Who Regulates a Biological Computer?

What a biological computer in Singapore reveals about the infrastructure beneath AI governance

By Louize Clark

Almost every AI governance conversation of the last few years has quietly assumed something about the technology underneath it: compute happens in silicon. Chips sit in racks, racks sit in data centres, and data centres are things we can locate, secure, insure, audit and eventually regulate. The systems running on top have become increasingly complicated, but the physical infrastructure supporting them has remained comparatively familiar.

That assumption became rather less reliable this month. At the National University of Singapore, NUS Medicine, data-centre operator DayOne and Australian biotechnology company Cortical Labs unveiled a prototype Biological Data Centre containing twenty biological computing units. Inside those units are living human neurons, cultured from stem cells and connected to conventional computing hardware through microelectrode arrays. They require feeding, controlled conditions and life-support systems, and they are being used to perform computational work.

It is the kind of story that immediately invites a futuristic response. Human neurons inside a computer inevitably lead us towards questions about consciousness, sentience and whether we are beginning to blur a line that should perhaps remain clear. There is also the more practical technology argument: biological neurons may ultimately prove capable of performing certain kinds of learning or adaptive computation using far less energy than conventional silicon.

Both conversations matter. Neither is the one that stayed with me.

I am not the person to tell you whether biological computing will work at scale, whether it will become commercially viable or whether it will remain confined to specialist research environments. Those are scientific and engineering questions, and there are people considerably better qualified than me working on them.

What interests me is something slightly different. The technology does not need to become mainstream before it exposes a problem. Its existence is already showing us how heavily our current ideas about AI governance depend on assumptions about what the infrastructure underneath AI actually is.

We built governance around a particular kind of machine

Most of the frameworks organisations use to govern technology were developed around infrastructure that is inert, replicable and relatively easy to categorise. A server is equipment. A processor is hardware. Software is code. Human biological material belongs largely within medicine, research and biotechnology.

Biological computing sits awkwardly between those worlds.

A system built from human-derived neurons may simultaneously be a biotechnology platform, a research environment, a computing system and, eventually, a commercial service. Each of those categories already has regulation around it, but they have historically developed separately because there has been little reason for them to overlap.

That is what makes this development interesting from a governance perspective. It would be misleading to suggest that biological computing is somehow entirely unregulated. Human biological material, stem-cell research, data processing, cybersecurity and commercial technology are already subject to different forms of oversight. The difficulty is that those frameworks do not necessarily line up neatly around a system that combines all of them.

A health or research regulator may be interested in how the cells were derived and under what conditions they are maintained. A bioethics committee may be concerned with consent and the possibility of sentience. A cybersecurity team will be concerned with system integrity. A data regulator will be concerned with the information moving through the system. A commercial customer may simply want to know whether the service is reliable and whether it meets the terms of a contract.

None of those perspectives is wrong. The problem is that each can see only part of the architecture.

The regulatory problem, though, is only one half of it. Even if the boundaries between health regulation, bioethics, cybersecurity and data governance were perfectly clear, most organisations would still face another difficulty: they are increasingly distant from the infrastructure they actually depend upon.

Most organisations do not really know what sits underneath the services they use

One of the themes I keep returning to in these papers is that AI rarely enters an organisation through one clean procurement decision. Sometimes it does. A company identifies a tool, evaluates it, signs a contract and introduces it deliberately. But increasingly AI is inherited through software organisations already use, or embedded into products so deeply that the people using them barely register that AI is involved.

Biological compute introduces the possibility of the same thing happening one layer further down.

An organisation does not need to own a biological computer in order to depend on one. If this technology becomes useful for particular workloads - fraud detection, cybersecurity, robotics, drug discovery or something we have not yet anticipated the most likely commercial model is not that every business installs a rack of living neurons in its own building. The capability will be consumed as a service.

A company may therefore buy a product from one supplier, which relies on another platform, which obtains specialised compute from another provider further down the chain. Somewhere beneath all of that, part of the processing could be biological. To the organisation at the top, nothing particularly dramatic has happened. It still sees software, a contract, an API and an invoice, yet the infrastructure underneath the service has changed, and I think that is the part that matters.

The nature of the infrastructure may eventually become a governance issue in its own right

For most of computing history, the physical substrate has not mattered greatly to the customer. If the processor running your payroll system changed from one generation of chip to another, you probably neither knew nor cared. What mattered was that the service remained available, secure and reliable.

Cloud computing pushed organisations even further away from the physical infrastructure supporting them. AI has extended that separation again. Businesses can now consume increasingly powerful capabilities without necessarily knowing which model is operating, where it is hosted or what dependencies sit underneath it.

Biological computing challenges the assumption that the substrate will always be irrelevant to the customer.

Living biological material has characteristics that conventional processors do not. It has an origin. It has a life cycle. It may carry consent conditions associated with the material from which it was derived. It requires maintenance to remain viable and may change over time in ways that ordinary hardware does not. Depending on how the science develops, it may also create ethical considerations that cannot be dealt with by a conventional technology risk assessment.

Once those characteristics become part of a commercial computing service, questions that currently belong largely to laboratories and ethics committees can begin to move into ordinary supply chains.

That is not because every procurement team suddenly needs to become expert in neuroscience. It is because provenance carries responsibilities.

Businesses are already becoming more familiar with technological provenance. They are increasingly asked where their software comes from, which AI model is being used, where data is processed and which suppliers sit underneath a service. If biological computing develops commercially, that chain may eventually include another form of provenance altogether: the origin and status of the biological material forming part of the computing system.

Now that would be a very strange question to find on a supplier questionnaire today, but in the future it may not be.

The bigger lesson is not really about neurons

Biological computing may remain niche. It may prove too difficult or expensive to scale. It may end up solving a handful of highly specialised problems without ever entering mainstream enterprise technology. None of that would make what is happening in Singapore unimportant.

The reason I think this prototype is worth paying attention to is that it exposes something much broader about the way we govern technology.

We tend to build governance around categories we already understand. We identify a technology, give it a name, decide which teams and regulators are responsible for it and gradually build standards, controls and procurement processes around it. Infrastructure rarely evolves in such an orderly way. It changes first. The vocabulary and governance structures catch up afterwards.

Biological computing appears to be sitting in that uncomfortable space now. It is not necessarily outside regulation and it is not, simply by virtue of being unusual, inherently dangerous. It is simply difficult to place neatly inside structures that were created when computing infrastructure meant something much more predictable.

Those moments are useful because they expose assumptions that otherwise remain invisible.

One of those assumptions is that organisations do not really need to know what their computing infrastructure is made of. For a long time that was largely true. Increasingly, I am not sure it is.

Today the unusual example is a prototype data centre containing living human neurons. Tomorrow the infrastructure beneath a service may change in some entirely different way. The governance challenge is not to predict every technology that could emerge.

It is to make sure an organisation has enough visibility to recognise when the environment underneath it changes.

That is why I keep coming back to the same distinction. Asking an organisation whether it uses AI may tell us something about the applications people can see. It tells us considerably less about the infrastructure the organisation has actually become dependent upon.

And as the technology beneath those applications becomes stranger, more complex and increasingly remote from the organisations consuming it, I suspect the more important question will be a much simpler one: What are we actually connected to?

AI Policies UK helps organisations see the AI infrastructure they're already standing on, chosen, inherited and embedded — before decisions like this one have to be made under pressure. Get in touch: louize@aipolicies.uk

Next
Next

You Cannot Secure What You Cannot See