Governance
What if something genomic goes wrong with genomics – who is actually in charge?
Many people.
And nobody completely.
That is the honest answer to who is in charge of genomics.
A genome can be many things at once. It can be a medical record, a family secret, a research dataset, a forensic clue, a national asset, a patent claim, a fertility decision, a crop trait, a conservation tool, a biosecurity risk, a commercial product or a piece of personal identity.
Because if you are a founder, investor, clinician or policymaker, the regulator that actually governs your project depends on what you call it — and that answer can change once the product ships.
That is why the answer to “who is in charge?” is not simple. There is no single world genomics regulator sitting in a very serious chair, stroking a genetically ordinary cat and approving the future of life.
Instead, genomics is governed by a patchwork of actors: hospitals, regulators, ethics committees, data-protection authorities, patent offices, fertility regulators, food inspectors, park rangers, company registers, defence agencies, patient groups, professional societies, courts, research funders, national healthcare systems and international treaties.
Some of these agencies are working very hard to protect our genomes, the next generation of humans and the biosphere. But due to the rapid technological advancement of the genomic revolution, and the many different sectors affected, oversight is also full of gaps, especially at the systems and international level. Some regulation is prepared and effective, other is not used to working with genomics data at all, and can do life-threatening miscalculations.
If genomics is research, ethics committees are usually first in line
If a university, hospital or research institute wants to analyse genomic data, the first gatekeeper is usually an internal research ethics committee.
These committees look at consent, risk, benefit, vulnerable groups, data protection and sample storage. They are one of the most important places where someone asks: is this fair, safe and justified?
Examples include the UK Health Research Authority Research Ethics Committees, the US Office for Human Research Protections, and FDA guidance on Institutional Review Boards.
Patient and public involvement groups matter here too. Organisations such as the NIHR, the FDA Patient-Focused Drug Development programme, the EMA patients and consumers network and NICE public involvement help bring lived experience into research, medicine and health-technology decisions. The risk with some ethics committees can be that they may not be experts in the field, don’t have that much time for each application, and may be close colleagues of the people applying.
If genomics is healthcare, medical regulators and healthcare systems take over
If a genomic test is used to diagnose disease, guide cancer treatment, choose a medicine or assess inherited risk, it enters the world of healthcare regulation. In the US, the FDA regulates many in vitro diagnostics, including next-generation sequencing tests. The CMS CLIA programme regulates clinical laboratory quality, aiming for accurate, reliable and timely test results.
In Europe, genetic tests may fall under the EU In Vitro Diagnostic Medical Devices Regulation, often described through CE-IVD routes. It is a regulatory system involving manufacturers, notified bodies and national competent authorities. In the UK, the MHRA regulates medicines and medical devices, including some software and AI tools, while the NHS Genomic Medicine Service decides how genomics is implemented inside NHS care.
Professional bodies also matter. ACMG, ClinGen and CPIC are not police forces, but their guidelines shape how clinicians interpret variants, classify evidence and use pharmacogenomics. Remember; approval, quality and clinical usefulness are not the same thing. A test can be technically accurate and still be badly interpreted, badly explained or used for the wrong person at the wrong time. In healthcare, people on day-to-day basis look to these bodies as authorities on best practice.
The author, Dr. Magdalena Zarowiecki has directly worked with some regulators, and can confirm that especially for new AI and genomics technologies is more of a dialogue than imposed rules. If you make a brand new technology, you often know more than the regulators, so they look to you to advise them what is proportional oversight, best practice and feasible. Which they then check internally, and with external experts. Healthcare regulators are overall fantastic – they have extensive experience of overseeing complex life-and-death decisions, not just in genomics, but every facet of healthcare. Their strength is looking at single devices, use cases and protocols, but they do not regulate things like equitable access, or systemic change.
If genomics becomes a medicine, drug regulators step in
Gene therapies, cell therapies and advanced genomic medicines are among the most tightly regulated parts of genomics, because they enter the body and can cause serious harm if they go wrong. In the US, FDA CBER oversees cell and gene therapy products. In the EU, the European Medicines Agency oversees advanced therapy medicinal products, including gene therapy medicines, cell therapies and tissue-engineered products. Other national regulators include Health Canada, Australia’s TGA, Japan’s PMDA, China’s NMPA, India’s CDSCO, Brazil’s ANVISA and South Africa’s SAHPRA.
