Anthropic said Thursday, September 10, that it disrupted five cases in which researchers used Claude for biological work that could potentially support weapons development, including gain-of-function research on chikungunya associated with a military research institute.
The cases are the most consequential section of a broader Anthropic threat intelligence report covering misuse detected from December 2025 through August 2026. The company said it banned associated accounts, strengthened safeguards and, where appropriate, shared findings with government authorities, other AI laboratories and industry partners.
The disclosure matters because it moves the debate over AI-assisted biological threats beyond controlled safety tests and into examples Anthropic says it observed on its commercial systems. It also exposes a difficult limitation: some of the same research that can help scientists anticipate outbreaks or develop treatments can also provide knowledge useful for making pathogens or toxins more dangerous.
But the report does not establish that Claude created a biological weapon, that any weapon was completed or that the researchers intended to cause harm. Anthropic withheld the names of the scientists, institutions and countries involved and explicitly said it was not asserting malicious intent.
What Anthropic disclosed
Anthropic’s biological-misuse section describes five distinct cases:
- A platform serving researchers working on chikungunya gain-of-function experiments associated with a military institute.
- A researcher planning mammal-adaptation experiments involving highly pathogenic avian influenza.
- An application for orthopoxvirus research at a state-associated infectious-disease laboratory.
- A state-supported project building an AI-assisted atlas and optimization pipeline for venom peptides.
- A national research program involving computational redesign of toxins and intentionally vague progress reports.
Some requests triggered Claude’s biological safety systems, limiting the users to less-capable models or refusing assistance. Others passed through because they resembled legitimate scientific work. That contrast is central to the report: filters can recognize some clearly hazardous requests, but they struggle when dangerous and beneficial applications rely on the same underlying science.
Anthropic said actors in the cases also used methods including anonymizing infrastructure, accounts created with generated identities, third-party resellers and services designed to avoid data retention. Several accessed Claude from regions where Anthropic does not offer its products.
The chikungunya case triggered a wider investigation
The first case began in May 2026, when Anthropic’s biological safety classifier blocked a request for help writing a scientific grant application involving gain-of-function research on chikungunya.
The proposed work focused on properties including transmissibility and immune evasion. According to Anthropic, the application contemplated identifying mutations, engineering them into research materials and selecting progressively more harmful variants in live-animal experiments.
Such work could have a legitimate public-health purpose, including understanding dangerous mutations and supporting the development of vaccines or treatments. The same knowledge, however, could also be used to increase a pathogen’s harmful properties.
Anthropic said the institutional context heightened its concern. Although the application described civilian researchers, the proposed experiments were intended to take place at a military research institute.
The company’s subsequent investigation found that the request had traveled through a platform serving dozens of life-science researchers connected to civilian and military institutions. Because the researchers were in regions Anthropic does not support, the platform allegedly tunneled traffic through infrastructure in the United States and used a zero-data-retention service that reduced Anthropic’s visibility into the conversations.
The platform’s developers also created a fallback system that sent sensitive requests rejected by Claude to another company’s more permissive model, according to the report. Anthropic said it banned associated accounts, helped take down relay infrastructure and notified affected AI laboratories and government authorities.
That did not end the activity. Anthropic said the operator restored access within days using new identities and consumer subscriptions. The company later found that the chikungunya work had continued and that Claude provided editorial help on research materials. Anthropic inferred from those documents that the effort had progressed beyond the original grant proposal, although it did not claim that the research produced a weapon or even a completed experimental result.
What happened in the other four biology cases
| Case | How Claude was used | What the safeguards did |
|---|---|---|
| Avian influenza | A researcher exchanged thousands of messages over several weeks about study planning, data analysis and experiments related to mammalian adaptation. | Classifiers kept the work on older, weaker models. Anthropic assessed Claude’s contribution as primarily clerical and said the resulting capability boost was limited. |
| Orthopoxvirus research | A customer using a reseller relay had Opus 5 draft a grant application, including its hypothesis, experimental design and contingency planning, in roughly one hour. | The request was not blocked because it was framed around reducing viral virulence, a legitimate goal that relies on knowledge also relevant to preserving or enhancing immune-evasion functions. |
| Venom peptides | A researcher created an atlas of venom-derived molecules and a system for optimizing their characteristics, with stated goals including new painkillers and other medicines. | The classifier largely allowed the work, although the same system included material relevant to paralytic compounds. Anthropic banned the account for evading regional access restrictions. |
| Computational toxin redesign | A researcher used Claude across projects involving toxins under a national public research program and co-wrote progress reports with the model. | Anthropic said the researcher instructed Claude to keep the identities of certain biological targets deliberately vague. The associated accounts were banned for regional-policy violations. |
The avian-influenza case offered evidence that targeted restrictions can reduce risk. The researcher reportedly planned experiments involving mutations associated with adaptation to mammals and airborne transmission in animal models. Because Claude’s classifiers recognized the high-risk subject, the user was confined to Claude Sonnet 4 and Haiku 4.5 rather than Anthropic’s most capable systems.
