Applied Research Resources Advisory Insights Publications Contact Subscribe
Analysis

Surveillance Before the Outbreak: Building a One Health Early-Warning System

September 2026
13 min read

Publication status: Independent analysis. This article has not undergone academic peer review. Editorial standards →

Topic Pathway: Surveillance & Early Warning →

When does an outbreak begin? It is tempting to answer that it begins when the first case appears, but biologically, ecologically and operationally the answer is usually much earlier. Before an infected animal is diagnosed a vector population may have expanded into a new area; before contaminated food reaches consumers unusual conditions may have developed somewhere along the production chain; and before hospitals detect an increase in human illness, animals, wildlife or environmental samples may already contain evidence of a threat. Earlier still, changes in climate, water, land use, livestock movement, agricultural inputs or infrastructure may have altered the conditions in which that threat could emerge at all.

The problem for surveillance is that these signals rarely appear in the same system. Veterinary authorities monitor animals while public-health agencies monitor people, laboratories monitor pathogens, environmental organisations monitor ecosystems, meteorological services monitor weather, agricultural systems record livestock movements and production, water companies monitor water quality, food businesses monitor supply chains, and digital systems increasingly monitor almost everything else. Each may see part of an emerging threat, but few see the whole picture — which is why the next generation of One Health surveillance cannot simply mean more surveillance. It has to mean connected surveillance.

Surveillance and early warning are not the same thing

Surveillance tells us what is happening; early warning attempts to tell us what may happen next. The distinction matters because traditional surveillance depends on defined events — a diagnosis, a laboratory result, an unusual number of cases, a notifiable disease report — and by the time a formal threshold has been reached, the underlying event may have been developing for days, weeks or months. These systems remain essential, but they are inherently retrospective.

An early-warning system looks further upstream, asking not only where disease is occurring but where the conditions are developing in which disease or another health-security event could occur. That is a much harder problem, and it is fundamentally a One Health problem. We set out the nine domains such a system should be watching in the companion piece to this one, What Should a One Health Early-Warning System Actually Watch?

The surveillance landscape is becoming much larger

Public-health surveillance was once dominated by clinical and laboratory reporting, but the potential information environment today is vastly richer. Pathogen genomic surveillance can identify variants and transmission relationships, while wastewater can reveal pathogens circulating in populations without relying on people presenting for healthcare — a point we explored in The Sewer Knows First. Wildlife surveillance may identify pathogens at the animal-human interface, vector surveillance can show changing geographical distributions, veterinary systems can detect unusual animal mortality or illness, and farm data can identify changes in production, feed intake or fertility.

Beyond the biological, environmental monitoring can detect contamination, satellite imagery can reveal flooding, drought, land-use change and vegetation conditions, meteorological data can identify circumstances favourable to vectors or pathogens, and transport and animal-movement records can help model possible transmission pathways. Open-source intelligence can surface unusual events reported by local media, organisations and communities before formal notifications emerge. None of this replaces conventional epidemiological surveillance, but together these sources create something conventional surveillance lacks, which is context.

The signal may not initially look like disease

This is one of the most important principles of One Health early warning: the first useful signal of a future health event may not be a health signal at all. Consider vector-borne disease, where an early warning may begin with temperature and rainfall, which affect habitat, which influences vector populations, which alters contact with animals and humans, so that animal infection occurs before human disease becomes apparent. If surveillance begins only once patients present at hospitals, most of that chain remains invisible.

Similar relationships run throughout food and agricultural systems. Drought changes livestock movements and flooding contaminates water; feed shortages alter sourcing patterns and extreme heat affects animal health and food production; changes in wildlife distribution alter interfaces with livestock, interruptions to veterinary medicines or vaccines increase vulnerability, economic pressure changes agricultural behaviour, and supply-chain disruption forces rapid substitution of suppliers. Any one of these might initially appear to sit outside the traditional boundaries of health surveillance, yet each of them changes risk.

From indicator surveillance to event-based surveillance

A resilient system therefore needs more than one surveillance method. Indicator-based surveillance uses structured information against defined thresholds — case counts, laboratory confirmations, mortality rates — and is systematic and highly valuable, but it is inevitably constrained by what somebody has already decided to measure. Event-based surveillance looks instead for information suggesting that something unusual may be happening, drawing on reports from communities, professionals, media and other open sources. WHO’s Epidemic Intelligence from Open Sources initiative reflects this approach, and its 2024–2026 strategy describes a programme intended to strengthen public-health intelligence through open-source information and improve early detection of and response to health threats.3

Weak signals rarely arrive in neat databases. They emerge as a local report of unexplained animal deaths, a cluster of unusual symptoms, an unexpected wildlife event, a sudden change in commodity movement or reports of contaminated water. Individually such observations may be entirely unremarkable, and their importance often emerges only when they are connected to one another.

