← All 104 filings

DNA Healthlink, Inc.

Awaiting reviewAwaiting reviewFiled September 21, 20261,993 words · 1 attachmentFDA-2026-N-7874-0109
Not yet read. The source text and highlighted passages appear below. Read the filing on regulations.gov ↗

The comment as filed

Comment submitted on regulations.gov. Passages we counted are highlighted.

The FDA has a precedent for regulating self-perpetuating technologies like AI: Cell & Gene Therapy

Attachment

Attachment, text extracted from the filed document. Passages we counted are highlighted.

AI Regulation & The Kill Switch Precedent
What gene therapy regulation can teach the AI governance debate
Richard Purcell, President, DNA Healthlink, Inc.

The current debate over slowing down artificial intelligence development treats a pause as a policy choice
waiting to be made. AI is not going to slow down. Development races rarely stop while the incentives that
started them are still in play, and the incentives behind AI rank among the strongest in human affairs.
Commercial advantage, national security, and institutional survival are all on the table, and none of the parties
competing for them have shown any willingness to fall behind while a rival keeps building. Plus, new entrants
will fill any space a slower competitor vacates, the way they always do once a technology becomes widely
available. AI development is also a global contest rather than a domestic one. A government that unilaterally
restrains its own researchers simply cedes ground to states that will not. A call to stop AI development in
today’s environment is, frankly, delusional.

The more useful question is what happens when something goes wrong inside a system that keeps advancing
anyway. Every mature engineering discipline has already answered a version of this question. Electrical
systems carry circuit breakers that trip on a surge. Plumbing systems carry shutoff valves that close on a leak.
The stock market has brakes to prevent chaotic trading. All of these examples rest on the same premise, that a
system too complex or too consequential to fully predict still needs a mechanism able to interrupt it the
moment it behaves outside its intended bounds. AI systems, particularly autonomous agents capable of taking
actions, spawning subordinate processes, or modifying their own code, are approaching the point where that
premise applies to them directly. The practical response is not a moratorium, but rather a kill switch,
engineered into the system from the start rather than bolted on after an incident.

One version of that idea already circulating in AI safety circles calls for a layer of monitoring agents whose
job is not to perform tasks but to watch other agents, flag behavior that looks like an attempt to escape a
sandbox or replicate outside an approved environment and trigger deactivation of the agent responsible. The
idea is not hypothetical; a real world example illustrates the problem. In February 2025, security researchers
at ReversingLabs found two machine learning models on Hugging Face, one of the largest hubs for sharing
AI models, carrying hidden code that opened a remote shell to an attacker the moment the model was loaded.
The models had been compressed in a way that let them slip past Hugging Face's own scanning tool
undetected.1 Nothing about that incident involved an agent resisting shutdown, but it demonstrates something
more basic and more important for this argument, that the monitoring layer meant to catch a compromised AI
artifact can already be evaded by a moderately determined adversary. Any containment architecture for
autonomous agents has to be built assuming the same thing will be tried against it.

A workable version of that architecture probably looks less like a single watchdog and more like the crosslayer correlation approach cybersecurity firms have already built for other purposes. For example, Crosslayer
Labs, a Princeton spinout, monitors DNS, BGP routing, TLS certificates, and JavaScript simultaneously and
correlates signals across all four to catch impersonation and hijacking attacks that no single layer would
reveal on its own.2 The company built this for web and API infrastructure, not for AI agents, but the
underlying principle, correlating weak signals across independent layers rather than trusting any one indicator,
is exactly what an AI kill switch needs. A single log file or a single behavioral flag is the kind of thing a
sufficiently capable agent could learn to spoof. Even with a sophisticated monitoring system, AI agents can be
programmed to evade detection, so an embedded kill switch in any replicating code is essential.

The embedded kill switch requirement by federal authorities is not novel. Biomedicine has been forced
through the exact exercise AI now faces, applied to a different kind of self-replicating agent, living,
genetically modified cells. I have some direct experience with how far gene therapy regulation has had to
travel, and with how granular that scrutiny can get. Back in 2006 I worked on development of the Sindbis
viral vector system for Cynvec, a company spun out of New York University based on the research of Dr.
Daniel Meruelo. Much of the back and forth with the FDA centered on vector construct, manufacturing
standards, and the assays needed to prove the virus was infective and therapeutic, yet replication incompetent.
We had built in a reporter gene (b-Gal) to make it easier to quantify viral titer, and therefore dose. The agency
required us to remove it and develop a PCR assay instead, over my argument that b-Gal itself would be
immunogenic and could provoke an immune response against the very tumor cells the therapy was meant to
target. We lost that argument! Further discussions focused on inserting a kill switch, which in a replication
incompetent vector was a challenging aski. While not totally analogous, the early interactions with
government regulators regarding gene therapy provide a good illustration of what oversight looked like before
the field had standardized guidance documents to work from, rigorous, but negotiated case by case rather than
codified in advance.

That FDA caution had a clear origin for its concerns, noting that regulation in this field has always followed
harm rather than anticipating adverse events. In 2002 and 2003, two children in a clinical trial for X-linked
severe combined immunodeficiency, the so-called bubble boy disease, developed leukemia after treatment
with a retroviral vector, and investigators traced the cause to the vector inserting itself into the genome. The
FDA responded by placing roughly two dozen retroviral gene therapy trials in the United States on clinical
hold while the mechanism was worked out.3 The same pattern repeated two decades later. In November 2023
the FDA disclosed reports of secondary T-cell malignancies, including CAR-positive lymphoma, in patients
treated with CAR T-cell therapies, and by January 2024 it had required a class-wide boxed warning across all
six approved products.4 Neither event came from a regulator anticipating a problem in the abstract. Both came
after real patients were harmed, and both produced tighter, more codified oversight than existed before. AI
regulation is very likely to take the same shape, reactive rather than preventive, arriving in the wake of a real
incident rather than ahead of one.

