Stanford researchers have demonstrated that their genomic AI model Evo can design functional viruses from scratch. Published in Science on August 6, the study describes 16 novel bacteriophages—viruses that infect bacteria—generated by the AI system that successfully infected E. coli cells.
From Genome to Functional Virus
The Evo model was trained on approximately 2 million viral genomes, learning the patterns that allow viruses to infect host cells. The AI-generated designs departed significantly from natural templates, yet several demonstrated infection capabilities that matched or exceeded naturally occurring bacteriophages like the well-studied ΦX174.
“What’s remarkable is that these are genuinely novel designs, not just minor modifications of existing viruses,” said the research team. “The AI learned the fundamental principles of viral infection and applied them to create new solutions.”
The implications for medicine are significant. Bacteriophages offer a potential alternative to antibiotics for treating antibiotic-resistant bacterial infections—a growing global health crisis. AI-designed phages could be customized for specific pathogens or patient backgrounds.
Biosecurity Warning Signs
However, biosecurity experts warn that the same technology could lower barriers to creating harmful biological agents. Dr. Moritz Hanke from a leading biosecurity institute noted that the technique could theoretically be adapted to design viruses targeting human cells rather than bacteria.
The Stanford team explicitly excluded human-pathogen data from their training set as a safeguard. However, critics argue that excluding certain data from training provides limited protection since the learned principles could transfer to related domains.
Imperial College London’s Tom Ellis, who was not involved in the research, suggested that built-in genetic sequence restrictions could help mitigate misuse risks—but acknowledged that determined actors might find workarounds.
The Dual-Use Dilemma
This research underscores the broader challenge of advancing AI capabilities in sensitive domains. The same fundamental research that enables beneficial therapeutic development could, in other hands, enable biological weapon design.
The scientific community is grappling with how to publish such findings responsibly. Some have called for pre-publication biosecurity reviews, while others argue that openness is essential for scientific progress and that safeguards can be implemented at the application layer rather than through research restrictions.