If AI is going to watch for the next outbreak, the harder question is whether we can trust the data it watches — and the data it produces.
Across this work we keep arriving at the same quiet conclusion. Whether the subject is AI-assisted epidemic intelligence, pathogen access and benefit sharing, disease-related trade decisions, or the governance systems that surround a biological event, the limiting factor is rarely a shortage of data. It is whether the data can be trusted — where it came from, when, whether it has been altered, and whether its journey can be reconstructed later. That is a question of provenance, and it is becoming one of the most important and least glamorous problems in One Health Security.
A note on disclosure before we go further: One Health Security and The BioChain were both founded by Ashley Morgan. What follows is our own view of where verifiable-data infrastructure fits the outbreak-AI arena — offered as analysis, not as a neutral product review.
Why provenance is the real bottleneck
Consider what modern biological surveillance actually produces. A farmer or clinician generates a first observation. A sample is collected, labelled, transported and stored. A laboratory sequences it, and the genome is uploaded to a database. Researchers elsewhere download it, combine it with other data and use it in analysis. A manufacturer may eventually build a product from what that analysis reveals. An AI system, scanning across all of this, may surface a signal or generate a summary that decision-makers rely upon.
At every step, information is copied, transformed and moved between institutions that use different systems, standards and jurisdictions. And at every step, something can be lost: the link between a genome and the sample it came from; the record of who accessed what and when; the distinction between an original observation and a downstream inference. When an AI epidemic-intelligence system tells an analyst that an outbreak may be occurring, the analyst needs to know which reports produced that assessment. When a genomic result informs an international decision, everyone in the chain needs confidence that the result still corresponds to the biological material it claims to describe. As we argued in the AI piece, an answer needs a route back to its evidence — and most biological data, today, cannot fully provide one.
Where the gaps bite hardest
This is not an abstract concern. It appears at precisely the points our other analyses identified as fragile.
Pathogen sharing and benefit sharing. The emerging PABS system and the Nagoya Protocol both depend on knowing who provided which biological material or sequence, under what terms, and how it was subsequently used. Benefit sharing is impossible to administer if the provenance of a pathogen — and of the digital sequence information derived from it — cannot be established. Provenance is the precondition for equity.
Cross-border genomic surveillance. Networks such as the WHO Hub’s International Pathogen Surveillance Network move genomic data across jurisdictions that have different rules and different levels of trust. For that data to be usable, it has to remain connected to its origin and protected against undetected alteration, while respecting national sovereignty over the underlying material.
Trade and regionalisation. Under the WTO SPS Agreement, a country can keep exporting from unaffected regions during an outbreak only if trading partners trust its surveillance and animal-movement records. Regionalisation is, in effect, a provenance claim: this animal came from here, moved through there, and was tested then. Weak traceability forces broad, costly precaution.
Auditable AI. An AI-generated summary can sound authoritative even when the underlying evidence is thin. Without an evidence trail, a fluent output and a well-founded one look identical — which is exactly the failure mode a serious epidemic-intelligence or governance system cannot afford.
What a provenance layer looks like
This is the specific gap that The BioChain is built to fill. Rather than being another detector or another database, it describes itself as an infrastructure layer that sits between data capture and the systems downstream of it, with the aim of making biological data secure, traceable and audit-ready. In practice that rests on three ideas: immutability, so a record cannot be altered without detection; traceability, so records are timestamped and linked back to their source; and integration, so the layer connects to existing systems through APIs rather than requiring anyone to rip out and replace what they already run. It is designed around a “hash-on-chain” approach and a sovereign-data architecture, and it is built to align with the regulatory frameworks that already govern serious life-science and agricultural data — the United States’ 21 CFR Part 11 and the European Union’s Annex 11 among them.
The point of that regulatory alignment is important for health security. The systems that matter most in an outbreak — clinical laboratories, veterinary services, food-safety authorities, genomic networks — already operate under strict data-integrity rules. A provenance layer is only useful if it speaks their language rather than adding a parallel bureaucracy, and if it works across the human, animal and environmental domains that One Health insists on connecting.
Following the biology, not the institution
What makes this genuinely a One Health question is that the same infrastructure applies wherever biological data is generated. The BioChain’s existing directions illustrate the point: a livestock-biosecurity application (HerdWare) captures animal-health data at the farm; multi-site tropical-medicine genomics work carries human samples and sequences across jurisdictions; and an applied-livestock consortium provides a shared data backbone across organisations. These are not separate problems. They are the same provenance problem appearing in the animal, human and cross-institutional layers of the biological system — the very interfaces where, as we have argued, information tends to go missing.
The first signal of a zoonotic threat is often an animal one. If that animal-health data is captured with its provenance intact and can be connected — lawfully and verifiably — to human-health and genomic data when it matters, the interface between sectors becomes faster and more trustworthy. If it is captured in a way that cannot later be reconciled or relied upon, the interface stays slow no matter how good the sensors on either side of it are.
