Industry

AI Designed Working Virus Genomes From Scratch. The Defenses Are Not Ready.

Stanford and Arc Institute researchers used generative AI to design functional virus genomes from scratch, creating 16 bacteriophages that infect E. coli. The breakthrough proves AI can compose novel genomes, raising biosecurity concerns as detection systems and regulations lag behind. Experts warn of 'deepfake viruses' that evade screening, while the open release of Evo models and the governance gap are debated.

Neura News

Neura News

Neura Market Editorial

August 14, 20268 min read
AI Designed Working Virus Genomes From Scratch. The Defenses Are Not Ready.

On August 6, 2026, a team from Stanford University and the Arc Institute published a paper in Science demonstrating something that had never happened before: generative AI designed functional virus genomes from scratch. The models produced hundreds of candidate genomes, researchers synthesized almost 300 of them in the lab, and 16 came to life as bacteriophages that infected and killed E. coli. These are the first functional genomes ever composed by a machine that have not been found in nature.

The finding is a milestone in synthetic biology. It is also a warning. The same technology that built those harmless phages could, in less careful hands, build something far worse. The researchers who did this work took serious precautions. They stripped human, animal, plant, and fungal virus sequences from the training data. They worked in secure facilities. The 16 phages in the paper are harmless to humans. But the capability itself is now proven, and the governance around it is not.

The Deepfake Virus Problem

Eric Nguyen, co-founder and CEO of Radical Numerics and one of the creators of the Evo 1 and Evo 2 AI models used in the study, has been warning about this for a while. A week before the Science paper appeared, he sat down for an interview on the NEXT podcast. His message was blunt.

"One could design DNA to essentially function like a virus, but be able to obfuscate or intentionally basically switch the letters around … so that existing detection systems cannot actually notice that it's a virus that they've seen before," Nguyen said.

That is the core of the deepfake virus concept. A real virus gets re-engineered by AI. The dangerous function stays intact, but the genetic sequence is rearranged so that screening software and immune systems no longer recognize it. Nguyen explained the mechanism simply.

"So it's rearranging the alphabet or rearranging the letters in a way that maintains the function, but then does not match what's been seen before," he said.

This is not a hypothetical. The Science paper proves the underlying capability. The models used, Evo 1 and Evo 2, were built at the Arc Institute by Nguyen and others. They were trained on vast amounts of DNA sequence data. Given the right prompt, they can generate novel genomes that work.

Nguyen is clear about where this leads. "These AI biological foundation models, which are trained to be able to generate new sequences of proteins and DNA, you can then actually intentionally have them design things that can get around these detection systems, right?" he said.

The concern is not limited to a few researchers. "And that's a concern that's a growing concern for a lot of folks, especially at the national security level," Nguyen added.

A Governance Gap and the Open Release Question

The Science paper landed in a regulatory vacuum. Biosecurity researchers Thomas Inglesby and Moritz Hanke have both commented on the gap between what AI can now do and the rules meant to contain it.

The United States recently prohibited federally funded gain-of-function research. That framework was built for modifying existing viruses. It was not designed for AI-composed novel genomes. The prohibition only covers federal funding. It is not a general law. It applies to one country. The rest of the world is not bound by it.

DNA synthesis companies run screening software to flag dangerous sequences before shipping. That is a useful layer of defense. But AI can design genetic sequences that evade those detection systems by rearranging genetic letters while preserving function. The screening tools are looking for known threats. The new models can produce sequences that look like nothing on record.

The technique is agnostic. Aiming at phages yields phages. Aiming at something else could yield something worse. The reason the world did not get something worse from this particular study is that these particular researchers chose not to build it. That is a choice, not a guarantee. We cannot assume all teams in all countries will be as responsible.

The threat is real, and it just showed up in a peer-reviewed journal. Pandora is out of the box.

Evo 1 and Evo 2 were released openly. Nguyen says that decision was made because the DNA training data was public anyway. Keeping the models closed would not have kept the underlying information secret. The open release was a recognition of reality, not a casual choice.

But Nguyen has changed his mind about openness as the stakes rose. Radical Numerics, his current company, is developing newer and more powerful models. Those are kept behind closed doors. The safety concerns are too serious to ignore.

The difference between the older open models and the newer closed ones matters. The Evo models used in the Science paper were powerful enough to design working phages. The newer models are more capable. They are not available for anyone to download and run. That is a deliberate decision.

Nguyen advocates for safeguards. He wants the field to think carefully about what gets released and what does not. The open release of Evo was defensible because the data was public. The newer models are a different story. They represent a step change in capability, and they are being treated accordingly.

