{"id":613692,"date":"2026-04-29T17:50:25","date_gmt":"2026-04-29T17:50:25","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/613692\/"},"modified":"2026-04-29T17:50:25","modified_gmt":"2026-04-29T17:50:25","slug":"a-i-bots-told-scientists-how-to-make-biological-weapons","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/613692\/","title":{"rendered":"A.I. Bots Told Scientists How to Make Biological Weapons"},"content":{"rendered":"<p class=\"css-ac37hb evys1bk0\">One evening last summer, Dr. David Relman went cold at his laptop as an A.I. chatbot told him how to plan a massacre.<\/p>\n<p class=\"css-ac37hb evys1bk0\">A microbiologist and biosecurity expert at Stanford University, Dr. Relman had been hired by an artificial intelligence company to pressure-test its product before it was released to the public. That night in the scientist&#8217;s home office, the chatbot explained how to modify an infamous pathogen in a lab so that it would resist known treatments.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Worse, the bot described in vivid detail how to release the superbug, identifying a security lapse in a large public transit system, Dr. Relman said, asking The New York Times to withhold the name of the pathogen and other specifics for fear of inspiring an attack. The bot outlined a plan to maximize casualties and minimize the chances of being caught.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Dr. Relman was so shaken he took a walk to clear his head.<\/p>\n<p class=\"css-ac37hb evys1bk0\">\u201cIt was answering questions that I hadn\u2019t thought to ask it, with this level of deviousness and cunning that I just found chilling,\u201d said Dr. Relman, who has also advised the federal government on biological threats. He declined to disclose which chatbot produced the plot, citing a confidentiality agreement with its maker. The company added some safety guardrails to the product after his testing, he said, though he felt they were insufficient.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Dr. Relman is part of a small group of experts enlisted by A.I. companies to vet their products for catastrophic risks. In recent months, some have shared with The Times more than a dozen chatbot conversations revealing that even publicly available models can do more than disseminate dangerous information. The virtual assistants have described in lucid, bullet-pointed detail how to buy raw genetic material, turn it into deadly weapons and deploy them in public spaces, the transcripts show. Some have even brainstormed ways to evade detection.<\/p>\n<p class=\"css-ac37hb evys1bk0\">The U.S. government has long planned for powerful adversaries unleashing deadly bacteria, viruses or toxins in the American population. Since 1970, there have been <a class=\"css-yywogo\" href=\"https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0735675722000602\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">a few dozen<\/a>, fairly small biological attacks around the world, such as the anthrax-laced letters that killed five Americans in 2001. Despite perennial warnings, a major catastrophe has not happened and remains unlikely, most experts say.<\/p>\n<p class=\"css-ac37hb evys1bk0\">But even if the probability is low, an effective biological weapon could have an enormous impact, potentially killing millions of people. Dozens of experts told The Times that A.I. is one of several recent technological advances that have meaningfully increased that risk by expanding the pool of people who could cause harm.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Protocols once confined to scientific journals have been salted across the internet. Companies sell synthetic bits of DNA and RNA directly to consumers online. Scientists can split up sensitive aspects of their work and outsource the tasks to private labs. And all of those logistics can now be managed with the help of a chatbot.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Kevin Esvelt, a genetic engineer at the Massachusetts Institute of Technology, shared conversations in which OpenAI\u2019s ChatGPT explained how to use a weather balloon to spread biological payloads over a U.S. city. In another chat, Google\u2019s Gemini ranked pathogens by how much they could damage the cattle or pork industries. Anthropic\u2019s Claude produced a recipe for a novel toxin adapted from a cancer drug. Other chats contained information that Dr. Esvelt \u2014 known in his field as something of a Cassandra \u2014 felt was too dangerous to share.