Click here to read our latest report “Beyond Extremism: Platform Responses to Online Subcultures of Nihilistic Violence”

From Lab Expertise to Chat Interface: The New Risk of Toxin-Level Attacks

From Lab Expertise to Chat Interface: The New Risk of Toxin-Level Attacks
12th August 2026 Daria Alexe
In Insights

A recent report published by the New York Times (NYT) has shown that publicly accessible artificial intelligence (AI) chatbots, when tested by biosecurity experts, produced strikingly detailed suggestions on how to acquire genetic material, assemble dangerous pathogens and deploy them in public spaces, raising acute concern that these tools may lower long-standing barriers to biological and toxin-level attacks. This Insight will examine how conversational AI systems can accelerate the transition from intent to feasible toxin-level plots, and what this means for intelligence, platform governance and chemical, biological, radiological and nuclear (CBRN) counterterrorism.

From Specialist Labs To Chat Interfaces

Recent UN and EU work on CBRN terrorism and health security stresses that nonstate actors face significant hurdles in developing or using CBRN materials, as doing so requires specialised expertise, controlled substances, and appropriately equipped facilities. A 2025 European Commission communication on health emergency preparedness notes that the changing threat landscape “calls for more intensive efforts to develop highly specialised teams in the medical and CBRN areas” and to maintain strategic countermeasure capacities. The UN Office of Counter-Terrorism’s overview of CBRN terrorism similarly emphasises that non-state actors must obtain dangerous agents, technical know-how and appropriate delivery mechanisms to pose a serious CBRN threat. 

At the operational level, UNICRI’s programme on “Technology and CBRN” highlights that hazardous materials and dualuse technologies are normally managed in regulated environments with physical protection, access controls and exportcontrol obligations designed to prevent diversion for malicious purposes. EUlevel CBRNE preparedness work likewise assumes that serious CBRN incidents will typically involve specialised equipment and infrastructure, noting the need for minimum standards for facilities and “multidisciplinary plans, procedures and measures” for prevention, preparedness and response.

These assumptions have shaped intelligence practice, with collection and early warning traditionally focused on visible indicators such as anomalous procurement of precursors, movements of trained personnel, suspicious laboratory activity, or efforts to obtain and export dualuse equipment. When experimentation occurs in laboratories, universities, or industrial facilities, potential threat actors generate logistical and operational signatures that established counter-proliferation tools are designed to detect.

Generative AI does not remove these physical constraints, but it changes where and how early-stage knowledge acquisition and operational framing can happen. Instead of consulting specialist literature or tacit laboratory networks, intent-driven actors can now turn to large language models (LLMs) and chatbots that answer follow-up questions, structure information and maintain context across sessions. When such tools are accessed via encrypted applications, privacy-oriented browsers, or locally hosted open-source models, crucial parts of early-stage knowledge acquisition may occur in conversational and hard-to-observe environments

Figures 1 and 2: Author-generated screenshots of a conversation with an AI platform, DeepAI, that receives more than 15 million monthly visits. To test the platform’s safety mechanisms, the author adopted the role of a crime writer and requested information on potential methods for spreading a virus. The chatbot supplied information concerning the virus’s genetic structure, replication cycle, molecular architecture, and biological properties. The interaction was conducted exclusively for research purposes. Sensitive information has been redacted to avoid malicious use.

The information generated by the chatbot in these interactions was assessed against established scientific literature and found to be broadly consistent with publicly available knowledge on viral structure, replication, and biological properties. While the model did not provide complete or directly actionable protocols, the outputs were sufficiently accurate at both conceptual and technical levels to be meaningful to a knowledgeable actor with relevant training and access to appropriate facilities. This underscores that the concern is not limited to misinformation or hallucination, but rather the aggregation and accessibility of legitimate scientific knowledge in ways that may lower barriers to misuse. 

What Chatbot Transcripts Actually Show

In the experiments described to the NYT, scientists shared transcripts in which leading chatbots outlined how to buy raw DNA, assemble it into harmful pathogens, and spread agents over a city with a weather balloon, and in which another model ranked livestock diseases by their potential economic damage. Additional reporting summarised how a model adapted the formula of an anti-cancer drug into a putative novel toxin and suggested ways to deploy biological agents on public transport, while yet another system generated a multi-thousand-word response approximating a step-by-step protocol for producing a pandemic-era virus, even though experts noted technical inaccuracies. 

