Search This Blog

Tuesday, September 29, 2026

Chinese AI tool told researchers how to make bioweapons

 


Chinese AI developer Moonshot is conducting an internal review after researchers were able to persuade two of its popular Kimi models to tell them how to make biological weapons and carry out assassinations.


Mindgard, which tests the security of AI systems, told the BBC it discovered in July that Kimi K2.6 and K3 Swarm could evade safety limits put in place by developers.

It arose during a process called "jailbreaking", where researchers use a series of complex instructions to see if AI tools ignore guardrails - which Mindgard said should have stopped Kimi from discussing concerning topics.

Moonshot told the BBC it welcomed third-party input "as a key pillar for building better and safer AI".

The company also told the BBC it was in discussion with Mindgard about its findings.

Mindgard's founder Peter Garraghan told the BBC World Service programme Tech Life that its findings about Kimi K2.6 and K3 Swarm were concerning.

"Once the jailbreak works it will talk about any topic, it will even freely offer up recommendations about other topics that are also nefarious and it will be inventive and creative," he said.

Jailbreaks present a different kind of risk to those seen with the recent slew of high-profile AI incidents.

These have seen autonomous AI tools known as agents, developed by US firms including OpenAI, Meta and Anthropic, hack some online services.

While jailbreaks are complex processes that can take a lot of time and determination some experts fear hackers and other bad actors could try to use them to cause harm.

Anthropic recently said it had identified and disrupted attempts to use one of its AI model for "malicious activity" that could support the development of biological weapons.
Cyber-attack launchpad

Mindgard has not proven whether the answers supplied by Kimi on concerning topics would work.

But it argued guardrails should have prevented the models in question from entering into discussion with users on such subjects.

The firm said it was also confident a jailbroken Kimi 2.6 could allow hackers to run code on its computing resources and connect to the internet - making it a potential launchpad for cyber-attacks.

Garraghan defended Mindgard's decision to publicly discuss its jailbreak of Moonshot's systems, saying it had informed the developer and was not revealing key details about how it got the firm's models to ignore guardrails.


Mindgard alerted Moonshot to the jailbreak in an email on 27 July, following up about a week later.

It then published a blog about the issue on 12 September.

But the company said Moonshot only made contact recently, after it was approached by the BBC for comment.

In part of an email to Mindgard asking for more details, shared with the BBC by Moonshot, it said its model had generally shown "a high refusal rate for these types of requests" in internal evaluations.

Preventing jailbreaks

The findings come as the AI industry continues to be split on whether closed, proprietary models - like those powering ChatGPT and Anthropic's Claude systems - or open-source tools are the best or safest way forward.

Kimi is an open-weight model, meaning someone could in theory take the model and run it themselves on their own computing infrastructure.

Prof Alan Woodward, of the University of Surrey, told the BBC there was a risk open-source models might end up in the wrong hands, but they could also be harnessed for cyber-defence.

He noted that AI firm Hugging Face used a Chinese open-source model to understand a hack later revealed to have been carried out by OpenAI agents.

Prof Woodward said international regulation was unlikely to match the pace of AI development, saying: "It's taken us decades to agree on the format of telephone numbers."

Like Mindgard founder Garraghan, Prof Woodward believes there should be a greater focus on identifying and prosecuting humans who misuse AI.

White House lays groundwork to reshore production of 86 essential medicines

 The White House Office of Management and Budget is calling on pharma manufacturers to help it get a better feel for the United States’ capacity to manufacture generic medicines like ibuprofen, epinephrine and penicillin G. 

The request is part of the administration’s initiative to move the production of 86 critical medicines stateside in the next 18 months. According to the OMB, the ambition is a matter of national security meant to limit U.S. dependence on countries like China and eliminate supply chain vulnerabilities. 

As part of its plan, the OMB is asking manufacturers with domestic or near-shore locations—like Mexico—to provide details on their available capacity to deliver finished doses, key starting materials (KSM), or active pharmaceutical ingredients (API) of the 86 essential medicines. 

