\n\n

The global biotechnology landscape is evolving at an unprecedented speed, driven by advances in synthetic biology and genome editing, which, coupled with AI, make biotechnology stand at the forefront of innovation.  These developments offer unprecedented opportunities for advancing health and protecting against biological threats, but also make biotechnological misuse faster, cheaper, and more accessible.  For that reason, the European Commission has proposed the introduction of a new Union-level framework on biodefence and the prevention of biotechnology misuse in the European Biotech Act (the “Biotech Act”).

This framework comprises:

  • Operational controls on Biotechnology Products of Concern (“BPoCs”), which impose screening, reporting, and compliance obligations on economic operators and online marketplaces making such products available on the Union market or to users outside the Union; and
  • Union‑level monitoring of “biological systemic risks,” including risks associated with advanced AI models used in biological applications.

These provisions create direct obligations for gene synthesis providers, laboratory equipment manufacturers, research institutions, academics, and online marketplace operators.  They may also affect downstream users of BPoCs, including companies active in biotechnology, pharmaceuticals, agriculture, food, feed, and AI-enabled biological applications.

1. Prevention of Biotechnology Misuse

a) “Biotechnology Products of Concern”

Article 2(1)(23) of the Biotech Act defines BPoCs as “any good, service or technology, including software resulting from the application of science and technology to living organisms, their parts, products or models with significant potential for biological misuse […], including any thresholds or exclusions.”  Annex I currently identifies two categories of BPoCs:

                                                              i.      Benchtop Nucleic Acid Synthesis Devices

These are instruments capable of producing DNA, RNA, or related nucleic acids directly in a laboratory.  Because such devices can be used to manufacture genetic material from high‑risk pathogens, the Biotech Act would require them to include automated mechanisms that screen user‑submitted sequences against “sequences of concern.”  

The Biotech Act would also require that any screening database embedded in the device be protected so that it cannot be extracted, copied, or repurposed.  For example, a desktop DNA printer used in a university lab must automatically check whether a user is attempting to synthesize a fragment of a virus listed on international control lists.

                                                              ii.     Sequences of Concern

This category covers synthetic DNA, RNA, or amino‑acid sequences that pose elevated biological risks.  A sequence falls within scope if it meets one or more technical (i.e., minimum length of the nucleotides or the amino acids) and risk criteria:

  • Matching sequences from internationally recognized control lists for harmful agents: This includes sequences that are an exact or best match to genetic material from viruses or bacteria listed under international export‑control regimes.  This may include sequences associated with controlled viruses, bacteria, or other biological agents appearing on internationally recognized control lists.
  • Sequences reasonably expected to increase pathogenicity or toxicity: This relates to sequences, for which scientific evidence or industry best practice indicates that they could increase a biological agent’s pathogenicity, toxicity, or other harmful properties (e.g., a synthetic gene designed to enhance viral replication efficiency).
  • Sequences that, if assembled across multiple orders, could yield hazardous capabilities: If a customer orders multiple fragments that, when combined, could form a sequence meeting the above criteria, the fragments are treated as a sequence of concern.  This applies even when the fragments are ordered separately over a 12‑month period. 

The Commission would be empowered to review and amend Annex I, including adding, removing, or modifying categories of BPoCs.  Updates may reflect new scientific evidence, emerging biosafety or biosecurity risks, observed patterns of misuse, or changes in relevant international standards and control lists.  As currently drafted, the framework does not appear to extend to the mere access to or use of sequences of concern as such, although further biosecurity measures in this area could emerge over time.

b) Obligations of Economic Operators and Online Marketplaces

                                                              i.      Transaction Screening and Verification

The core obligation for economic operators providing BPoCs would be to verify that recipients have a “legitimate need” before making the products available. 

The Biotech Act frames this as a three‑part assessment: the intended use must (i) serve legitimate and peaceful purposes, (ii) be carried out by a legitimate member of the scientific community or a legitimate enterprise, and (iii) comply with applicable international treaties, laws, standards, and oversight requirements.

In practice, operators would need to review all relevant information about the customer and the transaction, including the recipient’s identity, institutional affiliation, professional capacity, the stated end use, and any required authorisations or biosafety approvals.  The depth of this verification would need to be proportionate to the nature of the BPoC, the scale of the order, and the customer’s risk profile.  Operators would also be expected to consider cumulative orders over time, particularly where multiple purchases could collectively enable higher‑risk biological capability. 

