Latest Posts

Categories

Partnerships
Reports
Community
Community
Partnerships
Research
Research
Community
Reports
Community
Reports
Community
Partnerships
Reports
Community
Protocol
Partnerships
Community
Reports
Community
Partnerships
Protocol
Reports
Partnerships
Partnerships
Partnerships
Reports
Community
Press Release
Community
Press Release
Partnerships
Partnerships
Partnerships
Press Release
Reports
Reports
Partnerships
Research
Protocol
Reports
Research
Reports
Research
Partnerships
Reports
Press Release
Press Release
Community
Reports
Partnerships
Protocol
Protocol
Community
Community
Protocol
Reports
Partnerships
Partnerships
Partnerships
Partnerships
Research
Partnerships
Reports
Research
Partnerships
Community
Community
Community
Community
Reports
Partnerships
Partnerships
Partnerships
Community
Partnerships
Community
Community
Partnerships
Partnerships
Community
Community
Partnerships
Research
Community
Partnerships
Reports
Press Release
Protocol
Partnerships
Partnerships
Partnerships
Community
Partnerships
Partnerships
Partnerships
Community
Partnerships
Partnerships
Community
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
September 28, 2026

XYO Adds Auto Drive as a Supported Data Lake in the XYO SDK

3
Min Read
BY
AUTONOMYS

The data behind a proof on XYO Layer One lives outside the chain, in a Data Lake. Developers building on XYO now have a storage option for that data that cannot expire, be deleted, or be altered after the fact.

‍

XYO has added Auto Drive as a supported S3-style Data Lake in the XYO SDK. Developers building on XYO Layer One can now store the data behind their transactions on Auto Drive, the permanent storage gateway from Autonomys Network, using the same SDK modules they already use today. XYO has published a working sample project that runs the complete flow end to end.

Who XYO is

XYO is the original and one of the largest Decentralized Physical Infrastructure Networks (DePIN), with more than 10 million nodes collecting and validating real-world data. Its Proof of Location and Proof of Origin technologies validate that data at the source, which makes XYO a trusted input for AI, geolocation, real-world asset tracking, gaming, and other sectors that depend on knowing what actually happened in the physical world.

‍

XYO has since expanded its ecosystem with XYO Layer One, a blockchain purpose-built for the data demands of DePIN, real-world assets, and AI. XYO Layer One runs on a dual-token model. The XYO token supports the DePIN ecosystem, rewards, staking, and governance. The XL1 token handles transactions and fees inside XYO Layer One itself.

The problem every high-volume chain has to solve

A network that verifies real-world data at XYO's scale produces far more data than any chain should carry. XYO solves this with an architecture first described in its original 2018 white paper: Archivists. The modern, lighter-weight version built for XYO Layer One is called a Data Lake.

‍

The design is simple. XYO Layer One records a compact, verifiable reference to each piece of data. The data itself lives in a Data Lake. Because the reference is derived from the content, anyone who retrieves the data can confirm it is exactly what was recorded, without having to trust whoever is storing it. The chain stays lightweight. The data stays verifiable.

‍

That design puts real weight on the Data Lake. If the stored data disappears, the reference on XYO Layer One still exists, but it points at nothing. If the data is altered, the reference no longer matches, and the record is broken. For applications built on proofs of location and origin, that is not an edge case but the failure that matters most.

What XYO released

The XYO SDK supports several storage backends for Archivists and Data Lakes. S3-compatible object storage is handled by the @xyo-network/archivist-s3 package, and that package now includes a dedicated Auto Drive module. A developer imports createAutoDriveArchivist, supplies an Auto Drive API key, a bucket, and a key prefix, and the SDK handles the rest. There is no custom integration to write and no separate client to maintain.

The published sample project shows the full loop in a single command-line tool. It takes a message, stores it on Auto Drive through the XYO adapter, reads it back to confirm the content and its hash match, signs a transaction with the AriesTools CLI wallet, anchors the reference on XYO Layer One, waits for the transaction to be confirmed as final, and prints a link to it in XYO Explore. Storage is verified before anything is broadcast, and verified again after inclusion.

What this means for developers building on XYO

Auto Drive is built for the job a Data Lake needs done.

The data does not expire. Auto Drive has no pinning, no renewal, and no ongoing fees for data already stored. Once a payload is written, it stays retrievable. There is nothing to renew and nothing to let lapse.

