Who sets the rules for genomic AI?
A peer-reviewed review mapped 90 publicly documented national genomics initiatives across 70 countries and territories. Thirty-two reported current or planned AI use, but the researchers found public AI-specific governance in only three programmes.
Editorial responsibility: The Impact of AI Editorial Desk · Report a factual concern
Research topic
How national genomics initiatives publicly govern AI use, model export and participant-level data

At a glance
- 1The researchers searched 240 countries and dependencies and retained 90 government-led, government-funded or de-facto national genomics initiatives across 70 countries and territories.
- 2Current or planned AI use appeared in 32 of 90 initiatives, but publicly available AI-specific governance was found in only All of Us, Genomics England and UK Biobank.
- 3The review measures public documentation, not every internal control: unpublished, non-indexed and non-English policies may have been missed.
Living evidence record
Impact record IAI-1W4M84M
Evidence stage
Studied
Confidence
Corroborated
Reporting basis
Multi-source analysis
Independent support
Present
Record status
Monitoring
Last checked
2 October 2026
Source trail
4 direct sources across 3 source types.
People impact
Documented in this record.
Uncertainty
Limits and next checks are explicit.
Stages describe the evidence available—not whether a technology is good or bad. See the public method.
The study asks whether governance is keeping pace with use
National genomics programmes collect or connect some of the most sensitive data a public research system can hold. A genome can identify a person, say something about biological relatives and remain informative long after a password or account number can be changed. Artificial intelligence adds a further question: once a model has learned from those records, should its parameters and outputs be treated as ordinary software, as research results or as another form of potentially disclosive data?
The University of Amsterdam team did not test an AI model or audit a security platform. It mapped the public rules around national-scale genomics resources. The research question was practical: which initiatives say they use or plan to use AI, and which publish specific rules about where that work may happen, whether a trained model may leave a secure environment and whether participant-level information can be sent to an external generative-AI service?[1]
The denominator covers 240 countries and dependencies
The researchers built a list of 240 countries and dependencies, then ran structured searches in Google, Bing, Google Scholar and PubMed. Search strings combined the place name with terms for national scope, genomics, DNA, sequencing, precision medicine, biobanks, programmes and infrastructure. Initial searches ran from March 2024 to June 2025 and were repeated from 1 to 14 February 2026 to verify status and capture newer policy material.
An initiative qualified when public evidence showed that it collected, generated, analysed, shared or enabled access to human genomic information from a population or patient cohort, and when it was government-led, government-funded or operated as a de-facto national resource. Purely commercial consumer testing, isolated disease cohorts without a wider national-resource role, genealogy projects, strategy papers without a qualifying programme and non-human genomics were excluded. That process produced 90 initiatives in 70 countries or territories.[1]
AI appeared in 32 programmes; explicit public rules in three
Thirty-two of the 90 initiatives, or 36%, publicly described current or planned AI use. Those programmes spanned 29 of the 70 countries and territories represented in the review. Descriptions were often broad—predictive modelling, data-processing pipelines or analytics infrastructure—rather than precise accounts of a model, training dataset, deployment purpose or approval process. The number therefore measures public mention, not operational maturity or the amount of AI work under way.
The contrast was sharp on governance. The authors identified public AI-specific guidance in three programmes across two countries: the US All of Us Research Program, Genomics England and UK Biobank. They also examined an NIH funder-level notice for controlled-access genomic data. That does not mean the remaining initiatives have no protections. General privacy law, ethics review, contracts and data-access rules still apply. The finding is that programme-level public documents rarely explain how those protections translate to AI-specific risks.[1]
Three controls recur among the early adopters
The first recurring control is a secure computation environment: participant-level records stay inside an approved platform, and AI tools that process them must run there. The second is model-export control. Genomics England does not permit trained machine-learning models to be exported from its secure research environment under the rules reviewed. UK Biobank allows researchers to retain or license architecture but treats parameters learned from participant data as results data and restricts sharing where a model could reveal or reconstruct participant-level information.
The third control limits external generative-AI services. All of Us guidance says participant-level data cannot be sent to an external API such as ChatGPT; UK Biobank likewise bars incorporation of participant-level data into publicly available generative models. NIH goes further for controlled-access human genomic data: its notice classifies trained generative models and their parameters as data derivatives subject to the underlying access restrictions. These policies recognise that information can leave a dataset through a model, not only through a downloaded row or file.[1][2][3][4]
What is missing is as important as what is present
The study found no reviewed initiative-level policy that required bias auditing or fairness assessment for AI models trained on programme data. It also found no initiative embedding AI governance clearly in participant-facing policies. Most AI material sat in researcher FAQs, airlock rules or standalone guidance rather than in core consent information. Participants may therefore be unable to see how AI could alter secondary uses, model licensing or commercial development even when researchers are given operational instructions.
