Researchers at Stanford and the Arc Institute used AI to design 16 working viruses. The bacteriophages cannot harm people. The capability behind them is another matter, and it is arriving faster than the oversight meant to govern it. Every safeguard now under discussion rests on one quiet requirement: a permanent record of what was designed, requested, and built, that no one can alter or erase. That kind of record is exactly what Autonomys Network’s Auto Drive was built to provide.
In August 2026, a team at Stanford University and the Arc Institute reported something that had not been done before. Using the genome-language models Evo 1 and Evo 2, they generated complete viral genomes that do not occur in nature, synthesized the DNA, and confirmed that 16 of roughly 285 candidates were functional bacteriophages (any of a group of viruses that infect bacteria). The work was published in Science.
Two parts of that sentence deserve equal weight. The first is that it is a real advance. Bacteriophages are viruses that infect bacteria, and designed phages could one day be aimed at the antibiotic-resistant infections that conventional drugs are steadily losing ground against. The second is that the capability is general. The kind of system that designs a harmless phage is the same kind of system that, aimed at a different target, could design something dangerous.
Precision matters here, because the precision is the reassurance. The phages in this study were built from ΦX174, a virus that infects laboratory strains of E. coli. They pose no threat to people. The concern is not these organisms. It is that genome design, DNA synthesis, and automated laboratories are each advancing on their own timeline, and the safeguards meant to sit between them are not keeping pace.
That gap is where the public conversation usually stops. Breakthrough, or biosecurity risk. It is the wrong place to stop, because it skips the question that decides whether any safeguard works at all. When an AI system designs a biological sequence, can anyone prove afterward what was designed, who asked for it, whether any human asked at all or an AI agent acted on its own, and what was actually made?

This is not a fringe worry. In a companion article in Science, “AI-designed viral genomes,” researchers at the Johns Hopkins Center for Health Security wrote: “Although this is promising for life sciences applications, it also raises urgent biosafety and biosecurity questions.” Their sharpest line named the gap directly: “The ability to compose viral genomes using generative AI now exists; the governance to safely steer it does not.” They flagged one line of work they say should not be pursued at all, the design of eukaryote-infecting pathogens, the kind behind disease in humans, animals, and plants. “Such genomes,” they warned, “might encode new pathogens that can infect humans, animals, or plants in ways that cannot be contained by existing countermeasures.”
Look at the safeguards that experts are already calling for. Screening the DNA synthesis orders that turn a digital sequence into physical material. Controlling who can reach the most capable design tools. Monitoring for unusual patterns of sequence generation. Every one of those controls produces a record, and a safeguard is only ever as strong as the record behind it. If the log of a dangerous request can be quietly edited or deleted, screening and monitoring lose their meaning. The control still runs. The proof that it ran, and what it saw, does not survive.
Picture the moment that record matters most. An incident, an audit, or a regulator asking, months or years later, what really happened. At that moment an audit trail is either trustworthy or it is worthless, with no setting in between. If the party under scrutiny could have altered the record, no one outside it can rely on it, and the inquiry stalls before it starts.
This is the same accountability gap that runs through AI everywhere, and biology raises the stakes to their limit. Provenance is the heart of it. For that provenance to support oversight, it has to be two things at once. It has to be permanent, so it is still there whenever someone needs it. And it has to be tamper-evident, so that anyone can confirm it was not changed after the fact. Conventional systems offer neither. Logs live in databases that administrators can rewrite, and records that turn out to be inconvenient have a way of quietly disappearing.
Auto Drive, Autonomys Network’s gateway to permanent storage, was built to solve exactly this problem. A record can fail in two ways. It can disappear, or it can be altered. Permanence prevents the first, immutability the second. A provenance trail for AI-designed biology needs both at once, and most storage manages one at best.
What that combination buys is verification without exposure. Anyone can confirm that a record was not altered, without having to trust whoever stored it. When the sequences themselves are sensitive, they can be encrypted, with the keys held by the institution that owns them, so the record stays publicly verifiable while its contents stay private. No single operator, the storage provider included, can quietly rewrite or remove an entry. That is what turns a log into evidence, and evidence is what oversight of any dual-use technology actually runs on.
The governance the Johns Hopkins authors say is missing will not come from any single measure. The screening, access controls, and oversight already being called for all do part of the work. A permanent, verifiable record is a different part, and only one part: the evidence layer beneath them, the thing that makes every control auditable. It is the part Auto Drive provides. You can build careful oversight on top of records you can trust. You cannot reconstruct what was quietly erased, and you cannot govern what was never reliably kept.

The AI-designed virus is a milestone, and the honest reading of it is neither celebration nor alarm. It is a signal that the ability to design biology now moves at software speed, while the accountability around it still moves at the speed of paperwork. Closing that gap starts with the least glamorous part of the whole system: a record of what happened that no one can rewrite.
That record is not enough on its own. But no credible oversight will work without it.
None of this is a future capability.
Auto Drive is free to start, with 20 MB of upload and 5 GB of download each month at ai3.storage, and the Subspace Foundation Grants Program (the Subspace Foundation oversees the Autonomys Network) coordinates larger storage grants for the teams that need them.