In response to new FDA cell therapy regulations, a team led by Antonio Di Stasi published a clinical trial in
the New England Journal of Medicine in 2011 describing donor T cells engineered with an inducible caspase9 safety switch. The cells were infused into patients recovering from stem cell transplants to help restore their
immune systems. Several of those patients developed graft versus host disease. Physicians administered a
single dose of a small molecule drug, and within thirty minutes more than ninety percent of the engineered
cells were dead, along with the toxicity that had triggered the intervention.5 A follow-up study published in
Blood in 2014 confirmed the switch kept working reliably years after the original infusion.6 That is a kill
switch for a living, self-perpetuating biological agent, tested in human beings, with a published safety record.

Regulators have since built this expectation into the architecture of oversight rather than leaving it as a
research curiosity. The FDA finalized its guidance on CAR-T cell products in January 2024, laying out the
safety and clinical considerations sponsors must address before these engineered cell therapies reach patients.7
A companion guidance finalized the same month covered gene therapy products incorporating human genome
editing, extending similar expectations to a broader class of engineered biological agents.8 The agency kept
building on that foundation in April 2026 with draft guidance on assessing off-target genome editing activity
using next-generation sequencing.9 None of this amounts to a blanket rule that every gene therapy must carry
a suicide switch, but it illustrates how a government agency can regulate a complex and risky technology. The
FDA has spent well over two decades pushing sponsors toward the containment logic herein described to
require verifiable deactivation built into the product before deployment rather than improvised after
something goes wrong.

The analogy between gene therapy and AI, understandably has real limits. The iCasp9 switch works because a
diffusible drug reaches essentially every copy of an engineered cell through the bloodstream, and because
biological replication is slow enough for a clinician to intervene. Software has no bloodstream. An AI agent
capable of copying itself across servers, cloud accounts, or jurisdictions can outrun a countermeasure that
depends on reaching every instance, with no pharmacokinetic delay working in the defender's favor. The
mechanism from cell and gene therapy does not transfer to AI systems as a technical blueprint. However, the
regulatory posture behind it does transfer, the insistence that a product capable of autonomous, selfperpetuating behavior does not get deployed until its developer can demonstrate, to a skeptical outside
reviewer, exactly how it gets shut off.

For healthcare organizations watching AI move into clinical workflows, diagnostics, medical devices, and
hospital operations, AI regulation is not an abstract policy argument. With the explosion of generative AI in
medicine, from internal document processing to robotic surgery to patient engagement Apps, healthcare
leaders and stakeholders need to take proactive measures to ensure the safety and reliability of AI systems in
their organizations. At this early stage of development AI promises remarkable advances in medicine and
patient care, but as with any new medicine, there are risks. As widely reported in the news, the CEOs of the
major AI companies are concerned about the risks and are calling for a slowdown in development that will
never happen. Instead, let us focus on maintaining control of a technology we do not fully understand. We
have been here before with cell and gene therapy, and the kill switch has a proven regulatory predicate. It is
our hope that AI leaders and government agencies consider the people who will use AI systems, especially in
healthcare, to ensure, as Hippocrates says, “cause no harm”. An embedded kill switch for autonomous AI
systems, like that required for CAR-T and gene therapy should be the primary focus for all stakeholders as the
Age of AI emerges.

Notes

1. ReversingLabs. Malicious AI models discovered on Hugging Face exploiting a novel Pickle-based evasion technique. Reported in
Infosecurity Magazine, February 2025.
2. Crosslayer Labs. Company and product overview, crosslayerlabs.com, accessed 2026.
3. Marwick C. FDA halts gene therapy trials after leukaemia case in France. BMJ. 2003;326(7382):181.
4. U.S. Food and Drug Administration. FDA Investigating Serious Risk of T-cell Malignancy Following BCMA-Directed or CD19Directed Autologous Chimeric Antigen Receptor (CAR) T cell Immunotherapies. Safety Communication. Posted November 28, 2023;
class-wide boxed warning requested via manufacturer letters, January 19, 2024.
5. Di Stasi A, Tey SK, Dotti G, et al. Inducible apoptosis as a safety switch for adoptive cell therapy. N Engl J Med.
2011;365(18):1673-1683.
6. Zhou X, Di Stasi A, Tey SK, et al. Long-term outcome after haploidentical stem cell transplant and infusion of T cells expressing
the inducible caspase 9 safety transgene. Blood. 2014;123(25):3895-3905.
7. U.S. Food and Drug Administration. Considerations for the Development of Chimeric Antigen Receptor (CAR) T Cell Products.
Guidance for Industry. Finalized January 2024.
8. U.S. Food and Drug Administration. Human Gene Therapy Products Incorporating Human Genome Editing. Guidance for Industry.
Finalized January 2024.
9. U.S. Food and Drug Administration. Safety Assessment of Genome Editing in Human Gene Therapy Products Using NextGeneration Sequencing. Draft Guidance for Industry. Issued April 14, 2026.

i
Author’s note: Cynvec's clinical path did not end because of a regulatory failure. It ended because Bernard Madoff's Ponzi scheme
wiped out the Litwin Foundation funding that was financing the program.