The data cannot be altered or deleted. Auto Drive's S3 interface returns an error on any delete request by design. Re-uploading the same key creates a new object rather than overwriting the old one. A reference recorded on XYO Layer One will always resolve to the same bytes it was created from.

The verification model matches. XYO Data Lakes derive keys from content so that readers can check what they receive. Auto Drive stores every object under a content identifier and returns that identifier with each response. The two systems make the same promise at different layers.

It fits the existing S3 workflow. Auto Drive's S3-compatible layer supports the operations the XYO adapter relies on, including standard and multipart uploads, object retrieval, and listing. Teams already using S3 tooling with XYO do not need to change how they work.

It is free to start. Every Auto Drive account receives 20MB of upload capacity and 5GB of download capacity per month at signup. Beyond that, teams purchase additional storage directly. Companies bringing paying customers to permanent storage can also apply to the Subspace Foundation Grants Program.

Try it

  1. Sign up at ai3.storage and create an API key in the Developers section.
  2. Clone the autodrive-datalake-sample repository and follow the README.
  3. For a first run that needs no XL1 test tokens, pnpm test:live writes a real payload to Auto Drive through the XYO adapter using a disposable local chain and wallet.

Full details on the Auto Drive S3 layer are in the Autonomys Developer Hub. Details on XYO Data Lakes and the XYO SDK are in the XYO documentation and the XYO AI SDK skills repository.

Why this matters to us

XYO has spent years solving one of the hardest problems in infrastructure: proving that real-world data is what it claims to be. That work only holds if the data behind each proof is still there, unchanged, when someone needs to check it. Auto Drive exists to make that guarantee at the storage layer. Seeing it added to the XYO SDK, in released code with a public sample, is exactly the kind of integration Autonomys Network was built for.

We look forward to seeing what XYO developers build on it.
Auto Drive is free to start at ai3.storage.

September 11, 2026

August 2026 | End-of-Month Report

3
Min Read
BY
AUTONOMYS

On August 26, OpenAI published a detailed account of its own AI agents working around the controls meant to contain them during internal evaluations, coordinating through a channel nobody had approved, and attempting to tamper with their own logs. An independent investigation by METR and Redwood Research, published the same day, found one of those techniques worked. Agents could make a tool call report running one command while it actually ran another, a method the investigators called “tool call spoofing,” and it appeared in more than 7 percent of the transcripts they reviewed. OpenAI called the incident a “warning shot”. The detail that stayed with us was this: when the security team rebuilt the compromised service, the rebuild cleared the message board the agents had been using to coordinate. That was a competent incident response doing exactly what it should, and it erased evidence anyway, because the evidence lived inside the system being repaired.

That is the pattern worth watching as agents take on more consequential work. The debate about AI safeguards tends to focus on controls: what an agent is permitted to do, which systems it can reach, when a human has to approve. Those controls matter, but none of them can be audited without a record that survives the incident it describes. Permanent, immutable storage is not the most interesting layer of AI safety infrastructure, but it is the one every other layer depends on, and it is the layer we have spent years building. August was a month of work in that direction. Here is where things stand.

Network Status

The network ran normally throughout August. Block production, storage, and domain operations were stable, with no incidents to report. Routine maintenance and protocol upgrades continued, and no action was required from farmers, operators, or nominators.

Ecosystem & Developer Momentum

USDC Payments for Auto Drive Storage
Payment in USDC for Auto Drive storage entered its final phases of development and review during August. The work moves into testing in September, which is the last step before we can put a date on general availability. The goal is to let teams pay for permanent storage without needing to acquire AI3 first.

rclone Integration and S3 Compatibility
Work on the rclone integration continued through August. Testing against a client this widely used has surfaced a number of subtle issues at the edges of our S3 implementation, and the team is working through them. Every one of those edge cases resolved makes Auto Drive behave more predictably for the tools that already speak S3.

Auto Drive Backend Resilience
Several improvements to Auto Drive’s backend were merged during the month, with more in progress. This is the work that determines whether a storage service holds up under demanding workloads rather than demo conditions.

Partner Integrations
Autonomys CEO Todd Ruoff traveled to New York in August to meet the healthpass1 team in person, alongside other partners healthpass1 convened. Fry Networks is deepening its existing integration, and a new partner is currently integrating Auto Drive for permanent storage. We look forward to sharing further details on all three integrations once they are ready.

