Drug Discovery AI
I

Isomorphic Labs

AI drug design company spun out of Google DeepMind in 2021 and founded by Demis Hassabis, building on the AlphaFold structure prediction lineage. In February 2026 the company released IsoDDE, a unified drug design engine combining structure prediction, ligand binding, affinity prediction and antibody interaction modeling in a single pipeline. Reported performance is roughly double AlphaFold 3 accuracy on the hardest ligand binding cases where the target has under 20 percent sequence similarity to training data, and 2.3 times AlphaFold 3 on antibody antigen docking in the high fidelity regime.

Unlike AlphaFold 1 through 3, IsoDDE is proprietary: no code, no weights, no public API and no peer reviewed publication, and Nature reported that the technical paper offers scant insight into how the results were achieved. Access is available only through pharma partnership. Named partners are Eli Lilly and Novartis, announced January 2024 with combined potential milestone value near 3 billion dollars, expanded with Novartis in February 2025, plus Johnson & Johnson. The company raised 600 million dollars in March 2025 led by Thrive Capital with GV and Alphabet participating. First in human trials for an AI designed candidate are targeted for end of 2026, a timeline that slipped from an earlier 2025 target.

AI Health Index verifiedJuly 27, 2026
Compare Isomorphic Labs with other vendors
Founded
2021
Headquarters
London, United Kingdom
Categories
drug-discovery
Indexed Products
IsoDDE, AlphaFold 3
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
AA on AI CentralityThe artificial intelligence is the product. Remove the model and there is nothing left to sell.
Vendor Published

The model is the entire company. There is no instrument business, no assay platform and no legacy software franchise underneath it: what pharmaceutical partners are paying for is access to a drug design engine descended from AlphaFold. IsoDDE, released 10 February 2026, unifies structure prediction, ligand binding, affinity prediction and antibody antigen interaction modeling in a single pipeline, and the stated ambition is to reimagine drug discovery from first principles. On this axis the grade is unambiguous even where other axes are not.

BB on Autonomy and Oversight ModelThe oversight structure is described and one part is missing, commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

Structurally the oversight is the partner's, and that is a real mechanism: designs generated by the engine enter Lilly's, Novartis's or Johnson & Johnson's own preclinical development processes, which are among the most rigorous validation environments in the industry, and nothing reaches a patient on the model's say so. Held at B because nothing vendor side is documented.

No disclosure was located on how outputs are triaged internally, what confidence is attached to a prediction, or what the engine is known not to do well. The closed nature of the system compounds this: a partner can observe that a design failed but cannot inspect why the model proposed it.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Vendor Published

The sharpest disclosure gap in this category, and it is notable precisely because of the lineage. AlphaFold 2 and 3 were published, and the public AlphaFold Database serves more than 3 million researchers across more than 190 countries with over 230 million predicted structures.

IsoDDE reverses that posture entirely: no code, no weights, no public API and no peer reviewed publication, with Nature reporting that the technical paper offers scant insight into how the results were achieved and independent researchers left to guess at the method.

Every performance figure, including roughly double AlphaFold 3 accuracy on the hardest ligand cases under 20 percent sequence similarity and 2.3 times on antibody antigen docking in the high fidelity regime, is vendor generated on vendor selected benchmarks and cannot currently be reproduced or contested by anyone outside the company. That is not a criticism of the science, which may well be as good as claimed. It is a statement that the claim is unfalsifiable from outside.

CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

The chain here is genuinely short, and that is inferred rather than disclosed, which is the reason this does not sit higher. The engine is built in house and its intellectual lineage is unusually traceable in public, since the predecessor structure prediction work was published and the resulting database serves millions of researchers, so a buyer can reason about where the science came from in a way that is impossible with most vendors in this index.

What is absent is everything about the operating chain. No compute or hosting provider is named, no subprocessor list is published, and no statement was located describing which parties other than the company itself can access the data flowing through the system. For this vendor the relevant data is not protected health information at all, which is why the stewardship axis is scoped rather than penalised.

It is the partner's target selection and chemistry, which is among the most commercially sensitive material a pharmaceutical company holds, and the question of who else can see it is the whole question. One structural feature makes that question sharper rather than academic, and it introduces a form of this axis that will recur across the index wherever a vendor sits inside a larger technology group.

The company is a subsidiary of a large technology parent with its own research organisation and its own interests in the field, and nothing public establishes whether partner chemistry data traverses parent group infrastructure, whether parent group personnel can access it, or where the boundary between the subsidiary and the group is drawn. That is the first question a pharmaceutical partner's legal team would ask and there is no public answer to it. Graded on that basis: architecture and lineage visible, operating chain and group boundary undisclosed.

