All posts

When the Lab Meets the Cloud, Part 1 of 5: The Problem, and Why It Isn't New

Senserva Watch

Join Senserva Watch and get Three Free Unlimited Audits with our full Claude MCP, a fresh audit credit every quarter, alerts when a CVE or KB you follow changes, critical security updates when they land, the Patch Tuesday wire on release day, and 20% off when you buy.

Join Senserva Watch

One email address. No tenant connection, no agent, no call.

This is the first installment in a five-part series on cybersecurity, AI governance, and the future of biological research. Part 2 walks through documented cases where the guardrails weren't there yet. Part 3 looks at where AI in this field is headed next. Part 4 lays out governance a research organization can build today, with examples of what implementation actually looks like. Part 5 looks at how Senserva helps close the gap at the infrastructure layer.

I spent years in biology research environments where data integrity was the foundation of everything. Every sample had a chain of custody. Every assay had a protocol that could survive a regulatory audit. Data auditing, standardized assay protocols, SOPs, and Good Laboratory Practice requirements exist because science has a documented history of results that could not be reproduced, samples that could not be traced back to their source, and studies that turned out to be sloppy or fabricated once someone looked closely, and regulators and journals built these controls to make sure a result could be trusted before anyone acted on it. If the data could not be traced and verified, it did not count. At bottom, this is a data governance problem: rules for who can touch a piece of data, under what conditions, and with what accountability.

When I moved into cybersecurity, the thing that surprised me most was how familiar the problem felt. The same data governance principles that protect a clinical sample, chain of custody, access control, an auditable trail, are the principles that should protect the cloud environments where biological research now lives, and increasingly, the AI and machine learning models being trained on that data. That is the connection most research organizations have not made yet: the same discipline that governs who can touch a blood sample should govern who can touch a shared drive or a training set. The connection runs three layers deep: the infrastructure (the cloud), the data itself, and the AI model (whether that is a large language model or a narrower predictive model like AlphaFold). Get the data governance layer wrong, and you also have an AI governance problem, because a model is only as trustworthy as the data and access controls underneath it.

That gap is becoming dangerous, fast. The science is accelerating. The data and the AI governance meant to keep pace with it is not.

On June 30, 2026, Anthropic launched Claude Science, a research workbench designed to support scientific work the same way Claude Code supports software engineering. It can autonomously execute meaningful scientific work from high-level instructions, interface with more than sixty scientific databases, and maintain a traceable record of how every result was produced (MIT Technology Review, June 30, 2026). It is not the only tool moving in this direction, and it will not be the last. Part 3 of this series looks at the wider landscape of autonomous research agents entering biology labs right now and what that trajectory means for governance. For now, the point is narrower: the governance gap this blog series is about is not a Claude-specific problem or an Anthropic-specific problem. This is the AI governance problem in miniature: it is what happens whenever an autonomous agent gets database access, code execution, and the ability to act on biological data with limited human review, regardless of which company built it.

This is genuinely significant. But as Barbara Salami, CEO of Kaindly AI, observed, most of the conversation about AI in pharma and biotech is about the front of the drug discovery and target identification process, and the front of the process was never where the industry got stuck. Between 2011 and 2020, the likelihood that a drug entering Phase I would eventually win approval was 7.9 percent (BIO, Informa Pharma Intelligence & QLS Advisors, 2021). Better targets do not move that number. What improves the approval rate is everything downstream. AI will do little about the science's ceiling. It could do a great deal about the time and money burned before organizations accept the science's verdict, if anyone lets it.

That hesitation to let AI's verdict override slower, established review is one thread running through this series. Two others run in the opposite direction: a misuse risk, that more capable AI design tools make deliberate harm easier, and a model-trust risk, that the models themselves, whether large language models or narrower predictive models, may not be producing trustworthy biology in the first place. This series works through all three, institutional hesitation, misuse, and model trust, but it starts here, with why the risk exists at all.

