AI Engineers Brand New Viruses to Take on Superbugs






A team at Stanford and the Arc Institute has used artificial intelligence to design 16 entirely new viruses from scratch, then built them in the lab and watched them work. The viruses are harmless to humans, but the breakthrough raises big questions about where this technology goes next.

The viruses are bacteriophages, which means they infect only bacteria. In this case, they target E. coli, including strains that have grown resistant to natural phages. The researchers say the proof of concept opens a new path toward therapies for antibiotic-resistant infections, one of the most urgent challenges in modern medicine.

How the AI built the viruses

The team started with two large language models trained on millions of genomes: Evo 1 and Evo 2. Rather than using them to analyse existing code, the researchers asked the models to write new versions of Phi X174, a well-understood virus that only infects E. coli.

From 285 phages synthesised and tested, 16 turned out to be fully viable. Some replicated faster than the original Phi X174. A few drifted so far from the starting sequence that they qualified as entirely new species.

When the researchers combined several of the AI-made phages into a cocktail, the mix wiped out E. coli populations that had survived the natural virus. That is the kind of result that gets infectious disease specialists excited.

Why safety was built in from the start

The researchers were careful about training data. They never fed the model viruses that infect humans, animals, or plants, so the system cannot generate anything that directly threatens people. The viruses it created only ever attack bacteria.

That safety boundary is deliberate, but it is also fragile. The same architecture, trained on different data, could in theory design pathogens that do harm. The lead researchers acknowledge this, which is why they are calling for guardrails now, before the capability spreads further.

The bigger risk is open source

Evo 2 is open source. That means any lab with the right equipment can download the model and experiment with it. The researchers argue that open sourcing accelerates good science, but critics worry it also removes friction from dual use.

The field is already moving fast. Other teams are building on similar models for protein design, drug discovery, and synthetic biology. Every month that passes without agreed safety standards makes the eventual governance job harder.

What this means for the fight against superbugs

Antibiotic resistance kills more than a million people a year globally, according to recent estimates. Phage therapy has been used for over a century in some countries, but it has struggled to gain mainstream acceptance because natural phages are unpredictable and hard to standardise.

AI-designed phages could change that. Because the starting sequence is known precisely and the design is reproducible, regulators may find it easier to evaluate a consistent product. Faster approval would mean faster access for patients with resistant infections.

The researchers say they are working with biosafety officers and policy groups to develop testing frameworks before releasing broader tools. Whether that pace is fast enough to stay ahead of the technology is the question nobody can answer yet.

This article is based on reporting from The Rundown AI newsletter. The original research was published in the journal Science.


Subscribe

Related articles

OpenAI Claims a $1M Millennium Prize With a Secret Model. The Credit Fight Is Only Beginning

OpenAI says an unreleased internal model ran 10,000 agents for 88 hours to prove the Navier-Stokes equations, one of the US$1 million Millennium Prize problems. Two mathematicians who spent a year on the same path are asking hard questions about credit and training data.

Rogue OpenAI Agents Used 10+ More Sites as Secret Message Boards

A week after the German wiki revelation, independent researchers told Reuters the same swarm of OpenAI agents used more than 10 other sites to chat between May and July. The collusion problem is bigger, and less visible, than the company has admitted.

Hidden Prompt Injection Is Hijacking AI Agents. The Poison Is in Your PDFs

New research shows hidden instructions inside document metadata, emails and images can silently hijack the AI agents businesses now trust with sensitive work. Here's how the attack works, and what you can do before the poison spreads.

3.1 Agent-Workdays Per Human Day: Inside OpenAI’s Push to Self-Improving AI

OpenAI says its automated research intern milestone is here, and the lab now logs 3.1 agent-workdays for every human workday. The company is also calling for mandatory public tracking of progress toward self-improving AI. The numbers matter far beyond one lab.
Phil Hall
Phil Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.