AI Designed Working Viruses From Scratch. Here's What That Actually Means
Stanford researchers used a large genome model to generate functional bacteriophage viruses. The viruses work. They're not weapons. But the same researchers are asking whether we should plan ahead before someone builds a version that targets humans.

Key points
- Stanford University researchers used a large genome AI model to generate the genomes of bacteriophages, viruses that infect bacteria but do not harm humans, in a study published in 2025.
- Every AI-designed virus was closely related to a naturally occurring virus already known to science, not built from unrelated parts.
- The same class of AI model previously produced DNA sequences that encoded working proteins inside bacteria.
- The researchers formally recommend that the biosecurity community begin preparing now for the possibility that future models could design viruses targeting vertebrates, including humans.
For decades, the big prize in biological AI was proteins. Proteins are the machines inside every living cell: they speed up chemical reactions, build structures and carry signals. If you can design a new protein, you can potentially tinker with biology in useful ways, from medicines to materials.
DNA sits one step back. It is the instruction manual that cells read in order to build proteins. Until recently, it was not obvious that an AI trained purely on DNA sequences could do anything useful, because that layer of abstraction, the gap between the instructions and the actual machinery, made the task harder to define.
Then researchers built large genome models, AI systems trained on enormous libraries of DNA from many species, similar in concept to the large language models behind ChatGPT but fed genetic code instead of text. Those models turned out to be surprisingly capable: they could generate DNA sequences that, when placed inside bacteria, produced working proteins. They could also mimic the gene structures found in complex cells like ours.
So what did the Stanford team actually build?
The Stanford group took those same models and pointed them at a specific target: bacteriophages. A bacteriophage, often shortened to phage, is a virus that infects bacteria. They are everywhere, they are harmless to humans and animals, and they are well understood by scientists, which made them a sensible test case.
The AI generated complete phage genomes, full sets of genetic instructions for a virus. Crucially, those genomes encoded functional proteins. The viruses the model designed actually worked.
None of this is runaway science fiction. Every virus the AI produced was closely related to a phage that already exists in nature. The model did not invent something from a blank page. It produced novel variations on a known theme, some with distinct features that would be genuinely difficult to arrive at through ordinary evolution, but still clearly in the same family as natural phages.
| Feature | Detail |
|---|---|
| Model type | Large genome model trained on DNA sequences |
| Target | Bacteriophages (viruses that infect bacteria only) |
| Relatedness to known viruses | Closely related to existing natural phages |
| Proteins encoded | Functional, verified in bacterial systems |
| Human risk (current) | None: phages do not infect vertebrates |
| Researchers' concern | Future models could potentially target vertebrates |
Should anyone be worried right now?
Not about these specific viruses. Phages cannot infect human cells. The risk today is essentially zero.
What the Stanford team is flagging is a trajectory. The same capabilities that let a model write a working phage genome could, with more development, point at viruses that do infect vertebrates. The researchers are not claiming someone has done this. They are saying the gap between here and there is worth thinking about before it closes.
First reported by Ars Technica, the story sits inside a broader pattern: powerful biological AI tools advancing faster than the policy and safety frameworks built to govern them.
For most people, the practical message is simple. This research is legitimate science, conducted openly, with a clear warning attached. The researchers are waving a flag, not hiding the ball.
What happens next?
The ball is now in the biosecurity community's court. The Stanford team explicitly recommends that governments and scientific bodies start planning for AI-designed pathogens now, while the window is still open.
That conversation will matter far more than the viruses themselves.



