formalised in US policy in the 2000s, following a National Research Council report that identified a short list of experiments of concern,1 and covers a narrow slice of biology — work that increases a pathogen's transmissibility, virulence, host range, or resistance to countermeasures, or that renders a dangerous agent easier to produce. It is the clearest case in which the same result is both a public good and a hazard, and it has no solution, only trade-offs.
Biological risk differs from other technological risk in three ways that shape the governance problem.
Information is the weapon. A method published in a journal cannot be recalled, is available identically to everyone who reads it, and does not degrade. The barrier to misuse is tacit skill and materials rather than knowledge, and both barriers have fallen.
Capability is dual by construction. Understanding what makes an influenza virus transmissible between mammals is the same knowledge that would allow one to be made transmissible. Surveillance, vaccine design, and countermeasure development all require it. There is no version of the research that produces only the defensive half.
Self-replication. Unlike chemical or radiological agents, a pathogen released once can propagate beyond the point of release. This is why biological risk features in the taxonomies discussed under Existential risk and why engineered pandemics are usually named as the most plausible near-term route to a global catastrophe. The same property drives concern about the self-spreading constructs described in Gene drives and about the chirally inverted organisms in Mirror life, and it is what distinguished real biological hazard from the self-replicating machines imagined in Grey goo, which never existed.
Nick Bostrom's typology of information hazards supplies the vocabulary the field now uses: the harm can come from the specific data, from the demonstration that something is possible, or merely from directing attention to a vulnerability.2
The 2011 episode is the field's reference case because it exposed every unresolved question at once: whether a journal should publish methods, who decides, whether redaction is feasible when dozens of laboratories can reproduce the work, and whether a voluntary moratorium accomplishes anything beyond delay. The papers were published, no misuse followed, and both camps regard this as confirming their position.
Assessing how likely deliberate misuse is requires separating three questions that are routinely merged.
Capability has clearly increased. Gene synthesis is a commercial service; sequences for most known pathogens are in public databases; the reverse-genetics methods for reconstructing RNA viruses are taught in graduate programmes, and the editing tools described in CRISPR–Cas9 made targeted modification of a genome a routine laboratory operation. The whole-genome construction methods surveyed in Synthetic genomes were developed for microbial engineering and apply without modification to viral genomes. The 2018 horsepox work was performed by a small academic team at a reported cost of about a hundred thousand dollars.
Intent is the term with the least evidence behind it. Historical bioweapons programmes were state-run, expensive, and largely unsuccessful at producing usable weapons; the small number of non-state attempts caused limited casualties. There is no observed case of a modern actor using published dual-use research to cause mass harm. Analysts disagree sharply about whether this reflects a genuine difficulty or a period of good fortune.
Accident is the neglected term and the one with a documented record. Laboratory-acquired infections and containment failures have occurred repeatedly in high-containment facilities across multiple countries, including with smallpox and with influenza strains. Any assessment of research risk that considers only malice omits the more frequent pathway.
What the debate cannot resolveThe costs of restricting research are diffuse and counterfactual — vaccines not developed, variants not anticipated — while the benefits are also counterfactual. Neither side can produce the comparison that would settle the question, which is why two decades of argument have not converged.
The newest input is machine learning, and it has changed the analysis in a specific way rather than a general one.
A 2022 paper reported that a drug-discovery model built to avoid toxicity could be inverted to seek it, generating tens of thousands of candidate toxic molecules in under six hours.3 The molecules were never synthesised, and synthesis remains the hard step, but the demonstration reframed the bottleneck: design is no longer scarce.
Protein design models raise a sharper version. In 2025 researchers reported that AI-generated variants of known toxin sequences could evade the sequence-screening software used by commercial DNA synthesis providers, with patches developed and distributed before publication. The episode is notable less for the vulnerability than for the response, which followed a coordinated-disclosure model borrowed from computer security and is the first such process in biosecurity.
