Brian Reed: Eliza, hey — rough week for anyone who thought biology needed to stay complicated.
Eliza Ward: That's one way to frame it. What's been nagging you?
Brian Reed: There's a paper in Science — August, this year — and the number I can't shake is sixteen. A PhD student at Stanford feeds an AI a bunch of known virus sequences, and sixteen of what comes back are... real. Self-replicating. Never existed before. So today that's what we're getting into — what it actually means to write a virus the way you write a sentence.
Eliza Ward: Wait — wrote them? Like, the AI invented them?
Brian Reed: Yeah, and that's — let me try to land this right, because I think the instinct is to reach for science-fiction framing and it's actually simpler and weirder than that. You know how autocomplete on your phone predicts the next word in a text? This model was trained on known bacteriophage genomes — phages are viruses that attack bacteria, not people — and it learned the grammar of those sequences. So instead of predicting the next word, it's predicting the next protein. String enough predictions together and you get a genome. And sometimes that genome... works.
Eliza Ward: And sixteen out of 285 worked. That's the hit rate — 5.6% — first pass, Samuel King and Dr. Brian Hie, standard lab conditions.
Brian Reed: Right, and that hit rate is almost beside the point — because here's what nobody put in the press release. The screening systems that are supposed to catch dangerous biology work like a wanted poster. They scan a sequence, compare it against databases of known pathogens, flag anything that looks familiar. That's the whole mechanism.
Eliza Ward: So if the thing has never existed before—
Brian Reed: There's no face on the poster. The alarm is literally looking for the wrong thing. It clears the sequence not because it's safe — because it's invisible to the system.
Eliza Ward: Wait. So picture a biosafety officer at a synthesis company — routine check, software scans, no match to any flagged pathogen, order clears. And the gap isn't a missing rule. It's that the rules were built assuming threats come from evolution. Something that mutated, that has ancestors, that leaves a recognizable signature. Generative AI just... skips all of that.
Brian Reed: And the governance gap is structural, not — I mean, it's not that someone forgot to write the AI paragraph. The Biological Weapons Anti-Terrorism Act, the select agent regulations — those predate a world where a language model can output a functional genome. The category of object didn't exist when the rules were drafted.
Eliza Ward: Okay, but — and I want to be honest about what we don't know here — did Stanford actually run these 16 through existing biosafety channels? Because if they did and the system cleared them without flagging anything, that's a very specific kind of failure on record. If they didn't, that's a different problem. I haven't seen that confirmed publicly either way.
Brian Reed: And that gap in the public record is — honestly, that's the tell. But the part that comes later makes this worse: the methods are already published, which means the barrier now is basically a journal subscription.
Eliza Ward: A journal subscription and a standard lab — that's what I keep snagging on. Because the methods being published isn't a mistake. That's how science is supposed to work.
Brian Reed: Right, and that's — okay, the reason it's so hard to land is that the thing creating the risk is the same thing that could actually save people. Bacteriophages aren't some theoretical intervention. Eastern Europe and Russia were using them clinically decades ago — because antibiotic resistance hit them hard, early, and they couldn't just wait for penicillin to keep working. So phage therapy has a track record. AI-designed novel phages could be the version that keeps working when every antibiotic we have left fails.
Eliza Ward: Hold on. We already use phages as medicine? Like, this is not hypothetical treatment.
Brian Reed: Clinically, yes — for decades, in Georgia, Poland. Western medicine went all-in on antibiotics and mostly didn't follow the research. So the capability the Stanford paper unlocks isn't just a weapons concern — it's potentially the antibiotic-resistance exit ramp. And you can't regulate that away without — I mean, you'd be restricting the tool that might be the answer to a crisis killing people right now.
Eliza Ward: And any country that unilaterally restricts it just hands the research to whoever doesn't. The risk window doesn't close — it just moves.
Brian Reed: Which is — yeah, that's the actual structural problem. It's not that regulators are slow. Jurisdiction-specific restrictions are reactive by design. If a lab in Taipei runs the same model tomorrow, Science is already on their desk.
Eliza Ward: And we genuinely don't know whether a bad actor would even use this method over, say, just ordering from a synthesis company. That uncertainty matters — because what you're governing
Brian Reed: ...shapes determines what you even build to stop it. And that keeps coming up — there's near-universal agreement among biosecurity people that current governance isn't adequate. But the moment you ask what adequate looks like, the consensus falls apart completely. Because adequate screening might mean real-time surveillance of AI outputs, and that's a cost to research freedom that nobody has actually agreed to pay.
Eliza Ward: And every framework trying to answer that is jurisdiction-specific. Reactive by design. Which means — wait, actually this is the thing that I don't think has a clean resolution — biosafety governance was built to catch slow threats. Things that leave evolutionary fingerprints. Things that take generations to emerge. We just made threats fast.
Brian Reed: And most experts agree on that part. They just don't agree on what comes next.
Eliza Ward: Which is — rough week for anyone who thought biology needed to stay complicated, I guess. Thanks for working through this with me.