AI Designs Working Viruses, Leaving Biosecurity Governance Behind
A Stanford-led team built 16 functional bacteriophages using genome language models, and Johns Hopkins biosecurity researchers warn the oversight framework to govern the technique doesn't yet exist.
A study published August 6 in the journal Science describes what its authors call a first: researchers at Stanford University and the Arc Institute used generative AI to produce complete viral genomes that, when synthesized and tested in a lab, produced working bacteriophages. The viruses killed strains of E. coli that had already evolved resistance to naturally occurring phages. That's a meaningful result for antimicrobial resistance research. It's also a governance problem that nobody has solved.
The mechanism is worth understanding before the alarm. Brian Hie and graduate student Samuel King led the effort, according to reporting reviewed from Science's own coverage. Their team ran two genome language models, Evo 1 and Evo 2, on a training corpus of two million bacteriophage sequences. As reported by Betanews and confirmed in the primary paper, sequences from viruses capable of infecting humans, animals, or plants were deliberately withheld from training. The team produced 16 distinct, viable bacteriophage genomes, none of which match anything currently found in nature.
The self-imposed training-data restriction is the only governance measure described. That's the part that should concentrate attention.
In a Perspective piece published alongside the paper in the same issue of Science, Thomas Inglesby and Moritz Hanke of Johns Hopkins University were direct about what's missing. As reviewed by CIDRAP, they wrote that "the ability to compose viral genomes using generative AI now exists; the governance to safely steer it does not." They went further, warning that the same technique applied to eukaryote-infecting viruses could generate pathogens that existing countermeasures can't contain. Their position, as reported by the resultsense.com analysis of the paper, is currently a norm rather than a rule, and it holds only as long as every lab voluntarily agrees.
CIDARP also flagged biosecurity expert Steph Guerra's assessment that the paper signals a narrowing window to build safeguards before the underlying technology matures further. That's a moderate-confidence claim worth sitting with: the open-source status of at least one of the models used means the capability isn't locked inside a single institution.
The dual-use framing here is not hypothetical, but it also isn't settled. Bacteriophages that target bacteria are a legitimate medical tool: phage therapy is already used in clinics to treat infections that don't respond to antibiotics, and the Stanford team's approach could sharpen that process considerably. As reported by Phys.org, new AI-designed bacteriophages could be customized to target specific drug-resistant strains. Those are real benefits. The dual-use concern sits one architectural decision away: what happens when a model trained on sequences that include eukaryotic viruses attempts the same generative task?
The governance literature has been tracking this gap. A June 2026 policy review published by UNSW Sydney's Ruihan Zhang, highlighted in Global Biodefense Today, identified five overlapping threat pathways in dual-use research of concern, one of which is accidental release and another of which is insider misuse of lab systems. The review proposed eleven governance recommendations built on existing WHO and ISO frameworks rather than a new regulatory body, and explicitly cautioned that poorly calibrated oversight carries real costs of its own, including chilling effects on legitimate research.
That tension is real. What the Science paper clarifies is that the question is no longer abstract. A team has done this, the model is open-source, and as King's College London biosecurity researcher Filippa Lentzos told Scientific American, "the challenge is to connect that existing governance to the new upstream capability to design biology digitally." No such connection currently exists at the federal level for genome design models specifically.
The paper's own authors recommend consulting safety and security professionals throughout any whole-genome design effort going forward. That's a reasonable starting position. It's also not binding on anyone.
Sources cited:
- Science (DOI: 10.1126/science.aec2657) (https://www.science.org/doi/10.1126/science.aec2657)
- CIDRAP (https://www.cidrap.umn.edu/misc-emerging-topics/ai-created-bacteriophage-overcame-resistant-bacterial-strains-experts)
- Global Biodefense Today, September 2, 2026 (https://globalbiodefense.com/2026/09/02/global-biodefense-today-september-2-2026/)
- Biodefense Headlines, September 7, 2026 (https://globalbiodefense.com/2026/09/07/biodefense-headlines-september-7-2026/)
- Scientific American (https://www.scientificamerican.com/article/scientists-are-using-ai-to-design-new-viruses-should-they-be/)
- Phys.org (https://phys.org/news/2026-08-aidesigned-viruses-biosecurity-pace.html)
- Betanews (https://betanews.com/article/ai-designed-viruses-stanford-arc-institute/)
This release was originally distributed via ETL Newswire. Visit Science (DOI: 10.1126/science.aec2657) for the full story, related releases, and contact information.
Visit Science (DOI: 10.1126/science.aec2657) →