AI and the Design of Viral Bioweapons
In early August 2026, researchers at Stanford University and the Arc Institute published work in Science showing that genome language models (Evo 1 and Evo 2) could generate complete, novel bacteriophage genomes never seen in nature. Of the designs they selected and synthesized, sixteen proved viable in the laboratory: they infected E. coli, replicated, and in some cases outperformed the natural template phage ΦX174, including against resistant strains. The models had been trained on large libraries of bacteriophage DNA while deliberately excluding sequences from viruses that infect humans, animals, or plants. The work stayed inside secure labs and targeted only bacteria.
The medical promise is real. Phage therapy has long been limited by the slow pace of finding or engineering viruses that can kill specific bacterial pathogens, especially those that have already evolved resistance. An AI that can rapidly propose coherent, functional genomes and allow researchers to tune them could expand the toolkit against antibiotic-resistant infections. The researchers themselves described the advance as opening new territory that might improve human health if handled carefully.
Yet the same demonstration immediately drew sharp warnings. In an accompanying commentary in Science, Thomas Inglesby and Moritz Hanke of the Johns Hopkins Center for Health Security wrote that the ability to compose viral genomes with generative AI now exists, but the governance needed to steer it safely does not. They stated that work aimed at pathogens capable of infecting humans, animals, or plants "should not be pursued," because such genomes might encode new pathogens that cannot be contained by existing countermeasures. The original research team likewise flagged important biosafety, biocontainment, and biosecurity considerations and urged anyone designing whole genomes to consult safety and security professionals throughout the project.
This is where the stakes rise for the possibility of deliberate misuse. Until now, designing a functional virus from scratch required deep expertise, years of iterative lab work, and access to specialised resources. AI that can propose complete, coherent genomes lowers one conceptual barrier: the generation of novel sequence space that evolution never produced. Even if current models and training data are restricted, the principle has been shown. A determined actor with sufficient resources, access to DNA synthesis, and laboratory capability could, in principle, attempt to apply similar techniques to more dangerous starting points. The risk is dual-use in the classic sense, the same computational approach that helps fight bacterial infections could, if redirected and scaled, help invent pathogens outside the reach of current vaccines, diagnostics, or treatments.
Terrorist groups or state proxies have historically struggled with the practical difficulties of producing and deploying sophisticated biological agents. Most past attempts failed because biology is hard, containment is fragile, and delivery is unreliable. AI-assisted genome design does not magically remove those frictions overnight. Human viruses are far larger and more complex than the tiny bacteriophages used in the Stanford work; synthesis, assembly, viability testing, and weaponisation remain non-trivial. Experts note that simpler routes, such as gain-of-function modifications to already known pathogens, may still be more accessible in the near term. Yet the demonstration that generative models can write working viral genomes changes the long-term risk calculus. It expands the space of possible novel agents and reduces the time and specialised knowledge required to explore that space.
The governance gap is the core problem. DNA synthesis screening is still largely voluntary in many jurisdictions and was designed around known natural sequences; AI-generated designs that diverge substantially from nature can evade sequence-based filters. Access controls on powerful biological models, mandatory customer and sequence screening at synthesis houses, laboratory biosafety standards for genome-scale work, and international coordination on dual-use research of concern are all incomplete. Without them, the technology's diffusion increases the chance that a non-state actor could eventually leverage it.
The responsible path is not to halt beneficial research on bacterial phages or other low-risk applications. It is to treat genome-scale generative design as a dual-use capability that requires proactive limits: clear prohibitions or extreme scrutiny on models and experiments involving human, animal, or plant pathogens; stronger legal requirements for DNA synthesis screening that can handle novel sequences; controlled access to the most capable models; and continuous monitoring of capability progress. The scientists who achieved the breakthrough and the biosecurity specialists who responded to it both recognized the same reality, the technique works, the benefits can be large, and the downside of misuse is severe enough that certain lines of inquiry should simply not be pursued.
https://www.beckerbrief.com/p/should-not-be-pursued-scientists
