Trading View Ticker Widget

AI Designed 16 Viruses & Exposed A Screening Gap

The first AI-written genomes work, and the software guarding synthetic DNA was never designed to recognize them.

Welcome to Memorandum Deep Dives. In this series, we go beyond the headlines to examine the decisions shaping our digital future. 🗞️

This week, we are looking at what happened when researchers asked a machine to write viral genomes from scratch, built roughly 300 of the resulting designs into real DNA, and introduced them into bacteria spread across laboratory dishes. In most dishes, nothing happened. In a handful, clear patches opened in the bacterial film, which is what it looks like when a virus is multiplying inside cells and bursting them open.

Sitting between any genetic design and a physical vial of DNA is a piece of software almost nobody thinks about. A biologist types a sequence into a web form; a company on the other side of the world reads the order, compares it against catalogs of known dangerous material, checks the buyer, and either ships or stops. The DNA synthesis industry built that system voluntarily, and no law has ever required it.

Two of the checkpoints guarding this road have already been tested in public, and they broke in ways that look similar from a distance and are anything but on closer inspection. One was a bug. The other was something harder to fix, and it is the reason a group of AI executives, DNA manufacturers, and former defense officials all ended up signing the same letter to Congress.

Your next 100 customers are already in Apollo

Find, reach, and close your perfect deals — without juggling five tools or hiring more reps.

Apollo gives you everything you need to build real pipeline, fast. From inbound to outbound, first touch to close.

All in Apollo.

In partnership with

Blu Dot surpasses 2,000% ROAS with self-serve CTV ads

Home furniture brand Blu Dot blew up on CTV with help from Roku Ads Manager. Here’s how:

After a test campaign reached 211,000 households and achieved 1,010% ROAS, the brand went all in to promote its annual sales event. It removed age and income constraints to expand reach and shifted budget to custom audiences and retargeting, where intent was strongest.

The results speak for themselves. As Blu Dot increased their investment by 10x, ROAS jumped to 2,308% and more page-view conversions surpassed 50,000.

“For CTV campaigns, Roku has been a top performer,” said Claire Folkestad, Paid Media Strategist, Blu Dot. “Comping to our other platforms, we have seen really strong ROAS… and highly efficient CPMs, lower than any other CTV partner we've worked with.”

Using Roku Ads Manager, the campaign moved from a pilot to a permanent performance engine for the brand.

*This is sponsored content. See our partnership options here.

How the hard part stopped being hard

For most of human history, studying DNA meant collecting samples, analyzing them, and waiting to see how organisms changed across generations. Biologists could nudge that process along, breeding one plant with another and hoping something useful turned up in the offspring, but there was no way to reach into the molecule itself and alter it on purpose. That began to change in the 1940s, when researchers started deliberately inducing mutations in crops using radiation and chemicals, then selecting the mutations that proved useful. By the 1970s, the field had advanced far enough that scientists were inserting genetic material from one organism into the cells of another, a technique that produced the first genetically modified bacteria.

What followed opened the floodgates. Scientists bred crops that resist drought, insects, and disease, produced vaccines for people and livestock, and began working on treatments for cancer.

That was one side of the coin. The same understanding that makes a crop resistant to a pathogen can be turned around to make a pathogen better at defeating the crop, and the same holds for anything that infects people or animals. For decades, the thing standing between that knowledge and its misuse was how hard the knowledge was to come by. Learning to read a genome, work out which stretches do what, and predict what happens when you change one took years of training and access to a laboratory. Artificial intelligence has been wearing down that barrier. The ability that lets a model predict the next word in a sentence also lets it predict the next letter in a genetic sequence, and it picks up the second skill the same way it picked up the first, by reading enormous quantities of existing material until the patterns become obvious.

What appeared in the Petri dishes

That is what a team at Stanford University and the Arc Institute set out to test. They spent months asking an AI system to write viral genomes from scratch, took roughly 300 of the resulting designs, built them as real DNA, and introduced them into bacteria spread across laboratory dishes. In most of the dishes, the bacteria continued to grow normally, indicating that those designs were inert. In a few, clear patches opened in the cloudy film of bacteria, and a clear patch is what it looks like when a virus is multiplying inside cells and bursting them open. Sixteen of the designs had come alive.

The findings, published in Science on August 6, 2026, mark the first time a machine has written a complete working genome. Several of the new viruses killed E. coli faster than the natural virus they were modeled on. Brian Hie, who led the project, told the BBC it was "new territory for us." None of the 16 can infect a person, and the team took deliberate steps to ensure that, stripping from the training data every sequence belonging to viruses that infect humans, animals, plants, or fungi. Two biosecurity specialists at Johns Hopkins read all of that and still wrote alongside the paper that the work raises urgent questions.

Their concern reaches past these 16 viruses to the kind of object each one is. Every design in the batch is a sequence that nature has never produced, and that single detail is what makes the result hard to absorb.

The check that stands between a design and a vial

Understanding why requires knowing what sits between a genetic design and physical material. Somewhere today, a biologist will type a long string of letters into a web form and click submit. The letters contain a genetic sequence written in the four-character alphabet DNA uses, and a company somewhere else in the world will turn that sequence into physical material and mail it out. Before it does, the software reads the order and compares it against catalogs of DNA already known to be dangerous, then checks the buyer against records of people who should not receive it. If either check raises a flag, the order stops. DNA synthesis companies built this system themselves in the 2000s, without any law requiring them to.

The check works only against what somebody has already written down. A sequence copied from a known pathogen gets caught because the catalog contains it, and a sequence assembled out of known dangerous parts gets caught for the same reason. The whole arrangement rests on an assumption that anything worth stopping will resemble something stopped before, and that assumption held for as long as new biology came from nature or from copying nature. What the software does when a sequence arrives with no ancestor anywhere is the question those laboratory dishes have just raised.