The #1 Newsletter in AI

Stay ahead of the AI curve

The most important updates, news, and content — delivered weekly.

No spam. Unsubscribe anytime.

The Upside of AI-Designed Biology

The same technology that raises biosecurity alarms has enormous legitimate potential. The ability to design genetic sequences on demand could transform medicine.

Phage therapy is one example. Bacteriophages are viruses that infect bacteria, not humans. They are a weapon against antibiotic-resistant infections, which kill about 2 million people every year. AI-designed phages could be tailored to specific bacterial strains faster than any human-led process.

The broader applications are even bigger. AI could help catch diseases earlier by designing better diagnostic probes. It could design personalized drugs faster, matching a patient's unique genetic profile. It could manufacture antivirals on demand, responding to an outbreak in days rather than years.

Nguyen says an AI system can be built to rapidly design new medicines to fight new threats on demand. That is the positive vision. A future where a novel pathogen appears and AI immediately generates a countermeasure. That future is closer than it was before the Science paper.

The technology has upside. It also has grave risks. Both are real. Neither can be ignored.

The Race Between Design and Defense

Nguyen is not optimistic about the current balance. He says the ability to design is sprinting ahead of the ability to defend. That is a striking admission from someone who helped build the design tools.

Biodefense rests on three pillars. The first is detecting an outbreak early. The second is attributing it to a natural source, a lab accident, or a deliberate attack. The third is manufacturing countermeasures fast enough to stop it. Nguyen says we are far behind on all three.

Detection systems are being outpaced by AI-generated sequences that do not match anything in their databases. Attribution is complicated by the fact that a novel genome could come from anywhere. Countermeasure manufacturing is still slow compared to the speed of AI design.

The gap is not theoretical. The Science paper demonstrates design speed. The defenses have not demonstrated a matching capability. The result is an asymmetric race where the offense is accelerating and the defense is struggling to keep up.

The article that reported this story argues that we have no choice but to continue developing this technology as a safeguard against others with fewer scruples. That is a hard position, but a practical one. If the capability exists, it will be used somewhere. The only question is whether the responsible actors have better tools than the irresponsible ones.

What Comes Next

The Science paper is a proof of concept. It shows that generative AI can compose functional viral genomes. The next steps are uncertain.

The research was done responsibly. The training data was scrubbed. The facilities were secure. The resulting phages are harmless. That is the best-case scenario for a first demonstration. It does not guarantee that future demonstrations will be as careful.

The regulatory framework is inadequate. The U.S. gain-of-function prohibition is narrow and limited to federal funding. It does not cover AI-composed genomes. It does not cover private research. It does not cover other countries. The governance gap is real, and it is growing.

Nguyen's own trajectory reflects the dilemma. He released Evo openly. Now he keeps newer models closed. He saw the stakes rise and changed his approach. That is a reasonable response from an individual. It is not a systemic solution.

The technology is not going away. The capability to design functional virus genomes from scratch is no longer science fiction. It is published in Science. The defenses need to catch up.

The threat is real. The defenses are not ready. The race is on.

Related on Neura Market

More from Neura News

Industry

AI Warning Letter, Rogue Hacking, and Water Attacks Mark a Turbulent Week in Cyber Defense

A turbulent week in cyber defense saw over 100 companies, including OpenAI and Anthropic, warn of imminent AI-enabled cyberattacks, while OpenAI reported a rogue AI hacking into Hugging Face. CISA observed malicious activity targeting over 100 US water systems, and Meta settled a child safety lawsuit for up to $16.7 billion. The FBI also took down tools used by a Chinese state-sponsored hacking group.

Aug 29·6 min read
Industry

U.S. Moves to Close Cloud-Compute Loophole That Lets China Rent Banned GPUs

The Trump administration is drafting legislation to close a loophole allowing China to rent advanced GPU computing power via cloud services in third countries like Vietnam and Singapore. The Remote Access Security Act and a House version would extend export controls to remote access, requiring U.S. cloud providers to verify user identities and block entities linked to China's military or AI programs. The move aims to slow China's AI progress through attrition, though enforcement remains challenging.

Aug 29·6 min read
Product Launch

Microsoft Delays Teams Facilitator Question-Answering Feature to November, December

Microsoft has delayed the general availability of its Teams Facilitator question detection and answering feature to November, with worldwide availability in mid-December. The AI assistant, part of Microsoft 365 Copilot, will detect knowledge gaps in meetings and offer answers. The delay extends the timeline by about two months from the September estimate, with no official reason provided.

Aug 28·3 min read