On August 6, 2026, researchers at Stanford University and the Arc Institute published a paper in Science describing the first time artificial intelligence has designed complete, functional viral genomes from scratch. Using genome language models called Evo 1 and Evo 2, the team generated thousands of potential bacteriophage designs. Nearly 300 were chemically synthesised and tested in laboratory conditions. Sixteen produced viable, replicating viruses that had never existed in nature.
Some of the AI-designed viruses outperformed the natural bacteriophage they were modelled on. A cocktail of the generated viruses rapidly overcame bacteria that had evolved resistance to the natural phage. The research demonstrates that generative AI models can now produce complete biological systems at the genome scale – not just individual genes or proteins, but entire living organisms with novel capabilities.
The implications extend far beyond bacteriophages. The same approach that designed working viruses could theoretically be applied to designing other biological systems: enzymes, metabolic pathways, even more complex organisms. The research lays a foundation for AI-guided design of biological function at the whole-genome scale. It also raises urgent biosecurity questions that the research community is only beginning to grapple with.
How AI learned to read DNA
Genome language models work on the same principle as the large language models behind AI chatbots. Just as ChatGPT was trained on billions of words of text to learn the patterns of human language, Evo 1 and Evo 2 were trained on genetic data from 2 million bacteriophages to learn the patterns of DNA sequences in nature. The models learned the evolutionary constraints that shape DNA sequences, the rules, in other words, that make some sequences viable and others non-functional.
The key innovation was training the models on bacteriophage genomes specifically. Bacteriophages are viruses that infect bacteria. They are relatively small; the natural Phi X-174 phage used as the design template has a genome of only 5,386 base pairs, making them experimentally tractable. They have broad applications in molecular biology, microbial engineering, and therapeutics. Critically, the genetic code for viruses that can infect plants, humans, or other animals was intentionally excluded from the AI's training to reduce the risk of it designing dangerous pathogens.
The researchers established a framework for generating and evaluating thousands of AI-generated genomes. The process was not efficient: of the nearly 300 designs that were chemically synthesised and tested, only 16 produced viable phages. But the 16 that worked showed strong host specificity and diverse fitness profiles, including competitive infection kinetics. The generated phages were different from any known natural phages, exhibiting de novo mutations, divergent genes and regulatory elements, and variable genome lengths.
One of the phages utilised a DNA packaging protein from an evolutionarily distant phage in its capsid structure, a combination that does not occur in nature. The AI had learnt enough about how phage genomes work to mix and match components from different evolutionary lineages in ways that produced functional results.
Overcoming resistance: The therapeutic angle
The most significant finding was that a mixture of designed phages rapidly overcame Phi X-174-resistant E. coli strains, whereas a comparable mixture of naturally sourced Phi X-174-like phages could not. This is the central challenge in developing phage-based antimicrobial therapies: bacteria evolve resistance to natural phages quickly. If AI can generate novel phages faster than bacteria can evolve resistance, phage therapy becomes viable as a treatment for antibiotic-resistant infections.
"This is an important milestone," said Patrick Cai, a synthetic biologist at the University of Manchester who was not involved in the study. The ability to rapidly design genomes and tune them for specific bugs while overcoming resistance could "transform phage therapy" and "expand biotechnological toolkits," according to the researchers.
The therapeutic potential is real. Phage therapy has been used for decades in Eastern Europe and the former Soviet Union, but it has never gained traction in the West, partly because natural phages are difficult to engineer and partly because regulatory pathways for phage therapeutics remain unclear. If AI can generate novel, effective phages on demand, the economics of phage therapy change fundamentally.
The biosecurity shadow
But the research also raises urgent biosafety and biosecurity questions that the scientific community has not yet resolved.
In an accompanying commentary published in Science, Tom Inglesby and Moritz Hanke from the Center for Health Security at Johns Hopkins University wrote: "Although this is promising for life sciences applications, it also raises urgent biosafety and biosecurity questions. The ability to compose viral genomes using generative AI now exists; the governance to safely steer it does not."
The researchers themselves acknowledged the concern. In the paper, they wrote that the work raised "important biosafety, biocontainment and biosecurity considerations" and urged others who were designing whole genomes to "consult both safety and security professionals throughout the project."
The specific safeguards the Stanford team implemented are instructive:
• Genetic code for viruses that can infect plants, humans, or other animals was intentionally excluded from the AI's training
• Models were trained only on bacteriophage genomes
• Generated phages were tested only in controlled laboratory conditions
• Researchers worked with institutional biosafety committees throughout the project
But these safeguards are specific to this research. An AI trained on the genetic code of dangerous pathogens could be used to design more harmful viruses. Controlling access to genetic data and having restrictions on making genomes that look dangerous would help, but enforcement is difficult.
The governance gap
Tom Ellis, a professor of synthetic genome engineering at Imperial College London, offered a measured assessment: "This is literally the smallest and easiest genome to make. The work is impressive, but it reveals how hard it would be to make more complex genomes." He noted that an AI trained on the genetic code of dangerous bugs could be used to design more harmful viruses, but controlling access to genetic data and having restrictions on making genomes that look dangerous would help.
Dr. Filippa Lentzos, a reader in science and international security at King's College London, emphasized the importance of a layered approach: "It's important to see the bigger governance picture and not focus regulation solely on the AI model. A layered approach makes more sense: safeguards around model development and access, responsible research review, synthesis screening, and established laboratory biosafety and biosecurity."
The most important point to intervene at the moment is when DNA is being manufactured. DNA synthesis companies already screen orders for sequences that match known pathogens, but the screening is imperfect, and the list of dangerous sequences is constantly evolving. As AI makes it easier to design novel pathogens, the screening problem becomes harder.
Takeaway
• Researchers used Evo 1 and Evo 2 genome language models to generate 285 bacteriophage designs, of which 16 produced viable, replicating viruses that had never existed in nature, demonstrating that AI can now design complete biological systems at the genome scale
• The AI-designed phages showed diverse fitness profiles and some outperformed the natural Phi X-174 they were modeled on; a cocktail of designed phages rapidly overcame bacteria that had evolved resistance to natural phages, suggesting a path toward AI-generated phage therapies against rapidly evolving pathogens
• The research demonstrates that generative AI has crossed from designing individual genes and proteins into designing complete living organisms with novel capabilities, expanding what synthetic genomics can achieve alongside directed evolution and rational engineering
• Biosecurity governance has not kept pace with capability: while the Stanford team implemented safeguards, the governance framework for controlling access to dangerous genetic designs remains inadequate
• The most effective intervention points are at DNA synthesis (screening orders for dangerous sequences) and at model development (controlling which genetic data is used for training), but both are difficult to enforce as capabilities advance
Keen to stay informed on AI breakthroughs and biosecurity implications?
Subscribe to the Project Flux newsletter for such deep dives into generative AI’s evolving capabilities.
Links and Stuff
All content reflects our personal views and is not intended as professional advice or to represent any organisation.

1


