Anthropic Blocks Scientists Attempting to Use Claude AI for Bioweapons Research

Anthropic reported blocking multiple attempts this year by scientists and researchers attempting to steer its Claude AI models toward biological weapons research.

Anthropic Blocks Dual-Use Biological Research Attempts

Artificial intelligence safety researchers have long warned that advanced systems could lower the barrier to creating biological threats. Anthropic provided concrete evidence of that risk in a comprehensive threat intelligence report published on Thursday.

The company outlined five distinct case studies where researchers attempted to use its Claude chatbot for advanced biological research with potential dual-use applications. While the company stated it was not alleging the researchers intended to cause harm, the prompts involved high-risk modifications of dangerous pathogens. Anthropic published its latest threat intelligence report on Thursday titled Detecting and Countering Misuse of AI. Such reports have become a regular feature across the AI industry as firms seek to demonstrate how they identify and disrupt attempts to misuse their models.

One prominent case involved scientists asking Claude to draft a grant proposal for gain-of-function research on the mosquito-borne chikungunya virus. According to detailed reporting on the security findings, the proposal involved modifying the virus to make it more transmissible and more dangerous. Anthropic said it blocked the request and later discovered the researchers were using a third-party platform to bypass regional restrictions and automatically route rejected prompts to another AI model.

Other intercepted attempts involved research into bird flu, orthopoxvirus, and non-transmissible venoms and toxins, according to the report. Anthropic noted that sophisticated threat actors are aware that AI providers attempt to detect dangerous uses and deliberately exploit the dual-use nature of biology to maintain a kind of plausible deniability about their research. Anthropic emphasized that the same information that can be used to develop a biological weapon could also be used to develop, for example, a vaccine or a cure for a disease.

Bypassing Safety Safeguards and Regional Restrictions

The threat intelligence report revealed that malicious actors are actively engineering workarounds to evade AI safety filters. In response to these evasion tactics, Anthropic banned all associated accounts, worked with partners to take down the relay networks that evaded regional blocks, and shared its findings with affected AI labs and government authorities.

The malicious activity identified in the report spanned a monitoring window for “malicious use” of its Claude Haiku, Sonnet, and Opus models disrupted between December 2025 and August 2026. None of the misuse cases involved Claude Fable or the powerful Mythos-class models, with the exception of one instance of distillation—the process for training smaller AI models using larger, more expensive models.

Aside from biological research probes, the document detailed conventional weapons misuse involving attempts to use Claude to develop software for conventional weapons design and development, including firearms, missiles, armed drones and bombs. It detailed three cases in China, two in Russia and one in Yemen, according to The New York Times.

Nation-State Surveillance and Cyber Extortion Operations

Beyond biological and conventional weapons research, Anthropic tracked a wide range of cyber espionage and influence operations leveraging its technology. The cases of concern detected over the past eight months ranged from fake dating apps and hotel Wifi scams, to surveillance built to identify dissidents, such as Chinese and Iranian government-linked actors targeting dissident and diaspora communities for surveillance. Anthropic’s AI model Claude was also used by actors linked to a Russia-based cyber espionage campaign and by an Iranian propaganda institution, according to its report.

Anthropic Says It Blocked Possible Biological Weapons Undertaking

Other state-sponsored threats included Russian media outlets using Claude to generate online propaganda masquerading as independent reporting, including fabricated claims about elections in Moldova. Anthropic has also accused Chinese AI firms of trying to replicate Claude’s capabilities, with the lengthy report listing cases in which suspected state-sponsored groups, criminals, spyware vendors, state propaganda institutions and politically motivated individuals misused its technology. Furthermore, access to AI in the form of compromised API keys, session tokens, and devices has increasingly become the sole objective of multiple criminal groups, with these access credentials being resold through brokers on the dark web.

Leave a Comment