Dario Amodei
CEO, Anthropic
Within 2–3 years AI could let many more actors carry out large-scale biological attacks
01 / THE ORIGINAL CLAIM
“a straightforward extrapolation of today’s systems to those we expect to see in 2-3 years suggests a substantial risk that AI systems will be able to fill in all the missing pieces, if appropriate guardrails and mitigations are not put in place. This could greatly widen the range of actors with the technical capability to conduct a large-scale biological attack.”
Dario Amodei ·
Deadline given: within 2–3 years (by July 2026)
02 / THE REALITY CHECK
FAKEThe deadline passed in July 2026. With safety filters off, novices using frontier AI did no better in a real wet-lab trial than novices with only the internet, and no AI-enabled biological attack has been reported.
Deadline passed 58 days ago
03 / FOLLOW THE EVIDENCE
What actually happened.
-
01
Jul 25, 2023: In written Senate testimony, Amodei said today's AI could fill in some bioweapon steps 'incompletely and unreliably', and warned that systems 2–3 years out might fill in all of them.
judiciary.senate.gov ↗ -
02
Jan 2024: A RAND red-team exercise found 'no statistically significant difference in the viability of plans generated with or without LLM assistance' for biological attacks.
rand.org ↗ -
03
May 2025: Anthropic's uplift trial for Claude Opus 4 (safeguards removed, written plans only) measured 2.53× uplift, below the 2.8× it deemed acceptable, and 'all participants hit critical failures'. It still applied ASL-3 protections as a precaution.
www-cdn.anthropic.com ↗ -
04
Jan 2026: Amodei wrote that models 'are likely now approaching the point where, without safeguards, they could be useful in enabling someone with a STEM degree but not specifically a biology degree to go through the whole process of producing a bioweapon.'
darioamodei.com ↗ -
05
Feb 2026: In a pre-registered RCT run by Active Site with METR (153 novices, June–Aug 2025, models including Claude Opus 4, o3 and Gemini 2.5), 5.2% of the AI arm completed a viral reverse-genetics workflow versus 6.6% of the internet-only arm (P = 0.759).
arxiv.org ↗ -
06
Jul 2026: The WSJ reported that hundreds of users had asked ChatGPT how to make bioweapons and poisons, and experts judged some answers 'deadly accurate'. OpenAI banned the accounts, and no resulting attack was reported.
cybersecasia.net ↗
Why it didn't happen
His claim can be tested: did AI widen who can carry out a large-scale biological attack? The only large randomized wet-lab trial says no. With mid-2025 frontier models and safety classifiers switched off, 5.2% of novices completed a viral reverse-genetics workflow, versus 6.6% with the internet alone. RAND and OpenAI's own earlier studies found no significant uplift either, and no AI-enabled biological attack has been reported. Six months before the deadline, Amodei himself wrote that models were only 'approaching the point'. Labs labeling models 'high risk' as a precaution is not evidence the capability arrived, and chatbots handing out bioweapon instructions (WSJ, 2026) is an information risk, not the ability to carry out an attack.
Inspect the original source capture
Evidence
- RAND (Jan 2024): no significant difference in bio-attack plan viability with LLMs rand.org ↗
- OpenAI ChatGPT agent system card (Jul 2025): treated as 'High' biological capability as a precaution, without 'definitive evidence' of novice uplift openai.com ↗
- OpenAI (Jan 2024): GPT-4 gave 'at most a mild uplift', not statistically significant (100 participants) openai.com ↗
- Active Site RCT (Feb 2026): 5.2% AI arm vs 6.6% internet arm completed the wet-lab workflow arxiv.org ↗
- International AI Safety Report 2026: 'substantial uncertainty about how much these capabilities increase real-world risk' internationalaisafetyreport.org ↗
- Nov 2025 India ricin plot (chatbot used for research) disrupted before any toxin was isolated gnet-research.org ↗