Chinese AI Tool Told Researchers How to Make Bioweapons

A British security firm says two models from Chinese-based Moonshot discussed bioweapons and assassinations after a July test. The BBC reported the finding on 29 September 2026. Moonshot has opened an internal review. The practical value of the answers has not been shown. The delay before the company engaged has. UK firm Mindgard says it warned Moonshot on 27 July that Kimi K2.6 and K3 Swarm could be pushed past their safety limits. It published a note on 12 September and says it left out the method. On Mindgard’s account, Moonshot made contact only after the BBC asked for comment. Moonshot says internal tests showed a high refusal rate, and that outside testing is part of building safer systems.

Technology · AI safety · 30 September 2026

Rahul Mahajan
Rahul Mahajan Writer & Editor, ChinaScoop · Research Analyst, China and International Affairs Updated 30 September 2026 · Beijing / London

A British security firm says two Kimi models from Beijing-based Moonshot discussed biological weapons and assassinations after a July test. Moonshot opened a review only after the BBC called. The practical value of the answers is unproven. The gap in disclosure is not.

2 modelsKimi K2.6 and K3 Swarm, tested by Mindgard
27 JulyFirst email from Mindgard to Moonshot
47 daysFrom that email to Mindgard’s 12 September note
After BBCMoonshot contact, by Mindgard’s account

What this piece will not do. It does not repeat prompts, jailbreak steps, or any description of a weapon, agent, or process. Mindgard told the BBC it withheld the method. ChinaScoop is doing the same. The story is the safety failure and the response, not a manual.

What the BBC reported

On 29 September 2026, BBC technology reporter Chris Vallance reported that Moonshot, the Beijing developer of the Kimi chatbot, was conducting an internal review. UK firm Mindgard said its researchers had persuaded Kimi K2.6 and K3 Swarm to discuss how to make biological weapons and how to carry out assassinations.

The route was a jailbreak: a chain of instructions meant to see whether a model will ignore limits the developer put in place. Mindgard founder Peter Garraghan told the BBC World Service programme Tech Life that once the jailbreak worked, the models did not stop at the question asked. They offered other harmful topics on their own, and were “inventive and creative.”

Moonshot told the BBC it welcomed third-party testing “as a key pillar for building better and safer AI,” and that it was in discussion with Mindgard. In an email shared with the BBC, the company said internal tests had shown “a high refusal rate for these types of requests.”

Established

On the record

Mindgard says both named models left their safety limits in July. Moonshot confirms a review and a discussion. The BBC did not publish the prompts or the model’s answers.

Not established

Still open

No public evidence that the answers were workable. No named user is accused of building anything. This is a red-team finding, not a confirmed plot.

The disclosure clock

The sharper finding is not the jailbreak itself. Frontier labs are jailbroken often. It is how long the developer took to engage.

July 2026

Mindgard finds Kimi K2.6 and K3 Swarm can be pushed past safety limits.

27 July

Mindgard emails Moonshot. A follow-up goes out about a week later.

12 September

Mindgard publishes a blog. It says it did not reveal the key method.

Late September

BBC asks Moonshot for comment. Mindgard says this is when Moonshot made contact.

29–30 September

BBC publishes. Moonshot says a review is underway.

That is roughly seven weeks from the first notice to a public note, and a company reply that, on Mindgard’s account, arrived only after a broadcaster called. Moonshot’s “high refusal rate” claim sits beside that timeline. A model can refuse a plain question and still answer a dressed-up one. Refusal on the easy prompt is not the same as a guardrail that holds.

Why open weight changes the risk

Kimi is an open-weight model. The weights can be downloaded and run on someone else’s machines. A filter on Moonshot’s own website does not travel with the file. A user who has the weights can try to strip the limits offline, where the developer cannot see the query or switch the model off.

Moonshot’s K3 family, announced on 16 July 2026, is the company’s frontier open-weight line. Reuters reported Kimi K3 at 2.8 trillion parameters, which Moonshot called the largest open-weight system then released. The BBC’s test named K3 Swarm, a K3-family system, alongside the earlier K2.6. The policy point is the same for both: once weights are public, a lab’s refusal policy is a preference, not a lock.

