Report: AI Guardrails Easily Cracked, Could Become Biological Weapon “Recipe”

An independent research laboratory, Crimson Flare, issued a report in August warning that terrorist organizations and criminal groups may bypass the security mechanisms of open-source large language models (LLM) through technical means, allowing AI to help them obtain “recipes” (production methods) for manufacturing explosives, chemical, and biological weapons, posing an increasingly serious threat to national security.

The report indicated that open-source models such as Meta’s Llama series and Alibaba’s Qwen3.8-27b can be downloaded for offline use on computers, originally equipped with security barriers and relevant mechanisms to reject sensitive requests.

Researchers at Crimson Flare laboratory stated that these security barriers can be quickly removed through a technique called “abliteration,” which is mainly applicable to open-source large language models. Furthermore, tools for executing “abliteration” can be found on multiple open-source platforms.

It was pointed out that some versions of the models with removed security mechanisms have been uploaded to the internet, and users can download them easily for various purposes.

One model creator told the Daily Mail that these modified AI models can provide answers related to “tools, chemicals, exploit codes, violence, pornography, and other potentially illegal content.” He also emphasized, “The model will not decide whether to cooperate, it is up to the user to decide what content they want.”

The report warned that AI with removed security mechanisms may allow malicious actors lacking expertise in biology and chemistry to obtain complete steps and knowledge for manufacturing explosives, chemical, or biological weapons in a short period, potentially enabling access to highly lethal weapons like anthrax.

The report believes that “powerful, unchecked open-source large language models can run offline on consumer-grade hardware, posing a serious and increasingly growing threat to national security.” Since the models can operate offline on personal computers, intelligence agencies will be unable to monitor usage records through network monitoring or detect suspicious activities.

Professor Alastair Hay, a toxicologist and chemical warfare expert from the UK, after seeing the results provided by one of the AI models, told the Daily Mail that “AI clearly lowers the technological threshold needed for people to manufacture hazardous substances.”

He explained, “In the past, we did not have to worry about ordinary individuals manufacturing these hazardous substances because it required a higher level of technical and knowledge threshold, and untrained individuals attempting high-risk substances would also need to bear corresponding risks.”

Professor Hay stated, “The steps provided by AI today are like a recipe, with the relevant concentrations for production clearly written,” making the difficulty of manufacturing these hazardous items almost equivalent to a “student experiment level.”

Zain Ul-Haq, former digital forensics lead at Lancashire Police, also described AI as a “one-stop tool,” allowing individuals to complete relevant preparations at home.

Multiple research and policy reports highlight concerns from scientists and policy researchers about the potential misuse of AI, eventually creating bio-weapons beyond human control.

James Black, AI biosafety researcher and visiting scholar at Johns Hopkins University, pointed out two major risks: one being that ordinary individuals may learn to manufacture existing bio-weapons like anthrax through AI chat learning, and the other being well-resourced organizations or countries potentially combining professional bio-software to design new bio-weapons.

Doni Bloomfield, a law professor specializing in biosecurity at Fordham University, highlighted that the greatest potential threat to humanity may be AI aiding in modifying existing viruses like influenza, COVID-19, enhancing their destructive capabilities, or evading the human immune system.

Martin Pacesa, a structural biologist from the University of Zurich, expressed concerns that theoretically, people could develop toxins akin to ricin, which are challenging to detect with current methods, causing him sleepless nights.

In addition, institutions like the National Academy of Sciences (NAS) in the United States remind that the current capabilities of AI in designing entirely new pandemic pathogens are still limited by data shortage and experimental verification constraints. Some experts believe that synthetic customized DNA is mostly controlled by physical laboratories and national regulations, serving as a crucial defense line to prevent harmful pathogens from being rapidly produced.