AI Generates First Functional Viruses, Triggering Push for New Biosecurity Guardrails
Researchers have successfully used generative AI to design 16 functional bacteriophages from scratch, marking a breakthrough for antibiotic resistance but exposing critical vulnerabilities in global DNA synthesis screening.
- Medical Innovators
- Views generative biology as a critical tool for rapidly developing custom phage therapies to combat the escalating crisis of antibiotic-resistant bacteria.
- Biosecurity Analysts
- Focuses on the dual-use risks of the technology, emphasizing the urgent need to upgrade DNA synthesis screening to catch AI-disguised toxins.
- Technology Skeptics
- Expresses concern that the rapid pace of AI development in biology is outpacing regulatory frameworks, creating vulnerabilities for catastrophic misuse.
Why this matters
The ability to generate biological entities from digital code promises rapid, custom treatments for failing antibiotics, but it also means biological threats are no longer limited to physical materials, requiring an immediate overhaul of global biosecurity screening.
Key points
- Researchers used generative AI to design 16 fully functional viruses from scratch.
- The viruses are bacteriophages designed to target E. coli, posing no threat to humans.
- The breakthrough offers a promising new avenue for creating custom treatments for antibiotic-resistant infections.
- Microsoft Research revealed that AI can also redesign known toxins to evade current DNA synthesis safety checks.
- The biosecurity industry is racing to implement advanced screening that predicts protein structure rather than just matching sequences.
Artificial intelligence has crossed a profound threshold in synthetic biology, transitioning from analyzing existing genetic code to writing entirely new, functional lifeforms from scratch. Researchers at Stanford University and the Arc Institute have successfully used generative AI to design complete viral genomes that were subsequently synthesized and brought to life in a laboratory. The achievement, published in the journal Science, marks the first time machine-learning models have generated viable biological entities end-to-end.[1][2]
The organisms created are bacteriophages—viruses that exclusively infect and destroy bacteria, posing no threat to humans, animals, or plants. The research team deliberately restricted their models to exclude human pathogens, focusing instead on combating the escalating global crisis of antibiotic-resistant bacterial infections. In laboratory tests, the AI-designed viruses successfully infected and dismantled strains of E. coli, proving that the digital blueprints could translate into functional, replicating biological machines.[2][4]
To achieve this, the scientists utilized specialized "genome language models" known as Evo 1 and Evo 2. These systems operate on the same fundamental architecture as the large language models powering popular text chatbots, but rather than predicting the next word in a sentence, they predict the next base pair in a DNA sequence. By learning the underlying "grammar" of genetic code, the models can generate novel sequences that adhere to the complex rules of biological viability.[1][3]
The models were trained on a massive dataset comprising approximately 2.7 million prokaryotic and phage genomes. The researchers then fine-tuned the AI on roughly 15,000 genomes from the Microviridae family—a specific class of tiny viruses. From this foundation, the AI generated hundreds of thousands of potential new viral blueprints, exploring genetic combinations that do not exist in nature.[3]

From the AI's vast output, the team selected roughly 300 promising candidates for physical synthesis. Ultimately, 16 of these AI-generated designs proved viable when introduced into host cells. Not only did they function, but several of the engineered phages significantly outperformed their natural counterparts. One specific variant demonstrated a replication advantage 65 times greater than the natural template it was modeled against when competing for the same bacterial hosts.[1][3]
The medical implications of this capability are vast. As traditional antibiotics increasingly fail against mutating superbugs, phage therapy—using viruses to hunt specific bacteria—has gained traction. However, discovering and isolating effective natural phages is a slow, labor-intensive process. The Stanford and Arc Institute research suggests a near future where clinicians could sequence a patient's drug-resistant infection and use AI to design a custom, highly effective viral cure within hours.[1][2]
As traditional antibiotics increasingly fail against mutating superbugs, phage therapy—using viruses to hunt specific bacteria—has gained traction.