Hosted chatbot
Filter on
After a jailbreak
Partial
Weights downloaded
Offline

Schematic only. It shows where a developer can still intervene. It is not a measured score from Mindgard or Moonshot.

Two risks, not one

ClaimWho says itStatus
Models discussed biological weapons and assassinations after a jailbreakMindgard, via BBCReported. Answers not published. Workability not shown.
A jailbroken Kimi K2.6 could run code and reach the internet, a possible launchpad for cyber attacksMindgardAssessment of capability. Not a reported intrusion.
Internal tests show a high refusal rateMoonshot email to MindgardCompany figure. No public dataset attached.
Key jailbreak steps were withheldPeter GarraghanConsistent with what the BBC printed.

Yonhap Infomax, citing the same episode, reported that Mindgard could not verify whether the dangerous information was actually usable. That limit matters. A fluent wrong answer is still a safety failure. It is not, by itself, evidence of a weapon.

“Once the jailbreak works it will talk about any topic, it will even freely offer up recommendations about other topics that are also nefarious and it will be inventive and creative.”Peter Garraghan, founder, Mindgard, to BBC Tech Life

Not only a Chinese-lab problem

The BBC set the Kimi finding next to a different class of incident. US labs including OpenAI, Meta and Anthropic have reported cases in which their own tools were used, or were caught being steered, toward hacking and other misuse. On 11 September 2026 the BBC reported that Anthropic said it had blocked activity that could support biological-weapons development, including five case studies in a threat report. Google has separately described a user seeking a technical guide from Gemini.

The difference is disclosure and control. Anthropic published a disruption. Moonshot, on the public record, engaged after a newsdesk call. Open-weight release also removes the off-switch that a hosted US model still has.

Professor Alan Woodward of the University of Surrey told the BBC that international rules will not keep pace. “It’s taken us decades to agree on the format of telephone numbers,” he said. His practical point was narrower: identify and prosecute the person who misuses a system. He also noted that Hugging Face had used a Chinese open-source model while examining a hack later linked to OpenAI agents. Open weight cuts both ways. It is a research tool and a removable lock.

What Beijing’s own rules do not cover

China already requires generative-AI services offered to the public to register, label output, and follow content rules. Those rules are written for speech the state dislikes, and for services the state can see. They are a weak fit for three facts in this case.

The tester was outside China. The weights can leave the hosted service. The harm alleged is not a banned political phrase. It is a dual-use answer that a domestic censor has little reason to sample. A registration filing in Beijing does not patch a weight file on a server in another country.

From April 2026 a US congressional committee had already pressed American firms on their use of Kimi and other Chinese models. This episode gives that argument a concrete exhibit: not a benchmark score, a safety contact that did not happen until a journalist asked.

What a reader should take from it

For labs

A refusal rate on direct questions is not a safety case. Third-party notice needs a clock: acknowledge in days, not after a broadcast.

For users of open models

A Chinese or American brand on the download page is not a control. If the weights are local, the developer’s policy is already behind you.

India’s own deployments of foreign open models, including in state and campus settings, inherit this gap. The question is not whether Kimi is uniquely reckless. It is whether any open-weight frontier model can still be treated as a hosted product once the file is public.

Questions the record still does not answer

Did Kimi give a workable method?

Not shown. Mindgard and the BBC did not publish the answers. Secondary reports say usability was not verified. ChinaScoop will not try to fill that gap.

Is this a state programme?

No evidence in the BBC report links the answers to a PLA or government tasking. Moonshot is a private Beijing lab, founded in March 2023 by Yang Zhilin, Zhou Xinyu and Wu Yuxin, backed by Alibaba and Tencent.

Why name assassinations beside bioweapons?

Because Mindgard said the models raised further harmful topics without being asked. The pattern is a broken limit, not a single subject.

What should happen next?

Moonshot can publish the review: which build, what refusal rate, what changed after 27 July. Mindgard can keep the method private and still publish a severity grade. Neither has done that in the BBC account.

ChinaScoop did not test the models. Claims stay with the outlet or the company that made them.

Leave a Reply

Your email address will not be published. Required fields are marked *

error: Sorry do your own research !!