Artificial intelligence is moving into national genomics programmes faster than explicit public rules for governing its use, according to a new global review of national genomics initiatives.
Researchers from the University of Amsterdam examined publicly available information from 240 countries and dependencies and identified 90 qualifying national, territory-level or cross-border genomics initiatives across 70 countries and territories. Current or planned artificial intelligence use was documented in 32 of the 90 initiatives, or 36%. Yet the researchers found publicly available AI-specific governance policies in only three initiatives across two countries.
The finding matters because national genomics programmes combine unusually sensitive biological information with increasingly powerful computational tools. Genomic data can identify individuals, reveal information about biological relatives and support research extending far beyond the purpose for which a sample was originally collected. AI adds another layer of complexity because trained models and their outputs can themselves become possible routes through which sensitive information is disclosed.
A global search for genomics programmes and their AI rules
The study, published in npj Digital Public Health on 1 October 2026, used a structured review of publicly accessible programme websites, policy documents and related sources. Initial searches ran from March 2024 to June 2025 and were repeated between 1 and 14 February 2026 to verify programme status and identify newer AI-related documentation.
For each of 240 countries and dependencies, the researchers searched combinations of country names, terms indicating national scale, genomics-related keywords and descriptors such as programme, initiative, project, biobank and precision medicine. Initiatives were included when public evidence showed that they collected, generated, analysed, enabled access to or distributed human genomic information from a population or patient cohort and were government funded, government led or operated as de facto national resources.
Commercial consumer genetic-testing businesses, genealogy projects, standalone disease-specific cohorts without a broader national resource role, non-human genomics projects and strategy documents without a qualifying genomic resource were excluded.
The researchers then conducted targeted searches for terms including machine learning, deep learning, predictive algorithms, natural language processing and generative AI. They also looked for researcher-facing and participant-facing policies that explicitly addressed AI use.
AI was present or planned in more than a third of initiatives
The final dataset contained 90 initiatives in 70 countries and territories. Among the 73 initiatives reporting a cohort or sample size, the scale ranged from small pilots involving tens or hundreds of people to population-scale programmes approaching one million participants or samples.
Building national genomics capacity and research infrastructure was the most common stated objective, appearing in 79 of 90 initiatives, or 88%. Identifying disease predisposition and informing personalised treatment appeared in 73 initiatives, or 81%, while 71 initiatives, or 79%, aimed to build national reference genomic resources that better represent genetic diversity.
Clinical integration was an explicit objective in 27 initiatives, or 30%, and community engagement or education in 24, or 27%. Overall, 81 of the 90 initiatives pursued at least two of the objective domains coded by the researchers.
AI use was less universal but already substantial. Thirty-two initiatives, representing 36% of the 90 studied, reported current or planned AI use. At country level, 29 of the 70 countries and territories represented in the dataset, or 41%, had at least one initiative reporting current or planned AI integration.
Descriptions of that AI use were often broad. Programmes referred to predictive modelling, data-processing pipelines or computational infrastructure without necessarily identifying individual models or explaining whether AI was governed differently from conventional analysis.
Only three initiatives had identifiable public AI-specific policies
The sharpest contrast emerged when the researchers examined governance. Publicly available AI-specific governance guidance was identified for only three initiatives: Genomics England, UK Biobank and the United States All of Us Research Program.
This does not mean the remaining initiatives operate without governance. Many are subject to data-access agreements, confidentiality requirements, research ethics rules and national data-protection law. The narrower finding is that explicit, publicly discoverable rules dealing specifically with AI were rare.
Across the early AI-specific policies, three recurring strategies emerged. First, participant-level data were required to remain inside secure computing environments. Second, trained models could be treated as potentially disclosive outputs rather than harmless software artefacts. Third, programmes restricted the use of external generative AI services when participant-level data were involved.
These controls respond to a distinctive problem created by machine learning. A model trained on sensitive data may retain information about its training set. Techniques such as membership inference and model inversion can, under some conditions, reveal whether particular records contributed to training or recover sensitive characteristics. Exporting a trained model can therefore create a different disclosure pathway from exporting a conventional table of results.
