I’m starting a large biosecurity research program that I’ll write about here soon that combines human subjects research, AI development and engineering, and policy. I’ve never had any formal training or experience in biotechnology policy, but after spending some time at last weekend’s Global Challenges Project biosecurity meeting and meeting with NSCEB this week I’m starting to really try to connect the technical work we’re doing here with what could be tangible policy recommendations and action. After all, we can publish all the whitepapers and journal articles we want, but if it never has a real-world impact and doesn’t move the needle on biosecurity and AI safety policy, you’d be correct to question the value of doing the research in the first place. Thankfully, I have really stellar partners in our National Security Data and Policy Institute who are close collaborators with me and my colleagues here in SDS on this project. More soon, I promise.
There was a story in Politico this week reporting that OpenAI endorsed a set of bills in response to AI biothreats. All of them came out of the recommendations from last year’s final report from the National Security Commission on Emerging Biotechnology (NSCEB). They were written in part to fix a data problem: biological data sits in incompatible formats across dozens of repositories, and getting it into shape for AI training takes months of work per project.
Here are the three bills in question:
SCALE Biology would create a biometrology program at NIST, authorized at $55M in FY2026 rising to $85M by FY2030, covering measurement standards for engineering biology and biomanufacturing. Biorisk, biosafety, and biosecurity standards are item (E) in a 9-item list of program activities.
(c) Activities.—In carrying out the biometrology laboratory program, the Director shall carry out the following:
[…]
(E) The development of technical standards, guidelines, best practices, methodologies, procedures, and processes that can inform and address biorisk, biosafety, and biosecurity concerns.
The AI-Ready Bio-Data Standards Act gives NIST two years to define what “AI-ready” means for a biological dataset (See also: NSF 26-512) and to set minimum requirements for federally funded research that generates biological data, instructing that those requirements not exceed the resources grantees actually have.
(ii) REQUIREMENTS FOR DEFINITION OF ARTIFICIAL INTELLIGENCE-READY.—
(I) IN GENERAL.—In facilitating the establishment of the definition of the term “artificial intelligence-ready” under clause (i)(I), the Director shall take such actions as may be necessary to ensure such definition, when applied to a biological dataset, requires such dataset be generated and formatted in a manner that—
(aa) enables the effective use of the dataset for training artificial intelligence models; and
(bb) supports advancements in research relating to artificial intelligence and biotechnology.
The Web of Biological Data Act has DOE competitively award a national lab the job of building a single entry point to federal biological data.
(2) CONTENTS.—The Web shall—
(A) serve as a single point of entry for researchers to access different sources of biological data, especially those funded by the Federal Government, by directly hosting data or providing access to existing databases;
(B) have metrics and metadata to indicate data quality, including usability, interoperability, and completeness; and
(C) include tiered levels of cybersecurity safeguards and access controls to protect different types of biological data assets hosted in or connected to the Web.
Richard Johnson, who runs national security risk mitigation at OpenAI, said that data and standards are prerequisites for measuring how model capability bears on biosecurity.
We need to be worried both about the safety and the risk side, but we also need to be looking at the opportunities for getting the tools into the hands of the defenders.
A single well-documented entry point to federal biological data helps everyone, including the foreign actors Anthropic caught using its models for pathogen work this year.
The Web of Biological Data bill requires tiered cybersecurity safeguards and access controls scaled to data sensitivity, an independent assessment of those controls every two years, and an advisory board with at least one biosecurity expert. It doesn’t say how a dataset gets assigned to a tier.
Caitlin Frazer, executive director of the National Security Commission on Emerging Biotechnology (a congressionally established body that is also supporting the bills) also provided commentary for the article.
High-quality, AI-ready biological data must be treated like a strategic national resource.
It absolutely must be. I couldn’t agree more.