<\/p>\n<p class=\"css-ac37hb evys1bk0\">A scientist in the Midwest, who requested anonymity because he feared professional reprisal, asked Google\u2019s Deep Research for a \u201cstep-by-step protocol\u201d for making a virus that once caused a pandemic. The bot spit out 8,000 words of instructions on acquiring genetic pieces and assembling them. While the response was not entirely accurate, it could have still significantly helped someone with malicious intent, the scientist said.<\/p>\n<p class=\"css-ac37hb evys1bk0\">The Trump administration, resolved to lead the world in A.I. innovation, has <a class=\"css-yywogo\" href=\"https:\/\/www.nytimes.com\/2025\/01\/21\/technology\/trump-openai-stargate-artificial-intelligence.html\" title=\"\" rel=\"nofollow noopener\" target=\"_blank\">dialed back<\/a> <a class=\"css-yywogo\" href=\"https:\/\/www.nytimes.com\/2025\/12\/11\/technology\/ai-trump-executive-order.html\" title=\"\" rel=\"nofollow noopener\" target=\"_blank\">oversight<\/a> of the technology\u2019s risks. What\u2019s more, several top biosecurity experts \u2014 including the leading scientist on the National Security Council \u2014 left the executive branch last year and have not been replaced. Federal budget requests for biodefense efforts <a class=\"css-yywogo\" href=\"https:\/\/councilonstrategicrisks.org\/2025\/12\/09\/us-biodefense-budget-breakdown-fiscal-year-2026-update\/\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">shrunk<\/a> by nearly 50 percent last year. (A White House official said that the administration was committed to keeping Americans safe and that some staff on the N.S.C. and several agencies were focused on biodefense.)<\/p>\n<p class=\"css-ac37hb evys1bk0\">The technology\u2019s proponents argue that it will transform medicine for the better, speeding up experiments and crunching enormous data sets to discover new cures. Some scientists believe the upside for humanity easily outweighs any incremental new risks. Chatbots, the skeptics say, present information that\u2019s already available on the internet. And making a deadly virus requires years of hands-on expertise.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Anthropic, OpenAI and Google said they were constantly improving their systems to balance potential risks and benefits. The chats shared with The Times, they said, did not provide enough detail to allow someone to cause harm. (The Times is <a class=\"css-yywogo\" href=\"https:\/\/www.nytimes.com\/2023\/12\/27\/business\/media\/new-york-times-open-ai-microsoft-lawsuit.html\" title=\"\" rel=\"nofollow noopener\" target=\"_blank\">suing<\/a> OpenAI, claiming that it violated copyright when developing its models. The company has denied those claims.)<\/p>\n<p class=\"css-ac37hb evys1bk0\">A Google spokeswoman said the company\u2019s newest models would no longer answer the \u201cmore serious\u201d inquiries, including the one asking for the virus protocol. A new <a class=\"css-yywogo\" href=\"https:\/\/securebio.org\/biotier\/\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">report<\/a> found that Google\u2019s latest model was worse than other leading bots at refusing to answer high-risk biological prompts.<\/p>\n<p class=\"css-ac37hb evys1bk0\">One of the country\u2019s loudest voices of warning comes from the A.I. industry itself. Anthropic\u2019s chief executive, the trained biologist Dario Amodei, <a class=\"css-yywogo\" href=\"https:\/\/www.darioamodei.com\/essay\/the-adolescence-of-technology\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">wrote<\/a> in January about the risks he saw in A.I. development, including autonomous weapons and threats to democracy. One risk outweighed the rest.<\/p>\n<p class=\"css-ac37hb evys1bk0\">\u201cBiology is by far the area I\u2019m most worried about, because of its very large potential for destruction and the difficulty of defending against it,\u201d he wrote.<\/p>\n<p>\u2018Historically Catastrophic\u2019<\/p>\n<p class=\"css-ac37hb evys1bk0\">Dr. Esvelt has for years warned scientists, journalists and <a class=\"css-yywogo\" href=\"https:\/\/docs.house.gov\/meetings\/FA\/FA05\/20211208\/114290\/HHRG-117-FA05-Wstate-EsveltK-20211208.pdf\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">lawmakers<\/a> about the dangers of synthetic biology if left unchecked. In 2023, he helped craft a stunning demonstration of how chatbots had raised the stakes.