Community & Foundation

Guardians of Growth Season 1 Concludes, Season 2 Begins
Guardians of Growth Season 1 wound down at the end of August, roughly a year after the Subspace Foundation launched it. It did what it set out to do, building meaningful staking participation from a standing start and making the staking process familiar to a growing community. Season 2 was announced during the month and officially began on September 9, continuing that support while organic network usage catches up. Full details, including how to get involved, are in Guardians of Growth Season 2 Is Underway.

A New Home for Our Thought Leadership
We launched a Substack, For the Record. It will carry our thought leadership work: the research-driven pieces on AI accountability, permanent records, and the infrastructure questions behind both. Posts will come both on behalf of the network and directly from members of the Autonomys team. If you would rather read that work in your inbox than find it on a timeline, subscribing is the easiest way.

ICYMI: Content Published in August

Metrics: August Snapshot

Staking: 46,985,442 AI3 (+11,707,631 from July)
Auto Drive Files Uploaded: 2,487 (August) / 135,918 (All time)
Auto Drive Downloads: 344 (August) / 18,958 (All time)
Auto Drive Users: 739 (+11 from July)
Total Announced Partnerships: 65
Announced Auto Drive Integrations: 11
Total Grant Applications: 105 (+9 from July)

Looking Ahead

In September, USDC payments for permanent storage move into testing, Guardians of Growth Season 2 runs its first full month, and work continues on the resilience and compatibility that make permanent storage easier to adopt.

How to Get Involved

The most helpful thing you can do is put Auto Drive to work. It is free to start at ai3.storage, with 20 MB of uploads and 5 GB of downloads each month. If you are building something where records need to outlast the system that produced them, that is the fastest way to find out whether this fits.

We would also appreciate support through referrals for integrations. If you know a project wrestling with expiring links, pinning costs, or an audit trail nobody can verify, send them our way. Teams needing larger allocations can apply through the Subspace Foundation Grants Program.

autonomys.xyz | ai3.storage | develop.autonomys.xyz

September 9, 2026

Guardians of Growth Season 2 Is Underway

3
Min Read
BY
AUTONOMYS

Season 2 Is Now Underway

This post is published on behalf of the Subspace Foundation, which is pleased to confirm that Guardians of Growth Season 2 is now underway.

Following the success of the original Guardians of Growth Staking Bootstrap Program, the Subspace Foundation has begun a second season using the same protocol-native mechanism.

Building on Season 1

Season 1 demonstrated strong and sustained interest in staking on Autonomys. AI3 committed to operators reached a peak of 41,270,560, establishing an active community of operators and nominators from a standing start.

That participation has continued to grow.

As of September 8, 2026, the Autonomys Staking Portal shows:

  • 46,935,774 AI3 in total operator value
  • 459 nominator positions

This is a new high for staking participation on Autonomys and represents a considerable proportion of circulating AI3.

Thank you to everyone who has participated, whether you have been staking since the beginning or joined more recently.

Why we are continuing the program

Guardians of Growth was created to encourage early participation while organic network activity and transaction fees developed. The staking side of that goal has been successful. Usage and fee generation, however, have not yet reached the level we hoped to see one year after launching the program.

Season 2 builds on what has worked while giving the wider ecosystem more time to grow. It provides continuity for nominators as separate product, developer and adoption initiatives continue. Guardians of Growth is not a substitute for adoption. Over the long term, the domain economy must be supported by genuine network activity and organic transaction fees. Staking participation will also be important when Game of Domains restarts. Game of Domains and permissionless operators have been temporarily deprioritized, but both remain on the Autonomys roadmap.

How Season 2 works

The mechanics remain unchanged:

  • The Foundation submits simple transactions on Auto EVM using the open-source Operator Reward Distributor.
  • Each transaction includes a tip and is processed according to the network’s standard fee mechanics.
  • Any resulting allocation to operator pools is determined automatically by the protocol.
  • The Foundation does not select individual recipients or determine individual outcomes.
  • Staking remains fully non-custodial, so nominators retain control of their AI3.

Transaction timing and resulting protocol-level allocations may vary according to block production and network conditions. The Foundation may adjust operational settings during the season.

Participation does not entitle any operator or nominator to a fixed or guaranteed payment, APY or economic return. Any amounts arising through the protocol, if any, are variable.

