Stanford scientists build first AI-designed viruses that kill

Get the Health newsletter
Daily health & science — research, biotech, public health, the studies worth knowing. Free.
- Dr Brian Hie at Stanford used genome language models Evo1 and Evo2 — trained on 2 million bacteriophage genomes, with viruses that infect plants, humans, or other animals deliberately excluded — to design the first functioning AI-generated viruses, a milestone published in Science.
- The AI generated thousands of candidate genomes; researchers selected nearly 300 to synthesize in the lab, but only 16 proved viable, and a cocktail of those swiftly overcame resistance in two strains of E. coli that natural bacteriophages could not kill.
- Hie and colleagues themselves flagged "important biosafety, biocontainment and biosecurity considerations" and urged other whole-genome designers to consult safety and security professionals throughout their projects.
- In an accompanying commentary, Prof Tom Inglesby and Dr Moritz Hanke of Johns Hopkins's Center for Health Security warned that "the ability to compose viral genomes using generative AI now exists; the governance to safely steer it does not," and said work on human-, animal-, or plant-infecting pathogens should not be pursued.
- Prof Tom Ellis at Imperial College London called the work impressive but said the threat from full AI genome design is "very overblown," arguing that gain-of-function edits to existing pathogens are far easier and more likely to be a real risk.
- Dr Filippa Lentzos at King's College London pushed for regulation at the point of DNA manufacture rather than the AI model itself, advocating a layered approach spanning model safeguards, research review, synthesis screening, and lab biosafety.
- Ellis noted that bacteriophage genomes are the "smallest and easiest" to make, underscoring how much harder scaling the technique to more complex viruses would be — a built-in speed bump the most alarmist coverage tends to skip.
Why it matters: The research proves generative AI can produce functioning viral genomes from scratch, a capability that didn't exist before — but only 16 of ~300 designs worked, and the targets were bacteria-only phages deliberately walled off from human pathogens. The real governance gap, per Lentzos, is at DNA synthesis, not the AI model itself, meaning screen-the-order, not ban-the-algorithm, is the intervention most security experts actually back.