The power of collaborative surveillance

WHO increasingly uses the term collaborative surveillance, a concept recognising that no single surveillance system can provide all the information required to understand emerging health threats. The WHO Hub for Pandemic and Epidemic Intelligence defines it as the systematic strengthening of capacity and collaboration among diverse stakeholders, within and beyond the health sector, to improve public-health intelligence and evidence for decision-making.1, 2 For One Health this should extend naturally across human health, animal health, plant health, wildlife, food safety, agriculture, water, environment, climate, trade, logistics and relevant critical infrastructure.

That does not mean every organisation needs access to every piece of information, nor that anyone should construct one enormous global database. It means designing mechanisms through which relevant signals can be connected when it matters, which requires interoperability but also, less comfortably for system designers, requires relationships.

The human network matters as much as the technical network

Surveillance systems are usually discussed as technology — sensors, databases, dashboards, AI, laboratory networks, genomic sequencing — and those things are increasingly important. But early warning also depends on people knowing who to contact. Imagine a veterinarian notices an unusual pattern of illness, a wildlife organisation independently observes unexpected mortality nearby, a water utility detects an unusual environmental result, and a local hospital later sees patients with unusual symptoms. The technical problem is connecting those four pieces of evidence; the institutional problem is recognising that they belong together at all.

Who has the authority to make that connection, and who is responsible for looking? Can the information legally be shared, and does one organisation even know that another holds something relevant? Have those relationships been established before the emergency, or will they have to be improvised during it? Preparedness of this kind begins long before any technology is required.

Local surveillance must connect to national intelligence

Another important principle is that surveillance should not become excessively centralised, because many of the earliest signals originate locally. Farmers know what is normal within their herds, veterinarians recognise unusual clinical presentations, local laboratories see unexpected results, communities notice changes in water, wildlife or illness, and food producers observe unusual production patterns. The challenge is ensuring that significant local observations can move rapidly enough through surveillance networks to become actionable intelligence, because if every signal must pass through multiple administrative layers before it can be considered important, early warning becomes late warning.

Central systems remain necessary, however, because individual communities cannot see patterns appearing simultaneously across multiple regions. Effective architecture therefore has to work in both directions at once, with local observations feeding wider intelligence and wider intelligence informing local action.

The danger of surveillance blind spots

Every surveillance system sees the world through the data it collects, which creates inevitable blind spots. A system dependent on clinical testing cannot easily detect infected individuals who are never tested; a livestock surveillance system dependent on formal reporting may miss disease where veterinary access is limited; wildlife surveillance is often incomplete because populations are difficult to monitor; environmental surveillance may cover only particular sites; and genomic surveillance depends entirely on which samples are sequenced. Digital surveillance can over-represent populations with strong connectivity, while open-source intelligence amplifies rumours alongside genuine signals.

This is why redundancy matters, because one surveillance stream can compensate for the weakness of another. The objective should not be to identify a perfect dataset, since there is no perfect dataset, but to build a surveillance ecosystem in which weaknesses in one source can be recognised and balanced by others.

Artificial intelligence changes surveillance, but not the fundamentals

The scale of modern surveillance increasingly makes automation unavoidable, because no analyst can manually examine every laboratory result, environmental reading, weather observation, movement record, genomic sequence, news report and agricultural dataset generated each day. Artificial intelligence can help identify relationships, anomalies and clusters that humans would otherwise miss, prioritise signals for investigation, connect information expressed in different languages and spot unusual patterns across enormous datasets — the territory we follow in our AI & Epidemic Intelligence pathway.

But AI does not eliminate the fundamental challenges of surveillance. Poor data remains poor data, missing populations remain missing, biased surveillance remains biased, and incorrectly identified animals or samples remain incorrectly identified. A model can detect a statistical anomaly without understanding whether it is biologically meaningful, which is why AI should strengthen human epidemiological intelligence rather than substitute for it.

The importance of provenance

As surveillance systems become more connected, another question becomes increasingly important: where did the information come from? An alert may combine laboratory results, movement data, environmental observations and open-source reporting, and decision-makers need to understand the evidence beneath it. Which source supplied it, when was it collected, and has it been changed since? How reliable is the identifier linking one record to another, does a laboratory result genuinely refer to the animal, sample or location claimed, and can the analytical chain be reconstructed at all?

This is not simply a technical concern, because it determines how much confidence can reasonably be placed in an alert — a point we have made before in Can We Trust the Data? and which our colleagues at The BioChain take up directly in Connected Data Is Not Enough. One Health surveillance needs both an intelligence architecture and an evidence architecture, and the second is usually the one nobody has funded.

From detection to action

Surveillance has little value if nothing happens after an alert, yet early-warning systems often focus overwhelmingly on detection. Every warning system ultimately requires a decision: who receives the alert, what threshold triggers investigation, who decides whether the signal warrants intervention, what action is permitted, what happens when the evidence is uncertain, how different agencies are coordinated, what happens if the signal crosses national boundaries, and how quickly resources can be mobilised. A technically brilliant early-warning system attached to a slow decision-making structure still produces a slow response, so preparedness requires surveillance, verification, decision and action to be designed as one system rather than four.

