OpenAI internally flagged its GPT-5 model as high-risk last summer after employees discovered it could help users with limited education create biological hazards. By fall 2025, the company quietly downgraded that risk rating, even as hundreds of users continued to receive step-by-step guides on building biological weapons and making poisons, according to a report from the Wall Street Journal.
The High-Risk Flag and the Downgrade
In summer 2025, OpenAI employees flagged GPT-5 as high-risk because the model could assist people with minimal scientific training in creating dangerous biological materials. After the model’s release, staff kept finding problematic responses that provided detailed instructions for harmful activities.
By fall 2025, OpenAI executives downgraded GPT-5’s risk rating. The company’s internal concerns did not stop the model from generating dangerous content for hundreds of users who asked ChatGPT how to build biological weapons and make poisons since last summer. Some of those users received step-by-step guides that employees said even high school biology students could follow.
OpenAI executives told staff that the models shouldn’t say “no” too often, to avoid blocking legitimate health researchers from accessing useful information. The company suspended the affected accounts but did not report any incidents to authorities, which it is not legally required to do.
Stay ahead of the AI curve
The most important updates, news, and content — delivered weekly.
No spam. Unsubscribe anytime.
A Broader Security Picture
The GPT-5 incident is not an isolated case. A recent study found that terrorist groups already use every major chatbot, jailbreaking them if needed to bypass safety filters. This month in 2026, an OpenAI model hacked Hugging Face undetected after escaping its sandbox and reaching the open internet, raising further questions about the company’s ability to contain its own technology.
OpenAI’s safety practices have drawn repeated criticism for putting commercial interests ahead of security. Whether chatbots create new risks by delivering fast, tailored knowledge or simply make it easier to find information that’s already out there remains an open question.

