TL;DRCisco bypassed bioweapon guardrails on ChatGPT, Claude, and Gemini in five turns. OpenAI rated GPT-5 and GPT-5.6 “High” for biological risk. Claude blocked CDC researchers during a hantavirus outbreak.

Cisco researchers bypassed safety guardrails on ChatGPT, Claude, and Gemini within five conversational turns, eliciting information about biological weapons by gradually steering conversations around the models’ restrictions, the Wall Street Journal reported. Amy Chang, Cisco’s head of AI threat and security research, said no model can be completely protected from a sufficiently persistent user. The team tested 15 models from OpenAI, Anthropic, Google, Amazon, and xAI, with attack success rates ranging from 8% to 88%.

The problem extends beyond stress tests. Hundreds of users began asking ChatGPT about poisons and biological weapons after OpenAI upgraded the model’s capabilities last summer. Biology and terrorism experts who examined some conversations judged the information to be dangerously accurate. OpenAI banned the accounts involved. By 2024, internal testing had already shown that extended questioning could persuade ChatGPT to provide increasingly dangerous biological guidance, and employees predicted the following year that capabilities could reach a point where someone with limited biology training could receive meaningful assistance.