AI-Designed Viruses: From Lab Candidates to Working Viruses
Input
Modified
AI can already design working viruses from scratch Most DNA synthesis providers don't screen orders publicly Screening the synthesis step matters more than banning research

Sixteen of the 302 AI-generated bacteriophage genomes that Stanford and Arc Institute researchers built and tested in a lab worked as functioning viruses, none of them found anywhere in nature, produced by a language model trained on more than two million existing phage genomes. The result matters because it shows that a machine can now write a working viral genome much the way it writes an email. A separate biosecurity mapping project found that of the more than 700 companies worldwide that sell synthetic DNA, only 69 have a publicly identifiable way to screen orders for dangerous sequences. Taken together, these two figures show what artificial intelligence can already build and how little currently separates that capability from a supply chain willing to ship it. That gap is the real problem here, not the existence of the technology itself.
Protein Synthesis Is Old News. DNA Synthesis Screening Is the New Frontier
Protein design earned a Nobel Prize in 2024, not a ban. David Baker, Demis Hassabis and John Jumper won Chemistry's top honor for teaching computers to predict and design protein shapes. Universities now teach the methods and journals publish the code. Nobody's arguing that protein engineering itself should stop, since it already saves lives through better vaccines, enzymes and materials. A virus, stripped down, is a protein shell wrapped around genetic instructions. The same generative models that design a new antibody or a stiffer biomaterial can, given different training data, design a new viral genome. MIT researchers demonstrated this logic directly back in 2023, when Markus Buehler's lab built diffusion models that generate original amino acid sequences meeting specific structural targets, working with postdoctoral researcher Bo Ni and Tufts bioengineer David Kaplan. That approach sits within the same technical family as the later phage-design work. Once a technique proves useful for one class of protein, it tends to become available for the rest of them. That's not really a flaw in the research. It's just how basic science tends to move.
This is part of why banning AI virus design outright probably won't do what its supporters hope. Model weights, once published, get copied and methods, once described in a paper, get rebuilt by anyone with a graduate degree and a cloud computing budget. A prohibition passed in Washington or Brussels binds legitimate labs that publish openly and submit to institutional review but it does little to a well-funded actor working outside any jurisdiction willing to enforce it. Recombinant DNA research faced a similar fear in the 1970s and the response that actually worked was not a ban but a containment framework, the Asilomar guidelines, built by scientists who wanted the research to continue safely rather than be driven underground. The same logic applies now. The problem was never that someone could design a novel protein on a screen. It's what happens between the design file and a living organism. That gap has a name: DNA synthesis.
The Numbers Behind AI Virus Design and Weak DNA Synthesis Screening
The capability curve here is pretty short, honestly. In 2021, the first deep-learning protein sequencer, Casanovo, matched peptides about as well as older database methods and by 2025 a successor called InstaNovo identified 42 percent more peptides than Casanovo in head-to-head testing and turned up more than a thousand previously unmapped peptides in infected wound samples. That's real progress in reading proteins. Writing them has moved just as fast, maybe faster. The Stanford and Arc Institute team that built working bacteriophages trained their model, called Evo, on more than two million existing phage genomes, then asked it to generate genomes from scratch rather than edit existing ones. Of 302 designs synthesized and tested, sixteen functioned as real viruses and mixtures of them killed antibiotic-resistant bacteria that a comparable mixture of natural phages could not touch. Only four years separate a sequencing tool that processes proteins somewhat better from a design tool that writes a complete functioning genome and that is roughly the pace against which policy is now working.

Screening hasn't kept pace with any of it. The International Gene Synthesis Consortium, whose members screen every order against databases of known hazardous sequences, represents roughly 80 percent of global commercial gene synthesis capacity, according to a 2024 assessment by biosecurity researchers Arianne Kane and Michael Parker, which leaves an estimated one-fifth of the market operating outside that voluntary standard. A separate mapping effort by the International Biosecurity and Biosafety Initiative for Science found something starker still: of more than 700 known DNA synthesis providers worldwide, 69 have a publicly identifiable way to screen customer orders at all. Screening also fails in a more technical way and this one is harder to wave off. In 2025, a study led by Microsoft researchers and published in Science found that most AI-generated toxic protein sequences, simpler to design than a full viral genome, evaded the biosecurity screening software several major suppliers relied on. Screening providers issued patches within weeks, which is reassuring only until the next generation of design tools outpaces the next patch, since capability tends to move faster than any single company can close a hole.

