AI Generated 40,000 Potential Chemical Weapons Agents in Under Six Hours – but the Risk Is Contested
On the same day in September 2026, two articles reached conflicting conclusions: MIT Technology Review warns that it has never been easier to design dangerous pathogens, while WIRED quotes scientists who consider the risk — particularly of…

AI Generated 40,000 Potential Chemical Weapons Agents in Under Six Hours – but the Risk Is Contested
On the same day in September 2026, two articles reached conflicting conclusions: MIT Technology Review warns that it has never been easier to design dangerous pathogens, while WIRED quotes scientists who consider the risk — particularly of an autonomous AI deploying biological weapons — low. The disagreement is less about facts than about which scenario is actually being discussed.
The debate is no longer abstract. Recently, Anthropic CEO Dario Amodei argued that AI poses serious risk and that progress should be slowed. OpenAI CEO Sam Altman replied on X that he agreed the frontier needs pacing — "we need to pace the frontier" (MIT Technology Review, September 18, 2026). The week before, Anthropic published a report admitting that people had attempted to use its models to explore making the chikungunya virus more transmissible and a form of bird flu more dangerous. And on September 18, 2026, MIT Technology Review and WIRED both published pieces on AI and biological weapons — with profoundly different assessments.
One premise should be clear from the start: the 2022 study from Collaborations Pharmaceuticals and Anthropic's report are known here only through the two magazines' accounts. The underlying documents are not available in the present evidence base.
What the Warnings Rest On
The MIT Technology Review piece, written by Jessica Hamzelou, starts from the fear that AI could aid the design, production, and spread of biological weapons. The central evidence is not new, but remains the most cited: in 2022, researchers at Collaborations Pharmaceuticals used an AI molecular-design model in reverse — to generate potential chemical weapons agents rather than drugs. In under six hours, the model generated 40,000 molecules with potential as chemical weapons agents. Some were designed to be more toxic than known nerve agents (MIT Technology Review).
The experiment shows that a model trained on toxic-compound knowledge can quickly generate many candidates — not that any were actually produced, tested, or used. It is a distinction that recurs throughout the debate: between designing something in silico and producing it in the physical world.
Then there is Anthropic's report from the week before. According to MIT Technology Review, the company admitted users had attempted to use its models to explore making the chikungunya virus more transmissible, and creating a more dangerous form of bird flu. The source citation is cut off mid-sentence, so the report's details cannot be verified beyond this. What can be established is the company's own admission that such attempts occurred; how they were detected and handled is not detailed in the available accounts.
Biosecurity researcher Dunja Sabra at the University of Hamburg points in the same direction as the warnings. The chances, she tells MIT Technology Review, are that "someone determined would succeed eventually."
The Safeguards – and Why They Are Not Ironclad
MIT Technology Review lists three layers of protection that already exist:
- DNA synthesis screening: DNA synthesis companies can screen orders against sequences from dangerous pathogens before producing them.
- Red-team/blue-team analysis: Systematic tests in which security researchers try to get models to produce dangerous answers, and develop countermeasures.
- Model restrictions at AI companies: Companies have adjusted their tools to prevent them from providing scientific information that could be misused.
But the magazine notes that "none of these protections are ironclad." The safeguard architecture assumes the bottleneck lies in information and material access, and builds filter upon filter there. Each barrier can in principle be circumvented or fail — the question is how likely that is in combination.
The Counterargument: The Physical World Is the Bottleneck
The WIRED piece, titled "Why AI Isn't Likely to Wipe Out Humanity With Bioweapons," gathers scientists who rank the risk relatively low, despite what the magazine describes as alarm reaching "fever pitch, from Silicon Valley to Washington, DC" (WIRED).
The arguments point toward information — precisely what AI is best at delivering — not being the binding constraint.
David Bellamy, research scientist at the Institute of Foundation Models, says those capabilities are "not really the bottleneck in the production of bioweapons." Even if a model provided a complete design plan, materials, equipment, and practical know-how would remain.
Ginkgo Bioworks CEO Jason Kelly is more concrete: "The AI could not take over the lab," he says, partly because the humans working there could simply decline to procure the substances and equipment the bot requests.