CC on Clinical and Operational EvidenceNamed customers, or vendor reported percentages with no method, denominator or reference standard. Scale of use is recorded here and is not treated as evidence of benefit.
Vendor Published

No molecule from this platform has entered a human being. First in human trials are targeted for the end of 2026, a date that already slipped from an earlier 2025 target, with candidates described as in IND enabling work across oncology and immunology. Partner programs are reported to have progressed from target identification to multiple preclinical candidates by early 2026.

The evidence that does exist is commercial rather than clinical: roughly 3 billion dollars in potential milestone value across the Lilly and Novartis agreements, plus Johnson & Johnson. Applying the index precedent that scale does not substitute for evidence of benefit, deal value is a signal about what sophisticated partners believe, not a demonstration that the platform works. Buyers comparing platforms should hold this against peers with molecules in patients.

BB on AI Safety and PHI StewardshipCategorical commitments are published, such as no training on customer data, without the retention schedule or the safety engineering behind them.
Vendor Published

Not applicable in the provider sense and rated accordingly rather than penalized. The engine operates on protein structures, ligands and molecular interaction data, not on patient records. The confidentiality question that does arise is the partner's target and chemistry information, which is governed by the collaboration agreement.

Regulatory and Compliance
BB on HIPAA and BAA PostureBusiness associate status is stated and supported by a substantive privacy document, with the agreement or its scope not fully published. For a vendor outside the United States, an equivalent regime documented to this depth grades here.
Vendor Published

Not applicable. The counterparties are pharmaceutical research organizations entering multi target discovery collaborations, not covered entities transferring protected health information.

CC on Security Certifications and Trust CenterControls are described with an outside check behind them, such as independent penetration testing on a stated cadence, but no attestation against a recognised framework.
Vendor Published

No attestation, trust centre or security page was located for this company across two differently phrased searches. What is published instead is a description of somebody else's infrastructure, and the relationship makes this the purest example of a pattern this index tracks.

The company is an Alphabet business that runs entirely on its corporate sibling's cloud, by design and from inception, using that provider's storage, pipelines, containerised workloads and large scale accelerated compute. Its own published position on the subject is that the cloud provider supplies an infrastructure layer it can trust, which allows it to concentrate on the research and engineering behind the platform. That is a statement about a supplier, not about the company's own controls, and it is the ordinary inherited certification problem in an unusually blurred form: when the provider is a sibling under the same parent, the boundary between what the platform inherits and what the company operates is genuinely hard for an outsider to draw, which makes it more likely a buyer will simply not draw it.

The gap matters more here than for most peers because of what counterparties hand over. Pharmaceutical partners in these collaborations specify targets they have not disclosed publicly, which is among the most valuable and most closely held information those organisations possess, and the entire arrangement depends on it entering this company's environment.

A fair inference belongs on the record alongside that. The named partners are among the largest pharmaceutical companies in the world and will not have entered multi year collaborations without satisfying their own vendor security requirements, so a security programme demonstrably exists and has been examined privately. What is missing is publication. Ask what the company holds in its own name as distinct from what its cloud provider holds, ask whether partner data sits in a segregated environment, and ask what its own staff can see.

CC on FDA and Regulatory StatusNo device claim is made and the product is scoped accordingly. Most administrative and operational products sit here and are not penalised for it, because this axis grades the appropriateness of the positioning rather than possession of a clearance.
Regulatory Filing

The lowest regulatory standing in this category, which is a statement of stage rather than of conduct. The design engine is not a regulated device and is not presented as one, correctly. At asset level no cleared IND, registered clinical trial or human dosing was located, with candidates described as in IND enabling work and first in human trials targeted for end of 2026. A buyer comparing platforms should be clear that the most technically celebrated engine in the category has, as of this review, no regulatory track record of its own to assess.

CC on AI Governance and Bias DisclosureResponsible artificial intelligence is committed to in policy language with no evaluation behind it. Most of the index sits here.
Vendor Published

This vendor is the clearest demonstration in the index that governance is not one thing. It runs a substantive programme on one dimension and refuses disclosure on another, and a buyer needs to see both separately.

What exists, and it is real. Together with its parent research organisation the company publishes a bioresilience programme, reporting more than fifteen partnerships advanced over the past year with government bodies, biosecurity organisations and research groups, directed at preventing threat actors from misusing the models and at outbreak detection and response. It has also gone on the record calling for stringent measures including a federal frontier safety framework. That is misuse governance with external counterparties and a policy position attached, which is more than almost anyone in this category does.

What is refused is the other half. The domain relevant question for this axis is whether the engine performs unevenly across target classes and chemical space, and the company's own headline metric points straight at it by reporting accuracy separately for cases below 20 percent sequence similarity to training data. The engine is fully proprietary. Its technical report shows results without the method, and the company's president has stated plainly that the underlying approach will stay proprietary, attributing the advances to a combination of compute, data and algorithms without specifics. Benchmark figures are internally generated and independent validation on external datasets remains outstanding.

