Anthropic halts AI linked to bio-weapons research
Anthropic, an artificial intelligence startup, claimed to have discovered and stopped five instances where users tried to use its Claude models for “malicious activity” that might aid in the creation of biological weapons. The cases outlined in Anthropic’s ‘Detecting and countering misuse of AI: September 2026’ report encompass investigations into virus transmissibility and immune evasion, the mammalian adaptation of highly pathogenic avian influenza, orthopoxvirus research, toxin optimisation, and the computational redesign of toxins. Anthropic has prohibited the accounts associated with the incidents and utilised insights from its enquiries to enhance its protective measures. It also disseminated findings to government authorities and other AI firms when deemed appropriate. The company stated that it was refraining from disclosing the identities of the institutions, countries, and particular biological techniques involved. The report examines disruptions in activity from December 2025 to August 2026 across seven domains, encompassing cyber operations, influence operations, surveillance, conventional weapons, biological misuse, and fraud.
One of the cases involved a request to utilise Claude for the preparation of a scientific grant application concerning gain-of-function research related to the chikungunya virus. Anthropic’s biological safety classifier denied the request in May 2026. The proposed work concentrated on enhancing the virus’s transmissibility and its capacity to evade the immune system. The company stated that such research possesses valid scientific applications, encompassing the advancement of vaccines and therapeutic interventions. However, analogous efforts could also enhance the peril posed by a pathogen. The proposed research raised significant concerns due to its association with a military research institute, despite the grant application characterising the researchers as civilians. Anthropic subsequently discovered that an intermediary AI platform was employed to circumvent regional restrictions and gain access to Claude via US infrastructure. The platform featured a fallback system that redirected prompts rejected by Claude to alternative AI models with more lenient safeguards. Anthropic has taken measures to ban the associated accounts and has collaborated with partners to dismantle the relay networks. However, the operator subsequently reinstated access through new identities and persisted in utilising reseller networks to access AI models.
In a separate instance, a researcher based outside the United States utilised Claude for several weeks in the preparation of research concerning highly pathogenic avian influenza, often referred to as bird flu. The researcher engaged in extensive communication with Claude, utilising the model for various purposes including study planning, data analysis, experiment interpretation, and writing. Anthropic stated that the research encompassed genetic methodologies associated with mammalian adaptation and airborne transmission, with experiments scheduled in animal models. The company indicated that the work seemed to be in the initial phases of research planning. It also stated that the research was evidently dual use. Investigating the genetic underpinnings of perilous viral characteristics enables researchers to pinpoint naturally occurring strains that possess the potential to trigger a pandemic. Concurrently, the acquired knowledge may be utilised to intentionally engineer such variants. Anthropic stated that its safety classifiers inhibited the researcher from gaining access to its more advanced models. The work was instead conducted utilising less robust models, which resulted in Claude’s contribution being primarily confined to aspects such as data analysis and study design.
The company estimated that the AI provided only limited uplift and did not perform expert-level biology research in this instance. A third case involved a grant application for research into orthopoxviruses at a state-associated infectious disease laboratory. The application described operates with live viruses and requires access to high-containment facilities. It concentrated on comprehending the genes that play a role in the evasion of the immune response by viruses. Anthropic stated that the research may possess genuine scientific merit, as comprehending the mechanisms by which viruses circumvent immune responses could assist researchers in their efforts to diminish their potency. However, the same knowledge could also be utilised to maintain or improve those properties. In contrast to the initial two instances, Claude’s classifier refrained from obstructing the activity, as the research was centred on attenuation, specifically aimed at diminishing the pathogenic potential of a virus. The account was managed via an anonymising reseller system and catered to over a dozen clients. Anthropic reported that one customer utilised Claude’s Opus 5 model to develop a grant application from start to finish in approximately one hour, encompassing the research hypothesis, experimental design, and statistical planning. The company stated that this case underscored the challenges associated with discerning harmful intent when the foundational research possesses valid scientific applications. The concluding two cases pertained to investigations into innovative venoms and toxins. In one instance, a researcher employed Claude to construct an atlas of peptides derived from venom, subsequently devising a generative system aimed at optimising their attributes.
The objective was to develop potential analgesics, mood stabilisers, and other pharmaceuticals. However, the research encompassed both therapeutic and paralytic targets. Anthropic stated that this implies the resulting system could potentially be utilised to produce either beneficial pharmaceuticals or detrimental substances. The researcher participated in a state-supported research program, as indicated by information provided to Claude. Anthropic suspended the account in May 2026 due to attempts to circumvent its regional restrictions. In the fifth instance, a researcher employed Claude for multiple projects centred on the computational reengineering of toxins. The work was presented primarily within a therapeutic framework and was associated with a national public research initiative. The researcher additionally employed Claude to collaboratively draft progress reports. Anthropic indicated that the identities of the biological agents involved were intentionally obscured in those reports, which it interpreted as an indication of attempts to obscure the nature of the research. Both accounts were subsequently banned. Anthropic stated that monitoring biological research presents challenges, as the same scientific knowledge can be applied for both beneficial and harmful purposes. “The same information that can be used to develop a biological weapon could also be used to develop, for example, a vaccine or a cure for a disease,” the company said.
This overlap can enable sophisticated users to uphold “plausible deniability,” as individual requests may seem legitimate when viewed in isolation, despite their collective implications. Anthropic stated that its initial two cases demonstrated that its classifiers were capable of preventing distinctly high-risk biological research. However, other instances underscored the limitations of depending solely on automated systems. The company conducted a review of 30 days of activity associated with institutions in adversarial states, identifying approximately 35 research efforts. Most civilian scientific work was involved, although some possessed dual-use potential. Anthropic stated that these instances do not imply that Claude is creating imminent biological threats. Instead, they demonstrate that certain advanced biological research programs are pursuing access to cutting-edge AI models and, in some instances, attempting to circumvent safeguards. The company stated that enhanced safety measures will necessitate robust filtering systems for high-risk content alongside trusted-user initiatives aimed at verifying the identities of researchers and the authenticity of their work.