Olivia Scharfman, biotechnology fellow at the think tank Institute for Progress, draws the line between today and a future scenario: "It is impossible for AI to access a fully autonomous lab and autonomously build a virus today because fully autonomous labs do not exist yet," she says. "But I do think that an AI could pay someone to do it for them."
Finally, Francois Belloux, professor of computational biology, relativizes the weapons capability of pathogens themselves: "The risks tend to be somewhat misunderstood," he says, noting that people "overestimate the value of pathogens as weapons."
Where the Assessments Diverge – and Where They Do Not
It is tempting to read the two pieces as direct opposites, but they largely address different scenarios.
MIT Technology Review focuses mainly on misuse by actors: humans using AI tools to design pathogens, encountering safeguards that exist but are not ironclad. Sabra's statement concerns a human actor with AI as a tool, not an autonomous AI.
WIRED focuses mainly on autonomous AI deployment: the scenario in which an advanced AI autonomously designs, produces, and releases a biological weapon. It is this scenario Kelly, Bellamy, and Scharfman consider unlikely — because autonomous labs do not exist, because humans in the system would refuse, and because physical assembly is the bottleneck.
The two scenarios do not require opposite assessments of the same question. It is fully consistent to believe a human with AI assistance can lower the threshold for harm (MITTR's concern) while believing an autonomous AI covertly building a weapon today is remote (WIRED's conclusion). The divergence still concerns something real: which scenario deserves society's attention and resources now.
Where they do not diverge: both sides acknowledge safeguards exist, and neither claims they are sufficient in every context. MITTR calls them "not ironclad"; Scharfman's quote shows that even in WIRED's panel, barriers can fail through humans.
The Unresolved Scenario: AI Paying a Person
Scharfman's assessment sits precisely between the two frames: fully autonomous labs do not exist, but an AI does not need autonomous facilities — only money and a willing person. The scenario is neither "malicious actor finds the recipe themselves" nor "AI takes over the laboratory," but a blend: AI as client, human as hands.
The sources offer no assessment of how likely this is, or which countermeasures would stop it. It is unresolved — and worth keeping explicitly unresolved.
The Ginkgo Project: A Company Claim About GPT-5
Kelly claims that Ginkgo Bioworks, which specializes in autonomous labs, recently ran a project with OpenAI in which the GPT-5 model ran a lab. This is a company claim, reported in WIRED, not independently verified. If true, it illustrates that automated lab capabilities are under rapid development. Without details on scope, degree of autonomy, and safety framework, it should be taken as an indication of direction — not a measure of today's capability for harm.
What Remains Unresolved
Several things cannot be established from the sources:
- How likely the "payment scenario" is. Neither source quantifies the risk or points to concrete countermeasures such as payment controls.
- The Ginkgo project with GPT-5. Exists only as the company's own description.
- The details of Anthropic's report. Known through a truncated account; how detection and handling occurred is unclear.
- Exact dates. The Amodei/Altman exchange happened "last weekend" relative to September 18, 2026, the report "last week" — precise dates cannot be established.
- Primary studies. Neither the Collaborations Pharmaceuticals study nor Anthropic's report is available in the evidence base.
Why It Is Worth Watching
The disagreement between the two outlets reflects a real tension in risk assessment: whether resources should go toward strengthening today's safeguards against human misuse — DNA screening, red-teaming, model restrictions — or toward preparing for a scenario that does not yet technically exist. The answer is probably "both," but the balance is unresolved.
The concrete things to watch are three: whether autonomous labs begin to work in practice, whether safeguards hold as models become more capable, and whether reports like Anthropic's can be supplemented with independent oversight. Until then, the most cautious conclusion is the one the experts themselves give: neither that AI has made biological weapons an immediate threat, nor that the concern can be dismissed.
Sources
- The specter of AI-enabled bioweapons is a wake-up call for biotech | MIT Technology Review — www.technologyreview.com
- Why AI Isn’t Likely to Wipe Out Humanity With Bioweapons | WIRED — www.wired.com