US researchers have used AI to design 16 novel, fully functional viruses that successfully replicated in the lab, according to BBC News, marking what scientists described as the first time whole genomes have been designed by AI.

The Stanford team, led by assistant professor Brian Hie, used AI models called Evo1 and Evo2, trained on genetic sequences from viruses, bacteria, plants, and people, to design bacteriophages, viruses that infect only specific bacteria species and pose no threat to humans. Researchers synthesised 302 of the most promising AI-generated designs, of which 16 proved effective at killing E. coli.

Hie told the BBC the work represents new territory for generative AI, extending beyond simpler tasks like antibiotic design into designing something that can replicate and function inside cells. He said attempting simple AI-designed living organisms would probably be difficult but not impossible, and that the team is keen to pursue it.

The breakthrough has also raised safety concerns. In a commentary published alongside the research in the journal Science, Johns Hopkins Center for Health Security researchers reportedly warned the findings raise urgent biosafety and biosecurity questions, arguing viruses with disease-causing potential should not be pursued. The Stanford team said it took precautions, including excluding viruses capable of infecting complex organisms from its training data and conducting the work in a secure lab on bacteria-only phages.


Who Owns AI Security in the Enterprise? Governance Is Still in Its Infancy
Who actually owns AI security in your organisation — and how mature is your governance around it? Two senior CISOs from vastly different environments give a straight answer: ownership sits with the CISO for now, and governance, even in well-run programmes, is still in its infancy. AI is shifting enterprise risk from defending infrastructure to defending decisions. Agentic AI operates semi- or fully autonomously, traditional security controls don’t fit probabilistic systems, and no single vendor covers the full attack surface. Speakers: Andy Holliday, CISO at Petrofac, Lester Godsey, CISO at Arizona State University and Stewart Tinson, Project Director, AI-360 You’ll learn: • Why the CISO is the only realistic owner of AI security risk for the next 5 years • Why agentic AI breaks deterministic security controls and what to do about it • How ASU built an actionable AI framework supporting 60+ large language models • Practical controls: API key hygiene, command whitelists, blast radius reduction • Why no single vendor can cover AI security end-to-end Key topics: Agentic AI risk • AI governance maturity • Threat model transformation • CISO ownership • Incident response for AI • Ethics & training data bias • Vendor landscape reality • Probabilistic vs deterministic controls For CISOs, CIOs, and risk leaders making decisions about AI adoption now.
Share this post
The link has been copied!