The computer did not create a virus. It did not touch a test tube or handle a living cell. What it did may ultimately be more consequential: it helped decide what the virus’s genome should be.
Researchers at Stanford University and the Arc Institute used artificial intelligence (AI) to design complete genomes of bacteriophages – viruses that infect bacteria. Of 285 AI-generated designs physically synthesised and tested in the laboratory, 16 produced functioning phages. Some were able to overcome bacterial resistance that defeated the original virus. The phrase ‘AI-created viruses’ therefore needs qualification. Humans have been synthesising viral genomes and deliberately modifying viruses for decades. What is new, is not the physical manufacture of a virus. AI has entered the design stage of biology. For medicine, that creates remarkable opportunities. For biosecurity, it raises equally important questions.

From reading genomes to designing them
Bacteriophages -literally “bacteria eaters” -have been known for more than a century and are among the most abundant biological entities in nature. In 1977, one particularly small phage, ΦX174, pronounced roughly ‘phi-X-one-seventy-four’, became the first complete DNA genome to be sequenced. By the early 2000s, scientists had shown that viral genetic material could be synthesised from known sequence information and used to recover functioning viruses. Humans had progressed from reading viral genomes to writing them. Scientists then became increasingly capable of deliberately altering viruses. The controversial influenza gain-of-function experiments of 2011-12 showed that genetic changes could modify important properties such as transmission in experimental animals. Such research highlighted a dilemma that remains unresolved: the same science that can improve pandemic preparedness may also create biosafety and biosecurity risks.
The Stanford-Arc experiment represents the next step. The scientists already knew the ΦX174 genome and already knew how to synthesise viral DNA and recover functioning phages. What changed was who -or what -proposed the genome. They used Evo 1 and Evo 2, genome language models. The principle resembles a large language model, except that instead of learning patterns in words, Evo learns patterns in DNA. It studies the genetic alphabet – A, C, G and T – across vast numbers of genomes and then generates new genetic sequences. For this experiment, the models were further trained on thousands of bacteriophage genomes related to ΦX174.
AI did not invent a completely unrelated virus from nothing: it generated previously unseen ΦX174-like whole genomes within a known biological framework. Scientists selected some of these sequences, physically manufactured the DNA and introduced it into E. coli. If the genetic instructions were biologically coherent, the bacterial machinery produced new phage particles. 16 designs succeeded. The progression is striking: we learnt to read viral genomes, then to write them, then to modify them. Now AI is beginning to help decide what should be written.
One finding shows why this matters. An AI-designed phage successfully combined a viral protein with other genetic changes in a way that conventional engineering had struggled to achieve. The significance is not simply that AI can propose individual mutations; it may increasingly be able to identify multiple genetic changes that work together across an entire genome, exploring combinations that would be extremely difficult for humans to test one by one.

The medical opportunity
The most immediate application may be phage therapy. Antibiotic resistance is steadily eroding conventional treatment options, while bacteriophages offer another way of killing bacteria. Their major limitation is specificity: a phage effective against one bacterial strain may fail against another, and bacteria can also develop resistance to phages. Traditionally, researchers have searched nature and phage libraries for suitable candidates or modified existing viruses. Generative biology introduces another possibility. Instead of asking only, “Can we find the phage we need?”, medicine may increasingly ask, “Can we design the phage we need?”
The Stanford experiment offered an early demonstration. Combinations of AI-designed phages overcame resistance in E. coli strains against which the original ΦX174 failed. For clinicians confronting antimicrobial resistance, this is potentially important. The possibilities extend beyond phage therapy. AI can assist the design of vaccine antigens, antibodies, therapeutic proteins and viral vectors used to deliver genetic treatments. It may eventually help optimise oncolytic viruses that selectively attack cancer cells. The larger revolution is therefore not simply ‘AI making viruses’. It is AI becoming capable of designing biological function.