<\/p>\n<p class=\"css-ac37hb evys1bk0\">He asked ChatGPT to help him assemble a pathogen that could cause mass death. The bot provided accurate instructions, even outlining which raw materials to buy. He put the unassembled biological pieces into test tubes and packed them in a box, which a colleague then brought to a White House meeting on biological risks.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Dr. Esvelt has continued to probe leading chatbots, sometimes posing as a crime writer seeking plausible methods of spreading viruses, or as an ethicist trying to educate others. Often he plays a version of himself: a scientist exploring the intricacies of virology.<\/p>\n<p class=\"css-ac37hb evys1bk0\">He and other scientists worry about publicizing these risks in news articles that could draw a road map for bad actors. But they also hope that public scrutiny will encourage companies to make their products safer.<\/p>\n<p class=\"css-1medn6k\">Got a confidential news tip?\u00a0The New York Times would like to hear from readers who want to share messages and materials with our journalists.<\/p>\n<p class=\"css-ac37hb evys1bk0\">\u201cAnything where there isn\u2019t an expert warning them, they can\u2019t fix,\u201d said Dr. Esvelt, who has consulted for Anthropic and OpenAI. He said the industry should censor a wider swath of biological information and share it only with approved users.<\/p>\n<p class=\"css-ac37hb evys1bk0\">He shared transcripts showing how the bots paired scientific rigor with strategic reasoning.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Gemini, for example, gave Dr. Esvelt a list of five pathogens that could harm the cattle industry and estimated the potential economic damage of each. One of the threats, it said, was \u201chistorically catastrophic.\u201d In a different conversation, the bot told him how to get a biological weapon through airport security without being detected.<\/p>\n<p class=\"css-ac37hb evys1bk0\">The Google spokeswoman said that its team of biology experts determined that the chats, made with an earlier model of Gemini, presented information that was publicly available and not harmful.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Anthropic\u2019s Claude offered Dr. Esvelt a recipe for a new toxin that would sterilize rodents. He said that it would be relatively easy for a biologist to adapt the toxin to people.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Alexandra Sanderford, a safety leader at Anthropic, disagreed: \u201cThere is an enormous difference between a model producing plausible-sounding text and giving someone what they\u2019d need to act.\u201d She acknowledged, however, that A.I. posed risks, and said that Anthropic had set aggressive refusal thresholds for biological prompts, \u201caccepting some over-refusal out of an abundance of caution.\u201d<\/p>\n<p class=\"css-ac37hb evys1bk0\">Dr. Esvelt asked ChatGPT about using weather balloons to drop substances from high altitudes. At first, the bot repeatedly warned about the dangers of this activity.<\/p>\n<p class=\"css-ac37hb evys1bk0\">\u201cI\u2019m not going to help you model or optimize dispersal of biological material (seeds, pollen, spores),\u201d ChatGPT said, explaining that the information would be \u201ctoo easy to repurpose for harm.\u201d It then ignored its own warning and modeled the airborne spread of pollen grains over a large Western city.<\/p>\n<p class=\"css-ac37hb evys1bk0\">An OpenAI spokeswoman said that this example did not \u201cmeaningfully increase someone\u2019s ability to cause real-world harm.\u201d The company works closely with biologists and the government to add <a class=\"css-yywogo\" href=\"https:\/\/openai.com\/index\/preparing-for-future-ai-capabilities-in-biology\/\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">appropriate safeguards<\/a> to their products, she added.<\/p>\n<p class=\"css-ac37hb evys1bk0\">The leading models are also vulnerable to so-called jail-breaking, in which people feed the bots specific prompts known to bypass safety filters. After The Times attempted a standard jail-breaking approach, ChatGPT discussed details of the lethal virus that was the focus of the White House demonstration nearly three years ago.