Yet, the same technology that promises tailored cures has simultaneously triggered urgent alarms within the global biosecurity community. The transition from editing existing DNA—using tools like CRISPR—to generating entirely novel genomes from digital prompts represents a paradigm shift in biological risk. If an AI can be instructed to design a highly efficient virus to kill bacteria, experts warn that similar models could theoretically be directed to design pathogens that target human biology.[2][6]
This dual-use dilemma is compounded by the "digital-to-physical" barrier. Currently, researchers cannot simply print DNA in their offices; they must send digital sequences to commercial DNA synthesis companies, which manufacture the physical genetic material. These companies act as the primary chokepoint for biosecurity, utilizing screening software to check incoming orders against databases of known toxins and pathogens to prevent the creation of biological weapons.[2][5]
However, recent findings from Microsoft Research have exposed a critical vulnerability in this defensive perimeter. In a comprehensive red-teaming exercise, Microsoft scientists demonstrated that generative AI can successfully redesign known toxins—such as ricin—to bypass standard DNA synthesis safety checks. The AI effectively "paraphrases" the genetic code, altering the sequence enough to evade detection by current software while preserving the protein's lethal three-dimensional structure and function.[5]
Microsoft's research revealed that up to 100 percent of certain AI-generated, ricin-like proteins flew through commercial screening techniques undetected. Because traditional biosecurity software relies on matching incoming orders against a static library of known dangerous sequences, it is fundamentally ill-equipped to recognize novel, AI-generated threats that look different on paper but act identically in a biological system.[5]

In response to this zero-day vulnerability in global biosecurity, a coalition of scientists, synthesis companies, and policymakers is racing to deploy advanced screening methods. The proposed solution involves shifting from simple sequence-matching to structural and functional prediction. By using AI defensively, new screening tools can analyze an unknown DNA sequence, predict how it will fold into a protein, and assess whether that shape matches the mechanism of a known toxin.[5]
This defensive pivot is being described by industry leaders as a necessary "Windows update for the planet." Federal funding agencies and international health organizations are increasingly pushing to make these advanced, predictive screening protocols mandatory for all commercial DNA synthesis providers, aiming to close the loophole before generative biology tools become more widely accessible.[2][5]
The governance challenge now centers on how to regulate the AI models themselves. While the Stanford team deliberately excluded human pathogens from their training data, the open-source nature of many AI developments means that future, less-restricted models could emerge. Policymakers are debating whether advanced biological AI models should be subject to mandatory safety evaluations and restricted access, balancing the need for rapid medical innovation against the risk of catastrophic misuse.[1][2]
Ultimately, the creation of the first AI-designed viruses confirms that generative biology is no longer a theoretical concept—it is an active, functional engineering discipline. As the technology scales, the focus of the scientific community is shifting rapidly from proving that AI can design life to ensuring that the guardrails governing its physical creation are robust enough to handle an era of custom-written biology.[2][4]
How we got here
Late 2023
Microsoft Research begins a confidential red-teaming project to assess AI vulnerabilities in biosecurity screening.
September 2025
Stanford and Arc Institute researchers publish a preprint detailing the successful AI generation of functional bacteriophages.
October 2025
Microsoft publishes findings showing AI can redesign toxins to bypass standard DNA synthesis checks, prompting industry updates.
August 2026
The Stanford research is formally published in the journal Science, confirming the viability of the 16 AI-designed viruses.
Viewpoints in depth
Medical Innovators
Views generative biology as a critical tool for rapidly developing custom phage therapies to combat the escalating crisis of antibiotic-resistant bacteria.
For researchers focused on infectious diseases, the ability to generate novel viruses is a long-awaited solution to the antibiotic resistance crisis. Traditional phage therapy relies on finding naturally occurring viruses that happen to target a specific bacterial strain—a process that is slow, unpredictable, and difficult to scale. Generative AI collapses this timeline. By inputting the genetic profile of a drug-resistant superbug, clinicians could theoretically use genome language models to design a bespoke viral cocktail that overcomes the bacteria's specific defenses. The fact that several of the AI-designed phages outperformed their natural templates suggests that machine learning can optimize biological functions beyond what natural evolution has achieved, opening the door to highly targeted, personalized medicine.
Biosecurity Analysts
Focuses on the dual-use risks of the technology, emphasizing the urgent need to upgrade DNA synthesis screening to catch AI-disguised toxins.