The distinction matters because national genomics projects often recruit people in the name of public benefit, diversity or better representation. A secure environment can reduce one class of leakage without showing that a model performs fairly across ancestry groups. An export rule can keep parameters inside a platform without answering whether an AI-derived product fits the purpose people agreed to support. Technical containment, equitable performance and meaningful communication are separate governance tasks.[1]
The review is reproducible, but public documentation is an imperfect proxy
The authors publish their initiative-level dataset and source URLs in supplementary material, with no access restriction. Two authors directly accessed and verified the underlying data. The paper reports support from the University of Amsterdam's Artificial Intelligence for Health Decision-making programme, the Netherlands Organisation for Scientific Research through the AiNed ELSA Labs programme, and the European Commission's Erasmus+ EthicAI4Care project. The funders had no stated role in design, analysis, interpretation or publication, and the authors declared no competing interests.
Its biggest limitation is also explicit: absence from the public web is not proof that a control does not exist. Initiatives may rely on internal rules, institutional review, contracts or national law that the researchers could not discover. Searches relied mainly on English-language sources, with machine translation where possible, which may undercount programmes and policies elsewhere. The February cutoff also means later guidance—including a March 2026 All of Us clarification—was treated as context rather than used to change the study denominator.[1]
Why this changes decisions for researchers and participants
For research teams, the paper turns an abstract privacy debate into three procurement and workflow questions: must training occur inside a controlled environment, can a model or embedding cross the airlock, and may an external service receive participant-level prompts or files? Those questions should be answered before a tool is connected, not after a model has absorbed protected information. Programme operators also need tests for whether learned parameters are disclosive; the policies mapped by the paper do not yet offer validated technical thresholds.
For participants, the gap is about agency and accountability. A person may accept secondary health research without anticipating that a reusable model could be licensed, combined with other data or used in a different jurisdiction. Plain-language notices should explain material AI uses, model-export rules, commercial pathways and complaint routes. That does not require promising that every future algorithm can be predicted. It requires making the governing boundaries visible enough for consent, oversight and public debate to be meaningful.[1][2][3][4]
What would change the assessment
This is strong evidence of a public-policy documentation gap as of the study's search window. It is not evidence that 87 programmes operate without safeguards, nor proof that the three named programmes have solved genomic-AI governance. Confidence would strengthen if initiatives published current machine-readable policies, participant notices and audit results, and if independent researchers tested whether model-export controls actually prevent reconstruction, membership inference and unauthorised reuse.
The assessment would also change if a multilingual follow-up using direct programme contact found substantial unpublished governance outside the United States and United Kingdom. The most useful next comparison is not a league table of countries. It is whether programmes converge on enforceable controls while still enabling responsible cross-border science: secure environments, model-as-data review, restrictions on external services, bias evaluation, participant communication and a clear process for updating rules as models and attacks evolve.[1]
What this means for people
- Participants need to know when AI changes how their genomic data can be analysed, transformed or reused.
- Researchers need clear boundaries before they connect external tools or try to export trained models.
- Families and underrepresented communities may face harms that extend beyond the individual because genomic data reveal inherited relationships.
Global context
The review spans every UN-listed country and dependency but finds documented initiatives in 70 countries and territories. Regional comparisons are constrained by uneven public documentation and language coverage. The paper therefore supports a global governance-gap finding, not a conclusion that activity is concentrated only where English-language policies were easiest to find.
What the evidence does not yet show
- The study reviews publicly accessible documents and may miss internal, unpublished or non-indexed policies.
- English-language searching predominated, with machine translation used where possible, so non-English governance may be undercounted.
- Public mention of planned AI use does not show how extensively a programme uses AI or whether a model is deployed.
- The search dataset closed on 14 February 2026; later guidance is contextual and does not alter the denominators.
What to watch next
- Participant-facing explanations of AI use, model licensing and commercial pathways.
- Validated technical tests for whether trained parameters or embeddings can disclose participant information.
- Programme-level requirements for bias, fairness and subgroup-performance audits.
- Multilingual follow-up research that contacts initiatives directly and tests implementation, not only documentation.
Evidence trail
Sources used for this report
Links checked 2 October 2026
This report is labelled multi-source analysis. We summarise and analyse source material in our own words; company statements remain attributed claims until independently supported. Translated summaries preserve the meaning of the original source and link back to it. Read our editorial standards.
Continue the story
Related reporting
Government & Policy
Google appeals EU AI access and search-data orders
The 28 September court challenges contest July Digital Markets Act measures. Google raises privacy and security objections; the Commission says its safeguards protect users. No ruling has been made.
4 min · 2 sources
Government & Policy
India creates a senior group to coordinate AI governance and adoption
India's government announced an AI Governance and Empowerment Group to coordinate policy across ministries as the country expands public-interest AI, compute and sector adoption.
4 min · 1 source
Government & Policy
Governments are using AI—but how many can prove it improves public services?
The OECD reports government AI use in 35 of 36 participating member countries, yet only 10 say they measure financial or non-financial impact. The comparison maps national practice; it does not audit individual systems or prove public benefit.
7 min · 2 sources
Reader discussion
Add evidence, experience or a question
No account is required. Reader notes are published after a brief civility, relevance and safety check; disagreement is welcome.
Published reader notes
0No published reader notes yet. You can start the evidence-led discussion above.
Prefer a private correction or response? Contact the newsroom.