AI Designs Functional Viral Genomes, Outpacing Biosecurity Governance
A Stanford and Arc Institute team used genome language models to build 16 viable bacteriophages from scratch; a companion commentary in Science says the regulatory architecture to govern the technology doesn't exist yet.
Stanford University and Arc Institute researchers have done something that didn't exist six months ago: used artificial intelligence to write complete, working viral genomes from scratch. The study, published August 6 in Science, is a proof of concept with a narrow and defensible scope. The biosecurity questions it opens are considerably wider.
The team, led by Stanford assistant professor Brian Hie and graduate student Samuel King, used two genomic language models, Evo 1 and Evo 2, to generate bacteriophage genomes. Bacteriophages infect bacteria, not humans. The researchers produced 16 viable phages, confirmed they functioned in the lab, and showed they could destroy strains of E. coli that had evolved resistance to naturally occurring phages. The therapeutic angle is real: phage therapy is already used in clinics for antibiotic-resistant infections, and a tool that designs a phage around a specific resistant strain on demand could compress a process that currently takes months.
The precautions the team took are worth noting. As reported by CIDRAP and confirmed in the Science paper itself, the training data for Evo 2 excluded viruses capable of infecting humans, animals, or plants. That's a meaningful design choice, not an afterthought.
But the commentary published alongside the paper by Thomas Inglesby and Moritz Hanke of Johns Hopkins is where the biosecurity analysis lives. As CIDRAP reported, Inglesby and Hanke wrote that "the ability to compose viral genomes using generative AI now exists; the governance to safely steer it does not." That's a low-confidence-to-high-confidence gap worth unpacking: the capability is demonstrated fact; whether current governance is adequate is an assessment, and their confidence in its inadequacy reads as high.
Their specific concern, reported in the Science Perspective piece, is that the same approach used here for bacteria-targeting phages could be redirected toward eukaryote-infecting pathogens, including ones that target humans, animals, or plants. They recommended that sensitive viral sequences be excluded from training data going forward, and that existing biosafety frameworks be adapted explicitly to generative genomics. Both recommendations describe things that aren't being done systematically right now.
The dual-use ambiguity here isn't manufactured. Genomic language models are trained on sequence data drawn from millions of organisms. The exclusion of human-infecting viral sequences from a particular model's training set is a voluntary safeguard by a responsible lab. It is not a structural control. A different lab, a less careful team, or a commercial provider optimizing for capability over safety wouldn't necessarily make the same call.
Separate biosecurity research, flagged in coverage by Academic Education Australia, has found that AI-assisted protein design can substantially alter genetic sequences while attempting to preserve biological function, potentially making dangerous sequences less similar to the known examples used by conventional screening systems. That's a screening-evasion problem, and it's not hypothetical.
The DURC governance picture in the U.S. is already strained. A paper published in Frontiers in Bioengineering and Biotechnology on August 30, reviewed by Global Biodefense, proposed an 11-part national framework synthesizing existing tools, including WHO guidance, ISO biosafety standards, and the 2024 U.S. DURC/PEPP policy. That 2024 policy was itself rescinded by executive order before it fully took effect, per a review published in PMC. The governance gap Inglesby and Hanke are describing doesn't emerge from a vacuum.
The honest read on this Science paper is that it's not an alarm by itself. Sixteen bacteriophages that kill E. coli don't constitute a threat. The concern is what the capability class represents as it matures, and how far behind the governance frameworks currently sit. Biosecurity expert Steph Guerra, writing for CIDRAP, framed the paper as signaling "a narrowing window to build safeguards before the technology matures further." That's the right frame. The window isn't closed. But it's measurably smaller than it was a month ago.
Sources cited:
- CIDRAP (https://www.cidrap.umn.edu/antimicrobial-stewardship/ai-created-bacteriophage-overcame-resistant-bacterial-strains-experts)
- Science (King et al., DOI: 10.1126/science.aec2657) (https://www.science.org/doi/10.1126/science.aec2657)
- Science Perspective (Inglesby & Hanke, DOI: 10.1126/science.aej8512) (https://www.science.org/doi/10.1126/science.aej8512)
- Global Biodefense (https://globalbiodefense.com/2026/09/01/a-blueprint-for-managing-the-worlds-most-dangerous-research/)
- PubMed Central (DURC/PEPP policy review) (https://www.ncbi.nlm.nih.gov/pmc/articles/PMC12379582/)
- Phys.org (https://phys.org/news/2026-08-aidesigned-viruses-biosecurity-pace.html)
- Academic Education Australia (https://academiceducation.com.au/writing-genomes-at-the-keyboard-ai-has-designed-functioning-viruses-and-the-biosecurity-questions-are-just-beginning/)
This release was originally distributed via ETL Newswire. Visit CIDRAP for the full story, related releases, and contact information.
Visit CIDRAP →