16 Out of 302: When AI's First Viruses Are Rare but Already Better Than Nature's

Friday 7 August 2026 topic: AI-designed bacteriophages expose a potency asymmetry that the biosecurity governance gap isn't ready for

Lead illustration for 16 Out of 302: When AI's First Viruses Are Rare but Already Better Than Nature's

Scientists at Stanford and the Arc Institute have used generative AI to design complete, functioning viral genomes — the first time a machine-written genome has produced a working virus. Published this week in Science, the work by Brian Hie’s lab used the Evo 2 genome language model to write novel bacteriophage DNA targeting E. coli. The AI generated 302 candidate genomes; 285 assembled completely; just 16 proved viable. A 5.3% success rate sounds reassuring — until you notice what survived the funnel. The AI-designed phages didn’t merely match nature. They obliterated it. The top performer, Evo-Φ69, showed expansion rates of 16- to 65-fold over six hours, against 1.3- to 4-fold for the wild-type ΦX174 they started from. Several qualify as entirely new species. The funnel is steep, but what pours out the bottom is already more potent than anything that went in.

That potency asymmetry is the story the headlines are burying under biosecurity hand-wringing. Hie and his colleagues trained Evo exclusively on 2 million bacteriophage genomes — human, animal, and plant viruses were deliberately excluded. The model required extensive prompt engineering and inference-time guidance to produce coherent genomes at all. Hie argues this doesn’t lower the barrier to bioweapons: “If you wanted to design a bioweapon with AI, it would just be much harder than taking something from nature.” Tom Ellis, a synthetic genome engineer at Imperial College London, agrees, calling the threat from full AI genome design “very overblown” compared to conventional gain-of-function work on existing pathogens. Both are right — today. The ΦX174 genome is under 6,000 base pairs. HIV is around 10,000. SARS-CoV-2 is 30,000. The gap between “the smallest and easiest genome to make” and “a human pathogen” is one order of magnitude, not a categorical wall.

The governance vacuum is where the analysis gets uncomfortable. In an accompanying Science commentary, Tom Inglesby and Moritz Hanke of the Johns Hopkins Center for Health Security put it plainly: “The ability to compose viral genomes using generative AI now exists; the governance to safely steer it does not.” Evo 2 is open-source and freely available — a deliberate choice by Hie’s team, who argue that open tools let researchers build safety checks into AI systems in a way that doesn’t happen when pathogens evolve naturally. That framing is defensible for phage therapy, where the upside is genuinely large: antibiotic resistance kills over a million people a year, and AI-designed phage cocktails that overcome bacterial resistance could be transformative. But the same openness means the model weights, the training pipeline, and the experimental protocol are all sitting in a GitHub repository. The training data exclusion — the firewall keeping human pathogen genomes out of Evo — is a policy choice, not a technical constraint. A lab with different data and the same architecture faces no comparable barrier.

Filippa Lentzos of King’s College London offers the most pragmatic regulatory frame: the chokepoint isn’t the model, it’s DNA synthesis. “A layered approach makes more sense: safeguards around model development and access, responsible research review, synthesis screening, and established laboratory biosafety and biosecurity.” That’s correct but incomplete. Synthesis screening works when you know what to screen for. The AI-designed phages in this study qualified as new species — genomes that don’t exist in any reference database. A screening system trained on known pathogens would flag them as unknown, not dangerous. The governance challenge isn’t just preventing known bad sequences from being printed; it’s deciding what an unknown sequence means when AI can already generate ones that outperform nature.

The Hacker News thread on the Stanford announcement drew five points and one comment — a link to the GitHub repo. For a technology that just demonstrated AI can write living, infectious genomes more potent than evolution’s own, that’s a striking signal of where the tech community’s attention sits. AI safety discourse obsesses over hypothetical misaligned superintelligence while the infrastructure for designing real biological threats improves quietly and openly. The 5.3% viability rate will get better. The potency gap will widen. The governance will arrive late or not at all. The question isn’t whether AI can design a human pathogen. It’s whether anyone will notice before it does.

Sources