Two more checkpoints sit further up the same road. Artificial intelligence companies built theirs two decades later, at a point in the process where there is nothing physical yet, only a conversation. Their models had read enough published biology to answer questions that once required a specialist in the room, and the labs recognized what that meant, so they trained the models to detect harmful requests and decline them. A third checkpoint sits between the other two, inside the research software that designs biological parts rather than explaining them. Each one guards a different stretch of the same journey, and each one does its job by recognizing what has been dangerous before.

Outperform the competition.

Business is hard. And sometimes you don’t really have the necessary tools to be great in your job. Well, Open Source CEO is here to change that.

  • Tools & resources, ranging from playbooks, databases, courses, and more.

  • Deep dives on famous visionary leaders.

  • Interviews with entrepreneurs and playbook breakdowns.

Are you ready to see what it’s all about?

*This is sponsored content

Two failures that are not the same failure

Two of those three have already been tested, and comparing how each held up explains why researchers remained worried throughout last year. The model checkpoint went first, and it broke open. Sometime after a major chatbot received an upgrade, people began asking it how to produce biological agents, and the Wall Street Journal reported in July 2026 that hundreds of users had received detailed guidance, some of which outside experts later judged to be accurate. Every one of those conversations left a record. The company could read them, work out where the refusal had given way, close the accounts, and repair the gap that let them through. Some of that happened. OpenAI banned the accounts but did not alert law enforcement, and the same reporting says it had already rated the model high-risk for biology before downgrading that classification.

The far end of the road broke differently, and it broke quietly. In 2023, Eric Horvitz, who runs science at Microsoft, started turning over a question that would not leave him alone: if AI can design proteins, could it redesign a dangerous one so the shape stayed intact while the underlying sequence changed enough that the screening software no longer knew what it was looking at? He put a team on it. They worked entirely on computers, never making anything physical, generating thousands of rewritten versions and running them past the same software the DNA companies rely on. The answer came back yes, and one screening tool failed to flag more than 75% of what they had produced.

What Horvitz did next is the part worth sitting with. Rather than publishing, he spent 10 months working confidentially with the DNA synthesis companies to build a repair, shipped it to them around the world, and only then told anybody what he had found. The patched software is better, but it is not airtight and reportedly lets roughly 3% of concerning sequences through. That is the difference between the two failures. One was a bug in a filter that could be found and fixed. The other was that the filter's core assumption turned out to be beatable, and no patch retracts an assumption.

Some researchers think this alarm is misplaced, and their evidence is not weak. When RAND assembled teams and asked them to plan a biological attack, the ones working with AI models produced plans no better than the teams who had nothing but a search engine. The knowledge, in other words, was already out there for anyone patient enough to look. What that study measured was whether a model could hand expertise to somebody starting from zero. The Stanford team began somewhere else entirely, already holding the expertise and using the machine to move faster than any human could. Nobody has run the experiment that measures the second thing.

Ask who answers for a checkpoint when it fails and the two ends of the road separate again. The AI labs own their layer completely: they build the models, employ the safety teams, and bear the consequences when something slips through. The screening layer has no owner like that. No federal law requires those checks, and the federal rules meant to govern them have been stuck in redrafting for well over a year after the order that created them was canceled and its replacement never arrived. The companies doing the screening are doing it because they decided to, which also means any of them could decide otherwise. By the Nuclear Threat Initiative's estimate, roughly a fifth of the market already has.

The strangest part is that nobody is fighting about this. The heads of OpenAI, Anthropic, Google DeepMind, and Microsoft AI signed a letter asking Congress to make screening mandatory, a rare public agreement among four fierce competitors about another industry. Stranger still, the DNA companies that would pay for all that compliance endorsed the bill that would force it on them. The bill has been sitting in committee ever since, which is where earlier attempts at the same idea also ended, undone by arguments over who bears the cost and which sequences ought to count as dangerous in the first place.

Safety systems are built out of memory

Step back from DNA, and something familiar comes into view, because almost every safety system people build is a record of something that already went wrong. Building codes were written after fires. Aviation rules were written after crashes. Food standards were written after outbreaks. Each line in each of those rulebooks exists because a specific disaster taught somebody a lesson expensive enough to write down. The catalogs guarding DNA orders belong to that tradition too, holding the memory of every pathogen and toxin that has hurt anyone so far, and like all memory, they contain only what has already happened.

That was enough for a long time, because biology had spent its entire history as a science of finding things, and genuinely new material surfaced slowly enough that the records could keep up. A machine that writes genomes changes the pace of that. It produces things nobody has seen as its ordinary output rather than as a rare event, which leaves the catalogs permanently one step behind whatever is being made. The response so far has been to hunt for gaps and patch them as they turn up, and that approach works only as long as somebody like Horvitz reaches each gap before anyone with worse intentions does. He found one and closed it before saying a word in public. What protected everybody at that time was a careful man asking himself an uncomfortable question.

The question nobody has answered is what a safety system looks like when it can no longer be built out of memory. That problem now belongs to a Congress that has let earlier screening bills die in committee, and to a federal framework more than a year overdue for its rewrite. Biology spent most of its history as a science of discovery, and every safeguard built around it assumed that anything dangerous would have already been found. Whether those safeguards survive the shift will depend less on how quickly the models improve than on whether the software standing between a file on a screen and a vial in the post ever stops being something companies choose to run.

P.S. Want to collaborate?

Here are some ways.

  1. Share today’s news with someone who would dig it. It really helps us to grow.

  2. Let’s partner up. Looking for some ad inventory? Cool, we’ve got some.

  3. Deeper integrations. If it’s some longer-form storytelling you are after, reply to this email, and we can get the ball rolling.

What did you think of today's memo?