Researchers from Stanford University and the Arc Institute have designed complete, functional virus genomes from scratch for the first time using the AI model Evo. Of 285 tested designs, 16 actually infected and killed E. coli bacteria in the lab. The study published on August 6, 2026, in the journal Science also raises warnings about a regulatory gap.
Evo learns the grammar of viral DNA from millions of genomes
Evo is a so-called genome language model: it predicts the next word, the next DNA building block, similar to a language model. The researchers trained the base version on millions of bacteriophage genomes; for the new study, a targeted retraining followed on 14,466 sequences from the virus family Microviridae. The bacteriophage ΦX174 served as a template – the first completely sequenced genome in 1977 and the first artificially synthesized genome in the history of science in 2003.
From this starting material, Evo generated 285 complete, new genome designs, each with eleven genes, including overlapping reading frames that the researchers specifically identified with a self-developed annotation pipeline. The researchers then had each design synthesized as physical DNA and tested in wells with live E. coli bacteria. A drop in optical density within two to three hours indicated whether the artificial DNA actually assembled into a functional virus.
According to the study published in the journal Science, this approach succeeded for 16 of the 285 tested designs – the genomes assembled into complete, infectious phages. According to the authors, this represents the first generative construction of complete genomes that actually worked in the lab, rather than just predicting individual DNA segments.
AI phages break antibiotic resistances in lab tests
The 16 functional phages differed significantly from their natural counterparts: each variant carried between 67 and 392 new mutations, and 13 of the genomes contained sequence segments not found in any known natural phage. One variant deviated so significantly from the original genome that, according to the research team, it preempted several million years of natural evolutionary development.
Crucial for practical relevance was another test: the researchers mixed several AI-generated phages into a cocktail and applied it against three different antibiotic-resistant E. coli strains. Over several passages, the artificial mixture overcame the resistances of all three strains, while a comparable mixture of naturally occurring phages failed – a benchmark that has not yet been independently verified.
For phage therapy, which has been used for decades against resistant pathogens, especially in Eastern Europe, such an approach would be relevant: instead of painstakingly isolating suitable natural phages from environmental samples, custom-designed viruses could be created on a computer and then synthesized. However, clinical tests on patients are still pending.
Johns Hopkins researchers call for missing oversight rules
Alongside the study, Science published a commentary by security researchers Thomas Inglesby and Moritz Hanke from the Johns Hopkins Center for Health Security. They acknowledged that the Stanford team had taken precautions: human or animal pathogenic virus sequences were specifically removed from the training data, the host strains were exclusively harmless laboratory variants of E. coli, and all work was conducted in biosafety workbenches with separate disposal.
At the same time, the two warned of a growing gap between technical possibility and control: the ability to assemble viral genomes using AI now exists – however, binding rules for this are largely absent. Spanish biophysicist Jordi García Ojalvo from Pompeu Fabra University in Barcelona assessed the risk, as CNN reports, as currently limited due to the low success rate of about six percent per test series.
The debate gains additional urgency from the political context in the USA: the government under President Trump has rolled back several AI safety regulations from the previous administration, while Congress and the tech lobby have so far been resistant to further regulation. Even within AI research itself, bio-risk is currently a topic: just recently, another study showed that a language model could be manipulated via jailbreak to generate risky virus candidate sequences. Safety programs like OpenAI’s Bio Bug Bounty currently focus primarily on language models, not on specialized genome AI like Evo.
It will be crucial whether regulatory authorities and professional societies establish rules for genome language models before the technology is expanded from pure bacteriophages to more complex organisms. The study authors themselves advise researchers to deliberately involve safety and biosafety experts in future designs – a voluntary recommendation that, unlike a law, is not enforceable. Whether such a self-commitment is sufficient will only become clear when comparable models are used outside of academic controls.


