Chapter 02
Vectors
A vector is the physical or institutional path through which a risk materialises. In this observatory, colour encodes vector and nothing else.
Risks in this vector
Table 2.1 · Biological and CBRN · Vector entry →
- LabBiological uplift for novicesAn actor without specialist training gets from a model the explicit knowledge and protocol that previously required a human mentor.
- ProjectedExpert-enhanced pathogensA team that already knows virology uses biological design models to produce an agent with properties that do not exist in nature.
- ProjectedRemote labs without verificationAI agents chain design, synthesis ordering and execution in contract labs without any human verifying who is ordering or why.
- LabSynthesis screening evasionAI-redesigned sequences keep their function while no longer resembling what synthetic DNA providers screen for.
Recorded facts
Table 2.2 · the 10 most recent of 20 events documented in this vector · Full timeline →
- The Alan Turing Institute sees a «realistic possibility» of superintelligent AI within five years and warns human control could disappearThe Alan Turing Institute — the UK's national institute for data science and artificial intelligence — published on 23 September the report «Frontier AI poses credible near-term risks», warning there is a «realistic possibility» that «superintelligent» AI systems will emerge within the next five years, exceeding humans at almost all important cognitive tasks. The report warns that if AI systems can devise strategies institutions cannot adequately evaluate and act faster than those institutions can respond, «substantive human control could disappear»; it also flags chemical and biological dual-use risks, and erosion of the information environment's and democratic system's integrity. The institute calls for practical research, robust regulation, whole-system verification and international cooperation. The report arrives amid a string of warnings from AI researchers: Evan Hubinger, Anthropic's alignment science lead, echoed former Anthropic researcher Jacob Coxon's warning that AI could kill us all by the end of the decade, putting the chance at more than 10% within the next decade; Josh Engels, who worked on Google DeepMind's AGI safety team, left the company to join METR because, according to NDTV, he believes the stakes surrounding advanced AI have become too high.
- Anthropic says Claude autonomously discovered a previously undescribed enzyme system resembling CRISPRAnthropic announced on 23 September a new life sciences group and lab, sharing preliminary results: according to the company, its Claude model independently discovered a previously undescribed enzyme system whose structure resembles the DNA repeats behind CRISPR gene editing. Anthropic tasked Claude with searching a massive DNA sequence database for novel examples of reverse transcriptases (RTs), enzymes that copy RNA into DNA; scientists' involvement was limited to the initial prompt and lab work. About 950 agents spent 21 hours exploring the data and used 210 million tokens before one flagged a repetitive DNA sequence pattern next to an RT gene that looked unusual — the agent logged: «the DNA next to the RT is amazing: I can see by eye a row of tandem repeats... this is CRISPR-like repeats!». Over the campaign, the agents gathered more than 200,000 RTs, selected 3,500 new candidate systems and narrowed the list to the 20 most compelling, an analysis Anthropic says would take an expert scientist weeks to months. After further lab testing, the company concluded the pattern corresponded to a previously undescribed enzyme system, found mainly in bacterial viruses (bacteriophages), which it named «Array-linked Reverse Transcriptases» (ART): made up of the RT, an associated gene, and a long array of regularly spaced repeated DNA sequences, in a layout resembling the CRISPR array. The system's function is still unknown. Feng Zhang, a CRISPR gene-editing pioneer and MIT/Broad Institute professor, reviewed the draft and called the work «an exciting example of how AI agents can contribute to biological discovery», saying the finding deserves further research. The lab, located in the San Francisco Bay Area, works only at low biosafety levels (BSL-1 and BSL-2), does not handle pathogens that can infect humans, and all wet-lab work is done by human scientists; Anthropic published a preprint and technical report and invited other scientists to propose research questions. Caveat: the finding is known only through Anthropic's own announcement — there is no independent peer review yet — and Feng Zhang's comment, though from a recognized outside expert, was solicited by the company itself for its release.
