Onpode
Cover art for AI can now design viruses faster than regulators can write rules—the governance gap is widening

AI can now design viruses faster than regulators can write rules—the governance gap is widening

August 7, 2026 · 7 min

Eliza Ward & Brian Reed

A 2026 Stanford study published in Science showed that an AI trained on bacteriophage genomes generated 285 novel viral sequences, 16 of which were self-replicating and functional—a 5.6% hit rate. Existing biosafety screening tools cannot flag these AI-designed viruses because they scan for known pathogens, not novel ones.

In research published in the journal Science and reported widely on August 6–7, 2026, a Stanford University team led by PhD student Samuel King and chemical engineer Dr. Brian Hie used generative AI language models to design 285 novel bacteriophage (bacteria-infecting virus) genomes that have no counterpart in nature. Of those, 16 produced viable, self-replicating viruses in laboratory tests.

0:006:39
Get the next episode on Science

Follow it free — new episodes land in your feed.

Or make your own — any topic, in minutes

More Onpode episodes on Science

About this episode

Earlier this year, a paper in Science described something that's hard to fully absorb: an AI trained on known bacteriophage genomes generated 285 novel viral sequences, and 16 of them were functional — self-replicating viruses that had never existed before. The hit rate was 5.6%, first pass, standard lab conditions. The methods are published. The barrier to replication is now roughly a journal subscription and a working lab. What this episode explores is the specific nature of the governance failure that reveals — and why it's structural, not accidental. Current biosecurity screening compares sequences against databases of known pathogens. Generative AI produces sequences with no evolutionary ancestors, no recognizable signatures. The alarm is literally looking for the wrong thing. But the episode doesn't let that land as a clean horror story, because it isn't one. Bacteriophages have been used as medicine in Georgia and Poland for decades, and AI-designed phages could be a genuine answer to antibiotic resistance — a crisis already killing people. You can't regulate the tool away without also restricting what might be the exit ramp from that crisis. There's near-universal agreement among biosecurity researchers that current governance isn't adequate. What adequate actually looks like — real-time surveillance of AI outputs, international coordination, something else entirely — is where the consensus falls apart. This episode sits honestly inside that uncertainty rather than pretending there's a tidy answer.

Frequently asked

Can AI design functional viruses from scratch?

Yes. A 2026 study in Science by researchers at Stanford showed that a genome language model trained on known bacteriophage sequences generated 285 novel viral genomes, 16 of which were confirmed self-replicating and functional. None of these viruses had existed before; the AI predicted their sequences the way autocomplete predicts text.

Why can't current biosafety screening detect AI-designed viruses?

Current biosafety screening tools work like a wanted poster—they scan sequences against databases of known pathogens and flag matches. AI-designed viruses have no evolutionary ancestors and no known fingerprint, so they produce no match and clear screening by default, not because they are safe, but because they are invisible to the system.

What is the governance gap in AI biosecurity?

The governance gap in AI biosecurity is structural: laws like the Biological Weapons Anti-Terrorism Act and select-agent regulations were written before generative AI could output functional genomes. The category of threat—a novel, never-evolved virus designed by a language model—did not exist when the rules were drafted, leaving no adequate regulatory framework.

Are AI-designed bacteriophages dangerous or medically useful?

AI-designed bacteriophages present both risks and significant medical promise. Phage therapy—using viruses to kill antibiotic-resistant bacteria—has been used clinically for decades in Georgia and Poland. AI-generated novel phages could become a critical tool against antibiotic resistance, making blanket restriction difficult without sacrificing a potentially life-saving medical intervention.

What do biosecurity experts recommend for regulating AI-designed pathogens?

Biosecurity experts broadly agree that current governance is inadequate for AI-designed pathogens, but consensus breaks down on solutions. Proposals include real-time surveillance of AI model outputs, but that carries costs to research freedom no jurisdiction has agreed to accept. Unilateral national restrictions are also seen as ineffective, since published methods cross borders instantly.

Grounded in 12 sources
Generative Artificial Intelligence in Bioinformatics: A Systematic Review of Models, Applications, and Methodological Advances | Archives of Computational Methods in Engineering | Springer Nature Link · link.springer.com
Synthetic biology/AI convergence (SynBioAI): security threats ... · link.springer.com
AI-driven protein design - Nature Reviews Bioengineering · nature.com
AI proteomics: from protein identification to virtual cells · nature.com
AI-redesigned starting points and outcomes enhance protein evolution | Nature · nature.com
Artificial intelligence in drug discovery — what it is, where we stand and the path forward · nature.com
Governing the AI–biotech convergence · pmc.ncbi.nlm.nih.gov
Scientists used generative AI to design 285 novel bacteriophage genomes never found in nature; 16 produced viable, replicating viruses in lab tests. Experts including Tom Inglesby and Moritz Hanke of · science.org
Generative design of bacteriophages with genome language models · science.org
AI used to create viruses not found in nature for first time | Technology News | Al Jazeera · aljazeera.com
Now AI can create new viruses · axios.com
Artificial Intelligence used to design brand new viruses · bbc.co.uk
Read transcript

Brian Reed: Eliza, hey — rough week for anyone who thought biology needed to stay complicated.