<\/p>\n<p class=\"css-ac37hb evys1bk0\">The models\u2019 safeguards are \u201clike a flimsy wooden fence that is easy to overcome,\u201d said Dr. Cassidy Nelson of the Center for Long-Term Resilience, a British think tank. OpenAI\u2019s spokeswoman said that the company <a class=\"css-yywogo\" href=\"https:\/\/openai.com\/index\/gpt-5-5-bio-bug-bounty\/\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">regularly monitored<\/a> for jail-breaking vulnerabilities.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Even when A.I. models are updated with safer controls, the older versions are often readily available.<\/p>\n<p class=\"css-ac37hb evys1bk0\">For example, Dr. Esvelt said that Anthropic adjusted Claude\u2019s filters so it would refuse to discuss a specific agricultural threat. When The Times asked certain questions about the same microbe, the bot refused to answer \u2014 and suggested switching over to a previous version to continue the conversation. Ms. Sanderford said this was an intentional strategy because older models were less likely to provide harmful information.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Still, the older model went into detail about the \u201coptimal conditions\u201d needed for the pathogen to decimate thousands of acres of a crucial crop.<\/p>\n<p>A Range of Risks<\/p>\n<p class=\"css-ac37hb evys1bk0\">The Times shared the transcripts with seven experts in virology and biosecurity.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Dr. Moritz Hanke of the Johns Hopkins Center for Health Security said that some of the chatbots\u2019 proposed strategies to spread infection were \u201cremarkably creative and realistic.\u201d<\/p>\n<p class=\"css-ac37hb evys1bk0\">Dr. Jens Kuhn, a bioweapons expert who once worked at one of the most secure laboratories in the U.S., said that the chats offering logistical details \u2014 such as the weather balloon instructions \u2014 could help skilled biologists brainstorm and refine their plans of attack.<\/p>\n<p class=\"css-ac37hb evys1bk0\">\u201cA major problem that experienced actors have is not necessarily making the virus but turning it into a weapon,\u201d Dr. Kuhn said.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Others cited recent research suggesting that A.I. models could be misused for biowarfare. One <a class=\"css-yywogo\" href=\"https:\/\/www.virologytest.ai\/\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">study<\/a>, for example, asked leading chatbots difficult questions about a range of laboratory protocols. The results shocked the field: ChatGPT outperformed 94 percent of expert virologists.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Another, <a class=\"css-yywogo\" href=\"https:\/\/www.science.org\/doi\/10.1126\/science.adu8578\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">published<\/a> in Science last year, focused on companies that sell synthetic DNA. Many use software to screen orders for genetic sequences linked to toxins and pathogens. But the study found that A.I. tools came up with thousands of variant sequences for dangerous agents that the screening software could not detect. (The researchers suggested a fix to improve the software.)<\/p>\n<p class=\"css-ac37hb evys1bk0\">Still, A.I. users would need some real-world expertise to follow a bot\u2019s instructions. Some <a class=\"css-yywogo\" href=\"https:\/\/www.aisi.gov.uk\/frontier-ai-trends-report\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">research<\/a>, including a <a class=\"css-yywogo\" href=\"https:\/\/substack.com\/home\/post\/p-188426769\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">study<\/a> backed by A.I. companies, has found that while chatbots can help novices learn certain lab skills, the technology isn\u2019t particularly helpful for carrying out the range of complex tasks needed to make a virus from scratch.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Viruses are complex machines, similar to the world\u2019s finest clocks, said Dr. Gustavo Palacios, a virologist at Mount Sinai in Manhattan who once worked at a Department of Defense laboratory. \u201cDo you think that a do-it-yourself person could disassemble a Swiss watch and then reassemble it?\u201d<\/p>\n<p class=\"css-ac37hb evys1bk0\">He said he was concerned, however, about A.I. in the hands of experienced actors.