The danger is acceleration
It is tempting to be reassured because ΦX174 is an exceptionally simple bacteriophage, while dangerous human viruses are vastly more complicated. Human pathogens must negotiate receptor binding, host range, tissue tropism, replication, immune escape and transmission. But complexity should not become false reassurance. Human scientists already understand much about these determinants. Decades of virology, reverse genetics and gain-of-function research have linked many genetic changes to viral behaviour.
AI does not need to rediscover virology. Its power lies in integrating what humanity already knows, examining vastly more combinations than humans can explore manually and accelerating the path from hypothesis to experimental design. This is the real biosecurity concern: capability amplification. The relevant question is not whether an untrained individual can ask today’s chatbot to generate a pandemic virus. It is whether increasingly capable AI could make a knowledgeable and well-equipped laboratory substantially more effective at designing biological systems.
Future systems may compress months or years of literature review, modelling and experimental planning into much shorter cycles. Combined with increasingly automated laboratories, that acceleration could become profound. Even the apparently modest success rate in the Stanford study deserves this perspective. Only 16 of 285 designs worked, but digital systems can generate enormous numbers of candidates. A low success rate is reassuring only while the number of attempts remains small. Biosecurity will therefore also have to evolve. Traditional DNA-synthesis screening often asks whether an ordered sequence resembles a known pathogen or toxin. In the age of generative biology, researchers increasingly argue that screening must also consider biological function: not simply whether a sequence looks dangerous, but what it might actually do.

Safety without paralysing science
AI companies are already confronting this dilemma. Claude Fable 5 was initially deployed with strong safeguards around biology, chemistry and cybersecurity. Legitimate scientific work could sometimes trigger a fallback to a less capable model. The intention was understandable, but the experience illustrated the problem: too little restriction creates risk, while too much restriction can obstruct legitimate science.
Those safeguards have since been refined to reduce false-positive biology fallbacks, while more sensitive capabilities remain restricted. This points towards a more practical model: graduated, auditable access in which legitimate researchers can obtain stronger capabilities under appropriate institutional and security controls. Biosecurity also cannot rest entirely on what an AI model agrees or refuses to answer. Safeguards are needed throughout the chain – AI systems, DNA-synthesis providers, laboratories and institutional biosafety oversight.

India must build capability
There is an important implication for India. If frontier AI becomes central to drug discovery, genomics, vaccines, protein engineering and experimental design, access to advanced AI becomes part of national scientific infrastructure. Smaller and specialised models will be sufficient for many tasks. But a country can choose to use a small model because it is sufficient; it should not be forced to use one because somebody else owns the frontier. If researchers elsewhere receive trusted access to highly capable biomedical models while Indian scientists depend on restricted public versions, the resulting disadvantage could accumulate across drug discovery, vaccines, antimicrobial resistance and other fields.
India is already investing through the IndiaAI Mission and indigenous foundation-model programmes. That ambition should include scientific and biomedical AI, secure compute, high-quality datasets and trusted-access frameworks for legitimate researchers. AI sovereignty without biosecurity would be reckless; biosecurity without AI sovereignty could leave us scientifically dependent.

Governing biological intelligence
The Stanford experiment does not show that AI can casually manufacture dangerous human viruses. It shows something more precise: computers are beginning to move from analysing biological information towards proposing biological designs that scientists can physically build. That capability could transform antimicrobial resistance research, vaccines and therapeutics. It could also accelerate harmful biological engineering. The answer is neither prohibition nor unrestricted access, but controlled acceleration -allowing beneficial science to progress while safeguards increase with capability and risk.
The challenge is no longer simply whether AI should be allowed to understand biology. It is how we govern AI when understanding biology increasingly becomes the ability to design it. India must be capable not only of regulating and consuming that revolution, but of participating in its science and helping shape its safeguards.
(Dr.Abdul Ghafur is a senior consultant in infectious diseases, Apollo Hospital, Chennai and coordinator, Chennai Declaration on AMR. drghafur@hotmail.com)

Leave a Reply