16 viruses that have never existed in nature are now multiplying inside lab dishes in Palo Alto. A Stanford-led team built them from scratch using generative AI, and the achievement lands at the center of a debate American lawmakers have been slow to settle.
Researchers led by chemical engineering professor Brian Hie used two AI systems, Evo 1 and Evo 2, to compose full viral genomes letter by letter rather than editing existing DNA. The models trained on 2.7 million genomes before generating bacteriophage blueprints modeled loosely on ΦX174, a virus that targets E. coli. Out of 302 designs synthesized and tested, 16 came alive and functioned as working phages, according to findings published in the Science Media Centre on August 6.
The target was bacteria, not people

Every one of the 16 confirmed phages was built to hunt drug-resistant E. coli, work aimed at antibiotic resistance, a threat the CDC has linked to more than 35,000 American deaths a year.
No AI system available to the public has been trained to design a virus capable of infecting humans, and the genomes these models can currently write stay far below the genetic scale of a human pathogen. Stanford and the Arc Institute say that ceiling exists because of a filter over the training data, not a hard technical wall.
Scientists behind the work have acknowledged that the safeguard blocking human-infecting sequences can be reversed. A Science commentary accompanying the study, written by researcher Moritz Hanke, put the tension plainly: generative tools can now compose viral genomes, while the governance built to steer that power safely does not yet exist. That gap is the story lawmakers, biosecurity researchers and the AI industry itself are now racing to close.
Screening laws have not caught up
No federal law currently requires DNA synthesis companies to verify a customer’s identity before filling an order. Detection systems built to flag AI-generated sequences have also not been deployed at scale. The exposure is not theoretical.
An FBI-supervised red-teaming test found that 36 of 38 commercial DNA synthesis providers shipped fragments of the 1918 influenza virus without catching them, a result published in Nature Communications this year. Free tools such as SecureDNA have since screened more than 67 million nucleotides across the US, Europe and China, evidence that better screening is possible even without a legal mandate.
The gap is not new; it has just gotten harder to close. A British journalist mail-ordered a partial smallpox sequence back in 2006 with no screening in place at all, and the industry has spent two decades building voluntary safeguards on top of that early warning.
Homology screening, which compares an order against a list of known dangerous sequences, still forms the backbone of that system. AI-generated genomes built letter by letter can slip past that method entirely, since they resemble nothing already on the list.
Washington has bills, not a law
The Biosecurity Modernization and Innovation Act, introduced by Senators Tom Cotton and Amy Klobuchar in January, would tighten synthesis screening rules. However, it remains parked in the Senate Commerce Committee. A companion House measure has sat idle since April 2025.
Meanwhile, an executive order President Trump signed in May 2025 directed agencies to revise the government’s 2024 nucleic acid screening framework. So far, the revision still has not happened. Last month, the administration issued a separate policy barring federally funded gain-of-function research on dangerous pathogens, though it stops short of addressing AI-generated designs directly.
Industry is moving faster than regulators

Google DeepMind, OpenAI and Anthropic joined life sciences and DNA synthesis executives on an open letter in June. They urged Congress to make screening mandatory, an unusual alignment between AI labs and the industry their tools could destabilize.
OpenAI has offered researchers as much as $50,000 to find ways around its biosafety safeguards. Anthropic has proposed a framework requiring frontier developers to test for catastrophic risks and report findings to a government body. Know your customer rules, borrowed from anti-money laundering practice, are also gaining traction as a possible backstop for synthesis providers.
Scientists are policing the data, too
In February, more than 100 researchers from Johns Hopkins, Oxford, Stanford, Columbia, and NYU endorsed a new framework. It called for restricting access to certain high-risk infectious-disease datasets used to train biological AI models.
The move reflects a shift in how scientists talk about openness. Publishing pathogen data once built trust and accelerated cures. Now it can also hand a blueprint to whoever asks the right model the right question.
The medical upside keeps the debate alive
Phage therapy has drawn fresh attention as antibiotic-resistant infections climb, and AI-designed viruses could shorten a drug discovery process that traditionally takes years.
Researchers involved in the Stanford work described their method as a way to generate adaptive and resilient phage therapies against fast-evolving bacteria.
That promise is precisely why the technology cannot simply be shut down, and precisely why the safeguards around it now carry so much weight.