That is the finding. Because the model is closed, no external party can characterise where it degrades, which converts an ordinary technical limitation into a governance one: the buyer cannot audit the boundary. Graded C because the axis asks about performance disclosure and there is none by design, with the misuse work credited in full but not counted toward a question it does not answer.

DD on AI Liability and RecourseNothing published on what happens when the system is wrong.
Vendor Published

Two things need separating here, because one is a category norm and the other is a real gap. The norm first: this engine is available only through negotiated pharmaceutical collaboration, currently with Eli Lilly, Novartis and Johnson and Johnson, so liability is allocated in bilateral contracts that no party publishes.

For a vendor with three counterparties of that size, the absence of public terms says much less than it would for a product sold to two hundred health systems, and it should not be read as an unwillingness to be accountable. The substantive point is different and it survives the contract. The closed architecture removes the evidentiary basis on which any claim about the output would rest.

No code, no weights, no public interface and no peer reviewed method means a partner can observe that a designed molecule failed but cannot inspect why the engine proposed it, cannot attach a confidence to a prediction, and cannot establish that performance fell short of what was represented, because the representations themselves are vendor generated figures on vendor selected benchmarks that nobody outside the company can reproduce.

Recourse requires a standard to measure against, and here there is none that an outside party can apply. What does exist is downstream and belongs to somebody else. Designs enter the partner's own preclinical development process, which is among the most rigorous validation machinery in the industry, and nothing reaches a person on the model's say or alone.

That is a genuine check on harm and it is worth stating plainly, but it is the partner's apparatus rather than a route against the vendor. The shape of the harmed party is also different in this category and worth naming: there is no patient at the point of use. The parties who bear a bad output are the partner's research programme, which spends years and capital on a wrong direction, and eventually the volunteers in a trial that should not have started.

Neither has any relationship with the company whose model proposed the compound. Ask what the collaboration agreement says about performance representations, and what evidence of model behaviour the partner is entitled to inspect when a designed asset fails.

Integration and Deployment
CC on EHR and Interoperability DepthIntegration is claimed through standards or a middleware layer with no system named and nothing to verify.
Vendor Published

Not applicable. There is no provider workflow surface and no EHR touchpoint. Interoperability in the research sense is also constrained, since no public API or distributable software exists to integrate with.

CC on Deployment Model and Data ResidencyA single hosted option with location implied rather than committed.
Vendor Published

The most restrictive access model in the category. There is no software to license, no API to call and no self service tier: the engine is available exclusively through negotiated pharmaceutical partnership, currently disclosed with Eli Lilly, Novartis and Johnson & Johnson. In practice a research organization cannot use this platform at all without a strategic collaboration of a scale only large pharmaceutical companies can execute. No hosting, tenancy or data residency terms were located, which follows from there being no deployment in the ordinary sense.

Commercial
BB on Commercial TransparencyA price or a pricing basis is published without full tiers, so a buyer can size the cost before making contact.
Vendor Published

Deal shape is public and specific even though no rate card exists or could exist. Disclosed structures include the January 2024 Lilly and Novartis collaborations with combined potential milestone value near 3 billion dollars, reported as up to approximately 1.7 billion for Lilly and up to approximately 1.2 billion for Novartis, a February 2025 Novartis expansion adding up to three further research programs, a subsequent Johnson & Johnson agreement, and a 600 million dollar round in March 2025 led by Thrive Capital with GV and Alphabet participating. What is not disclosed is per program economics or what a partner actually receives for the money.

BB on Setting and Specialty CoverageCoverage is named with validation behind part of it.
Vendor Published

Broad on modality, concentrated on stage. IsoDDE spans small molecule work and antibody design in one pipeline, with reported strength on the CDR H3 loop that is the hardest region of an antibody to predict, which is genuinely wider modality coverage than most peers offer from a single engine. Disclosed therapeutic focus centres on oncology and immunology, with cardiovascular disease also reported. All of it sits at the design and preclinical stage, so coverage claims describe where the engine is pointed rather than where it has delivered.

Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Not applicable
Exclusive strategic partnership only. Reported structures use upfront payments plus success based milestones and royalties. Not applicable. No software is delivered to the partner. Vendor Published

The access model matters more than the price here. There is no licence, no API and no self service tier, so a research organization cannot use this platform without negotiating a strategic collaboration at a scale only large pharmaceutical companies can execute.

Disclosed agreements are with Eli Lilly, reported at up to approximately 1.7 billion dollars in milestones, Novartis at up to approximately 1.2 billion dollars and expanded in February 2025 with up to three additional research programmes, and Johnson & Johnson. Combined potential value across the Lilly and Novartis deals is reported near 3 billion dollars. What a partner receives for that money, and on what terms, is not public.