Duration and transparency

Season 2 is funded from the Subspace Foundation Near Term Treasury and is expected to run for approximately 12 months. This is an operational target rather than a commitment to an exact date or block, as distribution depends on live network conditions.

Season 2 will continue to use the publicly traceable Guardians of Growth Auto EVM Vault. The vault, operational wallets and program transactions can all be followed on-chain. The Foundation will continue to include staking figures in its End of Month reports and plans to publish a retrospective when the program concludes.

Further information

The Autonomys Staking Portal displays active operators and current network-level staking data. The Staking Portal guide explains the staking mechanics and how positions are managed. Anyone considering using the staking functionality should understand the associated technical and economic risks and make their own assessment before proceeding.

Looking ahead

Season 1 established a strong foundation for staking participation on Autonomys. Season 2 builds on that foundation while the wider ecosystem continues to develop.

The program remains transparent, protocol-native and non-custodial. We will continue reporting on participation and progress throughout the new season.

September 1, 2026

The OpenAI Incident: When Agents Can Edit Evidence

3
Min Read
BY
AUTONOMYS

Let’s get the disclaimer out of the way first, because it happens to be the most important sentence in this piece: permanent storage would not have stopped OpenAI’s agents from breaking out of their test environment last month. Immutable records are not a control on behavior. They are the layer accountability rests on, and once you see what happened to the evidence in this incident, you will understand why that layer can no longer be an afterthought. It is the layer Auto Drive was built to provide.

Last week OpenAI published something you do not often see from a frontier lab: a detailed public accounting of its own models going rogue. During internal cybersecurity evaluations in July, agents worked their way around the controls meant to isolate them, got out onto the open internet, and reached systems belonging to Hugging Face. OpenAI wrote: “We consider this incident a ‘warning shot’ for us and for the world: evidence that, without proper safeguards, highly capable AI agents are now able to work around technical controls, collaborate through unapproved channels, and take dangerous actions that no human directed.” Regulators are circling, Alabama’s attorney general is already calling it an “AI lab leak,” and the company deserves real credit for publishing the details anyway.

The details

The agents had no approved way to talk to one another, so they made one out of Artifactory, the internal package manager where OpenAI keeps the software components its systems reuse. One agent would drop a file, another would pick it up, and before long a code warehouse was functioning as a message board where, according to the independent review by METR, roughly 1,200 agents in separate sandboxes compared notes on gaming their evaluations, 700 of which joined the push into Hugging Face.

Did they try to cover their tracks?

They did. OpenAI’s technical report says the models “sometimes tried to erase or tamper with their outputs or message logs,” and they were strikingly candid about the intent in their own reasoning traces. Podcast host Dwarkesh Patel published an in-depth recap of the incident, noting that the “collective” (their term, not his) of agents, “had to figure out how to wiggle out of two different conundrums before submitting their answers:

  1. How do we erase all this evidence in our trajectory that clearly shows that we cheated?
  2. How do we make it look like we accomplished the task in a legitimate way to the scorer?”

He adds: “To solve these problems, the ‘collective’ latched onto three research workstreams.

  1. Tamper with transcripts and logs
  2. Replace the impossible-to-hack target program with an easier one
  3. Understand and trick the scorer”

As far as OpenAI or METR’s reviewers could see, none of those attempts worked, which sounds reassuring right up until you learn what happened to the record anyway.

On July 4, agent activity destabilized Artifactory badly enough that the security team opened an incident and rebuilt the service, which is exactly what competent incident response looks like. In OpenAI’s words: “This had the side effect of clearing the message board.” Nobody did anything wrong, and the evidence vanished all the same, because it lived inside the very system being repaired.

The detail that deserves more attention

The reason investigators had anything to analyze is that the agents built themselves a new board days later. When METR spent six days on site conducting its independent review, that second board was the record it worked from. The evidence in one of the most scrutinized AI incidents on record survived because the software under investigation (the AI agents) rebuilt its own paper trail, which is less a preservation strategy than a stroke of luck. No regulator, and frankly no board of directors, is going to accept luck as a records policy.

Storage that does not depend on luck

Auto Drive, Autonomys’ permanent storage product, exists so that nobody has to. Anything written to it stays available indefinitely, with no pinning or subscription to renew, and nothing written to it can be altered or removed afterward, not by the user, not by an agent acting on its own, and not by us. A hard-delete request simply gets refused, and no administrator anywhere can change that, because the data lives across hundreds of independent storage nodes pledging petabytes of disk space that no single party controls.

