Anyone who has seen I Am Legend knows what happens when humans try to play God with a virus.

In the film, a genetically engineered measles virus is introduced as a cure for cancer. It is elegant, revolutionary and celebrated as a triumph of human ingenuity. Then it mutates, escapes its intended purpose and remakes the world.

That is fiction. It is also an unusually effective illustration of a principle that extends well beyond Hollywood: Biological systems do not care what their creators intended. They respond to what humans actually build, release and fail to anticipate.

That distinction is worth considering now that researchers at Stanford University and the Arc Institute have used artificial intelligence to design complete viral genomes that do not exist in nature.

To be clear, the researchers did not create a virus that infects humans. They produced bacteriophages—viruses that infect bacteria—and tested them against nonpathogenic strains of E. coli. The models were deliberately trained without eukaryotic viruses, including those known to infect humans, animals and plants. The experiments were conducted under containment protocols, and the resulting phages retained a narrow bacterial host range.

Those facts matter. So does the legitimate medical promise behind the work.

Bacteriophages may provide new ways to treat infections that no longer respond to antibiotics. In the published preprint, researchers used the genomic language models Evo 1 and Evo 2 to generate thousands of possible viral genomes. They selected and tested 285 designs, 16 of which became functioning phages capable of propagating and inhibiting bacterial growth. Some combinations were able to overcome bacterial resistance that defeated the natural virus used as the experiment’s template.

That is an extraordinary scientific achievement.

It is also the kind of achievement that should make us stop—not because these 16 phages are poised to cause a pandemic, but because the experiment proves something far more consequential than the individual organisms it produced.

AI can now design a complete, functional viral genome.

The question is no longer theoretical.

The experiment is not the entire risk

The most obvious response to concern about this research is that bacteriophages do not infect people. That is true. It is also an answer to the narrowest possible version of the question.

The larger issue is not what these particular viruses can do. It is what the validated capability can eventually be adapted to do.

The researchers did more than generate unusual strings of DNA. They demonstrated a working process for teaching an AI system to coordinate genes, regulatory elements, host specificity, replication and evolutionary fitness across an entire genome. The system produced organisms containing mutations and combinations that had not previously been observed in nature.

In other words, this was not merely an AI suggesting a new molecule or predicting how an existing protein might behave. It was an AI proposing the complete genetic instructions for a replicating biological entity—and those instructions worked.

Arc Institute describes the progression as moving from reading genomes, to writing them, to designing them. Its own account of the research identifies larger and more complex genomes as a future direction for the technology.

That progression deserves far more public scrutiny than it has received.

A safe demonstration does not prove that the underlying capability will remain confined to safe applications. It proves that the capability exists.

There is a fundamental difference between saying, “We built a harmless version,” and saying, “This technology is structurally incapable of producing a harmful one.”

We currently have the first.

Excluding dangerous data is a precaution, not a governance system

The researchers took meaningful safety measures. Evo 2 excluded eukaryotic viruses from its training data, and testing indicated that those exclusions weakened the model’s performance on pathogenic viral proteins. The experiments used nonpathogenic bacterial hosts and specialized containment and disposal procedures.

Those were responsible choices.

They were still choices made by the developers.

Training-data exclusions are not laws. They are not international standards. They do not bind the next research team, a commercial competitor, a government laboratory or an individual who decides that safety restrictions are an obstacle rather than a feature.

They also do not resolve the long-term problem created when biological AI systems become more capable, easier to operate and less expensive to modify.

Evo 2 is a fully open biological model. In a March 2026 update, Arc Institute reported broad distribution through GitHub, Hugging Face and its application programming interfaces. The institute presented that reach as evidence of open and collaborative science. It is. It is also evidence that the capability cannot be governed solely through the judgment of the people who originally built it.

Open science has produced immense public benefit. But many of its norms were built for a world in which specialized knowledge, expensive equipment and years of training placed natural limits on who could reproduce complex biological work.

AI changes that equation.

It compresses expertise. It accelerates iteration. It converts bodies of scientific literature into operational assistance. It allows a person to explore thousands of biological possibilities at a speed that no unaided researcher could match.

The same quality that makes these systems scientifically powerful—their ability to discover patterns humans cannot easily see—also makes their outputs more difficult to anticipate and independently evaluate.

A safeguard based primarily on everyone continuing to make responsible choices is not a safeguard. It is a hope.

And hope, particularly where self-replicating biology is concerned, is not a containment strategy.

