AI Designs Novel, Functional Viruses From Scratch, Raising Biosecurity Alarms
Stanford and Arc Institute researchers have used generative AI to create entirely new bacteriophages capable of infecting and killing bacteria, marking a revolutionary advance with profound implications for both medicine and biosecurity.
✨ This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more
Listen to this story

In a breakthrough that simultaneously heralds immense potential and raises profound biosecurity alarms, researchers at Stanford University and the Arc Institute have successfully utilized generative AI models, specifically Evo 1 and Evo 2, to design and create entirely novel, functional bacteriophages from scratch. Published in *Science* on August 6, 2026, this landmark achievement demonstrated that these AI-generated viruses could infect and kill *Escherichia coli*, with some even exhibiting the capacity to overcome natural bacterial resistance to existing phages, a feat previously unachieved by natural variants. The AI models, trained on a vast dataset of over two million bacteriophage genomes, produced thousands of potential viral blueprints, from which 302 high-potential sequences were synthesized into real DNA. Out of these, 16 proved to be fully functional, showcasing AI's ability not merely to mimic but to optimize biological design.
This development carries immense implications, underscoring the escalating dual-use dilemma inherent in advanced AI. On one hand, the ability to "rationally design" bespoke viruses offers a revolutionary weapon against the looming crisis of antibiotic resistance, allowing scientists to create highly targeted biological agents for phage therapy. AI is already accelerating drug discovery and vaccine development, with companies like Sanofi building AI tools to optimize mRNA vaccines and predict human responses, and the global AI in biotechnology market projected to reach $22.72 billion by 2035. AI algorithms can rapidly identify genes of interest, predict protein structures, and assess the impact of modifying those structures, dramatically reducing the time and cost associated with traditional pharmaceutical research. Google DeepMind's AlphaFold, for example, which predicts protein structures, earned Demis Hassabis and John Jumper a share of the 2024 Nobel Prize in Chemistry and is widely adopted for disease study and drug development.
Conversely, the very power that enables such beneficial innovation simultaneously lowers the technical and knowledge barriers for malicious actors to engineer dangerous pathogens. Experts warn that AI could be repurposed to develop new bioweapons or enhance existing ones, potentially creating "superviruses" that combine traits like the rapid spread of measles, the mortality of smallpox, or the incubation period of HIV. This convergence of AI and genetic editing raises critical questions about biosecurity, especially given the increasing accessibility of synthetic genomic technology. While earlier assessments in early 2024 suggested that current large language models (LLMs) might offer only a "mild uplift" or no statistically significant increase in the operational risk of a biological attack compared to readily available internet information, more recent expert forecasts indicate a growing concern. A study involving 46 biosecurity and biology experts predicted a baseline annual risk of a human-caused epidemic causing 100,000 deaths at 0.3%, rising to 1.5% if LLMs achieve certain advanced virology troubleshooting capabilities, a threshold some models have already crossed. Anthropic's internal trials with its Claude Opus 4 model demonstrated "significantly greater" performance in biosecurity-expert graded scenarios than both Google search and prior models, highlighting the accelerating capabilities.
The rapid pace of AI advancement has outstripped regulatory frameworks, creating a vacuum that industry leaders are attempting to address. Major AI developers, including OpenAI, Anthropic, and Google DeepMind, have launched extensive biosecurity programs and frameworks. OpenAI, for instance, has its "Rosalind Biodefense" program, offering trusted developers access to advanced AI tools for epidemiological modeling, early detection, and vaccine design. The company also employs product policy managers specializing in biosecurity to guide safe model behavior and evaluate bio-relevant product launches. Anthropic has implemented a Responsible Scaling Policy (RSP) with AI Safety Level 3 (ASL-3) protections, including "constitutional classifiers" designed to detect and prevent misuse related to chemical, biological, radiological, and nuclear (CBRN) weapons development. Google DeepMind and its sister company Isomorphic Labs have initiated a "bioresilience" program, focusing on prevention through tools like SynthID watermarking for DNA-synthesis screening, detection via AlphaEvolve for pathogen sequencing, and response by providing trusted researchers access to models for vaccine and therapeutic design.
Despite these industry self-governance efforts, a significant regulatory lag persists. Nobel Prize-winning chemist Jennifer Doudna, in a June 2026 interview, acknowledged biology's complexity still requires human innovation, but conceded that AI's intersection with biotechnology is "not theoretical" and raises concerns about repurposing AI for harmful compound production. Leaders from OpenAI, Anthropic, and Microsoft AI, alongside over 50 signatories, have urged the U.S. Congress to mandate screening of orders for synthetic nucleic acids, a critical component in developing both vaccines and bioweapons, as voluntary screening since 2009 has proven insufficient. The Biden administration issued Executive Order 14292 in May 2025, directing revisions to policies on dual-use research and nucleic acid synthesis screening, though as of July 2026, some deadlines remained unmet.
The informed outlook suggests that the dual-use nature of AI in synthetic biology will only intensify. As AI models become more capable, the risk landscape is expected to expand, particularly after 2027, although the pace of evolution remains uncertain. The critical challenge lies in establishing proactive, robust governance that can keep pace with technological advancements. This includes implementing upstream, pre-development risk-benefit reviews for biological AI models, mandatory screening of synthetic DNA orders, and fostering international cooperation to develop a global standards body for frontier AI, as advocated by Google DeepMind CEO Demis Hassabis. Without such comprehensive and enforceable frameworks, the profound benefits AI offers in medicine and public health could be overshadowed by the catastrophic potential for misuse, leaving humanity vulnerable to threats of its own design.