Mara Quintero learned the shape of the new world on a Tuesday in 2034, watching a progress bar refuse to move.
She ran a four-bench community lab above a tire shop in East Oakland, the kind of place that used to feel like the future arriving early. Her order that morning was boring by design: a short stretch of synthetic DNA for a soil bacterium that pulls nitrogen out of the air, a project she'd been nursing for two years with a grant from a local farm co-op. She uploaded the sequence, paid the fee, and watched the screening queue hold her request in amber. Pending clearance. By noon it had become Flagged for review. By Friday it was Denied: identity tier insufficient.
Nothing she had designed was dangerous. The problem was Mara. Her lab held a community license, not an institutional one, and somewhere in the previous year the threshold for "verified researcher" had moved without an announcement. The gene she wanted was legal. The act of asking for it had become a privilege she no longer qualified for.
To understand how a nitrogen gene ended up behind a velvet rope, you have to go back to the decade when the people building this system were trying to solve a real and frightening problem.
The threat was genuine
In 2017, researchers at the University of Washington did something that sounded like a prank and wasn't. They wrote a piece of malware, encoded it into a strand of synthetic DNA, and fed that strand into a gene-sequencing machine. When the machine read the DNA, the hidden code ran and handed the researchers control of the computer doing the reading.1 The lesson landed hard in two fields at once. Biology had become information, and information could be weaponized. The seam between the two had a name now: cyberbiosecurity.
The fear that followed was not science fiction. A benchtop synthesizer can print a custom strand of DNA in an afternoon. Order the right sequence and you are a short series of steps from a pathogen. Through the early 2020s, security teams kept showing that the guardrails leaked. You could split a dangerous sequence into harmless-looking fragments, scatter the orders across different vendors, and slip past the screening software that was supposed to catch you.
So the state moved. In October 2023, a sweeping executive order told the U.S. government to tie its research dollars to screening: if you wanted federal money, you had to buy your DNA from suppliers who checked what they were selling and who they were selling it to.2 A year later, a federal framework spelled out the mechanics, down to scanning every fifty-nucleotide window of an order and matching the buyer against a list of sequences of concern.3 In May 2025, another order pushed the same logic deeper into the research system itself.4 Nonprofit tools appeared to do the checking for free, so no lab could claim it was too expensive to comply.5
Every piece of this was reasonable. Each step closed a door that genuinely needed closing. And each step also did something quieter, something nobody put in a press release: it moved the power to say no out of the lab and into a checkpoint.

The checkpoint became the asset
Screening only works if everyone screens against the same thing. That logic, sound on its face, pulled the whole industry toward a handful of clearinghouses that held the master databases: the catalog of dangerous sequences, the registry of approved buyers, the keys that turned a pending into a yes. By the early 2030s, the overwhelming majority of the world's gene-synthesis orders passed through three of them.
This is the turn the 2020s did not see coming. The thing built to protect synthetic biology became the thing that controlled it. Whoever ran the screening ran the field. The clearinghouses did not need to manufacture a single strand of DNA. They sat at the gate, and the gate was the business.

And the gate had a second product. To screen a buyer, you have to know the buyer, which means you have to collect and keep an enormous amount of identity. The system that had to verify everyone became the system that knew everyone. Genetic and biometric records, the most permanent data a person owns, piled up inside the same companies that decided who could build.
We already had a warning about what that pile is worth. In 2023, hackers walked into 23andMe using nothing more exotic than reused passwords and pulled profile data on roughly 6.9 million people, much of it about ancestry and DNA relatives.6 The company later settled for thirty million dollars and, by 2025, filed for bankruptcy, its vault of genomes turned into an asset to be sold in a liquidation. Your DNA, it turned out, was a security. Bio-securities, traded like any other distressed holding.
Who won, and who paid
By 2036 the consolidated screening regime can claim a real victory: no garage-built pandemic, no headline catastrophe, a genuine wall against the worst actors. That wall is not nothing, and the people who built it were not wrong to want it.
But walls have two sides. The winners are the incumbents who own the checkpoints and the brokers who trade the identity data flowing through them. The losers are the Mara Quinteros: the community labs, the small teams, the researchers in countries that never got a seat at the clearinghouse table, all of them now standing outside a system that decides, quietly and without appeal, who counts as legitimate. The open, distributed promise of synthetic biology, the version where a bench above a tire shop could fix a local problem, narrowed into a permissioned world where biology is something you are granted rather than something you do.
Mara eventually got her nitrogen gene. She borrowed an institutional login from a sympathetic professor two cities over and ordered it under his name. The sequence cleared in nine minutes.
She had not become more trustworthy. She had simply borrowed someone else's place in line. That is the whole story of cyberbiosecurity in one small act: the danger was real, the fix was real, and the fix handed a few institutions the keys to the most basic verb in biology, the permission to make.
Author's Note. Mara Quintero and the 2034 scene are fictional, a composite built to show a plausible end state. The events through 2025 are real and sourced below: the 2017 DNA-encoded malware demonstration, the 2023 and 2025 executive orders and the 2024 screening framework, the free screening tools, and the 2023 23andMe breach. The consolidation of screening into three clearinghouses and the 2030s "bio-securities" market are projections, not reported fact. They are where the documented drivers point, not a prediction of certainty.