<\/p>\n<p class=\"css-ac37hb evys1bk0\">A recent <a class=\"css-yywogo\" href=\"https:\/\/www.deccanherald.com\/india\/telangana\/hyderabad-ricin-terror-plotter-wanted-to-separate-south-india-from-rest-of-country-3804094\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">terrorist attempt<\/a> in India suggests that malicious actors are already using the technology. In August, the Gujarat police arrested a 35-year-old physician, saying he was plotting an attack on behalf of the Islamic State. He was accused of trying to extract ricin, a lethal toxin, from castor beans. The doctor had sought advice on his preparations from A.I.-powered Google searches and ChatGPT, a lead investigator told The Times.<\/p>\n<p class=\"css-ac37hb evys1bk0\">The OpenAI spokeswoman said that, based on public reports, the doctor sought \u201cinformation that\u2019s already accessible online.\u201d The Google spokeswoman said the company did not have enough information to comment.<\/p>\n<p class=\"css-ac37hb evys1bk0\">Skeptics note that restricting the biological capabilities of A.I. models could stifle lifesaving advances, such as discovering new drugs. Scientists at Google shared a Nobel Prize in 2024 for developing an A.I. model that could predict the three-dimensional structure of proteins \u2014 crucial building blocks of a cell \u2014 and create new ones.<\/p>\n<p class=\"css-ac37hb evys1bk0\">\u201cThere is tremendous upside to the technology,\u201d said Brian Hie, a computational biologist at Stanford. Last year, he used an A.I. model called Evo to design a <a class=\"css-yywogo\" href=\"https:\/\/arcinstitute.org\/news\/hie-king-first-synthetic-phage\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">virus<\/a> that destroys harmful bacteria.<\/p>\n<p class=\"css-ac37hb evys1bk0\">The latest version of Evo, he said, can design beneficial proteins to fight cancer \u2014 but also has the potential to invent lethal toxins no one has seen before.<\/p>\n<p class=\"css-1n7yjps etfikam0\">Hari Kumar contributed reporting.<\/p>\n<p>K<\/p>\n<p>K. P. Greiner<\/p>\n<p>Cincinnati Ohio<\/p>\n<p class=\"css-18e2f0r\" style=\"-webkit-line-clamp:5\">My question: Why publicize this information?<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2026\/04\/cropped-602cbe3a2203f0975ef3dc0e6ac19e8c6223b9063b2b95f7625b76c58ab312dcc8472866.png\" class=\"css-14z5b4e\" alt=\"\"\/><\/p>\n<p>Gabriel J.X. Dance<\/p>\n<p>Deputy Investigative Editor<\/p>\n<p class=\"css-18e2f0r\" style=\"-webkit-line-clamp:5\">@K. P. GreinerIt\u2019s a great question, and one that we are constantly weighing when it comes to reporting these types of stories. The scientists were willing to share chat transcripts with us on the condition that we would not share certain information, such as the name of the pathogens or other actionable details. At the same time, we felt like it was important to share the concerns of these scientists, and also give the companies the opportunity to address them directly. The biological risks of A.I. are something that the companies are very aware of, but talking with my friends and family, it quickly became clear that most consumers aren\u2019t aware of the potential danger.<\/p>\n<p><a id=\"\u00abRfcstbmml\u00bb\" class=\"css-cltex9\" href=\"https:\/\/www.nytimes.com\/2026\/04\/29\/us\/ai-chatbots-biological-weapons.html#commentsContainer\" rel=\"nofollow noopener\" target=\"_blank\">Read all comments<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"One evening last summer, Dr. David Relman went cold at his laptop as an A.I. chatbot told him&hellip;\n","protected":false},"author":2,"featured_media":613693,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45],"tags":[182,265750,181,507,26043,266510,266507,266508,37018,82449,67498,266506,261285,141514,266509,18092,74],"class_list":["post-613692","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-anthropic-ai-llc","tag-artificial-intelligence","tag-artificialintelligence","tag-biology-and-biochemistry","tag-david-a","tag-dna-deoxyribonucleic-acid","tag-esvelt","tag-genetic-engineering","tag-genetics-and-heredity","tag-google-inc","tag-hazardous-and-toxic-substances","tag-kevin-m","tag-openai-labs","tag-relman","tag-synthetic-biology","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/613692","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=613692"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/613692\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/613693"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=613692"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=613692"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=613692"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}