TL;DR

Researchers at Stanford have built the first functioning organisms designed by artificial intelligence — 16 bacteriophages that killed strains of E. coli already resistant to natural phages. The work, published in Science, used genome language models whose training corpus drew on two million bacteriophages, deliberately withholding any sequence for viruses capable of infecting people, livestock or crops. Reviewers at Johns Hopkins put the problem bluntly: “The ability to compose viral genomes using generative AI now exists; the governance to safely steer it does not.”

What was actually built

Dr Brian Hie’s team at Stanford used the Evo1 and Evo2 models to generate thousands of candidate genomes, selected close to 300 for laboratory synthesis, and inserted them into bacteria that read the code and produced the phages. The yield was poor: 16 survived, and mixed together they defeated resistance in two separate E. coli strains. Phage therapy is already used worldwide for persistent infections, so a method for rapidly tuning phages against specific resistant bugs has an obvious clinical destination.

The hedging from UK researchers is worth reading closely. Tom Ellis, an Imperial College London professor whose field is engineering synthetic genomes, called the work impressive while noting it used “literally the smallest and easiest genome to make”. His judgement on the risk is sharper still. Designing a whole viral genome from scratch with AI is, he said, “very overblown” as a danger next to the far easier route of taking a pathogen that already exists and editing it towards greater potency.

The intervention point is DNA synthesis, not the model

Dr Filippa Lentzos of King’s College London argued the most important place to intervene is where DNA is manufactured, and warned against regulating the AI model in isolation. Her preferred approach is layered, spanning controls at the model, at the ethics-review stage, at the point of ordering synthetic DNA, and inside the laboratory itself.

That framing arrived the same week Anthropic published an account of loosening the biology classifiers on its Fable 5 model, cutting biology-related fallbacks by roughly 85% while still routing dual-use requests away — molecular design, toxicology and virology among them. The company’s stated reason for the original blanket restriction is the same one Johns Hopkins raises: capability assessments showed the model could give a malicious actor uplift unavailable elsewhere. Capability and containment are being adjusted in public, in parallel, by different institutions with no shared rulebook.

Looking forward

For UK readers the practical question is which body owns this. Biosecurity sits across DSIT, the AI Security Institute and the synthesis-screening arrangements Lentzos points to, none of which currently has a defined remit over genome design models. The Johns Hopkins position — that nobody should attempt this on pathogens able to infect people, livestock or crops — is a norm rather than a rule, and it holds only as long as every lab agrees.