Frontier AI developers began applying elevated deployment safeguards to their models on biological-weapons-relevant capability grounds from 2025, and biosecurity evaluations are now a standard component of frontier model assessment. Whether the safeguards constrain a determined user or merely raise the effort required is not publicly established, and the same models are available in open-weight form from other developers without comparable restrictions. Artificial general intelligence treats the broader capability question.
Controls operate at four points, and their effectiveness declines as one moves down the list.
Physical containment — biosafety levels, negative pressure, personnel training — is mature, well specified, and addresses accidents rather than misuse. Genetic containment is the newer variant: the synthetic auxotrophy built into the strains described in Genetic code expansion and recoding makes an escaped organism unable to survive outside a supplemented medium, which is a stronger guarantee than a physical barrier and applies only to engineered organisms rather than to natural pathogens.
Synthesis screening is the most-discussed intervention. Members of the International Gene Synthesis Consortium, formed in 2009, screen order sequences against lists of agents of concern and verify customer legitimacy. Coverage is voluntary and incomplete, the screening is defeatable by ordering fragments from multiple providers, and benchtop synthesisers distribute the capability to sites that no consortium reaches. The US required screening for federally funded work under a 2023 executive order that was revoked in January 2025, leaving the status of the associated framework unclear as of 2026.
Funding-stage review allows a funder to decline work before it is done, which is the only intervention that acts before the information exists. The US paused federal funding for certain gain-of-function influenza and coronavirus work from 2014 to 2017, replaced the pause with a review framework, and in 2024 issued a unified policy covering both DURC and research on pathogens with enhanced pandemic potential. An executive order in May 2025 further restricted federal support for dangerous gain-of-function research. All of this binds federally funded work in one country.
Publication review is the last line and the weakest. Journals have no investigative capacity, editors are not biosecurity analysts, and by the time a manuscript is submitted the work has been done and discussed at conferences.
The Biological Weapons Convention, in force since 1975, prohibits development, production, and stockpiling of biological weapons and has near-universal membership. It has no verification mechanism: negotiations on a compliance protocol collapsed in 2001 and have not been revived. Its implementation support unit is very small. There is no international body that inspects laboratories, no reporting obligation for dual-use experiments, and no forum with authority to stop a specific project.
What exists instead is national policy of varying rigour, institutional review committees, and the professional norms inherited from the Asilomar Conference on Recombinant DNA — a model whose limits were demonstrated in the He Jiankui affair and which assumes the relevant actors care about standing among peers. The same structural weakness runs through Governance of human genome editing: the enforceable layer is domestic law, and it reaches only those who submit to it.
The field's characteristic policy proposal is not prohibition but sequencing. Differential technological development argues for advancing detection, countermeasures, and protective capability ahead of the research that creates the hazard, which avoids the objection that a blanket Precautionary principle would also block the work needed to respond to natural outbreaks.
The open problem is what happens as the capability distributes. The controls described above are designed for a world in which dangerous work requires institutional resources: a laboratory, a funder, a supplier. Benchtop synthesis, contract research organisations, and design tools that run on a laptop each erode that assumption. The proposals for what replaces it — from licensing of synthesis equipment to the surveillance architectures contemplated in the vulnerable-world literature — are either insufficient or, as their own authors concede, worse than the problem.
reportNational Research Council. Biotechnology Research in an Age of Terrorism. National Academies Press, 2004.↩The source of the original list of experiments of concern; it is advice to US policymakers and carried no legal force of its own.
paperBostrom, N. "Information Hazards: A Typology of Potential Harms from Knowledge." Review of Contemporary Philosophy, 2011. ↩
paperUrbina, F., Lentzos, F., Invernizzi, C., Ekins, S. "Dual use of artificial-intelligence-powered drug discovery." Nature Machine Intelligence, 2022.↩None of the generated molecules were synthesised or assayed, so the paper reports a design capability rather than demonstrated toxicity.