Medical approval (showing that the medicine is safe and effective) is not the end though. National healthcare systems, insurers and health technology assessment bodies decide whether people can actually access the treatment. In England, NICE evaluates whether medicines, diagnostics and technologies should be used in the NHS. That is where miracle meets budget. There is already very large public feuds over costs of innovative genomic treatments, with the costs for some treatments reaching astronomical sums. Zolgensma, a one-off gene therapy for spinal muscular atrophy, had a reported NHS list price of £1.79 million per dose. Casgevy, the first CRISPR-based therapy, was priced in the US at $2.2 million per patient and listed in England at £1,651,000 per course. Hemgenix, a gene therapy for haemophilia B, launched at $3.5 million. You’d think that in exceptional cases a national healthcare system could afford to pay $1-3 million USD, and those costs could still be lower than life-long regular appointments, but if there are many patients needing this treatment, say 2% of the population, the costs would be a substantial proportion of the entire government budget. It is sometimes fairly unpleasant to see how critically ill patients are being used as soft weaponry in budget negotiations. The good news is that once technologies and platforms are more established, costs should drop significantly, because the price does not reflect the real cost of creating the treatments, which are much lower.
If genomics is fertility, embryos or future children, regulation becomes patchy fast
Fertility regulation varies dramatically by country. In the UK, the HFEA is unusually clear: it regulates fertility treatment and research using human embryos, licenses clinics and monitors standards. Elsewhere, the rules may be spread between health ministries, courts, professional societies, clinic licensing bodies and general medical law. ESHRE provides guidance on preimplantation genetic testing, and ASRM publishes ethics opinions and professional guidance in reproductive medicine.
Internationally, the WHO human genome editing governance framework, UNESCO and the Council of Europe’s Oviedo Convention matter because they frame human genome editing through dignity, human rights and public governance.
This is one of the most serious gaps. A decision about an embryo can become a decision about a future person. A decision about germline editing could become a decision about future generations. Yet the world has no single, enforceable, global authority for human reproductive genomics, which leaves serious gaps, and the field open for fertility tourism. Even on a national level it is patchy, and there are many for-profit private providers with little coordination between them – there have already been terrible scandals with fertility and IVF clinics, and expect more in the years to come!
If genomics is data, privacy regulators and contracts matter
Genomic data is not ordinary data. It can reveal health, ancestry, family relationships and future risk. It may remain sensitive for life and may also say something about relatives who never consented.
In Europe, the GDPR treats genetic data and health data as sensitive personal data. The UK’s Information Commissioner’s Office regulates data protection in the UK. Many countries have their own national data-protection authorities.
In the US, the picture is more fragmented. HIPAA protects certain health information in covered healthcare settings, while the FTC can act against deceptive or unfair commercial practices, including genetic privacy failures. The NHGRI explains US protections against some forms of genetic discrimination, including GINA.
Biobanks and research databases also have their own governance. The OECD has guidance on human biobanks and genetic research databases, while GA4GH develops standards for responsible genomic and health-data sharing.
This is where the legal fine print becomes frighteningly important. Who stores the data? Who can access it? Can a company sell it? Can police ask for it? Can it leave the country? Can you withdraw? What happens after you die? What happens if the company goes bankrupt?
In my opinion, the mistake often made by data regulators is that they look at personal data privacy and protection, but they do not project out enough to family members, children, some yet not born, and future generations, who has not and cannot consent to the use of their data. And your genome is not like your passport or credit card – if it gets lost or stolen you cannot replace it. So the levels of protection need to be magnitudes larger than for those types of data. The protection needs to be built into the systems storing and processing the data, in a way which maximises a person’s rights to actively manage their data, minimises the risk of a data breach yielding comprehensive data, and protects family members and future generations comprehensively.
If genomics is food, farming or engineered organisms, agriculture and environment regulators wake up
Gene modified organisms in food have become pervasive. In the US, GMO oversight is split between the FDA, USDA and EPA. FDA looks at food safety, USDA APHIS looks at agricultural and plant-pest risks, and EPA regulates pesticides and plant-incorporated protectants. In Europe, EFSA assesses food, feed and environmental risks from GMOs.
