A Milestone Verified, Not a New Discovery
On Thursday, 6 August 2026, the peer-reviewed journal Science published a study describing the first generative-AI design of complete, functional bacteriophage genomes, led by Brian Hie, an Assistant Professor at Stanford University and an Innovation Investigator at the Arc Institute. Readers who recall similar headlines from last year are not misremembering.
The same research method first surfaced as a preprint on the bioRxiv server in September 2025, almost a year before this week's publication. What changed this week is not the underlying science, it is that the work has now passed formal peer review at one of the two most prestigious scientific journals in the world, meaning independent experts scrutinized the methods and results before publication rather than the claims resting on a single lab's own account.
How Evo 1 and Evo 2 Designed Living Genomes
The team used two genome-language AI models, Evo 1 and Evo 2, part of the Arc Institute's Evo model series. Both had already been trained broadly on more than 2 million phage genomes, and the researchers then fine-tuned them specifically on 14,466 sequences from the Microviridae family of viruses.
The target was bacteriophages that infect Escherichia coli C, a non-pathogenic laboratory strain used routinely in biology and posing no threat to humans or animals. As a reference template, the models worked from phiX174, a small natural phage with a 5,386-nucleotide genome encoding 11 genes that has served as a model organism in biology for decades.
From Thousands of Designs to 16 Working Viruses
The AI generated and filtered thousands of candidate genome sequences down to nearly 300 designs. Researchers then physically synthesized and assembled 285 of them in the laboratory, and growth-inhibition and infectivity assays confirmed that 16 of those were fully functional viruses, meaning they actually infected and killed the target bacteria.
Those 16 working genomes carried between 67 and 392 novel mutations compared with their nearest known natural relative. Evo-Phi2147 carried 392 mutations and only 93.0 percent sequence identity to its closest natural match, phage NC51, and thirteen of the sixteen functional genomes contained mutations absent from any known natural sequence. A separate design, Evo-Phi36, successfully combined a DNA-packaging protein borrowed from a distantly related phage called G4, a combination that had previously defeated human scientists' own rational engineering attempts; some AI-designed phages killed E. coli as well as, or better than, the natural phiX174 reference, and designed-phage mixtures also proved effective against E. coli strains that had already evolved resistance to phiX174 itself.
The Safety Design That Already Works
The most consequential design choice is what the Evo models cannot do: they cannot generate human viral sequences, because that category of data was deliberately excluded from their training from the outset. That exclusion is meant to prevent both accidental and intentional misuse for designing pathogens dangerous to humans, and in this study only non-pathogenic bacterial hosts were used throughout.
That distinction matters because it separates two different questions that often get blurred in coverage of AI and biology: whether the model itself can be steered toward danger, and whether the physical output of a safe model can still cause harm somewhere downstream. Here, the first question already has a structural answer built into the system; the second is where this week's real story sits.
The Real Gap: Who Fills the Order
In an accompanying Perspective essay published in the same issue of Science, Thomas Inglesby and Moritz Hanke of the Johns Hopkins Center for Health Security argued for legally required screening of synthetic genetic-material orders for potentially dangerous sequences, rather than leaving that screening to voluntary industry practice. Their point is not about Evo at all, it is about whichever company receives an order and physically synthesizes the DNA, no matter which AI model or human designer produced the sequence in the first place.
That is the detail EU and UK policymakers drafting AI Act biological-risk provisions and dual-use export controls should sit with. A model that refuses to output dangerous sequences is only one layer of protection, and this week's Perspective essay names the layer that current rules do not yet reliably cover: the synthesis step that turns any AI-generated design, from this lab or any other, into an actual physical genome. We are not asserting what EU or UK law currently requires on that point, only that the researchers' own commentary is pointing regulators at exactly this question.
Read next: Shopify Says AI Search Tripled Its Merchant Orders | 4,000 Apps in 30 Days: Cloudflare's AI Wager



