Sixteen viruses built by an AI model. Not modified, not tweaked from existing strains. Built. A study published in Science and reported by Engadget details how researchers used AI to design entirely new viruses capable of infecting and reproducing inside bacteria. The researchers were responsible. The next people to try this might not be.
Scientists at the Arc Institute in Palo Alto and Stanford University ran the experiment using genome language models called Evo 1 and Evo 2. These models work on similar principles to large language models like GPT-4 or Claude, except they were trained on genetic sequences instead of text. The team fed the models trillions of nucleotides, the building blocks of DNA, and the models learned what amounts to the grammar of genetic code. From there, the team trained the models further on roughly 15,000 viruses from the same family as Phi X-174, a small virus that only infects E. coli bacteria. The researchers were deliberate about scope, excluding any virus capable of infecting humans, animals, plants, or fungi.
Evo generated around 700,000 possible new viruses. The team narrowed that pool to 285 candidates, manufactured their DNA, and inserted it into bacteria. Sixteen of those candidates produced working viruses, some reproducing faster than the naturally occurring Phi X-174 they were modeled on. That’s a real result, not a theoretical one.
The legitimate applications here are worth taking seriously. AI-designed viruses could improve gene therapies, sharpen our understanding of how genomes function, and produce better tools for targeting harmful bacteria. In a controlled research setting with proper oversight, this kind of work has obvious scientific value. And that’s exactly the context this study operated in.
But the broader picture is harder to dismiss. Researchers have already shown that standard chatbots can offer concerning guidance to people exploring biological threats. A model that doesn’t just describe biological systems but actively designs functional ones is a different category of risk. More capable future versions could, in theory, help someone engineer a virus optimized for contagion or lethality. That’s not speculation designed to cause panic. It’s the direct extension of what this study demonstrated.
The science itself is not the problem. The problem is that the regulatory environment around AI biosecurity is still catching up to where the technology already is. There’s no equivalent of the nuclear non-proliferation framework here, no global body with real authority over who can train genome models and on what data. Right now, the main safeguard is researchers choosing to be responsible. That’s not a policy. That’s a bet.
As AI capabilities in biology advance, the gap between “possible in a top research lab” and “possible with widely available tools” will narrow. How fast that happens, and whether governance frameworks are in place when it does, is one of the more important open questions in AI right now.




