CBRN risks

CBRN risks

CBRN risks are dangers posed by chemical, biological, radiological and nuclear substances that can harm very large numbers of people at once. In the AI debate, the term refers to the concern that a language model might help someone build such weapons.

The four letters CBRN stand for chemical, biological, radiological and nuclear. They refer to substances that can kill or severely injure very large numbers of people at once: poison gases, disease pathogens, radioactive material and nuclear weapons. CBRN risks are the dangers posed by exactly these four categories. The term originates from the military and civil defense fields, where people used to speak of CBRN weapons. In the discussion around artificial intelligence, it has appeared regularly for a few years now. There, it revolves around a specific question: Can a computer program that answers questions help someone build such weapons?

Why these particular four letters show up in AI reports

Most mistakes made by an AI are annoying but fixable. A wrong date in an essay costs a grade, not a human life. With CBRN, it’s different: a single successful misuse can mean thousands of deaths and cannot be undone. That’s why companies and lawmakers treat this topic separately from all other risks.

The decisive argument is called the access threshold. Knowledge about nerve agents or dangerous viruses has long existed in textbooks and studies. Until now, however, one had to study for years to find, understand and apply it. An AI could sort, explain and translate this scattered knowledge into actionable steps. This lowers the threshold, widening the circle of potential perpetrators.

This is exactly where laws come in. The EU’s AI Act and the US safety guidelines explicitly cite CBRN as grounds for stricter reviews. Major providers such as OpenAI and Anthropic now publish their own tiered models, in which CBRN capabilities trigger the highest warning levels. Once a level is reached, the model may only be released after additional safeguards are put in place.

How providers keep this knowledge out of the model

The first point of intervention lies in the training material. A language model learns from vast amounts of text drawn from the internet and books. Particularly sensitive technical texts are filtered out beforehand so they never make it into the model in the first place. This never fully succeeds, however, because dangerous knowledge can be assembled from many harmless individual pieces.

That’s why a second layer is added: behavior during conversation. The model is trained to refuse certain requests. In addition, filter programs run alongside, monitoring the question and answer and cutting off the exchange if necessary. Think of it like two locks on the same door: one inside the model itself, one in front of it.

Whether this is enough is tested by so-called red teams. These are experts in chemistry, biology and nuclear physics who, on behalf of the provider, deliberately try to circumvent the safeguards. They break their questions into pieces, wrap them in fictional stories, or disguise them as research projects. If a red team finds a gap, the model is retrained. A common misconception, by the way, is that the model holds a ready-made set of building instructions as finished text. That’s not how it works: what’s dangerous is the ability to combine knowledge and answer follow-up questions.

CBRN in safety reports and headlines

The term most often appears in the safety reports that providers publish for every new model. These include a dedicated section on CBRN, often with a rating such as low, medium or high. Anyone wanting to know how risky a model is considered can find the manufacturer’s official answer there.

In the news, CBRN mostly comes up in disputes over regulation. Critics accuse companies of exaggerating the danger in order to push through strict rules that shut out smaller competitors. Others consider the warnings too cautious. For you as a user, the topic usually remains invisible. It only becomes noticeable when a chatbot refuses a harmlessly intended chemistry question because a filter has been set too cautiously.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.