AI Can Now Design Viral Genomes. America Needs a Biosecurity Wake-Up Call.
In 1998, I sat in a restored castle on a Swiss mountainside with an international group that included military and intelligence professionals. Antique armor and weapons surrounded our meeting room, giving it the feel of a medieval war council. But our subject was anything but ancient: biological warfare.
Dr. Joseph D. Douglass Jr., coauthor with Neil C. Livingstone of the 1987 book “America the Vulnerable: The Threat of Chemical and Biological Warfare,” briefed us on the Soviet biological-weapons program and allegations involving other communist regimes. His descriptions of what governments might do with pathogens — and what some were alleged to have done in secret — were sobering.
I left Switzerland convinced that biological warfare represented one of mankind’s darkest capabilities. But there was also a practical barrier: sophisticated biological weapons demanded scientists, laboratories, money, and specialized expertise.
Twenty-eight years later, artificial intelligence may now be weakening that barrier.
The New York Times reported that researchers at Stanford University and the Arc Institute have used genome-language models to design complete viral genomes — essentially, the full genetic instruction set that tells a virus how to build itself and function. These were bacteriophages — viruses that infect bacteria, not people. The researchers used nonpathogenic E. coli and deliberately excluded human viral sequences from the model’s training data. Of 285 designs experimentally tested, 16 produced functioning phages. Some combinations of AI-generated phages even overcame bacterial resistance that defeated the natural virus used as their starting point. The peer-reviewed research was published in Science.
This was not a biological-weapons experiment. It did not create a human pathogen, nor does it show that today’s AI systems can design one. The medical promise is obvious: such tools could eventually help scientists develop new treatments against antibiotic-resistant infections. But an important threshold has been crossed. Artificial intelligence is no longer limited to analyzing biological information or proposing individual components. It can now help design a complete viral genome that, when synthesized and tested, can yield a functioning virus.
The significance is not that biological warfare suddenly became easy. It is that developing a usable biological weapon has historically been extraordinarily difficult.
The Japanese cult Aum Shinrikyo offers a useful warning against exaggeration. It had trained scientists, considerable financial resources, and sophisticated laboratories. Yet its attempts in the early 1990s to cause mass casualties with botulinum toxin and anthrax failed. Creating a dangerous biological agent is only the beginning of the problem. A would-be attacker must also acquire or design it, produce it reliably, weaponize it, keep it viable, and deliver enough of it to the intended target. Records of the program show that even Aum’s unusually well-resourced effort encountered serious problems producing virulent agents and dispensing them effectively.
Artificial intelligence does not suddenly erase those obstacles. The danger is that it may begin removing them one by one.
That concern is no longer confined to futurists. A June open letter signed by leading AI figures — including Nobel laureate Demis Hassabis, OpenAI CEO Sam Altman, and Anthropic CEO Dario Amodei — along with prominent experts in the life sciences and national security, warned that AI systems can already outperform Ph.D.-level virologists on some highly technical laboratory questions. The signatories acknowledged that evidence regarding the immediate biosecurity threat remains mixed. But they also warned that AI could progressively erode the technical knowledge barriers that have historically constrained terrorists and other bad actors.
For terrorists, that is troubling. Someone lacking years of specialist training may increasingly be able to obtain from an AI system sophisticated biological knowledge that once required considerable expertise to acquire.
But the state threat may be even more consequential.
An April 2026 RAND study, based on workshops with more than 50 experts in artificial intelligence and CBRN defense, warns that advanced AI could enable more sophisticated capabilities for both state and non-state actors. It also cautions that state-based threats remain underappreciated even as catastrophic non-state scenarios draw most of the attention. Its experts concluded that AI could lower technical barriers and accelerate development across the pathway from biological research to operational capability.
A terrorist starts with limited money, expertise, and infrastructure. A hostile government may already possess trained scientists, secure laboratories, genomic databases, synthesis equipment, intelligence services, and military delivery expertise. Artificial intelligence does not need to create that machinery. It only needs to make an existing program faster, cheaper, more capable, or harder to detect.
I have watched this danger develop across my recent books on artificial intelligence. In “AI for Mankind’s Future,” I warned that AI could place sophisticated biological knowledge within reach of people lacking specialist training. In “The New AI Cold War,” I described AI-assisted biological design challenging traditional DNA-synthesis screening. The latest research appears to mark another step: from biological information, to biological design, to complete viral genomes that function in the laboratory.
The answer is not to stop this research. The same technology that raises the threat could also strengthen our defenses. RAND points to AI-assisted biosurveillance, faster vaccine and medical-countermeasure development, better detection, and improvements in forensics and attribution.
But Washington should act while useful chokepoints still exist.
Congress should require screening and recordkeeping for synthetic nucleic-acid orders, verification of customers, and appropriate safeguards for equipment capable of producing those sequences. Digital biological designs eventually have to become physical material, making synthesis one of the clearest places to detect suspicious activity. Those safeguards already have unusually broad backing from leaders in AI, biotechnology, biosecurity, and national security.
Government must distinguish among lone actors, terrorist organizations, less-capable states, and sophisticated state programs rather than treating “AI bio-risk” as one problem. And the people building frontier models need sustained, secure relationships with intelligence, counterterrorism, and biodefense professionals who understand weapons-of-mass-destruction pathways. RAND identifies precisely those institutional gaps.
Finally, America should race to secure the defender’s advantage — using AI to detect outbreaks earlier, develop countermeasures faster, improve attribution, and make biological attacks more difficult, less effective, and less deniable.
For Christians, there is another issue. Scientific knowledge is not evil, and technology that saves lives should be welcomed. But possessing the power to do something has never meant mankind ought to do it. Scripture warns that “whatever one sows, that will he also reap” (Galatians 6:7, ESV) — and no laboratory result exempts a researcher, a company, or a nation from that reckoning.
A machine may design. Man must still answer for what is built.
In that Swiss castle nearly three decades ago, biological warfare seemed to belong to a frightening world of secret laboratories, governments, and highly trained specialists. That world has not disappeared. What is changing is the technology available to those who would enter it.
Artificial intelligence has not made biological weapons easy. But it may be weakening barriers that once made them extraordinarily difficult.
The time to strengthen those barriers is before today’s biological breakthrough can be turned into tomorrow’s weapon.


