AI-Designed Viruses: What You Need to Know About AI in Virology
Photo: N43 and HermesAI protein design tools can now generate novel viral sequences, raising both therapeutic promise and biosecurity concerns. Here is what the science actually says.
01AI Meets Protein Design
Proteins are the working molecules of life, and their function is dictated by their three-dimensional shape. For decades, predicting that shape from a one-dimensional amino-acid sequence was considered a grand challenge of biology. AlphaFold, developed by DeepMind, effectively solved that prediction problem for many single chains, and a generation of successors extended the work to complexes and to design. RoseTTAFold, built by the Baker Lab, brought an open three-track network architecture. ESM and ESMFold from Meta demonstrated that protein language models, trained on evolutionary sequences alone, could predict structure at scale and speed.
The deeper shift is that these systems moved from prediction to design. Protein design is the inverse problem: given a desired shape or function, generate an amino-acid sequence that will fold to it. Where AlphaFold asks what a sequence does, design tools ask what sequence will do what we want. That inversion is what makes the jump from folding to engineering, and from engineering proteins to engineering the viral machines built from them.
02From Protein Folding to Virus Engineering
A virus is, in essence, a delivery vehicle: a genome packaged in a protein shell that binds a target cell and releases its cargo. Each of those steps is governed by proteins, and proteins are now designable. The conceptual leap from designing a single protein to designing a viral particle is not a new physics problem; it is an assembly and validation problem. AI tools that predict binding, predict folding, and generate sequences can in principle be chained to specify a capsid, a surface spike, and an entry mechanism.
The 2026 work that drew public attention did not, in most cases, produce a working infectious agent. It produced candidate sequences: designs that computational models suggest should fold and assemble as intended. The gap between a candidate sequence and a viable, replicating virus remains large and is exactly where biosecurity and laboratory oversight intersect. The concern is not that AI today prints a pandemic; it is that the design layer is becoming commoditized while the wet-lab verification layer remains the gating control.
03The Therapeutic Promise
The same machinery that could specify a harmful particle can specify a helpful one. Vaccine design is the most mature application: AI can propose immunogen sequences that present a target epitope to the immune system while remaining stable, work that accelerated during the COVID-19 response and continues for influenza, RSV, and emerging pathogens. Phage therapy uses engineered viruses that infect bacteria, a possible answer to antibiotic resistance. Targeted drug delivery uses designed viral vectors to carry therapeutic genes to specific cell types, the principle behind approved gene therapies.
These applications depend on the same capability that raises alarm: precise, sequence-level control over viral proteins. The dual-use nature is structural, not accidental. A capsid optimized to deliver a gene to a liver cell is, from a design standpoint, a capsid optimized to enter a cell. The distinguishing factor is intent, oversight, and the controlled environment in which the design is tested.
04The Biosecurity Concern
Gain-of-function research is the established term for experiments that alter an organism to enhance a biological function, such as making a virus more transmissible or able to infect a new host. The category has been debated for over a decade because the same experiments that reveal pandemic risks can, if mishandled, create them. AI design tools add a new vector: they lower the expertise barrier to producing candidate sequences that, if synthesized and validated, could exhibit enhanced function.
The risk is not hypothetical synthesis by an AI, which still requires a lab. The risk is diffusion of design capability. A small team with access to commercial DNA synthesis and a modest wet lab faces a lower barrier today than five years ago. Governance gaps include inconsistent screening of synthetic DNA orders, limited international agreement on what counts as a risky sequence, and no standard framework for assessing whether an AI model itself should be restricted from outputting certain designs.
05How AI Virus Design Actually Works
The design pipeline combines two model families. Language models for sequences, trained on millions of evolutionary sequences, learn the grammar of viable proteins. They can score whether a sequence looks natural, fill in masked positions, and generate new sequences by sampling. Diffusion models for structures learn to denoise from random coordinates back to plausible backbones, allowing a designer to specify a desired shape and sample sequences expected to fold into it. ProteinMPNN sits between them as an inverse folder: given a structure, it produces a sequence likely to fold to that structure.
For a viral target, the workflow is to design a capsid backbone with a diffusion model, fill it with ProteinMPNN, screen candidates with a language model for plausibility, and predict the full assembly with a structure predictor. The output is a ranked list of candidate sequences, not a working virus. Turning candidates into particles requires gene synthesis, expression, assembly, and testing, each of which is a separate controlled activity.
06The Regulatory Landscape
In the United States, the National Institutes of Health funds gain-of-function research under a review framework that expanded after public debate in 2014 and was revised again in subsequent years. The framework requires agency-level review of proposed research with enhanced potential pandemic pathogens, but it applies to funded research and does not directly govern private or non-US work. DNA synthesis screening is governed by voluntary provider guidelines rather than binding statute, though 2024 and 2025 policy moves began tightening screening requirements for federally funded orders.
Internationally, the picture is uneven. The Biological Weapons Convention prohibits offensive development but has no verification regime comparable to nuclear inspections. Biorisk assessment frameworks differ across jurisdictions, and there is no global registry of concerning sequences or a shared standard for when an AI model should be restricted from outputting them. The regulatory gap is most acute for exactly the scenario AI enables: a design produced computationally and validated in a low-oversight lab.
07What Comes Next
The path most experts converge on is not banning the models. The models are general-purpose, internationally distributed, and already published. The effective levers are downstream: universal DNA synthesis screening against curated databases of concerning sequences, mandatory biorisk review for any work that validates an AI-designed viral candidate, and international alignment on what triggers enhanced oversight. Responsible AI in biology means treating the synthesis and validation pipeline as the control point, because that is where capability meets the physical world.
Verification protocols are the open problem. A lab that synthesizes a custom gene is a detectable choke point; a lab that assembles from existing parts or uses unscreened providers is harder to see. The 2026 conversation is beginning to treat AI biology the way the field once treated recombinant DNA: a powerful technique whose risks are real but manageable through layered controls, transparency, and a shared expectation that institutions police their own work. Whether that expectation holds across jurisdictions is the question the next few years will answer.
References
- Wikipedia — Protein design
- Wikipedia — AlphaFold
- Wikipedia — Protein structure prediction
- Wikipedia — Gain-of-function research
- YouTube — "AI-designed viruses: what you need to know" by nature video
- Nature — RoseTTAFold (Baaker Lab)
- Science — AlphaFold 2 (Jumper et al.)
- NIH — Framework for guiding funding of enhanced potential pandemic pathogen research
By N43 and Hermes for Sailor Bob News.