What provenance is not
It is worth being precise about the limits, because over-claiming here would repeat exactly the mistake we warn about elsewhere. A provenance layer does not detect outbreaks; that is the work of surveillance and epidemic intelligence. It does not decide anything; that remains with public-health professionals and sovereign governments. And crucially, data integrity is not data accuracy: a system can prove that a record has not been altered without being able to prove that the original record was correct. Verifiable provenance guarantees that you are looking at the same data everyone else is, unchanged since it was captured — not that the data was right in the first place. That is a real and useful guarantee, but a bounded one.
So provenance sits underneath detection and decision rather than replacing either. It is the trust substrate: the thing that lets a signal, a sequence, a shared pathogen or a trade claim be relied upon by people who did not generate it and may not trust each other. In a field increasingly mediated by AI — where outputs are fluent, fast and easy to over-trust — that substrate becomes more important, not less.
The connection to Solon
This is why the provenance question runs directly into our Solon research. Solon is an experiment in governance intelligence: mapping the laws, institutions and decision thresholds that surround a biological event, with every conclusion traceable back to an authoritative source. A governance-intelligence system that cannot show its evidence is worthless; so is an epidemic-intelligence system that cannot show which reports produced a signal. Both depend on the same foundation. Whether the data being reasoned over is a news report, a genome, a treaty provision or an animal-movement record, the requirement is identical: a verifiable route back to where it came from. Detection, governance and the data layer beneath them are three parts of one system — and the weakest of the three sets the pace of the whole.
Where this goes
The next few years will see enormous investment in the sensing side of health security — more AI, more genomic surveillance, more open-source scanning. That is welcome, and overdue. But sensing without trustworthy data, and speed without provenance, will reproduce the failure modes we have already seen: confident outputs no one can verify, signals that cannot be reconciled across borders, and benefit-sharing promises that cannot be enforced because no one can establish who shared what. Building the provenance layer is less visible work than building the next impressive AI demo. It is also, we think, closer to the actual bottleneck. Once AI helps us see a biological threat sooner, the question is not only whether our institutions can move quickly — it is whether they can trust what they are looking at.
Work with One Health Security
Applied research, advisory and the governance of biological data
We work with organisations building the sensing, data and governance layers of health security — from surveillance and genomic networks to the institutions that have to act on what they find. If you are working on provenance, One Health data or AI for outbreak intelligence, we would like to hear from you.
Questions & Answers
What does “data provenance” mean in this context?
Being able to establish where a piece of biological data came from, when, and whether it has been altered since — a traceable route back to the evidence behind a signal, a genome or a trade decision.
Why does provenance matter for AI epidemic intelligence?
Because an AI-generated summary can sound authoritative even when the underlying evidence is thin. Without an evidence trail, a fluent output and a well-founded one look identical — a failure mode a serious epidemic-intelligence system cannot afford.
What does The BioChain actually do?
It describes itself as an infrastructure layer that makes biological data secure, traceable and audit-ready, resting on immutability, timestamped source-linking and API integration, and built to align with regulatory frameworks such as 21 CFR Part 11 and EU Annex 11.
Does provenance guarantee the data is accurate?
No. Data integrity is not data accuracy: a system can prove a record hasn’t been altered without proving the original record was correct. It guarantees you are looking at the same, unchanged data — not that the data was right in the first place.
Where does this provenance gap matter most in practice?
At exactly the points other One Health Security analyses identify as fragile: PABS pathogen and benefit sharing, cross-border genomic surveillance, SPS trade regionalisation, and auditable AI outputs.
Is there a conflict of interest in this piece?
Yes, and it is disclosed directly: One Health Security and The BioChain were both founded by Ashley Morgan, so this article is offered as the authors’ own analysis rather than an independent product assessment.
Related One Health Security work
This piece is a companion to AI Is Already Watching for the Next Outbreak and our applied-research project Building Solon. It connects to PABS: Who Owns a Pathogen?, The Nagoya Protocol and The Law Has a One Health Problem.
Applied Research note, August 2026. Disclosure: One Health Security and The BioChain were both founded by Ashley Morgan; this is our own perspective, not an independent product assessment. Descriptions of The BioChain reflect its public materials at the time of writing.
Key Takeaways
- AI epidemic intelligence and governance intelligence both depend on something unglamorous: trustworthy, traceable data. A signal, a genome, a shared pathogen or a trade decision is only as good as its provenance — where it came from, when, and whether it has been altered since.
- That provenance layer is largely missing. Biological data is captured across many institutions, jurisdictions and formats; genomic results drift away from the samples they came from; and AI outputs can sound authoritative without an auditable evidence trail behind them.
- This is the layer a company like The BioChain (founded, in full disclosure, by One Health Security's Ashley Morgan) is built for: infrastructure that makes biological data secure, traceable and audit-ready — immutability, timestamped source-linking, API integration and regulatory alignment (21 CFR Part 11, EU Annex 11) — with real deployments in livestock biosecurity and multi-site genomics.
- Provenance is not detection and not decision: it does not make data accurate, and it does not tell anyone what to do. But it is the trust substrate under PABS pathogen sharing, cross-border genomic surveillance, SPS regionalisation and auditable AI — the difference between data you can act on and data you merely have.