Eliza Ward: That's one way to frame it. What's been nagging you?

Brian Reed: There's a paper in Science — August, this year — and the number I can't shake is sixteen. A PhD student at Stanford feeds an AI a bunch of known virus sequences, and sixteen of what comes back are... real. Self-replicating. Never existed before. So today that's what we're getting into — what it actually means to write a virus the way you write a sentence.

Eliza Ward: Wait — wrote them? Like, the AI invented them?

Brian Reed: Yeah, and that's — let me try to land this right, because I think the instinct is to reach for science-fiction framing and it's actually simpler and weirder than that. You know how autocomplete on your phone predicts the next word in a text? This model was trained on known bacteriophage genomes — phages are viruses that attack bacteria, not people — and it learned the grammar of those sequences. So instead of predicting the next word, it's predicting the next protein. String enough predictions together and you get a genome. And sometimes that genome... works.

Eliza Ward: And sixteen out of 285 worked. That's the hit rate — 5.6% — first pass, Samuel King and Dr. Brian Hie, standard lab conditions.

Brian Reed: Right, and that hit rate is almost beside the point — because here's what nobody put in the press release. The screening systems that are supposed to catch dangerous biology work like a wanted poster. They scan a sequence, compare it against databases of known pathogens, flag anything that looks familiar. That's the whole mechanism.

Eliza Ward: So if the thing has never existed before—

Brian Reed: There's no face on the poster. The alarm is literally looking for the wrong thing. It clears the sequence not because it's safe — because it's invisible to the system.

Eliza Ward: Wait. So picture a biosafety officer at a synthesis company — routine check, software scans, no match to any flagged pathogen, order clears. And the gap isn't a missing rule. It's that the rules were built assuming threats come from evolution. Something that mutated, that has ancestors, that leaves a recognizable signature. Generative AI just... skips all of that.

Brian Reed: And the governance gap is structural, not — I mean, it's not that someone forgot to write the AI paragraph. The Biological Weapons Anti-Terrorism Act, the select agent regulations — those predate a world where a language model can output a functional genome. The category of object didn't exist when the rules were drafted.

Eliza Ward: Okay, but — and I want to be honest about what we don't know here — did Stanford actually run these 16 through existing biosafety channels? Because if they did and the system cleared them without flagging anything, that's a very specific kind of failure on record. If they didn't, that's a different problem. I haven't seen that confirmed publicly either way.

Brian Reed: And that gap in the public record is — honestly, that's the tell. But the part that comes later makes this worse: the methods are already published, which means the barrier now is basically a journal subscription.

Eliza Ward: A journal subscription and a standard lab — that's what I keep snagging on. Because the methods being published isn't a mistake. That's how science is supposed to work.

Brian Reed: Right, and that's — okay, the reason it's so hard to land is that the thing creating the risk is the same thing that could actually save people. Bacteriophages aren't some theoretical intervention. Eastern Europe and Russia were using them clinically decades ago — because antibiotic resistance hit them hard, early, and they couldn't just wait for penicillin to keep working. So phage therapy has a track record. AI-designed novel phages could be the version that keeps working when every antibiotic we have left fails.

Eliza Ward: Hold on. We already use phages as medicine? Like, this is not hypothetical treatment.

Brian Reed: Clinically, yes — for decades, in Georgia, Poland. Western medicine went all-in on antibiotics and mostly didn't follow the research. So the capability the Stanford paper unlocks isn't just a weapons concern — it's potentially the antibiotic-resistance exit ramp. And you can't regulate that away without — I mean, you'd be restricting the tool that might be the answer to a crisis killing people right now.

Eliza Ward: And any country that unilaterally restricts it just hands the research to whoever doesn't. The risk window doesn't close — it just moves.

Brian Reed: Which is — yeah, that's the actual structural problem. It's not that regulators are slow. Jurisdiction-specific restrictions are reactive by design. If a lab in Taipei runs the same model tomorrow, Science is already on their desk.

Eliza Ward: And we genuinely don't know whether a bad actor would even use this method over, say, just ordering from a synthesis company. That uncertainty matters — because what you're governing

Brian Reed: ...shapes determines what you even build to stop it. And that keeps coming up — there's near-universal agreement among biosecurity people that current governance isn't adequate. But the moment you ask what adequate looks like, the consensus falls apart completely. Because adequate screening might mean real-time surveillance of AI outputs, and that's a cost to research freedom that nobody has actually agreed to pay.

Eliza Ward: And every framework trying to answer that is jurisdiction-specific. Reactive by design. Which means — wait, actually this is the thing that I don't think has a clean resolution — biosafety governance was built to catch slow threats. Things that leave evolutionary fingerprints. Things that take generations to emerge. We just made threats fast.

Brian Reed: And most experts agree on that part. They just don't agree on what comes next.

Eliza Ward: Which is — rough week for anyone who thought biology needed to stay complicated, I guess. Thanks for working through this with me.

AI can now design viruses faster than regulators can write rules—the governance gap is widening · Onpode