The same tools that accelerate discovery can accelerate harm

The convergence of three technologies, CRISPR-based genome editing, affordable and widely distributed DNA synthesis, and AI systems that can design novel proteins, has created what biosecurity researchers now describe as an AI governance crisis of civilizational consequence. CRISPR-based genome editing has gone from laboratory curiosity to clinical reality in less than a decade. DNA synthesis has become so affordable and distributed that traditional gatekeeping mechanisms no longer function. And AI can now design novel proteins with structural or functional properties similar to known hazardous agents, but different enough to evade the sequence-based detection tools that most DNA synthesis services rely on (Global Biodefense, June 17, 2026). It is a governance crisis with a biosecurity dimension, a data governance dimension, and an AI governance dimension at once, which is exactly why no single fix closes it.

The same underlying capability that creates this risk is also what makes AI so useful for legitimate discovery, and that dual nature is not abstract. Part 2 of this series walks through the documented cases: a generative model that produced a nerve agent candidate list in under six hours, a machine learning system that surfaced roughly 160,000 previously unrecognized viruses in public sequence databases, and a government AI safety body confirming that today's language and biology models can already walk a sufficiently trained user through synthesizing a dangerous virus. None of those are hypotheticals. They already happened.

The regulatory architecture designed to prevent this kind of AI-enabled biological misuse was built for a different world. Frameworks conceived in the 1970s and 1980s, designed for a landscape where genetic manipulation required specialized infrastructure and years of advanced training, now confront a graduate student with modest resources who can synthesize complex genetic sequences from a university laboratory. The technology accelerates while the AI governance and to a limited extent the data governance decelerates, and the space between them grows wider with each passing year.

This is a specific, named problem in the governance literature, not just a general observation. Collingridge described it in 1980 as the "dilemma of control": early in a technology's life, its consequences are too uncertain to design good safeguards for, and by the time those consequences are well understood, the technology is already embedded in institutions, markets, and practice, which makes intervention far harder (Collingridge, 1980). AI-enabled biotechnology compresses that window further than genome editing alone did, because it also shortens the design-build-test-learn cycle itself, giving policymakers even less time to deliberate before the tools are in wide use (Trump et al., 2026).

The Spirit of Asilomar 2025 entreaty on AI and the Future of Biotechnology names this convergence directly at the policy level. It warns that AI tools built for legitimate purposes, such as predicting vaccine escape, "could be misused to design new pandemic agents that could evade current population immunity" (Bromberg et al., 2025). The entreaty's proposed guardrails, tiered data access, mandatory synthesis screening, and watermarking of AI-generated protein structures, are aimed at closing exactly this kind of gap. Part 4 of this series comes back to these guardrails in more detail.

History has already run this experiment once

The name "Asilomar" is not an accident, and it is worth pausing on why. In 1974, molecular biologists called for a voluntary moratorium on recombinant DNA experiments themselves, before any regulator or the public had raised the alarm. A year later, in 1975, a group of life scientists gathered at Asilomar, California, in response to those concerns and eventually produced a detailed, risk-based set of safety measures, with no representation from ethicists, legal scholars, or the wider public (Braun and Muller, 2025). Many of those specific safety measures went on to become funding agency regulations or outright legal requirements, in effect binding data governance controls built to mitigate a specific safety risk rather than voluntary guidance (Prunkl, 2024).

In 2017, the AI field ran the same play, but the outcome looked different. The "Asilomar Conference on Beneficial AI" again brought together researchers and influential private-sector actors to define the risks of AI research, again without the wider public at the table (Braun and Muller, 2025). This time, the result was not a detailed risk management plan but a set of principles spanning everything from technical transparency ("If an AI system causes harm, it should be possible to ascertain why") to geopolitics ("An arms race in lethal autonomous weapons should be avoided"). Those principles are, by design, "very broad and only provide rough guidance, if any at all" (Prunkl, 2024). The 1975 conference produced something specific enough to become law. The 2017 conference produced something too broad to be enforced by anyone, a missed opportunity to put binding, industry-wide AI governance controls in place before the technology scaled far beyond any one lab's ability to self-police. Researchers who have traced this pattern across genomics, nanotechnology, and AI describe a recurring failure mode: self-regulation preserves the autonomy of the people building the technology, but it does not produce the kind of independent, upstream, and participatory oversight that later proved necessary in genomics and nanotechnology research programs.

