Researchers at Stanford University and the Arc Institute used a genomic AI model to design new virus genomes, manufactured the most promising designs as DNA, and watched sixteen of them turn into working viruses that killed bacteria in a lab dish. The bacteriophages involved infect bacteria only, not human or animal cells, but the underlying capability, a generative model whose output functions in a wet lab rather than on a benchmark, is exactly the threshold biosecurity policy has been written to anticipate. That threshold now looks concrete rather than theoretical.

Evo, the model behind the work, is trained to generate DNA sequences rather than text. Its foundation spans roughly nine trillion base pairs pulled from microbes, plants, and animals, giving it a broad statistical sense of how genomes vary across life. Researchers then narrowed its focus to a single organism, fine-tuning it on the eleven-gene genome of the bacteriophage phiX174 plus roughly fifteen thousand related phage sequences. Only then did the team prompt Evo to generate new phiX174 variants, and it returned 700,000 candidates.

From that pool, the scientists selected a small subset to test physically: 285 sequences (an earlier preprint had put the number at 302), built as DNA strands and introduced into E. coli. Sixteen assembled into functioning viruses, replicating independently and destroying the bacteria they infected, and several replicated faster than the natural strain of phiX174. Brian Hie, the Stanford computational biologist who leads the Arc Institute lab behind the project, described watching an AI-designed virus take shape as genuinely striking.

Outside scientists were measured but not dismissive. Oxford protein chemist Oliver Crook, who had no part in the project, said the resulting viruses proved robust rather than weak copies of existing ones. Manchester-based synthetic biologist Patrick Cai called it an important milestone. Crook also drew a boundary around the claim: the AI did not invent new biology, and the genomes it produced stay close to natural sequences that rely on the same underlying mechanisms. Whether Evo performs as well on virus families beyond phiX174 is untested.

Oversight has not kept pace with the science. In late July, the National Institutes of Health published new guidance for high-risk life-sciences research, prohibiting work that increases how dangerous a known pathogen already is. Designing a virus’s genetic code entirely inside a computer sits outside that ban, the agency says, unless the design touches what regulators label an “entity of concern.” Moritz Hanke, a researcher at the Center for Health Security at Johns Hopkins, described a widening distance between how quickly this research advances and how developed the safeguards around it are. His worry is not this particular virus, but a model asked, with no built-in restriction, to design a pathogen that spreads more easily or kills more reliably.

The researchers layered on a restriction the NIH policy never required. Evo’s training data excluded every virus known to infect humans, along with related pathogens from animals, plants, and fungi. Because that material never entered the training set, the model has no basis for producing sequences in those categories, a limit built into the system rather than imposed afterward. Hanke called the choice commendable, noting that no rule obligated the team to make it.

That distinction is what makes this result land harder than the headline number suggests. A widely discussed essay circulating this same week argued that releasing biological foundation models with open weights carries this same category of risk, since a model’s restrictions are a design decision, not a property guaranteed by the underlying technology. Evo was not released openly for this study, and excluding human-pathogen data was a choice its authors made voluntarily. A differently trained copy of the same architecture, distributed without that restraint, would not carry any equivalent guarantee.

For regulators, the near-term fix is narrower than it sounds: extend the NIH’s policy to cover the design step itself, not only physical experiments on already-dangerous pathogens. For labs building models like Evo, the training-time exclusion used here, keeping human-pathogen sequences out of the data rather than relying on review after the fact, is currently the only demonstrated safeguard in this category, and nothing in current law requires anyone else to adopt it.

The Decoder (reporter Maximilian Schreiner) covered this research on August 7, 2026, crediting the underlying work to Brian Hie, Samuel King, and their colleagues at Stanford University and the Arc Institute.