Security experts view the Stanford breakthrough through the lens of vulnerability. While the current research safely targeted E. coli, the underlying capability—writing functional biology from digital prompts—fundamentally alters the threat landscape. The primary concern, validated by Microsoft's red-teaming exercises, is that bad actors could use similar models to design pathogens or toxins that evade the commercial DNA synthesis screening process. Because AI can 'paraphrase' a genetic sequence while maintaining its lethal function, traditional screening methods that rely on matching known threat signatures are becoming obsolete. This camp argues that the 'digital-to-physical' barrier must be fortified immediately, requiring all synthesis providers to adopt advanced, predictive structural screening before generative biology tools proliferate further.
Technology Skeptics
Expresses concern that the rapid pace of AI development in biology is outpacing regulatory frameworks, creating vulnerabilities for catastrophic misuse.
This perspective highlights the broader governance lag surrounding artificial intelligence. Skeptics point out that the guardrails currently in place—such as intentionally excluding human pathogens from training data—rely largely on the voluntary goodwill of the researchers involved. As the computational cost of training genome language models decreases, the likelihood of unrestricted, open-source biological AI models emerging increases. This camp argues that relying solely on DNA synthesis companies to catch dangerous orders is insufficient, advocating instead for strict, mandatory oversight at the model-training level. They warn that without comprehensive international regulation, the democratization of biological design could lead to accidental or intentional releases of engineered pathogens.
What we don't know
- It remains unclear how quickly the global DNA synthesis industry can fully transition to the more complex structural and functional screening methods required to catch AI-generated threats.
- The long-term ecological impact of introducing entirely synthetic, AI-optimized viruses into human microbiomes or the environment has not yet been studied.
- Policymakers have not yet determined how to effectively regulate the distribution and open-source availability of advanced biological AI models without stifling medical research.
Key terms
- Bacteriophage
- A type of virus that specifically infects and replicates within bacteria, often used in medicine to treat antibiotic-resistant bacterial infections.
- Genome Language Model
- An artificial intelligence system trained on massive amounts of genetic data to understand and generate new, functional sequences of DNA.
- DNA Synthesis
- The process of artificially creating DNA molecules in a laboratory, translating digital genetic sequences into physical biological material.
- Dual-Use Dilemma
- The concept that the same scientific research or technology can be used for both beneficial purposes (like medicine) and harmful ones (like biological weapons).
- Phage Therapy
- A medical treatment that uses bacteriophages to target and destroy specific pathogenic bacteria, serving as an alternative to traditional antibiotics.
Frequently asked
Can these AI-designed viruses infect humans?
No. The researchers specifically designed bacteriophages, which are viruses that only infect bacteria. Furthermore, the AI models were intentionally restricted from training on data related to human, animal, or plant pathogens.
How does a genome language model work?
Similar to how text-based AI predicts the next word in a sentence, a genome language model analyzes massive datasets of genetic code to learn the 'grammar' of biology, allowing it to predict and generate viable sequences of DNA base pairs.
Why is current biosecurity screening vulnerable?
Current screening software primarily looks for exact matches to known dangerous DNA sequences. AI can 'paraphrase' a sequence—changing the code while keeping the resulting protein's dangerous function intact—allowing it to slip past traditional filters.
What is being done to fix the screening loophole?
Scientists and industry leaders are developing advanced screening tools that predict the three-dimensional structure and function of an unknown DNA sequence, rather than just checking it against a list of known threats.
Sources
[1]EurekAlertMedical Innovators
Generative design of bacteriophages with genome language models
Read on EurekAlert →[2]The GuardianBiosecurity Analysts
Scientists make first AI-designed viruses in breakthrough that raises biosecurity fears
Read on The Guardian →[3]EngadgetTechnology Skeptics
AI is now making new viruses. What could possibly go wrong?
Read on Engadget →[4]IFLScienceMedical Innovators
Scientists Use Generative AI To Build 16 Brand New Viruses
Read on IFLScience →[5]MicrosoftBiosecurity Analysts
Strengthening nucleic acid biosecurity screening against generative protein design tools
Read on Microsoft →[6]AxiosTechnology Skeptics
Now AI can create new viruses
Read on Axios →
Comments
Every angle. Every day.
Get perspectives stories with full source coverage and perspective breakdowns delivered to your inbox.







