Brian Reed: Hi. How are you doing?
Eliza Ward: Genuinely not sure how to answer that after this week.
Brian Reed: That's a very specific kind of not sure.
Eliza Ward: There's a paper. Published August 6th in Science. Stanford, Arc Institute — a team led by Brian Hie, with a grad student Samuel King. They used a genome-language model called Evo to generate DNA sequences for 16 viruses that had never existed before.
Brian Reed: And then built them.
Eliza Ward: And then built them. Synthesized in a lab, confirmed functional, confirmed to replicate and infect E. coli. Sixteen of them.
Brian Reed: Hang on — so the confirmation that they actually replicated, that's in the paper itself? Peer-reviewed, in Science?
Eliza Ward: That's the confirmed fact, yeah. Not a preprint. Not a press release. Science, August 6th.
Brian Reed: Phage therapy isn't new. Viruses that kill bacteria instead of us, that idea's been around since the 1920s. What you could never do before was design one from scratch. You were always working with phages that already existed somewhere in nature.
Eliza Ward: Right — Evo 2 just ended that constraint.
Brian Reed: It's like — okay, the analogy I keep reaching for: it's the difference between a locksmith who can only copy keys that already exist, and one who can cut a key for a lock nobody's ever seen. Same craft, completely different capability.
Eliza Ward: And the lock here is antibiotic-resistant bacteria. Which, wait — this isn't a hypothetical problem. The pipeline for new antibiotics is almost empty. Bacteria that no existing drug touches.
Brian Reed: That's the part that actually reframes the risk conversation for me. Because when I read Thomas Inglesby and Moritz Hanke at Johns Hopkins raising urgent biosecurity concerns, I think — yes, and also, the other side of that ledger is real patients running out of options.
Eliza Ward: Hold on — so what's actually confirmed new here, specifically? Because Evo 2 trained on millions of genomes, learned DNA structural patterns, and produced sequences that don't match anything found in nature. That's the line. It's not remixing known phages.
Brian Reed: Genuinely novel sequences. Generated on demand. And the 16 E. coli-targeting viruses are — I mean, they're not a therapy yet. That's the thing I don't want to overstate. Proof of concept.
Eliza Ward: A proof of concept for something the medical system actually needs right now.
Brian Reed: Which is — yeah, that's the click. Not that AI helped biology. It's that on-demand design speed changes what's even possible therapeutically, and resistance keeps accelerating. Those two curves just met.
Eliza Ward: But that's exactly where the framing going around right now breaks down — the take is 'Stanford did it responsibly, they excluded human pathogen data from Evo's training set, so the safeguard worked.' And I don't buy that.
Brian Reed: Because a choice is not a rule.
Eliza Ward: That's — yeah, exactly. The Stanford team made a voluntary design decision. There's no requirement, no regulatory body, nothing at CDC or WHO that currently requires that exclusion. It's not a safeguard that exists. It's a safeguard one team chose.
Brian Reed: And I think that's why Thomas Inglesby and Moritz Hanke at the Johns Hopkins Center for Health Security used the word 'urgent' — not 'concerning,' not 'worth monitoring.' Urgent. Same week the paper came out in Science.
Eliza Ward: Those aren't people who missed the point. They read the study, they saw the capability, and they — wait, actually the thing that lands for me is the concrete version of what they're worried about. A researcher somewhere, 2027, downloads an open-weights genome-language model, runs it without the pathogen-exclusion filter Brian Hie's team chose, and those sequences are in a lab workflow before any review body even knows it happened. Because no review body has authority here yet.
Brian Reed: And the part that actually gets me — the negative capability, the precision of designing viruses that specifically can't infect humans, that's not a default. That restraint is what another actor could just... remove.
Eliza Ward: The biosecurity concern isn't about these 16 E. coli phages. Not at all. It's that the technique now exists.
Brian Reed: Right — but what evidence would actually change that reading? Like, is there anything confirmed right now that's closing that gap, or are we just — hang on, is the dual-use risk still purely theoretical at this point?
Eliza Ward: That's — we'll get to this, but the piece that makes all of this worse is the speed gap: AI design iterates in hours, biosafety review takes months, and nobody's confirmed any body has a timeline to close that.
Brian Reed: And that speed gap is — I mean, that's not a policy failure, that's a structural mismatch. The CDC and WHO built their frameworks for a pace of biotechnology where a lab might spend months engineering a single modification. AI just compressed that into an afternoon. The oversight was never designed for this clock.
Eliza Ward: The last time scientists actually self-governed something at this scale was Asilomar. 1970s. Recombinant DNA. That conference produced real norms that held for decades. And right now — there is no modern equivalent of that for AI-enabled synthetic biology. None confirmed.
Brian Reed: No Asilomar 2.
Eliza Ward: Nothing. And then the paper gets published in Science — which, wait, that's not a reckless act. That's how science works. Wide publication, methods available, reproducibility. But the method is the risk now. Not just the result.
Brian Reed: Anyone who reads the paper can try to reproduce the technique. That's the open-science norm — and it's also exactly the dual-use problem. A researcher in a lab with no biosafety committee oversight, no equivalent of what Brian Hie's team chose, runs Evo 2 or actually — hang on, do we even know for certain it was Evo 2?
Eliza Ward: That's — no, that's genuinely unresolved. Forbes attributed the model to OpenAI. Other sources say Evo, developed at Stanford and Arc. Those are not the same model, not the same organization, not the same access controls. And we don't know which is right.
Brian Reed: So if we can't confirm who built the model used in the actual published study, we definitely can't confirm who else has access to equivalent capability right now.
Eliza Ward: That's — yeah, that's the concrete unknown that makes everything else harder. No governance body has named a timeline. No authority has claimed jurisdiction. The thing to watch is whether any institution — CDC, WHO, a scientific body — actually convenes something, or whether the next signal we get is another paper with fewer voluntary safeguards.
Brian Reed: And we're not speculating that something bad is imminent. We're just — the gap is confirmed open, no one's confirmed it's closing, and that's where this actually sits right now.
Eliza Ward: That's where I actually land. Six days. The paper is six days old. The capability it describes is already here — not coming, not theoretical — and the open question isn't whether AI-designed viral genomes become routine. It's whether, by the time they do, there's any governing structure that has actual authority. Not guidelines. Authority.
Brian Reed: The benefit and the risk arrived in the same publication. Same paper, same August 6th date in Science. It's not like the therapeutic potential comes first and the dual-use danger follows later. They landed simultaneously. Which means whoever governs this has to hold both at once, and right now no one's confirmed they're even trying.
Eliza Ward: Right — and what would actually settle it for me? A named institution. CDC, WHO, a scientific body with the Johns Hopkins Center for Health Security at the table — convening something with a timeline. Not a statement. A process. That's the signal. If that doesn't happen before the next comparable paper, then the absence isn't an oversight gap anymore.
Brian Reed: It becomes the answer.
Eliza Ward: Yeah. The absence becomes the answer. And nobody's confirmed who's responsible for making sure that doesn't happen — not Stanford, not Arc, not Inglesby and Hanke raising the alarm. That question is just... open. Genuinely open.