The emerald ash borer arrived in Canada by accident. Nobody designed it, nobody deployed it, and nobody aimed it. It has still killed tens of millions of ash trees across Ontario, Quebec, New Brunswick and Nova Scotia, and Natural Resources Canada estimates the cleanup will cost municipalities up to $2 billion over thirty years.
That is what an invasive species does when no one is trying. It is worth asking what one would do if someone were.
We keep imagining the wrong attack
When biotechnology comes up in national security conversations, we default to pandemics. Engineered pathogens, aimed at people. That makes intuitive sense, because war has always been fought between humans, so we assume biological weapons would be too.
But the targets of modern conflict have been widening for years. Infrastructure, supply chains, energy grids, financial systems. There is no obvious reason biology would be the exception, and a great deal of Canada’s wealth is biological: forests, crops, livestock, fisheries, water.
This is not speculative. Between 1951 and 1969 the United States produced and stockpiled pathogens targeting wheat and rice. The Soviet Union ran an anti-agriculture program, code-named “Ecology,” that employed roughly 10,000 people and targeted crops, poultry and livestock. Both superpowers looked at attacking what a rival nation eats and exports, and both concluded it was worth serious money.
An attack like that would look like a bad harvest, or a new pest, or an unlucky year. That ambiguity is exactly what makes it attractive to an adversary who wants damage without attribution. It also means the response window is incredibly short. By the time you have established that something was deliberate, it has already spread.
The barrier that nobody legislated
Serious expertise in microbiology, immunology or chemistry has always taken a decade or more to build. That cost has functioned as security. The people capable of doing real harm in these fields were, almost by definition, people who had spent years inside institutions that screened them, trained them and watched them work. The barrier was never a regulation. It was the sheer difficulty of knowing enough.
AI is very good at compressing exactly that kind of difficulty, and the erosion is further along than most people assume. Work published by the Forecasting Research Institute found that current models already match teams of experts on a standard virology capabilities benchmark, a milestone most of the experts they surveyed had not expected before 2030. The protective factor we have leaned on for a century is not something that might weaken later. It has already shifted, and nobody voted to remove it.
The more useful finding in that same research is what happened next. When the experts were asked to account for safeguards, their risk estimates dropped back close to baseline. What did the work was access control on the models themselves and screening at the point where physical materials are ordered. The remaining constraints, in other words, are procedural and physical rather than intellectual, and procedural and physical constraints are precisely the kind of thing a government can build.
That reframes the policy question. It is not whether specialist knowledge stays scarce, because it will not. It is whether Canada has the institutions to operate in a world where it is not. The reasonable conclusion is that Canada should expect to face biological threats from a wider range of actors, foreign and domestic, than it does today.
Two races, not one
Most of the available policy attention right now is going to AI, and biotechnology is sitting in its shadow. That is odd, because they are not separate races. Synthetic biology, biomanufacturing, genomics and machine learning are converging, and AI is already accelerating discovery across the life sciences by letting researchers analyze biological data, model complex systems and test hypotheses at a pace that was not previously available. Treating biotech as its own sector misses that it has become a branch of the digital revolution. We cannot predict which capabilities come out of that convergence or when, but assuming they are coming is the only defensible planning position.
Why the data matters more than the model
The useful thing about AI in biology is also the thing that makes it a governance problem: these systems are built out of data.
Architectures and training methods get published, copied and commoditized within months. Large, clean, well-curated biological datasets do not. They take decades and enormous public investment to produce, through sequencing runs, field trials, clinical cohorts and environmental surveys. In a field where the methods are shared and the data is not, the data is the capability.
Canada has a lot of it. Decades of publicly funded research across genomics, agriculture, forestry, fisheries and human health. Right now it is a byproduct of grant-making rather than strategic infrastructure. Nobody can say what it will be worth in twenty years, and that is exactly the problem. You do not get it back once it is gone, and the decision to let it go is not being made in any one place. It is being made by default, across a hundred separate contracts, licensing deals and data-sharing agreements that nobody is reading as security decisions.
What Ottawa has done, and what it hasn’t
COVID-19 made North America’s lack of biological preparedness impossible to ignore, and it has genuinely shifted how governments talk about readiness. But policy still gravitates toward risks that have already happened, because those are the ones you can picture.
Canada still lacks a dedicated national biosecurity strategy. Its main framework for deliberate biological threats, the CBRNE Resilience Strategy, is more than a decade old. It was written in a counterterrorism era, it commits on its own terms to a review every five years, and it predates the gene-editing tools that now define the field. A recent federal evaluation of the Public Health Agency of Canada’s biosecurity program did name synthetic biology as an emerging risk, but did not address AI or data at all.
