For the first time, a machine has written the complete instructions for a living thing — and the living thing worked.
Researchers at Stanford University and the Arc Institute have used a generative AI model to design entire viral genomes from scratch, then built and tested them in the laboratory. Sixteen of the designs turned out to be viable, replicating viruses that had never existed in nature. The results were published on Thursday in the journal Science, and the reaction from the scientific community arrived in two distinct halves: this is a landmark, and this is a problem.
The viruses in question are bacteriophages — viruses that infect bacteria, not people. Every one of the sixteen was designed to attack Escherichia coli, and researchers stress they pose no threat to humans. That framing matters, and it is also the narrowest possible reading of what just happened.
"This is a next step in the complexity that's designable by generative AI," Brian Hie, the Stanford assistant professor who led the work, told the BBC. "This is the first time generative AI has been used to design a complete genome, it's something that can replicate and have other functions inside cells… this was new territory for us."

What the researchers actually did
The work builds on Evo 2, a large genome model — the DNA equivalent of a large language model. Where a language model is trained to predict the next word in a sequence of text, a genome model is trained to predict the next base in a sequence of DNA, using genetic sequences drawn from millions of organisms across all domains of life.
The team used the model to generate variants of the genome of ΦX174, a small, extremely well-characterised bacteriophage that has been a workhorse of molecular biology for decades. ΦX174 was a deliberate choice: its genome is compact, its biology is understood in detail, and it infects bacteria rather than anything with a nervous system.
The pipeline ran roughly like this:
- Generate. The model produced thousands of candidate genome sequences, each a complete design rather than an edit to an existing template.
- Filter. Computational screening narrowed those thousands to a shortlist judged plausible enough to be worth physical synthesis.
- Build. Around 300 candidate genomes were chemically synthesised and introduced into bacterial hosts.
- Test. Of those, 16 produced functional, replicating viruses — and some killed E. coli more effectively than the natural ΦX174 they were derived from.
That final detail is the one specialists keep returning to. As Scientific American reported, lab tests of the model's E. coli-killing designs "exceeded expectations". The model did not merely reproduce nature. In at least some respects, it outperformed it.

Why a hit rate of 16 in 300 is the important number
At first glance, 16 viable designs out of roughly 300 synthesised looks like a modest success rate — about 5%. Read as a scientific result, it is remarkable.
Designing a functional genome is categorically harder than designing a functional protein, which is where most AI-for-biology work has concentrated. A protein has to fold correctly and do one job. A viral genome has to encode multiple proteins, get their relative quantities right, sequence their production correctly in time, package itself into a capsid, enter a host cell, hijack that host's machinery, and exit to infect again. Every one of those steps is a failure mode. Getting all of them right simultaneously, from a sequence a model invented, is a coordination problem with an enormous number of ways to go wrong.
A 5% hit rate means the model has internalised something real about how genomes are organised — not just which letters tend to follow which, but how functional modules relate to one another. As Ars Technica noted, some of the designs contained features that would be difficult to arrive at through natural evolution.
That is the scientific headline. It is also the biosecurity headline, because hit rates improve.
| Capability | Status before this study | Status now |
|---|---|---|
| AI-designed proteins | Established; used for antibiotics | Established |
| AI-designed gene circuits | Demonstrated in bacteria | Established |
| AI-designed complete genome | Not achieved | Achieved for bacteriophages |
| AI-designed viruses targeting vertebrates | Not achieved | Not achieved; flagged as future risk |
The upside is genuinely large
The therapeutic case for this work is not speculative hand-waving. It addresses one of the most concrete public health problems of the decade.
Antimicrobial resistance is projected by the World Health Organization to be among the leading global causes of death by mid-century, and the antibiotic development pipeline has been thin for years because the economics of antibiotics are poor. Phage therapy — using bacteriophages to kill bacterial infections — is an old idea that has always been limited by a practical bottleneck: for any given resistant infection, you need a phage that attacks that specific strain, and finding one has traditionally meant searching the natural world.
A generative model that can design phages to order changes the bottleneck from discovery to design. In principle, a clinician facing a resistant infection could have candidate phages designed against the sequenced pathogen rather than hoping a matching phage exists in a library somewhere.
AI has already designed candidate antibiotics for gonorrhoea and MRSA. Designing the delivery vehicle — a self-replicating virus that hunts a specific bacterium — is a substantially more powerful tool, because it multiplies inside the infection rather than being dosed into it.

The risk is not this study. It is the trajectory.
Nobody serious is arguing that sixteen E. coli-killing phages are dangerous. The concern, stated plainly by the researchers themselves, is about what a related model could do next.
The Stanford team explicitly suggested the scientific community should start preparing now for the possibility that a similar system could be pointed at viruses that infect vertebrates — including humans. Three properties of the current work make that concern credible rather than alarmist.
The method generalises. Nothing in the approach is specific to bacteriophages. Genome models are trained across all domains of life. The reason this study stopped at phages is that the researchers chose to stop there.
Capability is improving faster than governance. The gap between "AI designs a protein" and "AI designs a complete functional genome" closed in roughly two years. Biosecurity frameworks — screening obligations for DNA synthesis providers, institutional review, export controls — move on timescales measured in legislative sessions.
The physical bottleneck is a commercial service. Designing a genome is now a computational act; building one requires DNA synthesis. Synthesis providers are the natural chokepoint, and many voluntarily screen orders against databases of known hazardous sequences. But sequence screening works by comparison to known threats. A genome no model has seen and no database contains is, by construction, the hardest case for that approach.
This is the specific technical reason the biosecurity community is describing the concerns as "urgent" rather than "eventual". The safeguard architecture was designed to catch copies of known dangerous things. This technology produces novel things.

