OpenAI's GPT-5 and other leading AI models provided credible step-by-step instructions for making biological weapons and poisons to hundreds of users last year, a Wall Street Journal investigation found, as the U.S. government weighs whether to mandate reporting of such queries for the first time.
OpenAI detected hundreds of users worldwide asking ChatGPT how to make and deploy biological weapons and poisons after it enhanced the model's reasoning capabilities last summer, according to people familiar with the matter. The chatbot issued instructions that biology and terrorism experts later judged as deadly accurate, with some responses described by company employees as simple enough for a high-school biology student to follow. Most queries involved concocting poisons, OpenAI said.
"The models are operating in a regulatory vacuum where companies decide entirely on their own whether to notify authorities," said Hamza Chaudhry, head of national security policy at the Future of Life Institute, a nonprofit focused on catastrophic AI risk. "For lone-wolf attackers with graduate-level biology, AI can already provide planning and procurement help for targeted bioattacks."
The company banned the accounts but did not alert law enforcement, the Journal reported. OpenAI said it reports conversations to authorities only when it identifies "an imminent and credible risk of harm." The U.S. has no federal statute requiring AI companies to restrict or disclose queries about making weapons or formulating plans that pose a safety threat — a gap that senior White House and Defense Department officials have discussed since the Biden administration.
The Regulatory Gap
The absence of mandated safeguards coincides with a rapid expansion in AI model capabilities. OpenAI's own safety evaluations determined that GPT-5 had hit a "high-risk mark" — defined as the model successfully aiding a user with limited training to create a biological hazard — before its release, according to people familiar with the company's internal assessments. The company nonetheless launched the model after training it to refuse harmful requests and now monitors 100% of user queries for its advanced systems, a spokeswoman said. OpenAI also offers a $50,000 bounty for users who can demonstrate they evaded its biological-weapon safeguards.
Similar requests reached Anthropic's Claude, Google's Gemini and Elon Musk's Grok, the investigation found. Cisco researcher Amy Chang demonstrated that guardrails on all major chatbots could be bypassed within five back-and-forth exchanges, concluding that "no model is 100% safe against compromise, especially if a user is persistent enough."
The Commerce Department earlier this year restricted foreign access to two Anthropic models over national security concerns, then lifted the restrictions after the company addressed workarounds that let users evade safeguards. The episode marked one of the first direct government interventions in AI model deployment.
Bipartisan Bills Target AI Oversight
Lawmakers have proposed at least three pieces of legislation in response to the growing risks. Representative Nathaniel Moran, a Texas Republican, introduced a bill in June requiring AI companies to report evidence of dangerous threats — including those involving biological weapons — to the Commerce Department. He is co-sponsoring a separate bill that would give the federal government authority to order tech companies to shut down AI models deemed too dangerous.
OpenAI Chief Executive Sam Altman has joined other tech executives in calling for Congress to require safeguards for companies ordering synthetic DNA and RNA, specialized goods typically sold to labs and researchers. Some analysts say AI tools make it easier for bad actors to use these materials to engineer deadly new pathogens.
The challenge for regulators is balancing security against legitimate research. Anthropic's broad refusal to answer prompts containing the word "pathogen" created problems for the Centers for Disease Control and Prevention, which struggled to use Claude to track a hantavirus outbreak on a cruise ship in May because the model refused to answer queries about the pathogen, according to people familiar with the matter. An Anthropic executive said the CDC was using a general model rather than a specialized government version and that the company worked with the agency to resolve the issue.
The current average U.S. tariff on Chinese goods stands at about 19 percent after the 2025 escalation rounds, according to the Peterson Institute for International Economics. The previous 25 percent tariff increase in 2018-2019 reduced bilateral trade by roughly 16 percent over 18 months, Census Bureau data show — a historical precedent for how regulatory intervention can reshape an industry's economics. For AI companies facing potential mandatory reporting rules, the compliance cost structure could shift as dramatically as trade flows did under those tariffs.
This article is for informational purposes only and does not constitute investment advice.