There is real movement on research security. Life science technologies including genomic sequencing, gene drives and synthetic biology appear on Canada’s Sensitive Technology List. Since May 2024, the Policy on Sensitive Technology Research and Affiliations of Concern has made researchers in those areas ineligible for federal funding if they are affiliated with named foreign institutions tied to military or state security bodies.
That is a meaningful step, and it addresses one question: who does the work. It says nothing about where the resulting data lives, who can access it in ten years, what happens when the spin-out gets acquired, or which jurisdiction’s law governs the server it sits on.
It is also worth noticing what none of this covers. Almost every instrument above is oriented toward human health and laboratory pathogens. The surveillance networks that would actually catch an engineered crop disease or a modified forest pest sit with the Canadian Food Inspection Agency and the agricultural and forestry research system, which are funded and mandated as regulatory and economic bodies. Nothing currently asks them to think about an adversary.
The case for moving first
Canada cannot opt out of this. China and the United States are not slowing down, and the only way to influence how these technologies get governed is to be building them. In practice that means controlling the stack end to end:
- Data, held in Canada under Canadian jurisdiction
- Compute, domestic enough to train and run models on it
- Models, with Canadian capacity to build, test and evaluate them
There is real progress on the middle one. The 2024 Sovereign AI Compute Strategy put roughly two billion dollars behind domestic compute. This June’s AI for All strategy promises a public AI supercomputer and a Sovereign Technology Alliance with trusted partners. Meanwhile the Canadian Genomics Strategy describes our own genomic datasets as “poorly coordinated and difficult to access due to institutional and jurisdictional silos.”
Not one of these initiatives treats biological data as a defence asset.
And if biology does become a contested domain, our universities and biomanufacturing capacity stop being purely economic assets and become defence ones. The ability to identify a novel biological threat, characterize it and manufacture a countermeasure at scale is a national capability in the same sense that shipyards and steel production once were. That holds for a crop pathogen as much as for a human one. You cannot stand it up during a crisis. Whether Canada has it in 2040 is being decided right now, in research funding and industrial policy, not in defence procurement.
Who should own this
A recommendation that lands on “the government” is not a recommendation. Canadian biological data currently sits with CIHR, Genome Canada, the Public Health Agency, the Canadian Food Inspection Agency, Agriculture and Agri-Food Canada, the provinces and the universities. Each has a legitimate claim to its piece. None has a security mandate, and none plans past its next funding cycle.
That horizon problem is why this cannot live with a research funder. A file that pays off in 2040 does not survive a four year electoral cycle. Defence institutions are built to think in decades because procurement forces them to.
But putting biological data directly under the Canadian Armed Forces would fail for a different reason. Health data is provincial, a great deal of it exists only because patients and research subjects consented, and military custody would drive away both domestic participants and international collaborators. You would end up with a better secured repository holding considerably less data, which is a net loss in capability.
Canada has already solved this problem once, in a different domain. The Communications Security Establishment is not inside the Department of National Defence. It has been a standalone agency reporting to the Minister of National Defence since 2011, operating under its own statute, with its chief reporting directly to the minister. It is reviewed by three independent bodies: the Intelligence Commissioner, the National Security and Intelligence Review Agency, and the National Security and Intelligence Committee of Parliamentarians. Its civilian-facing arm, the Canadian Centre for Cyber Security, advises infrastructure operators, industry and the public on securing systems it does not own.
That is the template. Canada should create an equivalent agency for biological data: attached to the defence portfolio, established by its own legislation, with a fixed statutory mandate and reporting obligations to Parliament rather than to a department. Its job would be to set security standards for biological datasets, accredit the repositories that hold them, operate the tiered access system, and advise universities and industry on custody and foreign access risk. It would hold federal data directly where consent allows, and accredit rather than absorb everything else, which leaves provincial jurisdiction and research ethics intact.
The CAF’s role in that structure is to be the requirements-setter and the customer. It defines what capability the country needs in order to detect, characterize and counter a biological threat, and it holds the procurement authority to contract biomanufacturing surge capacity before a crisis rather than during one. That is the part the military is genuinely best at, and it does not require the military to hold a single patient record.
The statute is what does the depoliticizing work here, not the uniform. The Bank of Canada and the Auditor General outlast governments because their mandates are legislated and their reporting runs to Parliament. A cabinet directive does not survive a change in government, and a line item in a departmental plan barely survives a budget. The independent review in that model is not decoration either. CSE generates sustained privacy controversy, and external review is the reason a structure like it is acceptable at all.
Deciding earlier
Meaningful advantage in national defence never comes from following, because following concedes that someone else sets the agenda and that our job is to react to it. The only route to genuine influence, in AI governance or in security, is to work on a longer horizon than the people you are competing with. For a middle power that is the one form of advantage that does not require outspending anyone. It requires deciding earlier.

Leave a Reply