Scientists have created the first viruses designed with artificial intelligence, a landmark advance that could open the door to new treatments while intensifying questions about how to keep such powerful technology under control.
The viruses are bacteriophages, a class of viruses that infect only bacteria and are already used in parts of the world to treat stubborn infections. In laboratory experiments, a mixture of the AI-designed phages destroyed E coli bacteria that had shown resistance to naturally occurring bacteriophages.
Dr Brian Hie, a chemical engineer at Stanford University in California, led the work using genome language models — essentially the genetic counterpart of the large language models that power AI chatbots — to generate working bacteriophage genomes. Researchers then built the viruses in the lab and tested them against E coli in petri dishes.
The capacity to “rapidly design” genomes, tailor them to particular bacterial targets and bypass resistance could “transform phage therapy” and “expand biotechnological toolkits”, the team wrote in the journal Science.
At the same time, the researchers stressed that the breakthrough brings “important biosafety, biocontainment and biosecurity considerations”. They urged scientists working on whole-genome design to “consult both safety and security professionals throughout the project”.
That caution was echoed in an accompanying article by Prof Tom Inglesby and Dr Moritz Hanke of the Center for Health Security at Johns Hopkins University in Baltimore. “Although this is promising for life sciences applications, it also raises urgent biosafety and biosecurity questions. The ability to compose viral genomes using generative AI now exists; the governance to safely steer it does not,” they wrote.
Hie and his colleagues relied on two AI systems, Evo1 and Evo2, to design the viral genomes. The models had been trained on genetic information from 2 million bacteriophages. To reduce the chance of producing harmful designs, the researchers deliberately left out genetic code from viruses capable of infecting plants, humans or other animals.
The AI produced thousands of candidate genomes, and the team chose nearly 300 to manufacture in the laboratory. These were inserted into bacteria, which interpreted the genetic instructions and produced the new bacteriophages. The approach was still far from efficient: only 16 phages were viable. Even so, a cocktail of those viruses quickly overcame resistance in two separate strains of E coli.
Bacteriophage genomes are tiny, but Inglesby and Hanke said the work nevertheless proved that generative AI could create functioning viral genomes. Whether the same approach could be applied to other viruses was unknown, but they said work on pathogens that could infect humans, animals or plants should not be pursued.
“Such genomes might encode new pathogens that … cannot be contained by existing countermeasures,” they wrote.
Tom Ellis, a professor of synthetic genome engineering at Imperial College London, said the work was impressive, but revealed how hard it would be to make more complex genomes. “This is literally the smallest and easiest genome to make,” he said.
An AI trained on the genetic code of dangerous bugs could be used to design more harmful viruses, Ellis said, but controlling access to genetic data and having restrictions on making genomes that look dangerous would help. “Governments are working hard to do this already,” he added.
“But honestly,” he said, “the threat from full AI design and writing of a genome of a virus or bacteria is very overblown when we consider that just taking existing pathogens and making gain-of-function changes to their genomes is so much easier and much more likely to be a real pathogenic threat.”
Dr Filippa Lentzos, a reader in science and international security at King’s College London, said the most important point to intervene at the moment was when DNA was being manufactured. “It’s important to see the bigger governance picture and not focus regulation solely on the AI model,” she said. “A layered approach makes more sense: safeguards around model development and access, responsible research review, synthesis screening, and established laboratory biosafety and biosecurity.”