Advances in AI are lowering barriers to biological design, raising a new biosecurity challenge: what researchers call deepfake viruses
Published Date – 3 September 2026, 10:52 PM
By Dr Sudhanshu Kumar
In 1346, the Black Death arrived at the port of Caffa in Crimea on Mongol catapults. The weapon was a corpse. The delivery mechanism was medieval. The death toll over the following six years was between 75 million and 200 million people across Eurasia. The most devastating biological event in recorded human history required no laboratory, no advanced knowledge of pathogen structure, and no understanding of viral replication. It required only proximity, movement, and time.
Now consider what changes when the laboratory is a language model.
In 2024, a company called Radical Numerics, founded by former Stanford PhD researchers, published the results of an AI model called EVO. The model treats DNA much as a large language model treats text: it reads sequences of genetic letters and learns the rules governing how those sequences produce physical biological function. Just as GPT-4 can generate a paragraph that follows the statistical patterns of human prose, EVO can generate a DNA sequence that follows the statistical patterns of biological life.
The researchers trained it on existing natural gene-editing tools and used it to generate novel CRISPR variants, which scientists then synthesised and verified in laboratory tests. They then used it to create the complete DNA genome for a bacteriophage, a bacterial virus, from scratch. The first AI-generated genome is not merely a theoretical possibility. It has already been written.
Between Capability and Catastrophe
The most important number in this story is not the model’s context window, which grew from a few thousand tokens to one to two million, enabling it to process massive genomic sequences. Nor is it the 30 minutes EVO took to rank causal genes for Alzheimer’s disease, matching two years of laboratory work. The most important number is the barrier to entry.
Programming biology used to require a PhD in molecular biology, years of laboratory training, expensive equipment, and institutional access to biosafety facilities. EVO and its successors are compressing that barrier the way the internet compressed the barrier to publishing, Midjourney compressed the barrier to visual art, and ChatGPT compressed the barrier to writing.
The capability is not yet democratised. But the trajectory is unmistakable. Every year, the knowledge required to instruct an AI model to design a novel pathogen decreases. At the same time, the models themselves become better at filling the gaps a non-expert user cannot provide.
India’s ability to detect and respond in time will depend on the investments it makes over the next three years, not the next three decades
Radical Numerics itself acknowledges this challenge. Its dual mandate for biodefence and therapeutic applications exists precisely because its founders recognise that programming biology lowers the barrier to creating synthetic threats, or what researchers call deepfake viruses. The people building the tool are warning about the tool. That is worth taking seriously.
Why India Is Particularly Exposed
India’s exposure to an AI-generated biological threat is not merely the general exposure that every densely populated country faces. It is compounded by three specific structural conditions.
The first is population density. India hosts over 1.4 billion people in a geographic area where urban concentration, inter-State mobility and climate create conditions for rapid pathogen spread. These factors mirror, and in some ways exceed, those that contributed to the rapid spread of Covid-19 in 2020 and 2021. A synthetic pathogen engineered for high transmissibility and designed to evade existing immune responses, the kind of variant that EVO’s architecture could theoretically optimise for, would find in India a propagation environment with few equals anywhere on earth.
The second is the gap in India’s biosurveillance infrastructure. The genomic sequencing capacity required to detect a novel pathogen quickly enough to contain it before it spreads beyond a manageable geographic radius remains unevenly distributed across India’s States. A synthetic pathogen, specifically engineered to produce symptoms that mimic existing illnesses during its early replication phase, could circulate for weeks before its artificial origin is detected, if it is detected at all.
The third is the adversarial context. India does not exist in a biosecurity vacuum. Its primary strategic adversaries, China and Pakistan, are both investing heavily in biotechnology. China’s People’s Liberation Army has a dedicated biological weapons research programme that Western intelligence assessments have consistently flagged as a concern.
The same AI tools that Radical Numerics is developing for therapeutic purposes are available, in various forms, to researchers operating under military rather than civilian oversight in countries with different ethical frameworks and different strategic motivations. An AI-generated pathogen does not require a state actor. But a state actor with access to advanced biological AI systems and without the kinds of biodefence mandate claimed by companies such as Radical Numerics represents a scenario that India’s strategic planners cannot afford to ignore.
No Name Yet
Covid originated in 2019 as a natural pathogen. Approximately two years elapsed between the first identified cases and meaningful population-level immunity. In those two years, India lost hundreds of thousands of lives, suffered its worst economic contraction in decades, and experienced social disruption whose consequences have not fully resolved.
Now consider an adversarially designed pathogen engineered by an AI system instructed to maximise transmissibility, minimise early symptom visibility, and evade specific immune responses that Covid vaccines generated. The engineering challenge is not purely theoretical. EVO has already demonstrated the ability to generate novel CRISPR variants. Radical Numerics is already moving beyond DNA-only sequences to tokenise epigenomics, RNA, proteins, and metabolomics in an effort to model complex biological processes more comprehensively.
The model that could generate a truly dangerous synthetic pathogen is not EVO as it exists today. It is what its successors will be capable of in three to five years, particularly in the hands of actors who are not publishing their work in peer-reviewed journals.
What India Must Build
The window to prepare is open. It is not wide. India’s National Centre for Disease Control, the Indian Council of Medical Research, and the Defence Research and Development Organisation were not designed for the specific challenge of detecting and responding to AI-generated biological threats. Building that capability requires three things.
The first is a genomic surveillance network capable of detecting synthetic signatures in pathogen sequences in real time, rather than retrospectively. An AI-generated pathogen will carry statistical regularities in its genome that differ from natural evolutionary pathways. Detecting those regularities requires AI-enabled genomic analysis running continuously across India’s hospital system, rather than relying on manual reviews of samples collected weeks after a cluster appears.
The second is a biosecurity AI programme with an explicit defensive mandate. India’s AI mission is currently oriented toward economic and governance applications. A dedicated strand focused on using AI to detect, characterise, and develop countermeasures against novel biological threats should be treated as a national security requirement, not an academic exercise.
The third is international engagement on AI biosecurity governance before the capability gap between the major AI powers and the rest of the world becomes permanent. India has the scientific capacity and geopolitical positioning to become a meaningful voice in the governance frameworks being designed right now for biological AI. Countries that help write those frameworks will have greater influence over how they are implemented and enforced.
The next pandemic may be natural, as Covid-19 was. It may not. The difference between those two scenarios, and India’s ability to detect and respond in time, will be determined by the investments India makes over the next three years, not the next three decades. EVO is not a threat. It is a preview. India should treat it as one.
(The author is expert on AI, Cyberwarfare and Cybersecurity at CENJOWS (Centre for Joint Warfare Studies), HQ (IDS), Ministry of Defence, New Delhi. He holds a PhD on ‘AI and Security policy’ from JNU and is also a Visiting Research Fellow at MGIMO, Moscow)