A bioengineer whose cross-disciplinary lab searches for antimicrobial candidates is using OpenAI's Codex and ChatGPT to search the genomes of living and extinct organisms for new antimicrobial molecules, as drug-resistant infections continue to rise globally.

In a case study published on 10 September, OpenAI said César de la Fuente's lab uses its own deep-learning models to scan genome and protein datasets for biologically active molecules, a process it says can cut the initial search for candidates from years to hours. Alongside these models, the lab uses ChatGPT and Codex to brainstorm hypotheses, write and refine code, process datasets and connect ideas across disciplines. De la Fuente said antimicrobial resistance was "one of the greatest existential threats to humanity" in his view, noting that no new class of antibiotics has emerged in 50 years.

De la Fuente described his transdisciplinary team, spanning biology, chemistry, computer science and engineering, and said AI tools help bridge gaps between members with different technical backgrounds, letting biologists build programs and programmers tackle biological problems. He said his lab's shared ChatGPT workspace functions as a collaborative sounding board fed by team members' ideas, though he cautioned that outputs must always be checked for accuracy. Antimicrobial resistance was linked to around five million deaths globally in 2021, according to OpenAI, a figure it says is projected to roughly double by 2050.

Even a promising molecule identified this way faces years of further testing, including toxicity, dosing and manufacturability studies, before any regulatory review or clinical trials.


Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.
Share this post
The link has been copied!