The Genome the Model Wrote: Inside the First AI-Designed Virus



The Setup: A Simple, Devastating Question
Imagine you're a biosecurity officer and someone hands you a genome. Not a genome copied from nature — one a language model dreamed up, base by base, the way a chatbot dreams up the next word in a sentence. Do you let it into a lab? You want to check it against everything known, every dangerous motif, every risky sequence. But what if the model was trained on two million genomes? What if it could generate thousands of candidates in an afternoon, any one of which might work? What if the thing that makes it powerful — the ability to design a genome for a purpose — is the exact same thing that makes it dangerous? Scientists just built that thing. Not in theory. In a dish, against real bacteria, with a genuine kill.
The Breakthrough: When AI Learns to Write Life
Here's what actually happened, with the caveats stripped out for a moment.
A team led by Dr Brian Hie, a chemical engineer at Stanford, took genome language models — architecturally the same kind of system behind large language models — and pointed them at bacteriophages: viruses that infect only bacteria, long used in "phage therapy" against infections that won't respond to antibiotics. The models, called Evo1 and Evo2, had been trained on genetic sequences from roughly two million bacteriophages. Crucially, the researchers stripped out genetic code from viruses capable of infecting humans, animals, or plants before training, an attempt to keep the models from ever learning how to design something that could hurt a person.
From there the AI generated thousands of candidate genomes. Researchers narrowed that down to around 300 worth attempting in the lab. Those sequences were inserted into bacteria, which read the synthetic code and assembled the new phages. The hit rate was low — only 16 of roughly 300 actually worked — but a cocktail of those 16 was enough to overcome resistance in two separate strains of *E. coli* that had shrugged off natural phages. The team's own framing, published in *Science*, is that the approach could let researchers rapidly tune phages against resistant bugs and expand what's possible in biotechnology more broadly.
Why It's Bigger Than It Looks
This is where a lot of coverage stops: cool, a machine designed a virus that works. But the interesting part isn't that it worked — it's what working proves. Bacteriophage genomes are tiny compared to almost anything else in biology. Getting an AI to design one that functions demonstrates, for the first time, that generative models can produce a viable viral genome at all, not just tweak an existing one.
That's a capability question, and capability questions don't stay contained to the system they were first demonstrated on. The same underlying idea — train a model on genomes, ask it to generate new ones, screen for what's viable — doesn't inherently know to stop at bacteriophages. Tom Ellis, a professor of synthetic genome engineering at Imperial College London, put it bluntly: this is close to the simplest and easiest genome there is to make. Which means the demonstration is as much a floor as a ceiling — a marker of where the technology currently sits, not where it's capped.
The Part Nobody Talks About: The Guardrails Are Already Doing Work
It's worth pausing on what the researchers actually built in as a safeguard, because it's a genuinely interesting design choice, not an afterthought. Excluding human-, animal-, and plant-infecting viral sequences from training data is a deliberate bet that a model can't design what it's never seen — that capability doesn't generalize past its training distribution in this domain the way it sometimes does in language.
Whether that bet holds is exactly the open question. The accompanying commentary in *Science*, from Prof Tom Inglesby and Dr Moritz Hanke at Johns Hopkins' Center for Health Security, doesn't dispute that the work is promising — it argues the tools to compose viral genomes now exist well ahead of any governance built to steer them safely. Their specific worry: genomes designed this way could describe pathogens that existing medical and public health countermeasures simply aren't built to contain, so the caution shouldn't stop at bacteriophages. Both the original researchers and the commentators land in the same place — this needs security professionals in the room from the start, not bolted on afterward.
The Meta-Twist: Is This Even the Real Threat?
Here's the part that undercuts the scarier headlines. Ellis, while calling the result impressive, argued the alarm over full AI-designed genomes is somewhat overblown — because there's a much easier and more realistic path to danger. Taking an existing, already-dangerous pathogen and making targeted gain-of-function edits to it is far simpler than generating a whole genome from scratch, and arguably a more plausible route to real harm. Full AI design might be the more dramatic story, but it isn't necessarily the most likely one.
Dr Filippa Lentzos, at King's College London, pushes the frame even further away from the model itself. Her view: the more important intervention point isn't the AI at all — it's the moment synthetic DNA actually gets manufactured. Rather than concentrating regulation on the model, she argues for layered safeguards across model development and access, research review, DNA synthesis screening, and ordinary lab biosafety — the AI is one link in a longer chain, not the whole chain.
Conclusion: The Capability Outran the Consensus
This isn't really a story about a virus. It's a story about a gap — the gap between what a tool can now do and what anyone has agreed it should be allowed to do. The researchers built in restraint by curating training data. The commentators are asking for restraint at the level of policy. And at least one outside expert thinks the restraint that actually matters is somewhere else entirely: in the synthesis machines, not the model weights.
None of that makes the demonstration less real. Sixteen working phages beat resistant bacteria in a dish. The genome was small, the target was narrow, and the guardrails held — this time, on this system, for this class of virus. Whether that holds as the genomes get bigger and the models get better is the actual question, and it's a governance question now as much as a technical one.
---
References:
1. https://www.science.org/doi/10.1126/science.aec2657
2. https://pubmed.ncbi.nlm.nih.gov/42561080/
4. https://news.stanford.edu/stories/2026/08/evo-2-ai-tool-e-coli-killer-bacteriophages
5. https://www.biorxiv.org/content/10.1101/2025.09.12.675911v1