That history matters here because biological AI research is now repeating it a third time, at the exact intersection this series is about. The Human Genome Project eventually devoted a dedicated funding stream and an independent review body to its ethical, legal, and social implications, governance controls in the fullest sense, and even that arrangement took years of criticism and revision before it produced anything close to upstream influence on research trajectories (Braun and Muller, 2025). AI-driven biological research has not yet reached that stage. A general structured, certifiable equivalent now exists on paper: ISO/IEC 42001, the first international AI management system standard, does build in requirements for human oversight and an assessment of the social and ethical impact of an AI system, unlike the broad 2017 Asilomar AI principles. But ISO 42001 certification is voluntary. Additionally, some institutions voluntarily follow AI governance and ethics guidelines published by the same organizations that build the technology, but this falls prey to the same critiques of the governance of early CRISPR genome editing technologies and DNA synthesis. A research organization does not need to wait for that policy debate to resolve before it puts governance in place internally. But it should not assume that a published AI ethics framework from a vendor is a substitute for a research organization's own independent review.

That is the shape of the problem: three converging technologies, CRISPR, DNA synthesis, and AI-designed proteins, a regulatory architecture built for a slower era, and a documented history of self-regulation of the infrastructure (the cloud), the data, and the AI model falling short exactly where independent oversight was needed. None of that is abstract. Part 2 of this series puts names, dates, and numbers on it.

About Senserva: Who We Are and What We Do

Senserva is a Microsoft-focused security posture management company based in St. Paul, Minnesota. Its platform continuously scans an organization's Microsoft 365, Intune, Defender, and Entra ID environment, running several hundred built-in checks across identity, privileged access, applications and service principals, endpoint and device compliance, email, logging, and Azure subscription roles.

For every finding, Senserva provides step-by-step remediation guidance, including validated PowerShell scripts and rollback notes, and maps results to recognized compliance frameworks such as the Microsoft Cloud Security Benchmark, CISA's SCuBA baselines, NIST 800-171, CIS, ISO 27001, SOC 2, HIPAA, and PCI-DSS. Senserva is a member of the Microsoft Intelligent Security Association (MISA) and a Microsoft Security Excellence Awards finalist.

Senserva also offers Three Free Unlimited Audits covering every tenant, user, and patch: one to Find, one to Fix, and one to Prove, using the same 650+ checks described above. Registration takes only a work email, with no cost and no obligation to buy. Request an evaluation key at senserva.com/request-key.html.

Senserva also runs Senserva Watch, a free membership that tracks CVEs and Microsoft patches on an organization's behalf and sends an alert only when something being tracked changes, including a same-day notice when Microsoft's Patch Tuesday updates ship. Signing up needs no tenant connection, agent, or call, just an email address, at senserva.com/senserva-watch.html.

Already a Senserva Watch member, or ready to join? Sign up at senserva.com/when-the-lab-meets-the-cloud.html to get the complete five-part series sent to your inbox, plus everything else membership includes: alerts when a CVE or KB you follow changes, a fresh audit credit every quarter, and 20% off when you buy.

Learn more at senserva.com.

Sources cited in this part

  • Salami, Barbara. "AI Can Find the Target. Pharma Still Has to Find the Courage." LinkedIn Pulse, July 7, 2026.
  • BIO (Biotechnology Innovation Organization), Informa Pharma Intelligence, and QLS Advisors. Clinical Development Success Rates and Contributing Factors 2011-2020. February 2021.
  • Huckins, Grace. "Claude Science Is Anthropic's Newest Flagship Product." MIT Technology Review, June 30, 2026.
  • Global Biodefense Staff. "CRISPR, AI, and Accessible DNA Synthesis Are Outpacing Global Biosecurity Oversight." Global Biodefense, June 17, 2026.
  • Bromberg, Yana, et al. Spirit of Asilomar Entreaty 2025.3.1: Artificial Intelligence and the Future of Biotechnology. February 2025.
  • Collingridge, David. The Social Control of Technology. New York: St. Martin's Press, 1980.
  • Braun, Maximilian, and Ruth Muller. "Missed opportunities for AI governance: lessons from ELS programs in genomics, nanotechnology, and RRI." AI & Society 40 (2025): 1347-1360.
  • Prunkl, Carina. "AI meets biology: a call for community governance." Nature Methods 21 (2024): 1407-1408.
  • Trump, Benjamin D., et al. "Governing the AI-biotech convergence." EMBO Reports 27 (2026): 259-264.

All posts