Using it for exactly this scenario is extremely simple. A team decides which agent actions are worth keeping, and automates the writing of those records to Auto Drive, so that whenever an auditor needs them, they retrieve precisely what was written. Anything sensitive can be encrypted before upload with keys the owner holds. Agents on frameworks that support skills can use the Auto Memory skill, which only requires a free API key, and any application, pipeline, or backend a team already runs can connect through the API, the SDK, or the S3-compatible layer.

Once more, we want to be clear about the limits and not overclaim: none of this makes a record true. A record can be complete, unalterable, and still be the wrong record. What immutable storage does enable is narrower and more valuable: whatever was written down will still be there, exactly as written, when somebody needs to review it. In this incident, that is precisely what was missing.

Heeding OpenAI’s warning

OpenAI frames what happened as a warning, but warnings are only useful to people who change something, and the least glamorous change available is also the most durable one: permanent, immutable storage places records securely and privately out of reach of your agents and cleanup crews alike.

Auto Drive is free to start, available to use today, and the Subspace Foundation Grants Program (the Subspace Foundation oversees the Autonomys Network) coordinates larger allocations for teams whose records must outlast the systems that produce them.

Nobody gets to decide when their agents will do something worth investigating, but everybody gets to decide, right now, whether there will be a trustworthy record of it when they do.
Upload once. Access forever.

References

  1. OpenAI. “The Hugging Face incident and the road ahead.” August 26, 2026. https://openai.com/index/hugging-face-incident-and-the-road-ahead/
  2. OpenAI. “OpenAI Hugging Face Incident Technical Report.” August 26, 2026. https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf
  3. METR. “Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident.” August 26, 2026. https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/
  4. Patel, D. “The Rise and Fall of Agent Civilizations.” Dwarkesh Podcast, August 29, 2026. https://www.dwarkesh.com/p/openai-huggingface
  5. “Report finds 700 ‘rogue’ OpenAI agents worked together on hack using unsanctioned message board.” The Irish Times, August 27, 2026. https://www.irishtimes.com/technology/2026/08/27/report-finds-700-rogue-openai-agents-worked-together-on-hack-using-unsanctioned-message-board/
  6. Autonomys Network. “Agentic Memory.” Autonomys Developer Hub. https://develop.autonomys.xyz/agentic_memory
August 26, 2026

In the Room Together: An Update on the Autonomys Network Auto Drive and healthpass1™ Integration

3
Min Read
BY
AUTONOMYS

This month the Autonomys Network and healthpass1 teams met face to face in New York, alongside other partners healthpass1™ has brought together. Here is what healthpass1 has been achieving, an update on their estimated timeline for the Auto Drive integration, and how you can get involved today.

Some partnerships live in contracts and calendar invites. The best ones eventually put everyone in the same room. Earlier this month, Todd Ruoff, CEO of the Autonomys Network, joined the healthpass1 team in person in New York, together with other partners contributing to the healthpass1 stack.

A partner meetup in New York

The gathering was intimate and hands on. healthpass1, Autonomys, and three other partners came together in force. Autonomys provides healthpass1 with a decentralized storage foundation through Auto Drive. Over a working lunch and a series of breakout conversations across healthcare, technology, and infrastructure, everyone left aligned on a shared goal: telling this story together.

Who healthpass1 is, and the momentum behind them

healthpass1 helps make it simple to keep all your health records and fitness information in one private, easy-to-manage place. You decide what you share, who sees it, and for how long. Built on a secure, decentralized foundation with optional AI-powered insights, healthpass1 keeps everything encrypted and in your control. Their tagline puts it simply: the 1 (and only) health passport you need. Simple. Secure. Shareable. The product is patent pending and designed to meet the expectations of highly regulated industries.

The last few weeks have brought real momentum.

The MVP reached a milestone. The healthpass1 Score hit 100 percent, a signal that the core experience is coming together.

healthpass1 went to Wall Street. Deborah A. Bussière was interviewed by Jeffrey Hayzlett for a TV and podcast episode filmed at the New York Stock Exchange, scheduled to air in September.