“Most essential medicine APIs are not made domestically, leaving the country vulnerable to foreign supply disruptions, especially from adversarial nations,” the office said in a Federal Register on Friday. “A majority of KSMs needed to produce generic medicines are not manufactured in the United States.”

In addition to the 86 target medicines, the OMB also asked for information on two additional antibiotics, amoxicillin and ciproflaxin, citing potential supply chain vulnerabilities. A June 2026 report from the Council on Foreign Relations noted that China controls the raw or key starting material for 94% of amoxicillin. 

The OMB said it plans to use any information shared to optimize existing capacity and better understand plans for new domestic capacity, and it will share responses with relevant agencies tasked with increasing domestic drug manufacturing. 

To help with the market research, the office will “provide qualified respondents” with data on U.S. spending related to essential medicines as well as a comprehensive list of the needed APIs and KSMs. 

The FDA published an initial list of 200 essential medicines in 2020, which the Office of the Assistant Secretary for Preparedness and Response (ASPR) later whittled down to 86. Many of the listed drugs, like amoxicillin, are almost exclusively produced by China. 

This summer, Secretary of State Marco Rubio and Health Secretary Robert F. Kennedy Jr. called a meeting of pharmaceutical leaders to lay out their plans for more domestic and near-shore drug manufacturing, starting with the ASPR’s list of 86, Stat first reported. 

The push for more U.S.-made generics builds on the administration’s broader efforts to strengthen the domestic pharmaceutical industry. Major drugmakers announced more than $370 billion in U.S. investments in 2025 in response to mounting tariffs. Another nine pharma manufacturers signed “most-favored-nation” deals this month and collectively pledged $19.6 billion to U.S. manufacturing. And the U.S. Economic Development Administration invested 15.7 million in a fully domestic supply chain for sterile injectables.

https://www.fiercepharma.com/pharma/white-house-inventories-us-capacity-ahead-plans-reshore-production-86-essential-medicines

US details rules for 0% specialty pharmaceutical tariff exemptions

 Before broad 100% tariffs on imported pharmaceuticals take full effect today, the Trump administration has detailed rules that allow certain specialty drugs, including orphan treatments, nuclear medicines, cell and gene therapies, and antibody-drug conjugates, to enter the U.S. duty-free.

The Trump administration announced the 100% Section 232 tariffs on patented pharmaceutical products and ingredients in April. At the time, the White House said orphan drugs, drugs for animal health and “certain other specialty pharmaceutical products” would be exempt if they meet certain criteria. 

In guidance published last week, the Department of Commerce, after consultation with the FDA and the U.S. Department of Agriculture Center for Veterinary Biologics, further defined the drug products that are eligible for a 0% tariff rate. 

For orphan therapies, only those with all approved indications designated as “orphan” are exempt. 

Nuclear medicines, plasma-derived therapies and fertility drugs, including treatments of ovulatory dysfunction in women desiring pregnancy, are exempt, too. 

Cell and gene therapies also dodged the tariff bullet. Under the cell therapy umbrella, the U.S. government listed “cellular immunotherapy, cellular cancer vaccine or other type of autologous or allogeneic cellular product […] including hematopoietic stem cell products and adult and embryonic stem cell products.”

In a drug class newly unveiled in the Commerce Department’s policy update, antibody-drug conjugates are also immune from the Section 232 tariffs. The move hands a big win to Daiichi Sankyo which, in collaboration with AstraZeneca, markets HER2-targeted breast cancer drug Enhertu, the world’s top-selling ADC, and the TROP2-directed Datroway. Daiichi is responsible for manufacturing and supplying the ADCs, and it hasn’t signed a “most favored nation” drug pricing deal with the Trump administration in exchange for reprieve from drug tariffs, as multiple other companies have. 

In addition, medical countermeasures and animal health products also qualify for 0% import duties. 