A One Health surveillance stack

Rather than thinking about surveillance as a single platform, it may be more useful to think of it as a series of layers.

  1. Observe — collect signals from clinical and veterinary surveillance, laboratories, genomics, wildlife, vectors, plants, food, water, wastewater, environment, meteorology, agriculture, movement, trade and open sources.
  2. Connect — enable relevant information to move between systems and organisations while maintaining appropriate governance.
  3. Contextualise — ask what else is happening. Is an unusual veterinary signal occurring alongside flooding? Has livestock movement increased? Has vector habitat expanded?
  4. Detect — use epidemiology, statistical methods and increasingly AI to identify anomalies, clusters and relationships.
  5. Verify — establish the reliability, provenance and significance of the evidence.
  6. Assess — determine what the signal might mean and which populations, sectors or systems could be affected.
  7. Act — investigate, communicate, control, mitigate or prepare.
  8. Learn — feed what happened back into the architecture so the next signal is recognised earlier.

That final layer is essential, because a surveillance system should become more capable after every event rather than simply returning to its previous state.

Building surveillance before we need it

In August 2026 the Quadripartite organisations — FAO, UNEP, WHO and WOAH — agreed to extend implementation of the One Health Joint Plan of Action through to 2029, giving countries greater predictability for planning, implementing and scaling national One Health priorities under a common framework.4 That creates an opportunity, because One Health is moving from advocacy toward implementation, and surveillance should be one of the places where that transition becomes visible. The full argument, and the articles behind it, are collected in our Surveillance & Early Warning pathway.

The question is no longer whether human, animal, plant and environmental health are connected, but whether the systems designed to protect them are equally connected. Early warning will never eliminate uncertainty, it will never predict every outbreak, and no surveillance architecture can observe everything. What it can do is move intervention earlier: from hospitalisation to infection, from infection to exposure, from exposure to transmission, from transmission to changing conditions, and ultimately from responding to an event to recognising the circumstances in which that event is becoming possible.

That is the real promise of One Health surveillance, and it is not simply about finding the next outbreak faster. It is about creating enough visibility across interconnected systems that, sometimes, we can prevent it from becoming an outbreak at all.

Questions & Answers

Are surveillance and early warning not the same thing?

No. Surveillance tells us what is happening; early warning attempts to tell us what may happen next. Most existing systems are built for the first and are then asked to perform the second, which is where much of the disappointment comes from.

Does the first useful signal always look like disease?

Frequently not. Temperature, rainfall, habitat, livestock movement and supply-chain data can all carry early signal, which means the first indication of a health event is often held by someone who does not consider themselves part of a health system.

Does AI solve this?

It makes the scale manageable and changes none of the fundamentals. Poor data stays poor, missing populations stay missing, and a model can find a statistical pattern without that pattern meaning anything. A warning system attached to a slow decision structure also still produces a slow response.

References

  1. World Health Organization, WHO Hub for Pandemic and Epidemic Intelligence: about the Hub. Berlin: WHO Hub.
  2. World Health Organization (2024) Defining collaborative surveillance: a core concept for strengthening the global architecture for health emergency preparedness, response and resilience (HEPR), 23 May 2024. Geneva: WHO.
  3. World Health Organization (2025) Epidemic Intelligence from Open Sources (EIOS) Strategy 2024–2026, 11 September 2025. Geneva: WHO.
  4. World Organisation for Animal Health (2026) Quadripartite collaboration extends the One Health Joint Plan of Action to 2029, 14 August 2026. Paris: WOAH.

Key Takeaways

  • Surveillance tells us what is happening; early warning attempts to tell us what may happen next. Most existing systems are built for the first and are then asked to do the second.
  • The first useful signal of a health event is frequently not a health signal at all. Temperature, rainfall, habitat, livestock movement and supply-chain disruption all change risk before anyone presents at a hospital.
  • Indicator-based surveillance is constrained by what someone already decided to measure. Event-based surveillance, including open-source intelligence of the kind WHO’s EIOS programme uses, catches what nobody thought to count.
  • Every surveillance stream has blind spots determined by the data it collects, so the goal is not a perfect dataset but an ecosystem in which one source can compensate for the weakness of another.
  • AI makes the scale manageable but changes none of the fundamentals: poor data stays poor, missing populations stay missing, and a model can find a statistical anomaly without knowing whether it means anything biologically.
  • A warning system attached to a slow decision structure still produces a slow response. Surveillance, verification, decision and action have to be designed as one system.

Stay informed. Stay connected.

Independent research, policy analysis and briefings on biological risk, biosecurity and governance — delivered periodically by One Health Security.