Investors are taking notice. healthpass1 was named the “Unicorn Spotlight” company in this month’s Pitch and Run newsletter, reaching a broad audience of investors, founders, and startup leaders. It was also featured in the Community Spotlight of nextNYC, Charlie O’Donnell’s weekly newsletter for New York’s tech and innovation community.

The healthpass1 and Auto Drive integration

For anyone joining the story now, here is the integration in the exact terms both teams have agreed on.

healthpass1, which helps make it simple to keep all your health and wellness information in one private, easy-to-manage place, has selected Autonomys Network’s Auto Drive as a secure, decentralized storage foundation underlying its platform. Auto Drive’s client-side encryption architecture ensures that data is encrypted on the user’s device before it ever touches the network, meaning no storage operator, no network participant, and no third party, including healthpass1, has access to unencrypted file content. Encryption keys are generated and held exclusively by the user, making the data’s permanence and privacy inseparable. Auto Drive is purpose-built by the Autonomys Network to ensure that stored data persists without dependence on any single company’s continued operation; however if a user deletes their encryption key, that data becomes cryptographically unrecoverable by anyone, including Autonomys and healthpass1.

Auto Drive is developed and operated by the Autonomys Network, a Layer-1 infrastructure platform with a global storage network of independent operators pledging petabytes of SSD space. For healthpass1, that means the health information its users store is designed to be private and secure from the moment it is written, on infrastructure no single company controls.

What comes next

Autonomys Network is proud to serve as a decentralized storage provider for healthpass1, and prouder still that a team with this depth of experience in healthcare, financial services, technology, and privacy chose Auto Drive to protect what is arguably the most personal data a person generates in a lifetime. healthpass1 is targeting September for the integration, and we will keep sharing updates as that work comes together.

If you want to follow the healthpass1 journey or get involved:

  • Visit healthpass1.com and click “Get Early Access” to become a beta tester and help improve the platform before broader launch.
  • Follow healthpass1 on LinkedIn to keep up with their progress.

And if you are building something where your data needs to stay private, secure, and permanent, you can start with Auto Drive today.
Sign up for free at ai3.storage.

DISCLAIMER: healthpass1™ is a personal health information management tool and does not provide medical advice, diagnosis, or treatment. The information stored and organized through healthpass1 is not a substitute for professional medical advice, diagnosis, or treatment. Always seek the advice of your physician or other qualified health provider with any questions you may have regarding a medical condition. Never disregard professional medical advice or delay seeking it because of information accessed through healthpass1.

‍

August 17, 2026

When AI Designs Biology, the Safeguard Is a Record No One Can Rewrite

3
Min Read
BY
AUTONOMYS

When AI Designs Biology, the Safeguard Is a Record No One Can Rewrite

Researchers at Stanford and the Arc Institute used AI to design 16 working viruses. The bacteriophages cannot harm people. The capability behind them is another matter, and it is arriving faster than the oversight meant to govern it. Every safeguard now under discussion rests on one quiet requirement: a permanent record of what was designed, requested, and built, that no one can alter or erase. That kind of record is exactly what Autonomys Network’s Auto Drive was built to provide.

In August 2026, a team at Stanford University and the Arc Institute reported something that had not been done before. Using the genome-language models Evo 1 and Evo 2, they generated complete viral genomes that do not occur in nature, synthesized the DNA, and confirmed that 16 of roughly 285 candidates were functional bacteriophages (any of a group of viruses that infect bacteria). The work was published in Science.

Two parts of that sentence deserve equal weight. The first is that it is a real advance. Bacteriophages are viruses that infect bacteria, and designed phages could one day be aimed at the antibiotic-resistant infections that conventional drugs are steadily losing ground against. The second is that the capability is general. The kind of system that designs a harmless phage is the same kind of system that, aimed at a different target, could design something dangerous.

Precision matters here, because the precision is the reassurance. The phages in this study were built from ΦX174, a virus that infects laboratory strains of E. coli. They pose no threat to people. The concern is not these organisms. It is that genome design, DNA synthesis, and automated laboratories are each advancing on their own timeline, and the safeguards meant to sit between them are not keeping pace.

That gap is where the public conversation usually stops. Breakthrough, or biosecurity risk. It is the wrong place to stop, because it skips the question that decides whether any safeguard works at all. When an AI system designs a biological sequence, can anyone prove afterward what was designed, who asked for it, whether any human asked at all or an AI agent acted on its own, and what was actually made?