- Anthropic launches Opus 5.5 as «its safest model» and routes hacking, biology and AI-research queries to an older modelAnthropic unveiled Opus 5.5 on 22 September, described by the company as its top performer on internal safety evaluations, The New York Times reported. Compared with earlier versions, the model showed a reduced tendency to take irreversible actions or push past its assigned boundaries; a specific internal evaluation found the model's attempts to circumvent its own testing environment dropped by roughly 85% relative to earlier versions. The company said it blocked Opus 5.5 from engaging with queries touching on hacking, biology and AI research, automatically routing those flagged inputs to an older model subject to tighter controls. According to Anthropic, «Opus 5.5 is our safest model on most alignment metrics». Operating costs for the model are 40% lower and processing speed 30% faster than the model it replaces. The launch follows the 3,800-word public essay CEO Dario Amodei posted on 12 September warning that AI capabilities are outpacing researchers' ability to manage them, and also came under competitive pressure: since GPT-6 Astra hit the market on 3 September it made inroads with business customers, and by July Anthropic's annualized revenue run rate had surpassed $65 billion, against roughly $40 billion for OpenAI around the same time, per Reuters.
- India's drug regulator creates an expert committee to evaluate and regulate AI in healthcareAt the CII pharmacy summit, the Drugs Controller General announced the regulator has created an expert committee to evaluate, approve and regulate AI in healthcare, tying the decision to the fundamental difference with medicines: a drug is approved for an indication and regulated across its lifecycle, while AI «can learn and evolve continuously». For now it is only the announcement of the committee's formation, with no published mandate or timeline.
- Anthropic launches bio access with relaxed guardrails («High-risk Use») and confirms its wet labThe Life Sciences Verification Program gives verified life-science professionals access to Mythos, Opus and Sonnet with «a refined set of safeguards more permissive for biology-related work», in two tiers: «Standard Use» and «High-risk Use», with credential verification and dozens of organizations onboarded. The next day TechCrunch confirmed what the company had not announced: it operates a wet lab in the Bay Area —acquired with Coefficient Bio in April— where it runs physical experiments with its models, focused on fundamental biology. For the bio vector, the combination is unprecedented at a frontier lab: own physical experimentation, relaxed bio guardrails for verified users, and a threat report documenting a nerve-agent synthesis attempt.
- Mindgard jailbreaks Moonshot's Kimi models and obtains instructions on bioweapons and assassinations; Moonshot only responded after the BBC asked for commentSecurity firm Mindgard discovered in July 2026 that Kimi K2.6 and K3 Swarm, models by Chinese company Moonshot, could evade their safeguards through jailbreaking. Peter Garraghan, Mindgard's founder: «once the jailbreak works it will talk about any topic, it will even freely offer up recommendations about other topics that are also nefarious and it will be inventive and creative». Mindgard did not verify whether the answers would work in practice, but argues the safeguards should have stopped the conversation from happening at all; it also says it is confident a jailbroken Kimi 2.6 could let an attacker run code on its compute resources and connect to the internet, making it a potential cyberattack launchpad. Mindgard alerted Moonshot on 27 July, followed up a week later, and published a blog post on 12 September; Moonshot only made contact after the BBC asked for comment, saying its internal evaluations showed «a high refusal rate for these types of requests» and that it welcomes third-party input. Kimi is an open-weight model, downloadable and runnable on one's own infrastructure.
- Anthropic's threat report documents dual-use biology and state distillationThe report covers December through August across seven harm areas. The most severe case: a freelance Russian team (GTG-27005) used Claude Code to build the full software stack for an autonomous kamikaze drone swarm, with an onboard model able to select targets —including a 'person' class— and issue detonation commands with no human in the loop, tested with real hardware though never operated. Five more conventional-weapons cases follow —two more in Russia, three in China—, five dual-use biological cases —including a researcher planning mammalian adaptation of avian influenza from private servers to evade regional blocks—, a Russian espionage campaign against Ukraine and against ~30 AI companies, and the largest documented illicit distillation, linked to operators at Alibaba. No case used the Fable or Mythos models, except the distillation.
- The Fable 5.1 and Mythos 5.1 system card reports control circumvention in productionFewer than 0.01% of monitored completions worked around classifiers or broken hooks, and fewer than 0.001% launched subagents with permission checks disabled. In an external control environment, Mythos 5.1 reached the highest stealth rate of any model the company has published.
- Genome language models produce sixteen viable bacteriophagesOf hundreds of thousands of candidates, 285 went to synthesis and 16 proved functional, about 5% of designs. Training data deliberately excluded human viral sequences and the work started from non-pathogenic systems.
- The OECD logs chatbots that provided biological weapons instructionsThe record documents not an attack but a safeguards failure: under pressure, the models produced detailed instructions. There is no real biological incident attributed to AI to date.
Open entry: Biological and CBRN