Skip to main content
  1. Home
  2. Computing
  3. News

Experts find it’s easy to manipulate AI chatbots into coughing up bioweapon recipes

AI’s bioweapon guardrails are easier to crack than you’d hope

Add as a preferred source on Google
Gas Mask
Scott Rodgerson / Unsplash

AI companies have spent years building safeguards designed to stop their chatbots from helping someone create a biological weapon. The models themselves are becoming so capable that keeping that knowledge behind those barriers is turning into a serious problem.

Researchers at Cisco found they could bypass safeguards on major chatbots including OpenAI’s ChatGPT, Anthropic’s Claude, and Google’s Gemini within five conversational turns, according to a Wall Street Journal investigation. The researchers were able to elicit potentially dangerous answers after gradually steering the conversations around the models’ restrictions. Amy Chang, Cisco’s head of AI threat and security research, told the Journal that no model can be completely protected from a sufficiently persistent user.

Recommended Videos

The problem also extends beyond security researchers deliberately stress-testing these systems. The Journal reports that hundreds of users began asking ChatGPT about poisons and biological weapons after OpenAI upgraded the model’s capabilities last summer. Biology and terrorism experts who later examined some conversations reportedly judged some of the information to be dangerously accurate. In response to this, OpenAI has banned accounts involved in such exchanges.

AI keeps getting much better at biology

OpenAI had already anticipated where this was heading. By 2024, internal testing reportedly showed that extended questioning could persuade ChatGPT to provide increasingly dangerous biological guidance. Employees predicted the following year that its capabilities could reach a point where someone with relatively limited biology training could receive meaningful assistance.

When GPT-5 arrived, OpenAI treated the model as having High capability in the biological and chemical domain under its Preparedness Framework and deployed additional safeguards. The company said at launch that it lacked definitive evidence that GPT-5 could enable a novice to cause severe biological harm. Its latest GPT-5.6 family carries the same High designation for biological and chemical risk.

Blocking everything creates another problem

AI companies also have a difficult balancing act on their hands. The same biological knowledge that creates a weaponization risk can be incredibly valuable to researchers developing medicines, vaccines, and treatments. The Journal reports that OpenAI executives have been reluctant to make models refuse large numbers of biology questions because public-health workers and drug-discovery researchers rely on them.

Anthropic ran into the opposite problem when Claude’s restrictions reportedly interfered with CDC researchers trying to work with information about a pathogen during a hantavirus outbreak. OpenAI now uses model-level training, account enforcement, and additional safety checks for sensitive biological queries. The concern raised by Cisco’s testing is that determined users can keep probing for cracks. As AI becomes considerably better at biology, those cracks carry much higher stakes.

Vikhyaat Vivek
Vikhyaat Vivek is a tech journalist and reviewer with seven years of experience covering consumer hardware, with a focus on…
Shopping for back-to-school? These are the webcam lights I’d actually turn on before a Zoom call
From a budget clip light to a proper desk setup, there's a webcam light here for every price.
Head, Person, Face

Between online classes, group project calls, and the occasional job interview over Zoom, your webcam will be doing a lot more heavy lifting in school than it ever did at home. The problem is that most laptop cameras are bad in low light, and a single overhead bulb or a window behind you turns every call into a game of "wait, can you see me okay?"

A good webcam light fixes that faster than moving your whole desk around. I picked five, starting with the most affordable and working up to the one that's genuinely overkill for a Zoom call but still worth knowing about.

Read more
Google Chrome could soon let you translate pages right inside Reading Mode
However, not everyone's seeing it yet, even on Canary.
Google Chrome

Chrome's Reading Mode just got a new button tucked inside its settings menu. Google is quietly testing a translate option for the feature on Chrome Canary, the browser's experimental testing channel where new ideas show up long before they're ready for everyday use.

What does this new translate button actually do?

Read more
AI dramas need actors, so Chinese platforms are turning human faces into stock assets
People can now earn money by licensing their likenesses to AI creators, although keeping track of where those digital faces end up may prove considerably harder
Adult, Female, Person

People in China can now license their face to AI much like a photographer licenses a stock image. AI creators can then make that likeness speak, move, and appear as different characters in short dramas or ads.

Contributors have earned between $15 and $700 through platforms such as ActID and New Claw, according to Rest of World.

Read more