Home Technology Anthropic Says Claude Used in Possible Bioweapon Research

Anthropic Says Claude Used in Possible Bioweapon Research

7
0


Claude was built to help with complex research. Anthropic says some scientists pushed that capability into territory with possible bioweapon implications.

In a Sept. 10 threat intelligence report, Anthropic detailed five biological-research cases involving its AI models. The company said the activity could support biological weapons development and that some users bypassed regional controls or concealed the purpose of their work.

Anthropic blocked some requests and banned accounts, but said it could not determine whether the scientists intended harm.

For organizations using frontier AI in research, the cases show that risky activity may not be obvious from a single prompt. Account behavior, location, and the wider research context can matter just as much.

Five cases show the dual-use problem

Anthropic said the cases included work on chikungunya, avian influenza, orthopoxviruses, venom peptides, and toxins. One researcher spent weeks planning avian influenza experiments, while another used Opus 5 to draft an orthopoxvirus immune-evasion grant application.

The Guardian reported that researchers in several cases circumvented safeguards for users in unsupported regions and took steps to obscure their work. Anthropic banned the accounts but withheld the scientists’ names, institutions, and countries because it remained uncertain about their intent.

The biological cases were part of wider abuses Anthropic investigated between December 2025 and August 2026. The Associated Press reported that Anthropic described the examples as some of the most notable and novel threat activity it had identified, rather than typical misuse.

Must-read security coverage

The chikungunya case moved beyond a grant request

The clearest example involved a state-sponsored grant for gain-of-function research on chikungunya. Anthropic said the work was intended for a military research institute and sought mutations that could make the mosquito-borne virus more harmful, although similar research could also contribute to vaccines or treatments.

Anthropic also said an intermediary platform tunneled traffic through US infrastructure to bypass regional blocks and relied on gray-market resellers and synthetic accounts. After blocking sensitive requests, the platform routed some biology prompts to more permissive models. Claude later provided editorial help on research outputs, which Anthropic said showed the effort had progressed beyond the grant proposal.

Even with those warning signs, Anthropic stopped short of calling it a weapons program.

“What we don’t know is if the research was meant to be weaponized,” Jacob Klein, Anthropic’s head of threat intelligence, told The New York Times.

AI safeguards may need more than prompt blocking

Anthropic said older Claude models were well below the threshold for meaningfully assisting sophisticated users with dangerous biological research. With newer models, the company said it can no longer make that same assurance, prompting stronger safeguards around dual-use biology queries.

The chikungunya case shows why a model refusal may not be enough. Anthropic blocked relevant exchanges, yet the intermediary later routed sensitive requests to more permissive models. For organizations using multiple AI providers, a safety control on one model can be undermined if an application automatically retries the request elsewhere.

The report also highlights the difficulty of judging biological research one prompt at a time. Anthropic said biology is inherently dual use because the same knowledge can contribute to vaccines or treatments while potentially making pathogens more dangerous. It warned that sophisticated actors can exploit that ambiguity to conceal the broader purpose of their work.

For sensitive research environments, organizations may need to look at the activity surrounding a prompt, not just the prompt itself. Repeated refusals, attempts to bypass geographic restrictions, unusual third-party routing, or efforts to conceal an account’s origin could all merit closer review.

For more on the company’s latest moves, read why Anthropic walked away from a reported $6 billion Decart AI deal after due diligence.



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here