Researchers at Stanford, working with Palo Alto's Arc Institute, used artificial intelligence to design viruses that actually work — the first time a generative model has produced viable viral genomes from scratch — and the scientists say it is time to start preparing for the day a related model could be trained to target humans.

The work, detailed this month in Science and independently reported by Ars Technica, is a milestone for the Bay Area's fast-moving "generative biology" scene: the same large-model approach that powers chatbots, pointed at DNA instead of English. The tools driving it — Evo and a newer framework called Proto — are being built in Palo Alto at Arc Institute and Stanford and released open-source, ahead of any binding rules on who may use them or for what. The most important caution comes not from an outside critic but from the researchers themselves, who flag that a related AI could one day design a virus aimed at vertebrates.

As a test case, the team chose ΦX174, a virus that infects E. coli and cannot infect humans. It is a workhorse of molecular biology: just 11 genes across roughly 5,400 bases, every gene's function already mapped. The models used — named Evo 1 and Evo 2, developed out of the Stanford lab of chemical engineering professor and Arc investigator Brian Hie — were trained on millions of natural genomes to predict the next chemical "letter" of DNA, according to Ars Technica's account of the paper. The researchers fine-tuned them on bacteria-killing viruses, prompted them with a short fragment of ΦX174's start sequence, and let the software write the rest of a genome.

The raw outputs were filtered hard. Sequences with a broken spike protein — the part the virus uses to latch onto a cell — or the wrong overall length were thrown out. According to Ars Technica, that computational screening left 302 candidate genomes. The team chemically synthesized 285 of them and inserted them into bacteria to see what would happen. Sixteen worked, inhibiting the growth of the E. coli the way a real virus would. Nine of those were direct AI outputs; the other seven had picked up additional mutations after being inserted into the bacteria. A viability rate of about 6 percent — from software that had never seen these exact genomes — is the figure that has biosecurity researchers paying attention.

The scientists built in guardrails. As Ars Technica reports, they deliberately withheld from training any viruses that target complex cells — the category that includes human pathogens — so the models could not, even by accident, output something dangerous to people. Yet the same account notes the Stanford team's own conclusion: that it may be time to start thinking about the possibility that someone could develop a related AI capable of designing a virus that targets vertebrates. The warning is striking precisely because it comes from the people who built the tool, not from a critic on the outside.

That warning lands in a specific place. The Bay Area has become the center of gravity for AI-driven biology, and the labs pushing it fastest are also the ones lowering the barrier to entry. Hie's Laboratory of Evolutionary Design, based at Arc Institute in Palo Alto, in June released a framework called Proto — a "programming language for generative biology" the team built so that human scientists and AI coding agents alike could design DNA, RNA and proteins fluently, according to Arc's own account. The team made it open source.

"Proto started as an idea to make generative biological design more accessible," said Aditi Merchant, a Stanford bioengineering PhD student and Proto co-author, in a Q&A published by Arc. Her colleague Daniel Guo described the goal as letting biologists "skip this stage of a project entirely" and focus on the science. Accessibility is the selling point — and, for anyone worried about misuse, the concern.

None of the viruses made in these experiments threaten anyone. The unresolved question is what happens when the same capability, trained on a different and more dangerous set of genomes, is pointed outside the narrow, carefully fenced conditions the Stanford team imposed on itself — and whether any regulator is positioned to notice before it does.