Novel Viruses Created With AI

October 2026
By Jocelyn Bridges and Michael T. Klare

For the first time, scientists have used artificial intelligence to design and manufacture viable viruses with DNA sequences, or genomes, not found in nature—demonstrating a technology that they said could be used to devise treatments for harmful, antibiotic-resistant bacteria.

Chemical engineer Brian Hie (L) and Aditi Merchant of Stanford University examine a protein structure generated by Evo 2, an AI tool that can suggest genome designs. As reported in Science, Hie and graduate student Samuel King used AI to design and manufacture viable viruses with DNA sequences, or genomes, not found in nature.  (Photo courtesy of Stanford Engineering)

According to the scientists at Stanford University and Arc Institute, who developed the technology and whose findings were published in the Aug. 6 issue of Science, these novel viruses were able to reproduce and infect E. coli bacteria in a laboratory.

“Our results demonstrate that generative models capture evolutionary constraints in DNA sequences with enough fidelity to produce complete bacteriophage genomes divergent from those observed in nature and with prespecified traits,” the article concluded.

“Our approach … lays out a path for generating adaptive and resilient phage therapies against rapidly evolving pathogens,” the article said.

Other scientists, however, have warned of its potential use in developing lethal biological warfare (BW) munitions. Dr. Susan Monarez, a microbiologist and former director of the Centers for Disease Control and Prevention, told The New York Times Sept. 10 that AI could “let bad actors hide in plain sight, using seemingly legitimate research to create pathogens we may not see coming and may not be able to stop once released.”

Scientists and arms control advocates have long expressed concern over the exploitation of biosciences for military use and have advocated binding constraints on such activities. These concerns were stoked during the Cold War by reports that the Soviet Union and United States had developed and were stockpiling a variety of BW agents, including anthrax.

In response to widespread international alarm over the potential for a BW-induced global catastrophe, the two superpowers, along with numerous other countries, signed the Biological Weapons Convention (BWC) in 1972, effectively prohibiting production, acquisition, transfer, stockpiling, and use of BW agents.

In accordance with the BWC, most major powers destroyed their stockpiles of active BW agents and ceased the development of such munitions. However, some analysts worry that certain states—including the United States—have investigated the possible use of bioweapons under the guise of developing “defensive” measures decades after signing the BWC. (See ACT, September 2001 and ACT, October 2001.) Despite these ongoing research efforts, U.S. military officials have concluded that traditional BW agents, such as anthrax, are too cumbersome and dangerous to employ as battlefield munitions.

Recently, however, scientists have warned that AI could be used to develop advanced BW agents without the limitations of traditional bioweapons. Such agents might, for example, be designed to spread among humans at an explosive speed or to target selected populations, according to a May 4, 2026, article in The New York Times. Some analysts view the advent of AI-generated viruses from this perspective.

In the case of the experiments reported in Science, the scientists specifically chose to devise genomes akin to a naturally occurring antibacterial virus, or bacteriophage, called Phi X 174, that poses no health risk to humans.

Similar to how generative-AI models, such as Anthropic’s Claude and OpenAI’s ChatGPT, are trained on vast text datasets, these scientists trained the genomic language models Evo 1 and Evo 2 using large genomic sequence datasets incorporating all domains of life: animals, plants, microbes, and bacteria. Once trained, the models were prompted to seek common patterns among the sequences that could be used in devising new genomes.

The researchers then tasked the models with devising genomic sequences that might resemble Phi X 174. From this template, they created thousands of AI-generated genomes, of which 285 were chemically synthesized, eventually yielding 16 viable bacteriophages that propagated and inhibited the growth of the target bacterial strains.

In the study, the scientists reported that the 16 AI-generated bacteriophages exhibited substantial evolutionary capacity relative to known natural phages, suggesting a potential to devise new antibacterial therapies. At the same time, this discovery has raised concerns among biosecurity experts that AI could be used to create deadly pathogens.

Dr. Moritz Hanke, a fellow at the Johns Hopkins Center for Health Security, expressed his concerns to The New York Times in an article published Aug. 6: “You could say, ‘Hey, genomic language model, make me an influenza genome that is modified to be more transmissible or to be more lethal.’”

Concern over the potential use of AI to generate novel BW munitions was further stoked Sept. 10, when Anthropic revealed that its engineers had detected several instances in which unidentified foreign actors used Claude to obtain information useful for BW manufacture.

The New York Times reported one case in which researchers employed Claude to study the spread of bird flu to mammals—research that, conceivably, could be useful in developing vaccines, but could also be used in designing bioweapons. Anthropic said it suspended Claude’s use by these entities when the incidents were discovered, but warned that, without international guardrails, AI could be used by malign actors to fabricate deadly pathogens, the newspaper reported.

“Biological misuse is one of the most serious risks of frontier AI models,” Anthropic noted in its Sept. 10 report on the incidents. “It has long been a concern that AI models might one day reach the level of capability where they can help to make existing pathogens more dangerous—or create entirely new ones. Without the correct safeguards, such capabilities could have catastrophic consequences.”