Biology is not software

Silicon Valley has spent decades normalizing a development model built around rapid release, user testing and continuous correction.

Ship the product. Find the failure. Patch the system.

That philosophy is already questionable when software governs transportation, finance, health care or critical infrastructure. Applied uncritically to synthetic biology, it becomes indefensible.

Software can often be deactivated. A defective model can be taken offline. Access credentials can be revoked. Servers can be isolated. An update can be rolled back.

Biology is not always so cooperative.

Biological systems reproduce. They mutate. They interact with environments that cannot be fully modeled in advance. They encounter other organisms and evolutionary pressures outside the controlled conditions in which they were designed.

Again, the phages created in this study were narrowly targeted and posed no identified danger to human health. The concern is the precedent established by importing the technology industry’s capability-first culture into a field where some mistakes cannot simply be patched after deployment.

The researchers themselves acknowledged that whole-genome generation creates serious biosafety, biocontainment and biosecurity questions. Their safety work is meaningful. But the order of operations remains backward.

We should not develop the ability first, distribute it second and begin discussing enforceable safeguards third.

The medical promise does not end the debate

None of this means phage research should stop.

Antimicrobial resistance is a genuine global health threat. Bacteriophages can target specific bacteria while leaving other organisms intact, making them a potentially valuable complement or alternative to conventional antibiotics. AI could help researchers design therapies for infections that are currently difficult or impossible to treat.

But the existence of a valuable use does not eliminate the need to govern the broader capability.

Nuclear physics gave us cancer treatments and nuclear weapons. Chemistry produces fertilizer and nerve agents. Cybersecurity research can defend critical systems or expose them. Dual-use technologies do not become single-use technologies simply because their inventors have admirable goals.

That is the part of the conversation that tends to disappear beneath the language of progress.

Researchers understandably focus on the disease they may cure, the resistant bacteria they may defeat or the discovery they may accelerate. Those benefits are concrete, immediate and professionally rewarded.

The risks are distributed. They may emerge years later, through another institution, in another country, using a model that did not preserve the original team’s restrictions. The people exposed to those risks did not consent to them, and the institutions creating the capability may not bear most of the consequences.

That asymmetry requires a higher standard than “the current experiment was safe.”

It requires asking whether society has the systems to keep future experiments safe.

At present, the honest answer is no.

Control must become part of the technology

Real governance would not mean banning biological AI or treating every genomic researcher as a potential threat.

It would mean recognizing that models capable of whole-genome design belong in a different risk category from ordinary research software.

Before more capable systems are trained or released, they should undergo independent risk-benefit review by experts who are not employed by the institutions building them. Any future models capable of assisting with pathogen design should use tiered access rather than unrestricted distribution. DNA-synthesis providers should be required to screen customers and sequences, including fragmented orders and AI-generated designs intended to evade conventional matching systems.

High-risk whole-genome research should be registered, monitored and subjected to enforceable containment standards. Governments should establish international reporting requirements before laboratories begin competing to produce increasingly complex organisms. Developers should also be required to invest in detection, medical countermeasures and response systems in proportion to the new capabilities they create.

Most importantly, responsibility cannot end when model weights or research findings are released.

The institutions building biological design systems should retain meaningful obligations for how those systems are distributed, adapted and secured. Otherwise, the benefits remain private while the most serious risks are handed to the public.

This is not an argument against scientific progress.

It is an argument about sequence.

Governance should precede proliferation. Containment should precede capability demonstrations. Public accountability should precede the normalization of technologies whose failures could affect people far beyond the laboratory that created them.

Intent is not control

The lesson of I Am Legend is not that scientists should stop trying to cure cancer.

It is that benevolent intent is not the same thing as control.

The scientists behind this work are not cinematic villains recklessly manufacturing a human plague. They appear to have taken the immediate safety of their experiment seriously, and the potential medical value of their research is substantial.

But history is full of technologies whose ultimate consequences were not determined by the character or intentions of their original inventors.

Once a capability has been demonstrated, it cannot be undiscovered. Once it has been distributed, control becomes exponentially more difficult. And once biological design is accelerated by systems that can operate beyond ordinary human speed and comprehension, the margin for institutional complacency becomes very small.

We should be able to hold two ideas at once: This research may help save lives, and the path it opens may create risks that its creators cannot fully control.

That is not fearmongering. It is the minimum level of seriousness warranted when artificial intelligence begins writing functioning genomes.

Human intelligence should not be measured only by what we are capable of building.

It should also be measured by whether we are wise enough to establish the rules before we build it.