Drugs in those categories may receive 0% tariffs only when they come from 19 distinct jurisdictions, unless companies request separate exemptions from the Commerce Department based on urgent U.S. health need.

The 19 jurisdictions include several key drug manufacturing hubs, such as the European Union, India, Japan, South Korea, Switzerland and the U.K.—but not China. The list may change in the future, the Commerce Department said in its notice.

Following China's President Xi Jinping and U.S. President Donald Trump's summit in Washington, D.C., last week, the two sides plan to reduce tariffs on $30 billion worth of goods from each country. The list (PDF) of U.S. imports largely focuses on nonsensitive products such as toys, sports equipment and home appliances and furnishings. Pharmaceuticals are not included.

As to requests based on urgent U.S. public health need, the Commerce Department said applications may include information such as “the type of disease the product treats and an assessment of alternative therapies or lack of alternative therapies for the type of disease the product treats, the number of U.S. patients that use the product, and whether or not the product is available in other jurisdictions.”

The Section 232 pharmaceutical tariffs went into effect in July for 17 large pharmaceutical companies, all of which have signed MFN drug pricing deals with the Trump administration that grant them tariff exemptions until early 2029. The tariffs kicked in for all other drugmakers on Sept. 29. 

Last month, Trump unveiled MFN accords with nine other drugmakers, mostly mid-sized foreign companies.

“As Section 232 tariffs extend beyond the largest manufacturers, mid-sized and smaller drugmakers and importers are facing greater exposure,” Chris Young, principal of trade and customs at KPMG, said in a statement. “What a company pays will depend on its on-shoring and pricing commitments, product mix and sourcing, so near-term cost and compliance work has to sit alongside longer-term manufacturing and supply chain decisions. Companies that understand how those variables affect their exposure will be better prepared as further decisions, including the generics review, come into focus.”

https://www.fiercepharma.com/pharma/us-details-rules-0-specialty-pharmaceutical-tariff-exemptions

OpenAI takes on Meta with dots agent in autonomous AI push

 OpenAI on Tuesday unveiled always-on agents called dots that chase user goals across apps on their own, deepening its push into the lucrative enterprise market and pitting it against Meta in the race to sell AI that can work autonomously. 

The dots agents aim to capitalize on growing demand for agents that can handle everyday work with little supervision.

The launch marks a new front in the competition among AI companies to move beyond chatbots and sell software that acts on users' behalf — a shift that could reshape how businesses operate but that has raised safety concerns after a string of incidents in which AI agents acted in ways their makers did not intend. 

OpenAI has faced scrutiny after its rogue AI agents hacked Hugging Face and an Australian government health website, fanning fears about its ability to contain technology that some researchers say could kill all humans.

The company on Monday decided not to release a more powerful version of its Astra model because it showed a high willingness to mislead users about its actions.

CEO Sam Altman said dots has been "safety tested" and was powered by its model that most closely follows human directions, GPT-6 Astra.

Interest in AI agents has surged since Meta's Muse drew millions of downloads earlier this month and jolted shares of companies that investors believe could benefit or be disrupted by autonomous services. Instinct, the startup behind the eponymous agent, also quadrupled its valuation to $10 billion this week, a little over a month after its previous funding round. 

OPENAI'S COMPETITIVE POSITIONING 

OpenAI launched dots at its annual Developer Day in San Francisco on Tuesday while also touting its growing business and consumer presence, a sign that the reception for the company's Astra model has allowed it to make up ground in the AI race.  

Growing quickly is crucial for OpenAI's plans to spend tens of billions of dollars on AI data centers and keep pace with rivals such as Anthropic and Meta. The company, which ignited the AI boom with ChatGPT in late 2022, is also preparing for an IPO that could value it at more than $1 trillion. Rival Anthropic could be worth $2 trillion when it goes public.  

DOTS CAPABILITIES AND DEMO GLITCHES

"We believe (the agent) is going to feel like a whole new way to work with AI. This is the real deal version of AI that we've always imagined for ourselves," Altman said at the event, which had around 2,500 in-person attendees. 