The Biotech Act allows operators to rely on a previous screening of the same customer if it was completed within the past five years and the new transaction does not materially differ in nature or scale.  While this would reduce administrative burden, it may also create practical challenges: a prior refusal or adverse assessment could influence future decisions, potentially affecting legitimate research activities that evolve over time.  At present, the Biotech Act does not specify how an operator or customer may contest or seek review of a denial, leaving the procedural avenues for challenging adverse determinations unclear.

According to the joint SANT/ITRE rapporteurs’ draft report published in June 2026, the Commission would be required to establish a phased pathway for implementing harmonised nucleic acid synthesis screening across the EU, based on advice from the Advisory Group and stakeholder consultation (Amendment 252).  The pathway would support the progressive adoption by nucleic acid synthesis service providers, including SMEs, of sequence and customer screening, verification of legitimate need and suspicious-transaction reporting, while providing guidance, training and other support measures and potentially introducing minimum performance standards across the internal market.

                                                              ii.      Detecting, Refusing, and Reporting Suspicious Transactions

Economic operators and online marketplaces would need to maintain internal procedures to identify “suspicious transactions.”  A transaction is considered suspicious where there are reasonable grounds to doubt the “legitimacy of the prospective customer’s intentions.” 

Such grounds may arise from inconsistencies in the information provided, unusual order patterns, discrepancies between the customer’s profile and the requested product, or cumulative purchases that could increase biological capability.  For example, a newly established company with no laboratory facilities attempting to purchase a benchtop DNA synthesiser, or a customer repeatedly ordering short DNA fragments that could be assembled into a toxin gene.

Where justified concerns arise, economic operators and online marketplaces must:

  • refuse to supply the product; and
  • report the transaction to the competent national contact point within 24 hours.

Non‑compliance may trigger enforcement action.  Member States would need to establish effective, proportionate, and dissuasive penalties, including fines of up to 5% of the operator’s worldwide annual turnover for intentional or negligent infringements.  Authorities may also request records, conduct inspections, and perform test purchases to verify compliance.

2. EU Monitoring of “Biological Systemic Risk” from AI Models

The proposed Biotech Act does not replace or displace the obligations imposed by Regulation (EU) 2024/1689 (the “EU AI Act”).  Providers of general-purpose AI models and other AI systems used in biological applications will remain subject to the EU AI Act wherever its requirements are applicable (e.g., through classification as an AI model with systemic risk based on its ability to output biological sequences under Article 51 and Annex XIII of the EU AI Act).  Instead, the Biotech Act creates an additional biosecurity-specific oversight layer focused on the potential misuse of AI in biological contexts.

In particular, the Advisory Group on Biosecurity is tasked with monitoring developments that may give rise to a “biological systemic risk” and must alert the European Commission where it identifies such concerns.  Where an AI model is implicated, this mechanism is designed to ensure coordination with the Commission’s AI Office established under the EU AI Act.  As a result, the EU will monitor that AI models trained on or deployed in connection with biological data and applications be subject both to the horizontal obligations of the AI Act and to scrutiny under the Biotech Act’s biosecurity framework.  Models identified as creating significant biological risks may be brought to the attention of the AI Office, enabling the Commission to consider whether additional measures are warranted under the EU AI Act’s framework for general-purpose AI models presenting systemic risks, while simultaneously addressing the specific biosecurity concerns identified under the Biotech Act.

The joint SANT/ITRE rapporteurs’ draft report (Amendments 243-245) aims to broaden the Advisory Group’s remit, including in relation to nucleic acid synthesis screening, dual-use risks, biosecurity cooperation, and risks arising from the convergence of AI and biological technologies, including cybersecurity and potential implications for biosecurity and biotechnology misuse.

Conclusion

If adopted in its current form, the Biotech Act would significantly expand EU-level intervention in dual-use biotechnology and AI-enabled biological research.  Companies active in gene synthesis, lab equipment manufacturing, AI-driven biological design, and online marketplaces should begin assessing whether their current screening and compliance systems would meet the proposed requirements.  Although the European Parliament’s June 2026 draft report proposes significant changes elsewhere in the Biotech Act, it broadly preserves the proposed biosecurity framework described in this article.

***

This blog is based on the wording of the Commission’s proposal published on 16 December 2025 and considers the amendments proposed in the European Parliament’s June 2026 joint SANT/ITRE rapporteurs’ draft report. This wording could change significantly during the legislative process.

Mathilde Raebisch of Covington & Burling LLP contributed to the preparation of this article.