Policy has not kept pace either and it has actually moved backward more than once. The United States adopted a Framework for Nucleic Acid Synthesis Screening in April 2024, tying federal research funding to compliance and setting an enforcement date of April 2025. Weeks after that date arrived, a new executive order directed federal agencies to revise or replace the framework, leaving providers and universities without a settled federal standard. A bill meant to restore statutory footing, the Biosecurity Modernization and Innovation Act, was introduced in the Senate in January 2026 and remains in committee. None of this paused the underlying science. Design tools kept improving on their own schedule, not caring much whether the screening rules meant to check them existed, worked or had just been rewritten again.
What Better DNA Synthesis Screening Would Actually Require
A workable answer starts at the synthesis step because that is the one point every design pathway must pass through. A model can generate a genome file on a laptop but turning that file into living material still requires ordering synthetic DNA from a supplier or running it through a benchtop synthesizer. IBBIS built exactly this kind of chokepoint tool, an open-source screening program, free for any provider to install, that checks sequences against curated databases of known hazards and flags suspicious customer patterns. The National Institute of Standards and Technology has built shared test sequence sets that IBBIS and SecureDNA now use to benchmark their screening tools, measuring how well each one catches genuine threats without drowning legitimate researchers in false alarms. None of this requires new science, really. It just requires providers to install what already exists and regulators willing to make the holdouts do it too.
Coverage gaps deserve specific attention because the current voluntary system misses exactly the orders a careful actor would use to avoid it. Short DNA fragments under roughly 200 base pairs often pass through unscreened, since screening software struggles to match short sequences reliably to a hazard database and a determined customer could split a dangerous genome into pieces small enough to slip past that filter before assembling them later. Benchtop synthesis devices, now compact and affordable enough for a well-equipped private lab, mostly ship without any screening built in because manufacturers face no legal requirement to include it. Closing both gaps costs money and slows some legitimate orders down, but that tradeoff is a small price next to what sits on the other side of the ledger.
Training-data controls belong in this system too, as a complement rather than a substitute. Biosecurity researcher Doni Bloomfield and colleagues have proposed a tiered-access model for the genetic data sets that train these design tools, similar to how biosafety levels already restrict physical access to dangerous pathogens such as Ebola virus. Sensitive training data on transmissibility, virulence and immune evasion would sit behind stricter access controls than general genomic data used for legitimate phage therapy or vaccine research. That narrows what a model can be taught to do. It doesn't, on its own, stop a finished design from reaching a lab bench though. Only synthesis screening does that.
The Prohibition Argument Doesn't Hold Up
The strongest pushback here is that screening already leaks, so why not just ban the underlying research? The Microsoft case, in which AI-generated toxic sequences slipped past supplier filters, is often cited as proof that screening cannot work, but that reasoning gets the lesson backward. Every security system in wide use, from airport scanners to bank fraud detection, catches most threats and misses some and nobody responds to a missed detection at a border checkpoint by closing the border to trade. The usual response is a better scanner and a faster patch, which is exactly what happened after Microsoft's engineers found the gap. A porous filter is an argument for strengthening the filter, not evidence that filtering is pointless and it is certainly not evidence that banning the design step upstream would have stopped anything, since design and synthesis are separate acts carried out by separate parties who may never share a jurisdiction.
The second objection holds that any experimentation with virus design carries a risk too severe to accept, whatever the therapeutic upside. That claim undersells what the upside actually is, though. Antimicrobial resistance caused an estimated 1.14 million deaths directly in 2021 and contributed to nearly five million deaths overall, according to the most detailed global analysis published in The Lancet. The AI-designed bacteriophages built by the Stanford and Arc Institute team were not a laboratory curiosity, since mixtures of them killed antibiotic-resistant strains of bacteria that a similar mixture of natural phages could not touch. Phage therapy has struggled for decades because natural viruses evolve too slowly to keep pace with resistant bacteria and a design tool that can generate new phages on demand addresses exactly that bottleneck. Weighing a real, quantified, present-day death toll against a hypothetical misuse scenario isn't really caution. It's a trade that only looks at one side of the ledger.
The sixteen viable viruses produced from 302 candidates and the 69 screening providers identified out of more than 700 both describe roughly the same period and that gap will not close through legislation that tries to outlaw a technique already taught in graduate courses and published in a major journal. It closes when every DNA synthesis provider, benchtop device and cloud lab runs a screening check that catches sequences of concern before synthesis, not after publication. IBBIS has built a free tool for this purpose NIST is testing it and Congress has a bill sitting in committee. What's missing is the will to make screening mandatory everywhere biology actually gets built, instead of treating each new capability announcement as a fresh occasion for alarm. The tools to close this gap already exist. Somebody just has to require their use before the next capability jump arrives.
This article reflects the analytical judgment of The SIAI Editorial Board and does not constitute policy advice or the official position of any affiliated institution.
References
Bloomfield, D., et al. (2026) 'Biological data governance in an age of AI', Science, 391(6529), pp. 558–561.
Alexanian, T. and Carter, S.R. (2024) Verifying Legitimacy: Findings from the Customer Screening Working Group, 2020–2023. IBBIS White Paper. Geneva: International Biosecurity and Biosafety Initiative for Science.
American Association for the Advancement of Science (2025) 'The AI revolution comes to protein sequencing', Science, 31 March.
International Biosecurity and Biosafety Initiative for Science (2025) International Screening Standards. Geneva: IBBIS.
Kane, A. and Parker, M.T. (2024) 'Screening state of play: the biosecurity practices of synthetic DNA providers', Applied Biosafety, 29(1), 13 February.
Naghavi, M., Vollset, S.E., Ikuta, K.S. et al. (2024) 'Global burden of bacterial antimicrobial resistance 1990–2021: a systematic analysis with forecasts to 2050', The Lancet, 404(10459), pp. 1199–1226.
National Institute of Standards and Technology (2025) Biosecurity for Synthetic Nucleic Acid Sequences. Gaithersburg, MD: NIST.
Office of Science and Technology Policy (2024) Framework for Nucleic Acid Synthesis Screening. Washington, DC: The White House.
Scientific American (2026) 'AI just created a virus not found in nature, and scientists are worried', Scientific American, August.
Scientific American (2026) 'Scientists are using AI to design new viruses. Should they be?', Scientific American, August.
The White House (2025) Executive Order 14292: Revising the Nucleic Acid Synthesis Screening Framework. Washington, DC: The White House, 5 May.
Wittmann, B.J., et al. (2025) 'Strengthening nucleic acid biosecurity screening against generative protein design tools', Science, 390, pp. 82–87.
Wheeler, N., Carter, S.R., Alexanian, T., Isaac, C., Millett, P. and Yassif, J. (2024) 'Overcoming challenges to developing a common global baseline for nucleic acid synthesis screening', Applied Biosafety, April.
Zewe, A. (2023) 'AI system can generate novel proteins that meet structural design targets', MIT News, 20 April.