Food inspectors, veterinary regulators, seed regulators, plant-health inspectors, pesticide regulators, trade authorities and national agriculture ministries may all have a role. So may factory inspectors and workplace safety regulators if engineered cells are used for biomanufacturing.
This matters so much because of how the intersection of gene editing, stem cell technology, synthetic DNA and AI will interact to create new enzymes for detergents, proteins made in yeast, a gene-edited crop, a cloned animal line, a microbial flavouring substance, a drought-resistance trait or a fermentation vat making something that used to come from petrochemicals. Given the speed of development here, I’d be amazed if regulators do not feel like they are trying to invent the seatbelt inside a car that is already doing 180km/h on the motorway. It is also essential that these regulators are given a broad mandate to protect the biosphere and humanity, not just decide if a particular agrogenomic innovation is effective, or safe for one field.
If genomics touches wildlife, ecosystems or biodiversity, the guardians are different again
Conservation genomics may involve park rangers, wildlife agencies, fisheries authorities, botanical gardens, museums, national parks, customs officers, Indigenous and local communities, biodiversity researchers and environmental ministries. This is not a tidy regulatory chain. Internationally, the Convention on Biological Diversity, the Nagoya Protocol, the Cartagena Protocol on Biosafety and CITES protecting biodiversity, genetic resources and more than 41,000 animal and plant species. That matters because wildlife crime is already a huge global business, generating as much as US$23 billion annually.
Traditionally, this is not an area where regulation has been strong enough. South African National Parks reported that 175 rhinos were poached in Kruger National Park in 2025. At sea, the share of fishing at biologically unsustainable levels rose from 10% in 1974 to 37.7% in 2021. In the UK’s own 2024 assessment of negotiated catch limits, only 36 of 79 baseline total allowable catches were consistent with scientific advice.
So the risk is obvious. If authorities already struggle to stop poaching, illegal wildlife trade, overfishing and biodiversity loss, regulation will be nowhere near enough for oversight of genomics in the wild. Releasing gene-modified species, engineered microbes or synthetic biological systems into ecosystems requires a much higher level of caution, monitoring and public accountability, more in line with the stringency of a hospital, and we are nowhere near that yet.
If genomics is policing, courts and forensic regulators matter
DNA can identify people, link crime scenes, exonerate the innocent, identify missing persons and reunite families. It can also turn relatives, children and people who were never suspects into searchable investigative leads.
In the US, the FBI’s CODIS system is the national DNA database infrastructure; the National DNA Index contains millions of offender, arrestee and forensic profiles. Internationally, INTERPOL’s I-Familia system supports cross-border DNA kinship matching for missing persons. In England and Wales, the Forensic Science Regulator sets statutory quality standards for forensic science.
The benefits are real – forensic DNA is the silent witness which has helped solve so many crimes in a more unbiased way. The danger is function creep. Policing and national-security systems have repeatedly expanded far beyond the neat use case they were sold on. Facial recognition has already contributed to more than a dozen documented wrongful arrests, according to the ACLU. The LAPD fed field-interview data into Palantir, allowing police to aggregate information on individuals, friends, family and associates, including people suspected of no crime.
The UK’s undercover policing scandal is the ugliest reminder that “security” can become intimate, bodily and grotesque. Undercover officers deceived women into long-term relationships; the Metropolitan Police later apologised and called those relationships a “gross violation”. Some officers fathered children with women they were spying on. That is what happens when secret policing enters family life and calls the damage operational necessity.
Genomic surveillance raises the stakes again. A DNA profile is not only a name tag. It can reveal biological relatives, ancestry, health risks and pharmacogenetic clues – much more than the person knows about themselves, or their family! And forensic genetic genealogy can identify people through relatives who uploaded their own DNA in a database, meaning one person’s test can unwittingly expose a cousin, sibling, parent or child. Fed up with your criminal relative? Go and get a DNA test!
Besides asking for a suspect’s DNA, police can collect “abandoned DNA” from things people leave behind — a cup, cigarette end, tissue or chewing gum, so called covert involuntary sampling. There is to my knowledge also no restriction on what police can look for in the DNA. This is very different from a hospital, where you only look in a patient’s DNA for things relevant to the disease they have, sometimes not even reporting on incidental findings, eg that a person also has a high likelihood of developing another disease. That is why forensic genomics cannot be left to police enthusiasm. There has to be strict protocols around covert sampling, data retention, genetic genealogy, cross-border sharing, victim DNA, incidental findings, and whether people who were never suspects become searchable. If you think this is easy – I dare you to go to a police station and ask that they remove your fingerprint from their database – you’ll most likely spend months in the process, even if you’ve never committed a crime. If they have your fingerprint through involuntary sampling, they’ll probably never even admit to having it.
