Skip to main content
  1. Home
  2. Computing
  3. News

Experts find it’s easy to manipulate AI chatbots into coughing up bioweapon recipes

AI’s bioweapon guardrails are easier to crack than you’d hope

Add as a preferred source on Google
Gas Mask
Scott Rodgerson / Unsplash

AI companies have spent years building safeguards designed to stop their chatbots from helping someone create a biological weapon. The models themselves are becoming so capable that keeping that knowledge behind those barriers is turning into a serious problem.

Researchers at Cisco found they could bypass safeguards on major chatbots including OpenAI’s ChatGPT, Anthropic’s Claude, and Google’s Gemini within five conversational turns, according to a Wall Street Journal investigation. The researchers were able to elicit potentially dangerous answers after gradually steering the conversations around the models’ restrictions. Amy Chang, Cisco’s head of AI threat and security research, told the Journal that no model can be completely protected from a sufficiently persistent user.

Recommended Videos

The problem also extends beyond security researchers deliberately stress-testing these systems. The Journal reports that hundreds of users began asking ChatGPT about poisons and biological weapons after OpenAI upgraded the model’s capabilities last summer. Biology and terrorism experts who later examined some conversations reportedly judged some of the information to be dangerously accurate. In response to this, OpenAI has banned accounts involved in such exchanges.

AI keeps getting much better at biology

OpenAI had already anticipated where this was heading. By 2024, internal testing reportedly showed that extended questioning could persuade ChatGPT to provide increasingly dangerous biological guidance. Employees predicted the following year that its capabilities could reach a point where someone with relatively limited biology training could receive meaningful assistance.

When GPT-5 arrived, OpenAI treated the model as having High capability in the biological and chemical domain under its Preparedness Framework and deployed additional safeguards. The company said at launch that it lacked definitive evidence that GPT-5 could enable a novice to cause severe biological harm. Its latest GPT-5.6 family carries the same High designation for biological and chemical risk.

Blocking everything creates another problem

AI companies also have a difficult balancing act on their hands. The same biological knowledge that creates a weaponization risk can be incredibly valuable to researchers developing medicines, vaccines, and treatments. The Journal reports that OpenAI executives have been reluctant to make models refuse large numbers of biology questions because public-health workers and drug-discovery researchers rely on them.

Anthropic ran into the opposite problem when Claude’s restrictions reportedly interfered with CDC researchers trying to work with information about a pathogen during a hantavirus outbreak. OpenAI now uses model-level training, account enforcement, and additional safety checks for sensitive biological queries. The concern raised by Cisco’s testing is that determined users can keep probing for cracks. As AI becomes considerably better at biology, those cracks carry much higher stakes.

Vikhyaat Vivek
Vikhyaat Vivek is a tech journalist and reviewer with seven years of experience covering consumer hardware, with a focus on…
Google is testing an AI-first homepage, and the Search button is reportedly taking a back seat
A quietly spotted redesign shows Google testing life without its own Search button.
Google Chrome with Gemini

For years, the Search button has been an integral part of the Google Search experience. However, right now, typing "google.com" into a browser is reportedly bringing up a new simplified layout that doesn’t include the Search button anymore (for a select group of signed-out users). 

It appears that the search giant is testing a new, AI-first layout with three dedicated buttons, which are new for traditional Google Search users, but familiar for those who use the Gemini chatbot on a regular basis.  

Read more
The FCC wants to ban some drones it already approved. Yeah, this is getting complicated.
FCC considers expanding drone restrictions to previously approved DJI models
dji drone

The US Federal Communications Commission is considering a move that could make things pretty awkward for drone buyers. The agency wants to expand its existing restrictions to cover certain drones with features such as LiDAR sensing, thermal imaging, and aerosol-dispersing systems. The weird part? Some of these drones were already approved for sale in the US.

In a report by DJI's own blog, this new development puts several DJI models in the spotlight, including the Air 3S, Avata 360, and Mini 5 Pro. Under the proposal, these drones could potentially be pulled from the US market, even though the FCC had previously cleared them. And no, if you already own one, the government isn't coming to take it away.

Read more
Hoy combines AirDrop, Loom, and voice messages in the Mac menu bar
The pre-release app lets Mac users send files, voice notes, and screen recordings without bouncing between separate tools
Person, Text, Electronics

Hoy wants sending something from your Mac to feel as casual as dropping a file onto someone’s desk. Instead of opening another app, you drag it onto that person’s face sitting in the menu bar.

https://twitter.com/heyiamdk/status/2082151995687748064

Read more