Autonomy

AI Designed 16 Viruses to Fight Superbugs. The Panic Misses the Point.

CRAZE CRAZE Summary 3 things to know
  • AI generated 700,000 phage genomes; only 16 were viable, but they killed antibiotic-resistant E. coli strains better than natural phages.
  • The safeguards were voluntary and the model is open source, so anyone could fine-tune it on pathogen data—governance hasn't caught up.
  • Panic misses the point: generating harmful viruses still needs expertise, while antibiotic resistance kills 35,000 Americans yearly and AI phages offer hope.
Jeff Editorial | · 5 min read
AI Designed 16 Viruses to Fight Superbugs. The Panic Misses the Point.

Stanford researchers trained two genome language models, Evo 1 and Evo 2, on roughly 9 trillion DNA base pairs from plants, animals, microorganisms, and viruses. They used the well-studied Phi X-174 bacteriophage—a virus that only infects E. coli and is harmless to humans—as a template. The AI generated about 700,000 candidate genomes. The researchers selected 285, synthesized them as DNA, and inserted them into E. coli. Sixteen produced working viruses that replicated, destroyed bacteria, and spread.

Some AI-designed phages replicated faster than the natural Phi X-174. A mixture of them killed E. coli strains that had become resistant to the natural virus. A comparable mix of natural phages could not.

The Safeguards Are Voluntary. That's the Problem.

The Johns Hopkins commentary attached to the Science paper is worth reading carefully. Thomas Inglesby and Moritz Hanke put it bluntly: "The ability to compose viral genomes using generative AI now exists; the governance to safely steer it does not." They warned that AI-designed genomes "might encode new pathogens that cannot be contained by existing countermeasures."

The Stanford team built in safeguards. They excluded viruses that infect humans, animals, plants, or fungi from the training data. They used a phage that only attacks E. coli. All work was done in a secure lab. These precautions are commendable, but they are also voluntary. As the Johns Hopkins authors pointed out, someone else could fine-tune the same open-source model on pathogen data and circumvent them.

The policy gap is the problem. Last month the US administration issued a policy to curb high-risk life-sciences work, but it targets "gain of function" experiments on natural pathogens—not purely computational design. AI that dreams up new genomes on a screen falls through the gap. There are no guidelines on the risks of AI-designed viruses that do not exist in nature.

AI Designed 16 Viruses to Fight Superbugs. The Panic Misses the Point.
AI-designed viruses killed drug-resistant bacteria that natural phages couldn't touch. The panic misses the real story.

Generating a Harmful Virus Still Requires Expertise

Some experts have pushed back on the bioweapon framing. Tom Ellis, a synthetic genome engineering professor at Imperial College London, called Phi X-174 "literally the smallest and easiest genome to make." Its genome is about 5,400 DNA letters long. The simplest living cell needs 500,000. The human genome is three billion. Ellis told The Guardian the threat from a "full AI design and writing of a genome of a virus or bacteria" is "very overblown" compared to the simpler path of making gain-of-function changes to existing pathogens.

The hit rate was also low—just 16 viable designs from hundreds of thousands of candidates. Barcelona's Jordi García Ojalvo described this as making it "difficult to imagine these models automatically generating viable genomes 'out-of-the-box'." Generating a virus that could harm humans would require not just a model but a deliberate decision to train it on human pathogens and an understanding of what makes a virus dangerous—expertise that cannot be automated away.

Antibiotic Resistance Kills 35,000 Americans a Year

Antibiotic resistance is real. More than 2.8 million antimicrobial-resistant infections occur in the U.S. each year, killing over 35,000 people annually. The Stanford team's work demonstrates a path toward "more durable phage-based therapies" that can adapt as bacteria evolve resistance. As one Oxford researcher put it: "If AI can directly design viruses optimized for specific functions, it could become a useful biotechnology tool." Marc Güell, a professor of synthetic biology at Pompeu Fabra University, called it "a very important turning point" that "allows us to dream of exciting possibilities for tackling humanity's greatest challenges."

The question is not whether generative viral genome design will exist. It already does. The question is whether society can build oversight that allows the benefits to unfold while preventing it from enabling serious harm. The answer is not panic. It is regulation that moves as fast as the technology it governs.


P.S. The model used in the study, Evo 2, is open source—available for anyone to download. The safeguards the Stanford team built are commendable. But as the Johns Hopkins authors noted, those safeguards can be circumvented by fine-tuning on pathogen data. The science is public. The governance is not. That is the problem worth solving.


Frequently Asked Questions

Q: What did Stanford researchers actually do with AI?

A: They trained two genome language models, Evo 1 and Evo 2, on roughly 9 trillion DNA base pairs from plants, animals, microorganisms, and viruses. The AI generated about 700,000 candidate genomes for a bacteriophage—a virus that infects bacteria. They selected 285, synthesized them in the lab, and found that 16 produced working viruses that killed E. coli.

Q: Can these AI-designed viruses infect humans?

A: No. The Stanford team intentionally used a bacteriophage (Phi X-174) that only infects E. coli and is harmless to humans. They also excluded viruses that infect humans, animals, plants, or fungi from the training data.

Q: Why did the AI-designed phages perform better than natural ones?

A: A mixture of the AI-designed phages killed E. coli strains that had become resistant to natural phages. A comparable mix of natural phages could not. The AI-generated designs introduced mutations and variations that natural evolution had not produced.

Q: What are the biosecurity concerns?

A: Johns Hopkins experts Thomas Inglesby and Moritz Hanke warned in an accompanying Science commentary that AI-designed genomes "might encode new pathogens that cannot be contained by existing countermeasures." They noted that while the Stanford team built in safeguards, those are voluntary—others could fine-tune the open-source model on pathogen data.

Q: Is the bioweapon threat real or overblown?

A: Imperial College professor Tom Ellis called the threat from "full AI design of a virus genome" "very overblown" compared to the simpler path of making gain-of-function changes to existing pathogens. Generating a virus that could harm humans requires not just a model but deliberate training on human pathogens and deep virology expertise.

Q: What is the governance gap?

A: Current US policy targets "gain of function" experiments on natural pathogens—not purely computational design on a computer screen. AI that designs novel genomes falls through a regulatory gap. There are no guidelines on the risks of AI-designed viruses that do not exist in nature.

Q: Why does this research matter beyond biosecurity?

A: Antibiotic resistance is projected to cause 10 million deaths annually by 2050. AI-designed phages could offer a new therapeutic path: instead of searching for a natural phage that happens to work, doctors could call up an AI model to design a phage optimized for the specific bacterial strain in front of them.

Q: Is Evo 2 available for anyone to use?

A: Yes. Evo 2 is open source, with model weights and code available on GitHub and HuggingFace. Versions include 1B, 7B, 20B, and 40B parameter models.

Q: What do experts think about the potential impact?

A: Oxford researchers said: "If AI can directly design viruses optimized for specific functions, it could become a useful biotechnology tool." Marc Güell from Pompeu Fabra called it "a very important turning point" that "allows us to dream of exciting possibilities for tackling humanity's greatest challenges." The challenge is building oversight that allows the benefits while preventing misuse.

Q: What happens next?

A: The regulatory gap needs to be closed. Current rules focus on physical lab work, not computational design. Experts have called for a new governance framework that can keep pace with generative AI's ability to compose viral genomes—without stifling the legitimate medical applications.

Advertisement

CRAZE

Use CRAZE to turn this article into a faster answer: pull the summary, surface the key term, or jump straight to the next story in this thread.

Article