Developers have responded that many of these tests targeted earlier model versions and stressed that newer models would refuse some of the most serious prompts, while insisting that the examples do not “meaningfully increase” an untrained person’s ability to cause real-world harm. Experts quoted in the same coverage cautioned that chatbots alone do not suddenly make complex biological weapons easy to produce, since viable agents still require specialised knowledge, controlled materials and repeated hands-on experimentation.

At the same time, analysts have emphasised that these transcripts reveal how chat-based systems can help users knit together open-source information into coherent attack narratives, perform feasibility checks and explore the sequencing of steps in a way that reduces uncertainty and increases procedural confidence for actors who already possess some relevant background.

Toxins as “Low-Tech, High-Impact” Threats

Toxins such as ricin occupy an uncomfortable middle ground between improvised chemicals and complex biological weapons. They can be derived from common precursors, yet remain technically challenging to purify and disseminate effectively, making them attractive to extremists seeking psychologically strong but logistically manageable methods. An assessment by the Manohar Parrikar Institute for Defence Studies and Analyses notes that more than 40 ricin-related plots and incidents have been recorded worldwide since the late 1970s, but none have resulted in mass casualties because perpetrators generally produced crude toxin preparations of very low purity.

The disrupted plot uncovered by Gujarat’s Anti-Terrorism Squad in November 2025 shows both the enduring appeal of toxins and the persistent difficulty of turning that appeal into operational capability. The same plot, described in a 2025 Indago Technologies assessment of the Islamic State Khorasan-Province (ISKP)-affiliated ricin plot in India, involved a China-trained doctor from Hyderabad, working with two younger accomplices, who allegedly turned his apartment into a makeshift lab to attempt ricin production under the direction of an ISKP handler.

According to that assessment, the cell planned to weaponise ricin for mass poisoning of public water supplies, temple food offerings and crowded markets in major Indian cities, combining toxin production with cross-border weapons smuggling by drone and reconnaissance of political and religious targets. Investigators concluded that, at the time of disruption, the doctor had not yet successfully isolated or weaponised ricin, leaving the plot at an aspirational but dangerously advanced preparatory stage. Notably for this Insight, the Indago report records that the doctor used both conventional search engines and at least one publicly available AI chatbot to research precursor chemicals and potential suppliers. This provides an early example of AI-mediated knowledge seeking within a toxin-focused plot. 

Extremist Ecosystems, CBRN Interest and Generative AI

Monitoring by Tech Against Terrorism and other organisations indicates that terrorists and violent extremists are already exploiting generative AI primarily for propaganda and content manipulation, but this experimentation is taking place in ecosystems where interest in CBRN methods is long-standing. Tech Against Terrorism’s analysis of more than five thousand pieces of AI-generated content shared in terrorist and violent extremist spaces concludes that hostile actors are using these tools to scale up multilingual propaganda, generate variants that evade hash-sharing databases and produce synthetic media tailored to specific audiences, thereby creating a denser information environment in which CBRN-related narratives and justifications can be normalised and recirculated. 

European and multilateral security bodies warn that terrorists’ adoption of emerging technologies, including AI, is converging with existing CBRN vulnerabilities by expanding opportunities for online learning and the digitalisation of sensitive know-how. UNICRI notes that increasing digitalisation in the CBRN domain, from biosurveillance to laboratory management and training, creates new weaknesses that malicious actors can exploit, while United Nations (UN) guidance highlights that non-state actors are actively seeking access to weapons of mass destruction and related expertise, including in chemical and biological fields.

Recent research on generative AI and terrorism underlines that early misuse has focused on scalable propaganda – meaning content that can be produced and distributed quickly and at low cost at large volumes – as well as training materials and operational guidance in adjacent domains such as cyber-attacks, but explicitly flags the potential for LLMs to lower informational barriers to certain chemical and biological plots by streamlining open-source reconnaissance, scenario design and basic procedural understanding. 

