New U.S. Gain-of-Function Ban Meets a Framework It Wasn't Built to Cover
A peer-reviewed policy review published days after the White House's July gain-of-function prohibition reveals five threat pathways the new rules still leave ungoverned.
The White House locked in a sweeping new life-sciences oversight policy in late July, and researchers are already mapping its edges. A peer-reviewed framework published last week in Frontiers in Bioengineering and Biotechnology puts the gaps in sharper relief, and reading the two documents side by side is instructive.
First, the policy. On July 20, the White House Office of Science and Technology Policy approved the United States Government Policy for Stopping High-Risk Life Sciences Research. According to the ASPR policy page reviewed by ETL Newswire, the rule replaces the 2024 DURC and Pathogens with Enhanced Pandemic Potential framework and was developed under EO 14292. The mechanics are consequential: federal funding is categorically off the table for dangerous gain-of-function research, defined as work that "seeks, achieves, or has a substantial risk of achieving" outcomes that could produce significant negative societal consequences. A second category, International Research of Concern, bars federal funding for work conducted in or by entities in countries the government designates as concerns, or in countries with inadequate oversight.
As reported in an NIH Notice reviewed by ETL Newswire, agencies have 120 days to publish implementation guidance and 90 days to stand up an Independent Third-Party Review Body. Institutions and principal investigators now carry primary compliance responsibility, including written attestations on every federally funded life-sciences proposal, with noncompliance carrying penalties up to multi-year federal ineligibility. The American Society for Microbiology, in a statement dated July 29, expressed concern that the policy's broad definitional language for DGOF categories could reach research currently conducted in full compliance with existing biosafety guidance, warning it could impede national infectious-disease response capacity.
That definitional ambiguity is precisely what the parallel academic work surfaces. Ruihan Zhang of the School of Population Health at UNSW Sydney published a structured narrative policy review in Frontiers in Bioengineering and Biotechnology on August 31, updated through July 28. In the paper, reviewed by ETL Newswire, Zhang identifies five overlapping threat pathways in dual-use research of concern, including accidental release, insider misuse, and cyberattacks on laboratory systems. The last of those three isn't a primary focus of the new U.S. policy, which treats cybersecurity as a mitigation measure inside a DGOF mitigation plan rather than as a threat vector requiring its own governance lane.
Zhang's review proposes eleven integrated governance recommendations drawing on the WHO's 2022 Global Guidance Framework, the ISO 35001 biosafety risk management standard, and the now-superseded 2024 U.S. DURC policy. The approach is deliberately additive: rather than proposing a new regulatory body, it synthesizes existing tools and pushes for layered institutional ethics review, laboratory risk-management systems, and cyberbiosecurity protocols. That's a meaningful distinction from the new U.S. policy, which does create a new body, the Independent Third-Party Review Board, while leaving cyberbiosecurity largely to agency discretion.
The governance gap isn't abstract. As the Bulletin of the Atomic Scientists noted in a March analysis, biological data and tools are embedded in digital ecosystems that face persistent cyber threats, and governance frameworks built on arms-control logic weren't designed for that attack surface. Zhang's review flags the same problem from the compliance angle: oversight systems written around pathogen lists and physical lab controls haven't been adapted to the reality that lab systems are networked and that threat pathways run through software, not just select agents.
Two structural tensions are worth naming plainly. First, the new U.S. policy shifts compliance burden substantially onto institutions and PIs, requiring written determinations before proposals are submitted. That's a different accountability model than the old DURC framework, and it front-loads the dual-use judgment onto researchers who don't carry intelligence-community context about what adversaries can do with partial results. Second, Zhang's review cautions, citing Denmark's 2008 Biosecurity Act experience, that poorly calibrated oversight carries real innovation costs. The new U.S. policy has broad definitions and a 90-to-120-day implementation runway; whether the definitions tighten or loosen in agency guidance will determine whether this functions as genuine risk management or as a compliance exercise researchers route around.
Implementation guidance due out of NIH and HHS is the document to watch. Confidence, moderate, that the definitional edge cases will be contested before that 120-day clock runs.
Sources cited:
- ASPR, USG Policy for Stopping High-Risk Life Sciences Research (https://www.aspr.gov/readiness-response/medical-countermeasures-biodefense/s3/high-consequence-research-oversight/USG-Policy-For-Stopping-High-Risk-Life-Sciences-Research)
- NIH Notice NOT-OD-26-101 (https://grants.nih.gov/grants/guide/notice-files/NOT-OD-26-101.html)
- Mondaq, New Federal Policy Prohibits Certain Gain-of-Function Research (https://www.mondaq.com/unitedstates/healthcare/1825010/new-federal-policy-prohibits-certain-gain-of-function-research-and-restricts-certain-international-projects)
- ASM Statement on USG High-Risk Life Sciences Research Policy (https://asm.org/press-releases/2026/july/asm-statement-on-usg-high-risk-life-sciences-resea)
- Zhang R., Frontiers in Bioengineering and Biotechnology, 31 August 2026 (https://www.frontiersin.org/journals/bioengineering-and-biotechnology/articles/10.3389/fbioe.2026.1924238/full)
- Global Biodefense, A Blueprint For Managing The World's Most Dangerous Research (https://globalbiodefense.com/2026/09/01/a-blueprint-for-managing-the-worlds-most-dangerous-research/)
- Bulletin of the Atomic Scientists, What can biosecurity learn from cybersecurity? (https://thebulletin.org/2026/03/what-can-biosecurity-learn-from-cybersecurity-a-lot/)
- COGR, Summary of USG Policy for Stopping High-Risk Life Sciences Research (https://www.cogr.edu/blog/summary-us-government-policy-stopping-high-risk-life-sciences-research)
This release was originally distributed via ETL Newswire. Visit ASPR, USG Policy for Stopping High-Risk Life Sciences Research for the full story, related releases, and contact information.
Visit ASPR, USG Policy for Stopping High-Risk Life Sciences Research →