On August 6, Stanford University and the Arc Institute reported that researchers had used an AI model called Evo 2 to write functional bacteriophage genomes entirely from scratch, without copying any existing virus. They synthesized nearly 300 of the AI-designed genomes and tested each against E. coli; 16 turned out to be exceptionally effective killers of the bacteria. That is a real result, built and tested in a lab, not a simulation. The surface read is straightforward: AI has moved from predicting biology to authoring it.
It is worth slowing down on what that means for the systems built to stop someone from mail-ordering dangerous DNA. The sharper version of this question was already answered ten months earlier, and not in the screening system's favor.
Microsoft's Paraphrase Project, published in Science in October 2025, found that current DNA-synthesis screening software did not consistently catch AI-redesigned versions of known dangerous proteins. Researchers used open-source AI protein-design tools to generate 76,089 variants of 72 known proteins of concern, mostly toxins, and ran them past the screening systems that are supposed to flag risky synthesis orders before they ship.

Screening was built to catch known threats, not to judge unfamiliar ones.
How the gatekeeper actually works
DNA-synthesis screening exists because building a dangerous pathogen from scratch usually starts with ordering strands of DNA from a commercial supplier. A peer-reviewed analysis of the field describes the core method: providers computationally compare every ordered sequence against curated databases of known pathogenic sequences of concern, commonly using a tool called BLAST, and flag matches for human review. The industry's shared screening tool works the same way: it compares the ordered nucleic-acid sequence against public DNA and protein sequence databases to find the closest-matching known organism, then cross-references any match against international control lists.
Two checks anchor today's DNA-synthesis screening.
| Screening step | What it compares | What it flags |
|---|---|---|
| Sequence-of-concern matching | An ordered sequence against curated databases of known pathogenic sequences | A close match, sent for human review |
| Common Mechanism (industry-shared tool) | An ordered sequence against public DNA and protein sequence databases | The closest-matching known organism, checked against control lists |
Source: Applied Biosafety, 2024; Health Security, 2024.
Both methods rest on the same assumption: a dangerous sequence will resemble something already on file. Neither one asks whether a sequence is dangerous on its own merits, only whether it looks like something a human already catalogued as dangerous.
Why a genome written from scratch doesn't match anything
That assumption is exactly what generative AI breaks. Generative protein-design tools can produce entirely novel sequences with harmful functions but little or no resemblance to known sequences, so AI-generated dangerous proteins can pass undetected through screening software built to match against known sequences of concern. Evo 2 does the equivalent job at a larger scale: instead of redesigning one known protein, it writes an entire genome from a blank page. Out of the nearly 300 phage genomes Evo 2 designed and researchers synthesized, 16 worked well enough to be called exceptionally effective.

A genome written this way carries no fingerprint of a known pathogen for a database to catch. It was never copied from one.
The patch that shipped, and the gap that didn't close
Microsoft did not publish the screening gap and walk away. Before publishing, the company spent about ten months building a patch and distributing it to DNA-synthesis screening providers. It also alerted the US government; by the time the study appeared, the software makers had already patched their systems. That is the responsible-disclosure process working close to as designed. But the same account is explicit that some AI-designed molecules can still evade detection even after the patch. A patch closes the specific holes researchers found. It does not certify that every future AI-generated sequence will get caught.
What this means for India's fast-growing bioeconomy
This is not a story that stops at US borders. India's bioeconomy was valued at about $165 billion at the launch of the 2025 India BioEconomy Report, up from roughly $10 billion in 2014, a sixteen-fold rise built substantially on the same DNA-synthesis, gene-editing and protein-design capacity that the screening gap leaves unguarded.

That growth is arriving into a patchwork rulebook. A 2026 peer-reviewed review of nucleic-acid synthesis governance across Asia found that publicly documented, synthesis-specific screening rules remain inconsistent across jurisdictions including China, Japan, India and Singapore. A bioeconomy this size is exactly the kind of capacity where a documented, synthesis-specific screening standard matters most, and it is exactly where the 2026 review found the rules thinnest.
The honest objection
The strongest case against alarm is that the field caught itself. Microsoft ran the test, found the gap, and had it patched within ten months, before publishing, precisely so the finding would not double as a blueprint. Evo 2's phage work adds a beneficial capability, a possible tool against antibiotic-resistant E. coli, not a dangerous one, and it went through the same open, peer-reviewed process that surfaced Microsoft's finding. On this reading, two research teams caught two real problems and the field is visibly correcting itself in public, which is what a healthy dual-use research culture looks like.
That case holds well for the handful of major Western synthesis-screening vendors Microsoft could alert directly. It holds less well everywhere else. Microsoft's own account says some AI-designed molecules can still slip past detection even after the patch, and the most recent review of synthesis governance across Asia found the rulebook still inconsistent from country to country, India included. A patch that reaches a small set of major software vendors is not the same as a global fix, and the audit that would confirm every synthesis provider is covered does not yet exist in public.
The Signal
Evo 2 did not break biosecurity screening. It demonstrated, at genome scale, the exact failure mode Microsoft had already documented at protein scale ten months earlier: a detection system built to recognize what is already known cannot, by its own design, vouch for what has never been seen. The number to watch from here is not how good the next AI model gets at writing genomes. It is whether screening moves from matching known sequences to something that can flag a genuinely novel one, before the gap between design capability and detection capability gets tested by someone with worse intentions than a Stanford lab or a Microsoft red team.
Reporting basis: the Evo 2 phage-genome results are per Stanford University's press release, via EurekAlert. The Microsoft Paraphrase Project's screening-gap findings and its ten-month patch are as reported by IBBIS and by MIT Technology Review respectively, both describing the same October 2025 Science study. How DNA-synthesis screening works mechanically is per a peer-reviewed paper in Applied Biosafety and a peer-reviewed paper in Health Security describing the industry's shared Common Mechanism tool. The explanation of why generative AI evades homology-based screening is per Global Biodefense's account of the Microsoft study. India's bioeconomy valuation is per the Department of Biotechnology's India BioEconomy Report, via News on Air, and the inconsistency of synthesis-screening rules across Asia is per a 2026 peer-reviewed review in Frontiers in Bioengineering and Biotechnology.