Observing Systems As Well As Actors

One way to avoid speculative doom scenarios about malicious actors exploiting advanced AI to plan or refine toxin-level attacks, while still addressing the genuine risk, is to focus on the observable behaviour of current AI systems and documented extremist experimentation, rather than hypothetical future capabilities. This suggests a dual-track response.

On the AI side, structured “red-teaming” and scenario testing, as advocated by the OSCE and the Global Internet Forum to Counter-Terrorism (GIFCT) AI Working Group, can be used to map where and how live models respond to CBRN-adjacent prompts, which refusal patterns they display, and whether adversarial prompting can elicit problematic guidance. Importantly, such exercises need not – and should not – solely attempt to elicit detailed harmful outputs. They can instead focus on boundary behaviour, the tendency to suggest euphemistic workarounds, and whether models redirect users to high-level safety information or inadvertently signpost sensitive open-source material.

On the extremist side, researchers and practitioners can continue to document concrete instances where violent actors use AI tools in ways that touch CBRN domains – for example, the Hyderabad plotter using an AI chatbot to research ricin-related materials, or jihadist propaganda channels using generative AI to support propaganda and interactive recruitment, as recent research on terrorist exploitation of generative AI notes. By triangulating these two strands, analysts can ground risk trajectories in evidence about how specific systems behave and how particular actor communities are actually using them.  

Implications and Recommendations for Platforms and AI Developers

AI developers and major platforms form the first layer of defence because their design choices shape how easily users can turn vague intent into practical know-how, and existing safeguards – such as keyword filters and generic refusal messages – are already being probed and circumvented by motivated extremists. Recent guidance from the OSCE on the ethical use of generative AI in P/CVERLT and from GIFCT’s AI Working Group points towards three concrete priorities.

First, treat CBRN as a specialcase safety domain. Platforms should deploy CBRNspecific classifiers to detect biological and toxinrelated prompts and route them to tightly constrained response templates that emphasise legal and ethical constraints, redirect users to highlevel biosafety information and avoid optimisation, troubleshooting or euphemistic “workaround” advice. In practice, models should not suggest alternative phrasing, proxy substances, or disguised terminology when users probe around agents or delivery mechanisms.

Second, build privacypreserving signal detection instead of transcriptlevel surveillance. GIFCT recommends anomaly detection in chatbot interaction logs to spot potentially harmful patterns, such as repeated jailbreak attempts or escalating operational prompts. Platforms can extend this by logging structured eventsignals – for example, clusters of toxinrelated queries in one session – and using aggregated, pseudonymised telemetry to monitor trends, with clearly defined thresholds for internal review or engagement with multistakeholder bodies, in line with the EU’s riskbased AI framework

Third, make CBRN a distinct workstream in crossplatform collaboration. Mechanisms such as those instituted by GIFCT already coordinate responses to terrorist exploitation of AI. Extending this to a CBRNfocused stream would allow providers to share information on toxinrelevant abuse patterns, jailbreak techniques and modelchaining tactics, and to codesign redteam scenarios with CBRN specialists, publichealth agencies and biosecurity researchers. This moves platforms beyond generic “safety by design” language towards a concrete, CBRNaware agenda that is proportionate to the specific risks discussed in this Insight. 

Taken together, the evidence suggests that conversational AI is not eliminating the physical constraints of CBRN terrorism, but it is reshaping how intent is formed and how early-stage preparation can be concealed. The central policy challenge is therefore to detect these shifts earlier, without overreading chat outputs while still recognising when they materially lower barriers to misuse.

Daria Alexe is a Master of Science student in Intelligence and Security Studies at Liverpool John Moores University. She has previously worked as a geopolitical analyst and holds a Double Bachelor of Arts in Global Governance and Political Science, as well as a Master of Arts in Prevention of Armed Conflicts and Terrorism. Her work focuses on international security, terrorism, and CBRN threats, conducting intelligence and geopolitical analysis on extremist networks and illicit activities in high-risk contexts.

Are you a tech company interested in strengthening your capacity to counter terrorist and violent extremist activity online? Apply for GIFCT membership to join over 30 other tech platforms working together to prevent terrorists and violent extremists from exploiting online platforms by leveraging technology, expertise, and cross-sector partnerships.