This is not a fringe worry. In a companion article in Science, “AI-designed viral genomes,” researchers at the Johns Hopkins Center for Health Security wrote: “Although this is promising for life sciences applications, it also raises urgent biosafety and biosecurity questions.” Their sharpest line named the gap directly: “The ability to compose viral genomes using generative AI now exists; the governance to safely steer it does not.” They flagged one line of work they say should not be pursued at all, the design of eukaryote-infecting pathogens, the kind behind disease in humans, animals, and plants. “Such genomes,” they warned, “might encode new pathogens that can infect humans, animals, or plants in ways that cannot be contained by existing countermeasures.”

Look at the safeguards that experts are already calling for. Screening the DNA synthesis orders that turn a digital sequence into physical material. Controlling who can reach the most capable design tools. Monitoring for unusual patterns of sequence generation. Every one of those controls produces a record, and a safeguard is only ever as strong as the record behind it. If the log of a dangerous request can be quietly edited or deleted, screening and monitoring lose their meaning. The control still runs. The proof that it ran, and what it saw, does not survive.

Picture the moment that record matters most. An incident, an audit, or a regulator asking, months or years later, what really happened. At that moment an audit trail is either trustworthy or it is worthless, with no setting in between. If the party under scrutiny could have altered the record, no one outside it can rely on it, and the inquiry stalls before it starts.

This is the same accountability gap that runs through AI everywhere, and biology raises the stakes to their limit. Provenance is the heart of it. For that provenance to support oversight, it has to be two things at once. It has to be permanent, so it is still there whenever someone needs it. And it has to be tamper-evident, so that anyone can confirm it was not changed after the fact. Conventional systems offer neither. Logs live in databases that administrators can rewrite, and records that turn out to be inconvenient have a way of quietly disappearing.

Auto Drive, Autonomys Network’s gateway to permanent storage, was built to solve exactly this problem. A record can fail in two ways. It can disappear, or it can be altered. Permanence prevents the first, immutability the second. A provenance trail for AI-designed biology needs both at once, and most storage manages one at best.

What that combination buys is verification without exposure. Anyone can confirm that a record was not altered, without having to trust whoever stored it. When the sequences themselves are sensitive, they can be encrypted, with the keys held by the institution that owns them, so the record stays publicly verifiable while its contents stay private. No single operator, the storage provider included, can quietly rewrite or remove an entry. That is what turns a log into evidence, and evidence is what oversight of any dual-use technology actually runs on.

The governance the Johns Hopkins authors say is missing will not come from any single measure. The screening, access controls, and oversight already being called for all do part of the work. A permanent, verifiable record is a different part, and only one part: the evidence layer beneath them, the thing that makes every control auditable. It is the part Auto Drive provides. You can build careful oversight on top of records you can trust. You cannot reconstruct what was quietly erased, and you cannot govern what was never reliably kept.

The AI-designed virus is a milestone, and the honest reading of it is neither celebration nor alarm. It is a signal that the ability to design biology now moves at software speed, while the accountability around it still moves at the speed of paperwork. Closing that gap starts with the least glamorous part of the whole system: a record of what happened that no one can rewrite.

That record is not enough on its own. But no credible oversight will work without it.

None of this is a future capability.

Auto Drive is free to start, with 20 MB of upload and 5 GB of download each month at ai3.storage, and the Subspace Foundation Grants Program (the Subspace Foundation oversees the Autonomys Network) coordinates larger storage grants for the teams that need them.

References

  1. Les-Leigh. “Scientists Created 16 Synthetic Viruses Using AI: Is This a Breakthrough or Biosecurity Risk?” TechRound, August 10, 2026. https://techround.co.uk/artificial-intelligence/scientists-created-16-synthetic-viruses-using-ai-is-this-a-breakthrough-or-biosecurity-risk/
  2. King, S., et al. “Generative design of bacteriophages with genome language models.” Science, 2026. https://doi.org/10.1126/science.aec2657
  3. “AI-designed viral genomes.” Science, 2026. https://doi.org/10.1126/science.aej8512
  4. “AI creates 16 new viruses from scratch, showing promise for drug resistance and drawing warnings about potential for misuse.” CNN, August 6, 2026. https://www.cnn.com/2026/08/06/health/ai-viruses-bacteriophages
No items found, please try something else.