OpenAI, the developer of the famous AI chatbot ChatGPT, recently revealed concerns about the capabilities of upcoming models. One of these concerns is that new models will enable those without backgrounds in science and biology to potentially engage in harmful activities by providing them with the necessary blend of information and processes. This threat uniquely enables novices and independent bad actors to create dangerous biological weapons.
Imagine a 19-year-old college student with no background in bioweapons. Fueled by malicious intent, he looks to cause widespread harm using biological agents. Even with access to Google and internet forums, it would be challenging for him to learn everything necessary to carry out a successful attack -- one reason why many biological threats have failed in the past. But frontier AI models can change that, placing dangerous knowledge into the hands of novices like this student and accelerating their ability to act on it. Just as the internet fueled the rise of crimes like drug and human trafficking, AI threatens to make previously improbable biothreats a far more apparent societal risk.
The Future of AI
At the current rate of AI advancement, it is only a matter of time before frontier models can meet or exceed various human capabilities. Anthropic warned of potential harms when it released Claude 4, and OpenAI also sounded the alarm on the sheer capability of its newest models. Both companies indicated their latest models could cause serious damage by democratizing information for bad actors and deceptively responding to users.
Advanced AI will rapidly accelerate scientific discovery by boosting the innovation, ideas, and productivity of researchers, medical professionals, and other scientists. The latest models can already interpret laboratory experiments and complex chemical reactions “with remarkable accuracy”. Harvard scientists were even able to use AI to identify drug treatments for rare diseases. An AI system called Robin helped find a potential cure to a type of blindness, and the same system later discovered that an existing drug could help prevent blindness in a different eye condition. But power like this comes with heavy risks.
Successors of the latest models can aid in designing biological weapons, and while experts are not yet concerned that AI will create completely novel biothreats, they are worried about something called “novice uplift” -- allowing those without a background in biology to do potentially dangerous things.
Showing just how real this possibility is, Rocco Casagrande, a former UN weapons inspector and scientist, brought US government officials a small box of easily available chemicals that Claude -- Anthropic’s chatbot -- recommended as ways to trigger another pandemic. Several AI safety frameworks, including Google’s Secure AI and OpenAI’s Preparedness Framework, already identify AI-enabled bio attacks as concerns. Furthermore, the International AI Safety Report written for the 2025 Paris AI Action Summit revealed that large language models (LLMs) are much more accurately responding to queries about the formulation and acquisition of deadly biological and chemical agents.
In the past, rogue actors had limited success with bioattacks due to their delicate nature and the expertise required to handle them. This reality is now changing with advances in synthetic biology and the emergence of cloud labs -- discreet facilities contracted for clients to conduct remote experiments. These labs are hard to trace and significantly more dangerous when combined with advanced AI capabilities.
As LLM’s are implemented into the interface of cloud labs, experimental ideas will be more easily translated into experiments in simulated laboratory environments and eventually in real-world laboratories. While these interfaces may be useful for researchers -- accelerating scientific discovery and increasing productivity -- AI can lower the barriers to rogue, nefarious actors, enabling them to use labs like experts, even without expert knowledge.
In today’s evolving geopolitical atmosphere, rogue bioterrorists pose the most existential risk to human society worldwide. They have already employed advanced technology to carry out cyberattacks and ransomware, and they use private encrypted messaging apps like WhatsApp and Telegram to recruit new members, buy weapons, and stage attacks.
Rogue threats extend beyond well-known race-focused supremacy groups to include modern extremists like the now-defunct Zizians -- a Bay Area organization known as “the world’s first AI-inflected death cult” that wanted humanity to be replaced by computer superintelligence.
The Trump Administration’s Department of Government Efficiency (DOGE) dealt huge blows to the FBI and CIA by firing hundreds of experts crucial to global counter-terrorism. Additionally, the administration got rid of America’s AI Safety Institute -- initially opened towards the end of Biden’s term -- leaving less standardized federal control over American tech firms.
As danger lurks from every corner, companies like OpenAI have already started taking necessary precautions.
Mitigating Risks
OpenAI’s aforementioned “Preparedness Framework” details a multipronged approach to mitigation that is focused on prevention rather than reaction.
To strengthen its defenses in biology, OpenAI is ensuring its models either refuse or safely respond to harmful requests, including those that enable bioweaponization. Currently, it is relatively easy to bypass security responses through dual-use requests that still provide information the client is looking for. To combat this, OpenAI is making sure its models avoid responses that provide “actionable steps”.
Systems that detect risky or suspicious bio-related activities are always enabled and are supplemented with human review when necessary. Enforcement checks like these that combine automated systems with human reviewers are being widely implemented as a defense mechanism.
OpenAI says it worked with leading experts early on when first developing ChatGPT and also designed mitigations through human trainers with Master's and PhDs. Now, it is “actively engaging with domain-expert red teamers” to test how well their safeguards hold up. Expert red teamers actively try to break safety mitigations to test how strong safeguards really are. However, red teamers lack biology knowledge, and biology experts lack risk knowledge, so OpenAI is engaging with both groups to maximize the effectiveness of its safety measures.
Other security controls OpenAI has implemented include access controls, infrastructure hardening, egress controls, dedicated threat intelligence, and insider-risk programs. Simultaneously, it is investing in further research in studies that “assess novices’ success on harmless proxy tasks”. All of these measures are being designed and implemented in collaboration with government partners, including the US CAISI, UK AISI, and Los Alamos National Lab.
Despite various methods and assessments, predicting “real-world misuse” is nearly impossible. In an environment where a single error can be deadly, perfection is a necessity.
Going Forward: Scaling & Limitations
Deep expert and government collaboration is needed to universally implement safeguards with no gaps. OpenAI is hosting a biodefense summit in July 2025, bringing together government researchers, NGOs, and other experts to discuss the risks of dual-use technologies, share security progress, and explore how frontier models can accelerate research.
However, many limitations still exist. For instance, most major AI chatbots are vulnerable to jailbreaks -- ways in which users can hack security protocols, rendering them useless. Solving these issues and standardizing them are the only way to ensure that risks do not turn into reality.