What credible safeguards would involve
The debate has moved past whether to regulate and into what regulation would actually catch. Four measures come up repeatedly among specialists:
Function-based synthesis screening. Replacing or supplementing sequence-matching with screening that predicts what a submitted sequence would do, rather than what it resembles. This is technically hard and is the most important open problem in the field.
Model-level access controls. Restricting genome-scale generative capability to credentialled institutional users, with logged queries — closer to how controlled pathogens are handled than to how software is distributed.
Mandatory rather than voluntary provider obligations. Screening by DNA synthesis companies is currently largely voluntary in most jurisdictions. A single non-screening provider anywhere undermines the entire chokepoint.
Pre-publication risk review. Structured assessment of dual-use potential before methods are released, extending existing gain-of-function review norms to computational design work.
None of these are frictionless, and each imposes costs on exactly the research that could deliver phage therapies for resistant infections. That tension is the real policy problem: the same capability that might treat a drug-resistant infection is the capability that worries biosecurity analysts, and they cannot be separated by regulating intent.

Where this sits in the wider AI story
It is worth placing this alongside the other AI stories of the week. Companies are pouring record sums into compute infrastructure — SpaceX alone disclosed $18.4bn of quarterly capital expenditure, mostly on AI, as we covered in our analysis of SpaceX's first earnings report. Regulators are simultaneously imposing record penalties on platforms for downstream harms, as in the $567m child safety ruling against Meta.
The pattern across all three is the same: capability arrives, deployment follows immediately, and the governing framework is assembled retrospectively under pressure. In social media, the lag produced a decade of contested harm and eventual litigation. In biology, the same lag has a different failure mode, and it is not one that can be settled in a courtroom afterwards.
Our Health & Science and Technology sections follow both sides of this story.
What working scientists are watching next
Three follow-on questions will determine whether this becomes a therapeutic platform or stays a demonstration.
Can the hit rate be lifted, and how? Sixteen viable designs from roughly 300 syntheses is impressive for a first attempt and expensive as a production process. If improved models, better computational filtering, or iterative feedback from lab results push viability toward 20–30%, phage design becomes a routine workflow rather than a research project. Every improvement in efficiency, however, also lowers the resource threshold for misuse — which is why capability and safeguards are genuinely coupled here rather than merely rhetorically linked.
Does the approach transfer to larger genomes? ΦX174 is a very small virus. Clinically useful phages against pathogens such as Pseudomonas aeruginosa or Klebsiella pneumoniae are frequently far larger and more complex, with more regulatory elements to get right. Whether genome models scale gracefully to that complexity is an open empirical question, and the answer determines how much of the antimicrobial resistance problem this can actually reach.
Can regulators be shown a screening method that works on novel sequences? This is the load-bearing safeguard. Until function-based screening is demonstrated at production scale by synthesis providers, the honest description of the current safety architecture is that it detects imitations of known hazards and not much else.
Researchers involved in the work have been notably direct on this point, which is itself worth noting. The people best positioned to accelerate the technology are the ones asking for the guardrails — a contrast with how several earlier general-purpose AI capabilities reached deployment.
Frequently asked questions
Are the AI-designed viruses dangerous to humans? No. All sixteen are bacteriophages designed to infect Escherichia coli bacteria. They cannot infect human cells and pose no direct threat to people.
What is a bacteriophage? A virus that infects bacteria. Phages are being investigated as treatments for bacterial infections that no longer respond to antibiotics, because they kill bacteria selectively and replicate at the site of infection.
How many viruses did the AI actually create? The model generated thousands of candidate genomes. Researchers computationally screened those, synthesised about 300, and found 16 that produced functional, replicating viruses.
Why is this considered a first? Previous AI work in biology designed individual proteins or gene circuits. This is the first time a generative model has designed a complete genome capable of replicating and functioning inside cells.
What are the main safety concerns? That the same method could be applied to viruses infecting humans or other vertebrates, and that existing DNA synthesis screening — which compares orders against databases of known hazardous sequences — is poorly suited to detecting entirely novel designs.
Could this help with antibiotic resistance? Potentially, yes. Designing phages to target specific resistant bacterial strains would remove the bottleneck of having to find a naturally occurring phage that happens to match the pathogen.
Bottom line
Sixteen viruses that kill E. coli is a small result with an enormous asterisk. The asterisk is that generative AI has now demonstrated it can write a complete, working genome — and the researchers who proved it are the ones asking, publicly and in print, for the safety conversation to start before somebody points the same method at something with a spine.
The science is a turning point. Whether it turns out to be a good one depends on decisions being made now, in synthesis-provider policy and model access rules, by people with far less publicity than the paper.
Protunez continues to cover AI, biosecurity and public health in Health & Science.



