AI Can Now Design Working Viruses. Here's Why Biosecurity Experts Are Racing to Catch Up.
Artificial intelligence has crossed a significant threshold in biological engineering: researchers recently used AI to design complete genetic instructions for viruses that actually worked when built and tested in laboratories. While the viruses in question were bacteriophages designed to infect bacteria rather than humans, the achievement highlights a critical gap between rapidly advancing biological design capabilities and the safety systems meant to prevent misuse.
What Exactly Did Researchers Accomplish With AI-Designed Viruses?
Scientists used artificial intelligence models, including one called Evo 2, to generate complete sets of genetic instructions for bacteriophages, which are viruses that infect bacteria like E. coli. The remarkable part: when researchers physically built these computer-generated designs in the laboratory, some of them produced working viruses. Evo 2 was developed with deliberate safety restrictions, excluding viruses that infect animals, plants, and humans from its training data. Despite these precautions, the experiment demonstrates that AI can now help design biological systems that function in the real world.
Genome language models work similarly to the AI language models many people interact with daily. Instead of learning patterns in text and sentences, these models learn patterns in genetic code. Evo 2, for example, was trained on trillions of DNA building blocks from many different forms of life, giving researchers a powerful new way to study biology and generate possible DNA sequences.
Why Should We Care If AI Can Design Viruses That Target Bacteria?
The immediate applications sound beneficial. Bacteriophages could potentially treat bacterial infections, including those becoming resistant to antibiotics, a growing public health concern. However, the ability to design biological systems on a computer before anything is made in a laboratory creates new challenges for biosecurity. The concern is not that this specific research is dangerous, but rather that as AI tools for biology become more capable, the gap between what researchers can design and what safeguards can prevent could widen dangerously.
An AI-generated DNA sequence is still several steps away from becoming a real biological threat. A digital design must be turned into physical genetic material, assembled correctly, and tested under proper laboratory conditions. However, each of those stages also creates an opportunity to reduce risk, and experts argue that safeguards need to develop alongside the technology itself.
How Can We Build Better Safeguards for AI-Designed Biology?
- AI Model Design: Developers can deliberately remove dangerous sequences from training data, as the creators of Evo 2 did by excluding viruses that infect humans. Research found that Evo 2 performed poorly when tested on proteins from human-infecting viruses, suggesting that safety-conscious training can limit certain capabilities.
- DNA Synthesis Screening: Companies that manufacture DNA to order can check both the requested genetic sequence and the organization ordering it for potential security concerns. Researchers have argued for common international approaches as this technology becomes more widely available.
- Laboratory Oversight: Research institutions can assess potentially risky research before experiments begin, including questions about how biological material will be contained, who will have access to it, and whether expected benefits justify the risks.
- Public Health Preparedness: Health authorities need systems to detect and investigate unusual outbreaks quickly. The UK Health Security Agency runs a program called mSCAPE that analyzes genetic material from samples to help detect and track emerging pathogens, including those that might be AI-designed.
- Research Funding Oversight: Funding organizations like UK Research and Innovation have established teams to help researchers and institutions identify and manage security risks in collaborative research.
One significant challenge is that open science, which accelerates discovery and widens access to powerful tools, makes controlling how AI models are used much harder. Evo 2 was released openly, including the code and technical information needed for other researchers to use and develop it. Once such tools are widely distributed, preventing misuse becomes exponentially more difficult.
"No single safeguard can deal with all of these risks. Biosecurity will need to operate at several stages, from how biological AI models are developed and released to DNA screening, laboratory oversight and public health preparedness," noted Tuck Seng Wong, Professor of Biomanufacturing at the University of Sheffield.
Tuck Seng Wong, Professor of Biomanufacturing, University of Sheffield
A major weakness in global biosecurity is unequal preparedness across countries. Some nations already have established systems for identifying and responding to biological risks, while others are still developing them. Since biological threats can cross borders, effective preparedness depends on strengthening these capabilities internationally.
The recent bacteriophage study does not demonstrate that AI can design a pandemic virus. What it does show is significant enough: AI can already help design complete viral genomes that work when physically created. Experts argue that we have an opportunity to decide what responsible safeguards should look like while this technology is still developing, rather than waiting for more dangerous capabilities to emerge before building protections.