AI Inventing Biological Viruses: Should We Just Stick to Cybercrime?

AI Inventing Biological Viruses: Should We Just Stick to Cybercrime?

I sat through a lab briefing where a string of letters on a screen quietly became something that could infect a cell. You felt the air tighten—an experiment that favored design over discovery. For a moment the lab looked like a small stage where curiosity and consequence were sharpening each other.

In Palo Alto a team fed an AI thousands of viral sequences

I want you to picture a lab at the Arc Institute where researchers trained a genome language model named Evo on the DNA structure of known viruses. The goal was plain: teach the model the grammar of viral genomes and then ask it to write new sentences. They generated roughly 700,000 candidate genomes, ordered about 300 for synthesis, and only 16 came back as viable viruses that could infect bacteria.

The experiment used Phi X-174 as its template, a bacteriophage that targets E. coli, not humans. That matters: the work was limited to bacterial viruses by design. But I don’t want you to shrink from the scale—those 16 designs beat resistance in two strains of E. coli, which says the machine-made sequences were not mere photocopies of nature.

A single lab success looks technical on paper but unsettling in practice

On the bench the process looked incremental: model, synthesize, test. But watching the numbers—700,000 guesses to 16 successes—tells you how brute force and refinement coexisted. Evo worked like a locksmith trying thousands of keys.

That hit rate implies two things I want you to hold: first, human expertise and physical synthesis were still central; second, generative models can explore sequence space differently from natural evolution, sometimes finding shortcuts. The model was a blacksmith forging new shapes from a language of genes.

Can AI create viruses?

Short answer: yes, in the narrow sense the Arc team demonstrated. A trained model can propose novel genomes and, when those proposals are synthesized and assembled in a lab, some can become functional viral particles. The experiment didn’t conjure a new human pathogen, but it showed the pathway exists: computational design → DNA synthesis → biological test.

The biological limits were obvious but the risks are not

In the lab the team’s constraints were explicit: bacteriophage targets, safety measures, and peer review via a Science paper. Yet outside the paper, policy looked patchy. The Johns Hopkins Center for Health Security’s Tom Inglesby and Dr. Moritz Hanke flagged this in an accompanying piece—composition by generative AI is now possible, while governance lags behind.

Are AI-designed viruses dangerous to humans?

Not the ones made in this study. But danger depends on intent and context. The NIH recently released a policy aimed at stopping high-risk life sciences research that would make biological agents more dangerous. Still, it excludes purely computational work unless it involves an existing “entity of concern” like smallpox. That gap matters: computational design alone isn’t covered unless the target is already notorious.

Regulators issued guidance, but the rules have a blind spot

Public agencies reacted fast—NIH and White House documents landed in July—but the language leaves computational design in a gray zone. The White House policy defines prohibited wet-lab experiments, while NIH guidance restricts experiments that increase risk. Yet software and in silico design tools are not fully restricted under current rules.

That ambiguity matters for platforms and companies. DNA synthesis providers, sequencing firms, academic groups, and cloud platforms—names like Arc Institute, publishers such as Science, and outlets like The New York Times and the BBC—are part of the public conversation. Investors, labs, and cloud vendors such as Amazon Web Services and Google Cloud are watching because compute and synthesis access shape what’s possible.

Practical next steps for scientists, companies, and you

On the ground, labs need stricter screening of DNA orders and better threat modeling. Platforms that host models must rethink access controls and monitoring. As someone who follows this work closely, I think transparency from model builders and synthesis companies will be the clearest short-term defense.

Journalists and policy teams will push this story forward. The literature is already full of sober takes and warnings; the Science paper plus the Johns Hopkins commentary and media coverage from The New York Times and the BBC make a clear case for public debate.

I’ll leave you with the core tension: the same computational tools that might speed therapeutic discovery also make design of biological agents easier. Who claims responsibility when an algorithm crosses that line and society discovers it too late?