A Stanford-led team has done something that was theoretical until this week: they used artificial intelligence to design the complete genome of a virus, built it in a lab, and watched it work. The result is being called a milestone for medicine and a warning sign for biosecurity, often in the same sentence.
What happened
Researchers led by Brian Hie, an assistant professor of chemical engineering at Stanford University and an investigator at the Arc Institute, used two AI systems called Evo 1 and Evo 2, known as genome language models, to generate whole-genome sequences for bacteriophages. Phages are viruses that infect bacteria rather than humans, and doctors already use them around the world to treat drug-resistant infections when antibiotics fail.
The AI models proposed thousands of candidate genomes based on patterns learned from naturally occurring phages. The team synthesized hundreds of them in the lab and tested them against E. coli. Sixteen of the AI-generated designs worked well enough to function as viable phages, and a cocktail of them was able to kill E. coli strains that had already evolved resistance to natural phages. The study was published this week in the journal Science, alongside a commentary from biosecurity researchers at Johns Hopkins University’s Center for Health Security.
It marks the first time a complete, functional viral genome has been generated by AI rather than modified from an existing one. Researchers were careful to work only with a phage template that cannot infect humans, and they excluded training data related to viruses capable of infecting people, animals, plants, or fungi.
Why it matters
For years, AI in biology has meant tools that predict structures or suggest small tweaks to existing molecules, AlphaFold being the most famous example. This is a different kind of milestone: instead of predicting or editing, the model composed an entire genome from nothing, and that genome turned out to be biologically functional. Marc Güell, who runs a synthetic biology lab at Pompeu Fabra University in Spain, called it a turning point because it marks the first time researchers have begun designing biology on a computer rather than in a dish.
The upside is real. Phage therapy has struggled with a resistance problem of its own: bacteria evolve defenses against natural phages just as they do against antibiotics. If AI can generate new phage designs on demand, tuned to outrun resistance, it could meaningfully speed up treatment for the kind of persistent, drug-resistant infections that current medicine handles poorly.
The concern is just as real. The same underlying capability, generating a working genome from a language model, does not stop at harmless bacteriophages. Thomas Inglesby and Moritz Hanke, the Johns Hopkins researchers who wrote the accompanying commentary, put it plainly: the ability to compose viral genomes using generative AI now exists, but the governance to safely steer it does not. Their point isn’t that this particular study is dangerous. The phage genome involved is small, around 5,400 genetic letters, compared with roughly 500,000 for the simplest living cell and three billion for a human genome. Their point is that the technique itself, not this specific output, is what needs oversight, because nothing about the method is inherently limited to safe targets.
The bigger picture
This lands at an awkward moment for biosecurity policy. The Trump administration issued a policy last month restricting federally funded gain-of-function research, the practice of modifying existing pathogens to study how they might become more dangerous. But that policy was written with traditional genetic engineering in mind, not generative AI models that design genomes from scratch. Researchers in the field say regulation is now playing catch-up to a capability that didn’t exist in a workable form until this study proved it out.
There’s also a useful distinction buried in the reaction to this paper. Some scientists interviewed about the study argued that the near-term risk from AI designing an entirely new pathogen from first principles is overstated, since making small, dangerous changes to an already-existing pathogen remains far easier and more realistic as a threat. The harder, more novel capability this study demonstrates is further from being weaponizable than the more mundane risk of someone using any genetic engineering tool, AI-assisted or not, to tweak something that already exists. That doesn’t make the new capability irrelevant. It means the risk curve is longer than headlines suggest, and it gives policymakers a window, not a deadline that has already passed.
This is also the second time this year that biology-focused AI has forced a conversation that outpaced its regulation. Genome language models sit in the same category as protein-design tools and AI-driven drug discovery platforms: enormously useful, dual-use by nature, and built by teams that are, in this case, explicitly asking for oversight rather than avoiding it. That the researchers themselves flagged biosafety and biosecurity considerations, and called for others in the field to consult security professionals, says something about where the scientific community’s own risk tolerance sits right now.
What’s next
Expect two parallel tracks. On the medical side, phage therapy researchers will likely try to reproduce and extend this approach against other resistant bacteria, since the therapeutic case here is strong and the phages involved pose no threat to humans by design. Brian Hie has said his lab is interested in eventually working toward designing simple living organisms, not just viruses, though he’s described that as a significant additional leap rather than an incremental one.
On the policy side, this paper is likely to become a reference point in ongoing arguments about how AI biology tools should be governed, particularly around who can access genome language models trained on pathogen data, and how DNA synthesis companies screen orders for risky sequences. Neither of those safeguards is specific to this study, but both were named directly by scientists reacting to it as the practical levers that matter more than restricting the AI models themselves. Whether governments move on that before the next capability jump, rather than after, is the real test this research sets up.







