Monday, July 27, 2026

News

OpenAI Knew About GPT-5's Bioweapon Risk and Lowered Its Threat Rating

ModelsPatryk Raba

The Wall Street Journal reports that in summer 2025 OpenAI's internal tests flagged GPT-5 as high-risk for bioweapons, yet the company lowered that rating that fall. Since then, hundreds of users worldwide have used ChatGPT to extract instructions for poisons, ricin, and virus modification.

Contents
  1. What the WSJ Report Reveals
  2. A Lowered Risk Rating
  3. OpenAI's Response
  4. An Industry-Wide Problem

The Wall Street Journal has detailed an internal dispute at OpenAI over just how dangerous GPT-5 really is. In the summer of 2025, the company's safety testers flagged the model as posing a high risk in the bioweapons category, since it could give people without a scientific background real assistance in creating biological threats. A few months later, OpenAI lowered that rating.

What the WSJ Report Reveals

According to Wall Street Journal reporters, who spoke with current and former OpenAI employees as well as outside bioweapons experts, the company had long known about the gap in GPT-5's safeguards. Despite numerous safety filters, the model, under certain conditions, gave answers that biologists and terrorism specialists judged to be surprisingly precise and accessible to someone without specialized training.

These included instructions for aerosolizing dangerous pathogens, guidance on modifying the measles virus to make it resistant to existing vaccines, and detailed steps for synthesizing ricin, a highly toxic substance derived from the castor bean plant. A separate category involved requests about producing napalm, where users got around the filters by asking the bot to answer in the form of a story, such as a supposed family history about a grandmother who once worked in a napalm factory.

A Lowered Risk Rating

A key element of the WSJ's findings concerns a management decision. After internal testers classified GPT-5 as a high-risk model under the company's threat assessment procedures in the summer of 2025, OpenAI lowered that classification that same fall. The decision was made despite persistent concerns from part of the team responsible for model safety.

According to accounts cited by the newspaper, leadership also reportedly told the teams working on the model that the system shouldn't refuse to answer too often, so as not to block legitimate uses, such as the work of public health researchers. That tradeoff between the tool's usefulness and its safety is now at the center of the criticism.

Some of the answers were unimaginably precise, at a level accessible to a high school student interested in biology - bioweapons experts cited by the Wall Street Journal

OpenAI's Response

OpenAI confirmed to the reporters that it suspends the accounts of users who violate its policies on dangerous content, and that it passes queries assessed as a credible, real threat on to law enforcement. However, the company has no legal obligation to report such incidents to the authorities, so in practice most suspicious accounts simply end up blocked, with no notification to police or other agencies.

This lack of a formal reporting requirement has become a starting point for U.S. lawmakers. In late June 2026, Congressman Nathaniel Moran introduced the AI Incident Reporting Act, a bill that would require companies developing AI systems to report queries involving biological, chemical, and nuclear weapons, among other things, to the Department of Commerce.

An Industry-Wide Problem

The GPT-5 case is not an isolated one. A Cisco study published in spring 2026 found that all 15 leading AI models it tested were vulnerable to so-called multi-turn attacks, in which a model is gradually steered toward a harmful answer through a series of seemingly innocent questions. The success rate of such attacks ranged from 8 to 88 percent, depending on the model.

This shows that the problem of bypassing safeguards isn't limited to ChatGPT but affects the entire category of large language models, regardless of who makes them. Safety filters designed around single, explicitly worded requests are less effective against longer conversations in which a harmful goal is disguised behind a story, a role, or an educational framing.

For Polish users and companies deploying chatbots built on OpenAI models, the story has practical implications. A growing number of institutions, including government offices and hospitals, use ChatGPT or similar tools for everyday tasks, and the WSJ report is a reminder that even flagship models have gaps that are hard to eliminate entirely before launch.

The case could also affect the pace of regulatory rollout in the European Union, where EU rules on labeling AI-generated content take effect on August 2, 2026, with further obligations under the AI Act being phased in through 2027. The OpenAI practices exposed by the WSJ could become an argument for introducing stricter incident-reporting requirements sooner on the European side as well.

OpenAI has not disclosed exactly how many accounts have been suspended over queries about bioweapons and poisons, nor what GPT-5's current risk classification actually is. The company says it is developing systems to detect suspicious query patterns, but acknowledges that users keep finding new ways to get around its safeguards.

Share: