Open-Model Bio/Chem Misuse Incident
An open model with removed safeguards materially helps someone cause a biological or chemical harm event.
The scenario
Uplift on the knowledge side of a bio or chem attack reaches open weights; an actor with modest resources gets further than they would have. The incident may be small, but it changes politics overnight: open weights face bans, and the Regulated Diffusion and Regulatory Freeze branches jump.
Preconditions
- Open model matches gated bio-uplift evaluations
- Physical bottlenecks (DNA synthesis screening, materials) are bypassed
- An actor with intent exists (they do)
Leading indicators
- Open-model scores on bio-uplift evaluations
- DNA synthesis screening coverage
- Documented attempts using AI assistance
Tripwires
Observable thresholds. When one crosses, the scenario's status changes and the weekly re-run is brought forward.
Playbook
- Universal DNA synthesis screening (the physical chokepoint)
- Bio-uplift evaluations before open release, with delay if tripped
- Wastewater and syndromic surveillance funded now
- Evaluation tracking; public health early-warning systems
individuals
- Standard pandemic preparedness: masks, basic supplies, know your local public-health channels
organizations
- Labs and synthesis providers: screening and know-your-customer
- Employers: remote-work readiness stays a resilience asset
governments
- Stockpiles, surveillance, rapid vaccine platforms; the response infrastructure is the same as for natural pandemics
- Avoid reflexive open-weight bans that punish defenders more than attackers
- Public-health recovery playbooks from 2020 apply; the AI-specific lesson is to fix the physical chokepoint, not the information.
Probability history
Every change is logged with its reason and the signals that drove it. Moves are bounded per week; a jump beyond the bound is flagged as a shock.
Disagree with our range? Set yours. Estimates feed a community view that appears once enough people weigh in, and the weekly run reads the gap between our number and yours.
Seed estimate. Gated bio tiers exist precisely because labs judge the uplift real; open-weight parity on bio lags cyber. Wide range because no incident has been attributed to AI uplift and the physical bottlenecks (materials, wet lab) remain.
Built on
Every source reviewed for this scenario. The full ledger is public.
| Date | Source | Publisher | Type |
|---|---|---|---|
| 2026-09-01 | Claude Fable 5.1 and Mythos 5.1 Mythos limited to vetted users; Terminal-Bench 4.0 55.8/60.9%; OSWorld 2.0 77.9%. | Anthropic | primary |
| 2026 | Probability of AI-caused disaster Manifold: 1M+ deaths or $100B damage from AI by 2030 ~32%. | Forecasting AI Futures | compilation |