Scientists have crossed a threshold in artificial intelligence: using the technology, researchers have created real viruses that are entirely new to science. The achievement is impressive and raises obvious fears: Could AI, in the not-too-distant future, make viruses more deadly than those seen in nature?
The viruses the researchers created are not Frankenstein’s monsters. They are more than 90 percent similar to certain existing bacteria-infecting viruses, or bacteriophages. They are dangerous only to Escherichia coli. And they were designed by an AI model that wasn’t trained on viruses that could infect plants or animals.
But these safety measures, while welcome, were largely voluntary. The research, which published last week in Science, showed that AI-enabled biotechnology is moving much faster than regulation.
On supporting science journalism
If you're enjoying this article, consider supporting our award-winning journalism by subscribing. By purchasing a subscription you are helping to ensure the future of impactful stories about the discoveries and ideas shaping our world today.
“The frontier is moving very quickly,” says Toby Webster, a program director at Sentinel Bio, a nonprofit that researches biotech safeguards.
In fact, the Science paper describing the AI-designed bacteriophages is already old. It was first published as a preprint on the bioRxiv server in September 2025. The model is open-source and has already been fine-tuned for other tasks.
With additional training, future AI models might suggest totally new gene sequences for viruses or bacteria that evolution has not yet discovered, says Doni Bloomfield, an associate professor of law at Fordham University School of Law, who focuses on biosecurity. Future AI agents might also be able to coach nonexperts on the finer points of biological design—enabling a suite of possible bad actors to create novel bioweapons.
“We should be very cautious about extending this work into viruses that can infect more complex life,” Bloomfield says. “I don’t think we are at the point where we should be doing that without safeguards.”
Science isn’t starting from scratch when it comes to biosecurity. There are regulations around laboratory safety, biological research, genetic modifications and work with dangerous pathogens, says Filippa Lentzos, an associate professor who studies biosecurity at King’s College London.
“The challenge,” she says, “is to connect that existing governance to the new upstream capability to design biology digitally.”
The kind of research that AI might enable carries a lot of promise. New bacteriophages could hunt down and target antibiotic-resistant bacteria, or novel viral “shells” could be used to safely deliver gene therapies or other treatments for diseases. AI models could also reveal new information about how the genome organizes itself, Bloomfield says.
To balance the risks and benefits, Bloomfield and his colleagues recommend a tiered system of access to AI training data that would restrict information that teach the AI ways to increase viral transmissibility, virulence, immune evasion or resistance to medical treatment and other countermeasures. The idea is similar to the current biosafety level system that limits access to pathogens such as Ebola virus to certain high-security labs.
Another potential precaution would be to improve the screening of DNA and RNA sequences that scientists order from specialty suppliers. Many suppliers voluntarily check orders to make sure no one is requesting sequences that could yield dangerous products. But last year Microsoft discovered that AI-generated toxic protein sequences—which are simpler than viral genomes—made it past these safety measures. They hurried out software patches to reduce the vulnerability.
Basic knowledge gaps make shaping new regulations challenging. For example, it’s not clear how training data translate to models’ capability, says Allison Berke, a senior engineer at the RAND Center on AI, Security, and Technology. Would these models need specific training data on flu viruses to re-create the 1918 pandemic flu, for example? Or could they extrapolate the 1918 virus from a more general dataset of viral genomes? The latter is harder to protect against.
The learning curve is also in question.
“If we see indications of the beginnings of a viral design capability, does that mean we will get full 100 percent viral design capabilities in a year, in six months?” Berke says. “We don’t have a great sense of how that capability curve is progressing.”
Both scientists and policymakers are discussing these questions with increased urgency, says Tessa Alexanian, a technical lead at the International Biosecurity and Biosafety Initiative for Science. Indeed, the authors of the new bacteriophage study call for more effective biosecurity approaches in their paper. But, Alexanian says, policymakers also worry about overregulation slamming the breaks on useful research. In the U.S., lawmakers seem to be waiting for a “shocking demonstration” of biological capabilities before acting, Berke says.
That could mean that the research continues to outrun regulation for the near future.
“It’s great to see lots of people in this field caring about creating and releasing these powerful models responsibly, but they aren’t required to and often lack official guidance to navigate this properly,” Webster says. “Currently we’re running on a lot of goodwill.”