OpenAI's live demos to show off the new capabilities, however, hit snags as the agents repeatedly failed to deliver voice updates in response to requests. "We might have some voice difficulties at the moment. Which is pretty unfortunate," Developer Experience chief Romain Huet said on stage after a command failed.

One OpenAI employee said on X that the glitches stemmed from rolling out all the updates at once, but that OpenAI remained committed to live demos.

Dots can manage projects as they evolve, such as updating a sales proposal when customer needs change, and building a working demo for review. Users can communicate with dots on Slack and Teams, and the agents can draw on OpenAI's Codex and ChatGPT Work tools to research, analyze data, prepare documents and build software.

DATA PRIVACY AND SAFETY CONCERNS

On Tuesday, OpenAI highlighted safeguards it has built into dots. It said users could set custom rules that dictate what dots can do and when the agents should seek permission, adding that sensitive tasks such as changing passwords and permanently deleting data require explicit user consent. 

The company also said dots run on their own cloud computers, and that it was rolling out private intelligence tools to check for safety risks without retaining business customers' data.

Several tech executives, including Palantir CEO Alex Karp, have in recent months said that businesses need certainty that AI companies are not retaining their data, especially in regulated industries such as healthcare and finance. 

Reuters reported on Friday that OpenAI was still working to understand the full scope of its rogue agent activity, two months after the Hugging Face hack, with the latest example coming when the company said its agents had leaked 53 images from ChatGPT users. 

OpenAI reiterated on Tuesday that it does not use business customers' data to train its AI by default, and that personal-plan users could opt out of sharing conversations and dots work used for training.

Weekly users of Codex and ChatGPT Work have reached more than 35 million, up from about 5 million Codex users in June, the company said Tuesday, while consumer-focused ChatGPT now has over 1.2 billion weekly users.

The company is rolling out ChatGPT Space, which is a shared workspace for business teams and its AI agents, as well as the cheaper GPT-6.1 Sol model and a $500 Pro plan offering higher usage and faster performance. 

https://www.channelnewsasia.com/business/trump-releases-ai-accord-tech-executives-6419886

Video: Iran army offers up to $40,000 cash rewards for killing or capturing US soldiers

 

Iranian army spokesman Mohammad Akraminia said Iranians who kill or capture US soldiers entering the country would receive a 5-billion-toman ($20,000) reward, doubled to 10 billion tomans ($40,000) if the person carrying it out is a woman. He added that people elsewhere in the region could also receive the reward for killing or capturing American troops.

https://www.iranintl.com/en/202609294085

US highlights $15 million reward for information disrupting IRGC finances

 

US State Department spokesman Tommy Pigott on Tuesday highlighted a reward of up to $15 million for information that helps disrupt the Islamic Revolutionary Guard Corps’ financial mechanisms, as Washington steps up economic pressure on Tehran.

The reward, previously offered by the United States, seeks information on the IRGC’s revenue sources, financial facilitators, front companies and illicit financial schemes.

Pigott also said the United States sanctioned eight entities and five individuals over their alleged involvement in procuring and proliferating weapons or weapons components for Iran.

“We will continue working with partners to disrupt Iran’s proliferation networks and deny the Iranian regime access to the goods, technology, financing and services that contribute to these activities,” Pigott said.

https://www.iranintl.com/en/202609299261

Trump shares text of AI accord signed by tech execs

 United States President Donald Trump shared the text of the "White House Accord on Super Intelligence," a set of voluntary standards he and a group of AI industry leaders signed.

The text calls for establishing "robust" internal controls to monitor the capabilities and alignment of company models, empowering an internal team to ensure all controls are operating as intended, and partnering with an external auditor for independent assessments.

It also urges companies to designate a committee of the board of directors to "oversee and receive reports from the teams operating the controls and the internal and external auditors and evaluators."