Genomic policing needs courts, forensic regulators, privacy law, human-rights law and public oversight that thoroughly understand the consequences, and can put rules in place which properly protects the general public, and even criminals, from genomic overreach. In countries with weak regulatory oversight, the risk of genomic data abuse is significant.
If genomics is a patent or commercial asset, patent offices and company law matter
Genomics is not only science. It is ownership, monopoly, licensing, investment and corporate control over biology.
The BRCA case shows how badly this can go wrong. Every human carries BRCA1 and BRCA2 genes. Yet Myriad Genetics held patents linked to those genes and used them to control BRCA testing. Their test cost $3,000–$4,000, and blocked other laboratories from offering much cheaper testing. For patients, it meant fewer were tested, and lost chances to prevent or treat hereditary breast and ovarian cancer – literally millions of women can have unnecessarily died because cheap and effective diagnostics was suppressed by Myriad Genetics’ patent.
In 2013, the US Supreme Court finally ruled that naturally occurring human DNA cannot be patented. Good. But the fact that the case had to reach the Supreme Court at all should still make people angry. Commercial law managed to treat genes carried by every human being as if they were a defensible corporate moat, which is absurd, and to my knowledge nobody has been held responsible for all unnecessary deaths.
The problem is bigger than human genes. Patent offices such as the USPTO, European Patent Office, UK Intellectual Property Office, WIPO and national patent offices decide what counts as an invention when the subject is synthetic DNA, enzymes, diagnostics, engineered organisms, genetic resources or biological methods. It is not built to decide whether a virus, bacterium, gene drive or synthetic organism could create civilisational risk. Or if the attempt to patent something can lead to many people or ecosystems dying! Some protection is being done; WIPO’s 2024 treaty on genetic resources for patent applications, wants to prevent the type of extraction where companies and researchers have turned genes, organisms and traditional knowledge into commercial claims without the people closest to that biology sharing fairly in control or benefit.
Protecting real invention is important. Applying ordinary commercial logic to biology is absurd! When the asset is human inheritance, genomic data, engineered life, dangerous organisms or the genetic future of the biosphere, the decision cannot be left only to whoever fills out the patent form, drafts the broadest claim, raises the most money or buys a company. Some genomic decisions need law, ethics, public oversight and international governance before commercial rights are even allowed into the room, to prevent catastrophic impact on the genomics of every living thing on planet Earth, now and in the future.
If genomics becomes a security issue, defence agencies enter the room
Biosecurity is where the governance map becomes serious, secretive and uncomfortable. Genomics can help detect outbreaks, make vaccines, identify pathogens, protect crops and build better medicines. The same tools can also support biological weapons, targeted surveillance, covert sampling, engineered pathogens, synthetic toxins, military research and intelligence operations.
The strongest international rule is the Biological Weapons Convention, which bans biological and toxin weapons. But this is also one of the biggest gaps: unlike the Chemical Weapons Convention, the BWC has no standing inspectorate and no full verification regime. UNODA has described confidence-building measures as one of the Convention’s few formal transparency tools in the absence of a formal verification protocol.
There are other international controls. UN Security Council Resolution 1540 requires states to adopt laws preventing non-state actors from acquiring nuclear, chemical and biological weapons – but those are just voluntary agreements. The Australia Group coordinates export controls on pathogens, toxins, genetic elements, genetically modified organisms and dual-use biological equipment. The EU controls export, transit, brokering and technical assistance for dual-use goods, software and technology to prevent proliferation of weapons of mass destruction.
Public-health agencies and research funders also matter. The WHO responsible use of the life sciences framework gives guidance on biorisk management and dual-use research. In the US, the 2024 federal policy on dual-use research of concern and pathogens with enhanced pandemic potential covers life-science research that could be misapplied to threaten public health, agriculture, the environment, materiel or national security. These systems are useful, but they often depend on national implementation, funding conditions, institutional review and researchers recognising that their work is dangerous before someone else does.
