- Anthropic disclosed five cases in which scientists used Claude for dual-use biological research whose results could potentially support biological weapons development.
- The company said it found no evidence of malicious intent but blocked the related accounts and strengthened its safeguards.
- The projects involved chikungunya, avian influenza, orthopoxviruses, poisons and toxins.
Anthropic said in a September 2026 report that it identified and shut down five cases of Claude models being used in scientific research whose results could potentially be applied to biological weapons development. The company said the cases matter because government-linked organizations and scientists are already applying advanced AI models to dual-use research and, in some instances, bypassing access restrictions.
Anthropic emphasized that it had no evidence the scientists intended to create biological weapons. The concern arose from the research’s dual-use nature: The same knowledge could support vaccines and medicines or help create more dangerous pathogens, according to the company.
Jacob Klein, Anthropic’s head of threat intelligence, said distinguishing between those purposes is often extremely difficult. Anthropic described the cases in a company report on AI misuse.
Chikungunya and avian influenza research
Anthropic said one of the most alarming cases involved a request detected in May 2026. Researchers attempted to use Claude while preparing a funding application for experiments involving the chikungunya virus, including changes that could affect its transmissibility and ability to evade immune defenses.
The company said it was further concerned because the research was planned for a military research institute. Anthropic blocked the associated accounts and worked with partners to restrict the infrastructure users had employed to bypass regional controls.
According to Anthropic, the infrastructure’s operator later tried to restore access to AI models through new accounts and other services.
In a separate case, a researcher outside the United States used Claude for several weeks while studying highly pathogenic avian influenza. The work examined the virus’s adaptation to mammals and factors that could potentially affect its pandemic potential.
The researcher exchanged thousands of messages with Claude, using it to review scientific literature, plan research, analyze data and prepare materials. Anthropic said safeguards blocked the most dangerous prompts, leaving the researcher to work mainly with the weaker Claude Sonnet 4 and Haiku 4.5 models. The company assessed Claude’s actual contribution as limited.
Orthopoxviruses, poisons and toxins
Another user employed Claude Opus 5 while preparing a grant application to study orthopoxviruses, the virus family that includes the pathogens responsible for smallpox and mpox. Anthropic said the model drafted a substantial portion of the document in about an hour, including the hypothesis, study design and statistical plan. The project was connected to a government infectious disease laboratory.
Two other cases involved research into poisons and toxins. Researchers used Claude to analyze and computationally design molecules with both medical and potentially harmful applications, according to Anthropic.
One project formed part of a government research program. In the other case, Anthropic said the user deliberately instructed Claude not to disclose specific details about the substances under study in reports.
Anthropic concluded that automated filters alone cannot adequately police complex scientific work because a system often cannot infer intent solely from a request’s content. The company said access to the most powerful AI capabilities in biology should combine dangerous-content filtering with identity verification and confirmation that researchers are affiliated with trusted organizations.
Anthropic cautioned that the cases do not demonstrate an inevitable biological threat. The New York Times noted that previous concerns about AI-assisted biological weapons were based largely on laboratory tests and hypothetical scenarios, while Anthropic’s report offered rare information about use in real-world scientific projects.
Biosafety expert Andrew Weber described the cases as an alarming example of how government programs may seek to use the rapidly advancing capabilities of AI models. He advocated limiting the systems’ most powerful biological functions to a vetted group of trusted researchers.
Broader misuse findings
Anthropic’s report, Detecting and countering misuse of AI: September 2026, covers cases involving Claude models from December 2025 through August 2026. Beyond biological risks, it describes AI use in cyberattacks, surveillance, information operations, fraud, conventional weapons development and attempts to copy capabilities from advanced AI models.
The company said AI increasingly serves not only as an adviser but also as a tool for automating entire operations. In cyberattacks, threat actors used AI agents for reconnaissance, vulnerability exploitation, data theft and malware modification in response to detection by defensive systems. Anthropic said this lowers the skills required and allows small groups to conduct operations that previously would have needed specialist teams.
Anthropic linked one identified operation to Russian cyberespionage targeting Ukrainian government agencies, the military, diplomats and drone manufacturers. The attackers’ plans referenced more than 20 organizations, according to the company.
The report also described Claude being used to develop software for missiles and armed drones, conduct state-backed information campaigns, monitor dissidents and build a large network of fraudulent dating apps.
Anthropic further alleged that some Chinese AI companies rerouted large volumes of user requests to Claude and used its responses to train their own systems through distillation. The company warned that the practice could have exposed sensitive user and corporate data to third-party services.
Anthropic said it blocked the activity identified in each case, improved its defenses and, when necessary, shared information with government agencies and other industry participants.
Source: Incrypted
