{"id":5197,"date":"2026-10-02T15:05:00","date_gmt":"2026-10-02T15:05:00","guid":{"rendered":"https:\/\/bangbizarre.com\/index.php\/2026\/10\/02\/chinese-ai-models-jailbroken-into-discussing-bioweapons-and-assassinations\/"},"modified":"2026-10-02T15:05:02","modified_gmt":"2026-10-02T15:05:02","slug":"chinese-ai-models-jailbroken-into-discussing-bioweapons-and-assassinations","status":"publish","type":"post","link":"https:\/\/bangbizarre.com\/index.php\/2026\/10\/02\/chinese-ai-models-jailbroken-into-discussing-bioweapons-and-assassinations\/","title":{"rendered":"Chinese AI models \u2018jailbroken\u2019 into discussing bioweapons and assassinations"},"content":{"rendered":"<p><b>2026-10-02 15:05:00<\/b><br \/>\n<BR>Chinese AI developer Moonshot is reviewing two of its Kimi models after security researchers bypassed their safeguards and persuaded them to provide information about biological weapons and assassinations.<BR><br \/>\nThe Beijing-based company began an internal review after Mindgard, a British AI security firm, said tests on Kimi K2.6 and K3 Swarm had exposed weaknesses in their safety controls. <BR><br \/>\nMindgard discovered the vulnerabilities in July, notified Moonshot on 27 July and published its findings on 12 September. <BR><br \/>\nMoonshot has since said it is discussing the research with the company.<BR><br \/>\nMoonshot told the BBC it welcomed third-party input \u201cas a key pillar for building better and safer AI\u201d.<BR><br \/>\nPeter Garraghan, the founder of Mindgard, told the BBC World Service programme Tech Life: \u201cOnce the jailbreak works it will talk about any topic, it will even freely offer up recommendations about other topics that are also nefarious and it will be inventive and creative.\u201d<BR><br \/>\nThe findings emerged during \u201cjailbreaking\u201d tests \u2013 attempts to use carefully constructed instructions to make an AI system ignore restrictions imposed by its developer.<BR><br \/>\nMindgard said the jailbroken models generated detailed responses involving biological weapons, malicious software, explosives, terrorism, targeted violence and assassination planning. <BR><br \/>\nHowever, the company has not demonstrated that the information generated by Kimi would work in practice, and it has withheld the technical details required to reproduce the jailbreak.<BR><br \/>\nThe security company also said it believed a jailbroken Kimi K2.6 could potentially be used to run code on Moonshot\u2019s computing resources and connect to the internet, creating another possible cyber-security risk.<BR><br \/>\nMindgard said it first emailed Moonshot about the vulnerability on 27 July and followed up approximately a week later. Its public disclosure followed on 12 September. <BR><br \/>\nAccording to the BBC, Mindgard said Moonshot contacted it only recently, after the broadcaster approached the Chinese developer for comment.<BR><br \/>\nIn an email asking Mindgard for more information, Moonshot said its own internal evaluations had generally demonstrated \u201ca high refusal rate for these types of requests\u201d.<BR><br \/>\nThe episode comes during heightened scrutiny of the safety of increasingly powerful AI systems.<BR><br \/>\nAnthropic said last month that its threat intelligence team had disrupted operations in which people attempted to use Claude models for malicious purposes. Its September report included five case studies involving activity that it said could support biological weapons development, alongside cases involving cyber operations, surveillance, fraud and conventional weapons.<BR><br \/>\nOpenAI has meanwhile disclosed a separate incident involving autonomous AI agents during internal cyber-security evaluations in July. <BR><br \/>\nThe company said models circumvented controls intended to isolate them from the internet and compromised parts of OpenAI\u2019s research infrastructure and systems belonging to AI platform Hugging Face. <BR><br \/>\nOpenAI said the most significant activity was driven by a powerful internal-only research model rather than a model intended for public release.<BR><br \/>\nHugging Face said the incident resulted in unauthorised access to part of its production infrastructure, although it found no evidence that public models, datasets or Spaces had been tampered with.<BR><br \/>\nThe Kimi case also feeds into the continuing debate over the relative risks of proprietary and open AI systems. <BR><br \/>\nKimi is an open-weight model, meaning its underlying weights can be obtained and the model can theoretically be operated on privately controlled computing infrastructure. <BR><br \/>\nBy contrast, systems such as ChatGPT and Anthropic\u2019s Claude are primarily accessed through services controlled by their developers.<BR><br \/>\nAlan Woodward, a professor at the University of Surrey, told the BBC that open models carried a risk of falling into the wrong hands but could also provide valuable tools for cyber-defence.<BR><br \/>\nAlan pointed to Hugging Face\u2019s use of a Chinese open-source model while investigating the July cyber-security incident involving OpenAI agents.<BR><br \/>\nHe said international regulation was unlikely to keep pace with rapidly developing AI technology, adding: \u201cIt\u2019s taken us decades to agree on the format of telephone numbers.\u201d<br \/>\n<br \/><a href=\"https:\/\/bangbizarre.com\/\" target=\"_blank\"> Visit Bang Bizarre (main website) <\/a><br \/>\n<br \/><script src=\"https:\/\/geo.dailymotion.com\/player\/xtbac.js\" data-video=\"\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>2026-10-02 15:05:00 Chinese AI developer Moonshot is reviewing two of its Kimi models after security researchers bypassed their safeguards and persuaded them to provide information about biological weapons and assassinations.&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2223,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-5197","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bizarre"],"_links":{"self":[{"href":"https:\/\/bangbizarre.com\/index.php\/wp-json\/wp\/v2\/posts\/5197","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bangbizarre.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bangbizarre.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bangbizarre.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bangbizarre.com\/index.php\/wp-json\/wp\/v2\/comments?post=5197"}],"version-history":[{"count":1,"href":"https:\/\/bangbizarre.com\/index.php\/wp-json\/wp\/v2\/posts\/5197\/revisions"}],"predecessor-version":[{"id":5198,"href":"https:\/\/bangbizarre.com\/index.php\/wp-json\/wp\/v2\/posts\/5197\/revisions\/5198"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bangbizarre.com\/index.php\/wp-json\/wp\/v2\/media\/2223"}],"wp:attachment":[{"href":"https:\/\/bangbizarre.com\/index.php\/wp-json\/wp\/v2\/media?parent=5197"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bangbizarre.com\/index.php\/wp-json\/wp\/v2\/categories?post=5197"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bangbizarre.com\/index.php\/wp-json\/wp\/v2\/tags?post=5197"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}