Secure environments are becoming an important boundary
Genomics England provides one example of a tightly controlled model. Its Research Environment rules allow machine-learning work within an approved project but restrict exporting trained models from the secure environment. Researchers can export suitable testing statistics and outputs after review, while the programme has indicated that its policies on trained-model use and export remain under active review.
UK Biobank similarly uses controlled research infrastructure and restricts participant-level data from being fed into publicly available generative AI models. The distinction is important because a public chatbot or external application programming interface can transfer information outside the governance environment in which researchers originally received access.
The All of Us Research Program also requires participant-level data to remain within its Researcher Workbench. Its guidance gives the concrete example that individual-level data cannot be sent to an external ChatGPT API, while permissible aggregate information can be analysed externally when dissemination requirements are met.
At the funder level, the researchers also examined a 2025 US National Institutes of Health notice governing controlled-access human genomic data. The NIH classified trained generative AI models and their parameters derived from controlled genomic datasets as data derivatives, placing restrictions on their transfer and retention.
Important governance questions remain largely unanswered
Even the initiatives with explicit AI rules did not cover every issue raised by the technology. The review found no requirement among the identified initiative policies for bias auditing or fairness assessment of AI models trained on programme data. It also found no initiative embedding AI governance in clear participant-facing policies explaining how AI might be applied to contributed data.
That participant communication gap may become increasingly important as national genomics resources support secondary research, commercial partnerships and cross-border collaborations. Consent to contribute genomic information can be meaningful only when participants have a reasonable understanding of how their data may be used, yet rapidly changing AI capabilities make future uses difficult to anticipate.
The researchers argue that programmes should move AI governance into their core data-access rules and participant communications rather than leaving it mainly in FAQs or standalone guidance. They identify priorities including secure computation, explicit model-export rules, restrictions on external AI services, stronger attention to bias and clearer communication with participants.
Why the timing matters
The policy landscape is changing while genomics programmes are still deciding how to use AI. In Europe, the EU AI Act is introducing risk-based obligations, while the European Health Data Space will eventually shape cross-border secondary use of health and genomic information. Different national interpretations could make international genomic research harder if programmes develop incompatible rules for model training, export and reuse.
The authors therefore see national genomics initiatives as an early test case for a much broader governance problem. Similar questions apply to biobanks, electronic health-record repositories and other research infrastructures that combine sensitive personal information with machine learning. Rules developed in genomics could become precedents for how public research systems distinguish data analysis from model development and how they control the movement of trained AI systems.
The study maps public policy, not all policy
The authors emphasise several limitations. Their analysis was restricted to publicly accessible and web-indexed material. An initiative may therefore have internal AI governance that the researchers could not discover. Public documentation also varied greatly between countries and programmes.
The searches relied mainly on English-language sources, with machine translation used where possible for non-English information. This could undercount policies in jurisdictions where documentation is difficult to identify through English-language search terms. The presence of more detailed policies in the United Kingdom, United States and European contexts should consequently not be interpreted as proof that governance activity is absent elsewhere.
The study also maps stated policy rather than measuring compliance. A rule prohibiting researchers from sending participant data to an external generative AI service does not by itself establish how consistently that rule is followed or how effectively violations can be detected. Likewise, the review does not test whether existing controls prevent model inversion, re-identification or other technical disclosure risks.
Still, the numerical gap is striking. AI was already reported or planned in 32 national genomics initiatives, while explicit public AI-specific governance was found in only three. As AI becomes a routine part of biomedical research, the challenge for genomics programmes is increasingly not whether the technology will be used, but whether governance develops quickly enough to define where, how and under what conditions it can be used responsibly.
Source Information
Study: Global patterns and gaps in AI policies of national genomics initiatives
Authors: James W. Hazel, Menno Scheurwater, Anniek de Ruijter and Mahsa Shabani
Journal: npj Digital Public Health, volume 1, article 38
Published: 1 October 2026
DOI: 10.1038/s44482-026-00043-5