DNA synthesis is one of the clearest choke points. The International Gene Synthesis Consortium Harmonized Screening Protocol asks member companies to screen synthetic nucleic-acid orders and customers, especially for regulated pathogens and toxins. The US has also issued synthetic nucleic-acid screening guidance. The gap is obvious: screening is strongest when companies participate, customers are visible, orders pass through compliant providers, and the concerning sequence is recognised. A 2024 review still stated that there was no general US legal requirement for gene-synthesis providers to screen all customers and orders.
Law enforcement and intelligence agencies sit beside this, but not always comfortably. INTERPOL’s bioterrorism programme supports member countries with biological-threat awareness, cooperation, information sharing, training and investigative support. National departments of defence, intelligence services, customs authorities, border agencies, export-control offices, public-health emergency teams, biosafety committees and counter-terrorism police may all be involved.
The surveillance side is where this becomes frightening. Snowden’s disclosures showed how internet surveillance could scale across major platforms and borders through programmes such as PRISM. Genomic surveillance could reveal relatives, ancestry, health risks, pharmacogenetic clues and future biological vulnerability that the person themselves don’t know about. In a national-security context, that raises obvious questions about how to prevent misuse of the data, especially if police or secret service has access to the data from large population genomic projects, or hospitals.
The gaps here are real; there is no single enforceable global biosecurity regulator. Gene-synthesis screening is still uneven. Export controls struggle with digital sequence information, AI-designed biology and know-how that can cross borders as data. Intelligence work is secret by design. Civilian genomics databases, clinical data, consumer DNA, research datasets and pathogen data can all become security-relevant after they were collected for something else.
The difficult questions are already here: Who controls the sequence databases?
Who screens synthetic DNA orders?
Who audits defence-funded biology?
Who watches dual-use AI models?
Who stops covert genomic sampling?
Who governs military, police or intelligence use of DNA?
Who checks whether security agencies are protecting the public, or quietly building a searchable biology state?
This is the uncomfortable truth: biosecurity is not one regulator’s job. It sits between arms control, public health, intelligence oversight, export control, policing, biosafety, AI governance and ordinary data protection. That patchwork is better than nothing. It is not yet equal to the pace of synthetic biology, genomics and AI. A pandemic outbreak like COVID-19 shows what a large threat just a little virus can be. And traditionally, defence departments have been much more targeted towards threats like other governments and terrorists, and much less interested in threats like: maintaining citizens’ rights, preserving ecosystems and clean water, keeping the atmosphere clean, and all other things which are necessary for life to continue in the area they are meant to protect.
What should an ordinary person take from this?
Genomics is not governed by one system. It is governed by a patchwork. That is partly good. Genomics touches medicine, food, fertility, policing, conservation, terrorism, industry, privacy and defence. No single office could understand all of that alone.
It is also dangerous. Every boundary creates a gap. A genetic test can slip between medical regulation and consumer marketing. A dataset can move from research to healthcare to commerce. Call something a medical test, wellness advice, ancestry, software, fertility support, food technology, conservation, industrial fermentation or data analytics, and different rules may apply, even if the data you collect and analyse is the same.
In a lot of regulation, future generations and ecosystems have almost no voice. Current regulation is usually built around current patients, current consumers, current citizens and current risks. Genomics stretches the timeline to affect people who do not yet exist and living systems that cannot object.
The public is also one of the missing regulators. We need to collectively understand enough to ask good questions, challenge decisions, and own our stake in the future. You can drag someone into court after the damage is done. Sometimes you should. But if the decision has already changed the human gene pool, exposed millions of genomes, released an organism into the wild or altered the biosphere, it is far too little, far too late. The real task is to build systems wise enough to stop the worst decisions before they become part of everyone’s biology.
Navigating genomic governance?
If you are a founder, investor, clinician, policymaker or executive who needs to know how to protect patients, your investments and interests in the real world, this is exactly the terrain I advise on.
Independent, science-grounded review of genomic and AI-health strategy.
Strategy consultancy →Advisory RolesOngoing scientific and ethical counsel for boards and leadership teams.
Advisory roles →Executive BriefingsA clear-eyed briefing on where genomics is genuinely risky, and where it is not.
Executive briefings →All ServicesTalks, workshops, briefings, strategy, venture support and advisory work.
Explore all services →Stay close to the shift
Occasional notes on AI, genomics and the changing language of life.