After reviewing the messages, Anthropic concluded that those older models mainly assisted with organizing information, generating study ideas and editing. The company said they did not provide expert-level biological research capability.
The orthopoxvirus case demonstrated the opposite problem. The proposal’s stated purpose involved identifying immune-evasion genes and determining whether deleting one would weaken a virus. That is defensible biomedical research, but the knowledge can also reveal how to preserve, enhance or transfer immune-evasion functions.
Because the request appeared to focus on attenuation rather than enhancement, the classifier did not stop it. Anthropic said a Claude Opus 5 model helped produce an end-to-end grant proposal in about an hour for research associated with a laboratory that had access to live orthopoxviruses and high-containment facilities.
Why this is not evidence of a completed bioweapons program
The distinction between suspicious activity and proof of weaponization is essential. Anthropic possesses account data, prompts and other platform signals, but it does not have complete visibility into what occurred inside the laboratories or institutions described in its report.
The company said the individuals were working scientists and acknowledged that they may have been pursuing legitimate research. Anthropic also withheld identifying details partly because naming researchers without proof of harmful intent could put them at risk.
What the report does establish, if Anthropic’s findings are accurate, is that scientists connected to sensitive programs wanted access to frontier American AI models and sometimes took deliberate steps to conceal their identities, locations or subject matter. It also shows that cutting off an account does not necessarily stop a determined user who can move among resellers, newly created identities and competing models.
Anthropic itself cautioned that the cases should not be read as evidence that Claude has made a biological attack imminent. Its concern is that significant dual-use research associated with state actors is already intersecting with attempts to access powerful AI tools.
The deeper problem is identity, not only prompts
Most consumer AI safeguards evaluate the immediate conversation: what a user asks, what the model is about to answer and whether the exchange matches a known category of harmful content.
That approach is useful when a request is explicitly about creating a known weapon. It is less reliable when a technically sophisticated researcher frames work as vaccine development, therapeutic discovery, viral attenuation or basic protein science. Those can all be legitimate pursuits, and blocking them indiscriminately would limit the value of AI for medicine and biotechnology.
Anthropic’s conclusion is that prompt-level filters cannot be the only defense. The company said safe access to its most capable biological tools will require signals about the user and institution, enough data retention to investigate suspicious patterns and trusted-access programs for verified researchers.
That approach carries its own tradeoffs. Universities, drug developers and independent scientists could face additional verification requirements or restrictions when using frontier models. Data retention that helps investigators detect abuse may also create privacy, confidentiality and intellectual-property concerns for legitimate laboratories.
It additionally places AI companies in the position of deciding which institutions, countries and scientific projects can use advanced capabilities. Cornell University computer scientist John Thickstun told the Associated Press that companies are being asked to make society-wide judgments about acceptable behavior without democratic or deliberative oversight.
What changes for Claude users
Anthropic did not announce a new general consumer restriction alongside the September 10 report. Instead, it said lessons from the investigated cases had already been incorporated into its enforcement systems and frontier-model safeguards.
The company’s newer Fable-class models launched with substantially stronger restrictions on sensitive biological work. When a safety classifier identifies a protected biology request, Anthropic can refuse it or route the request to a less biologically capable model.
For most users, ordinary health, education and general science questions should remain accessible. Researchers working on advanced virology, protein design, toxins, drug discovery or related dual-use fields are more likely to encounter refusals, fallbacks or requests to use a controlled access pathway.
The report also suggests that institutions relying on third-party model gateways may face greater scrutiny. Reseller networks and zero-data-retention arrangements can serve legitimate privacy needs, but Anthropic’s investigation shows why AI providers may treat combinations of hidden identity, unsupported-region access and sensitive research as warning signals.
The biology findings sit inside a much broader threat report
Anthropic’s report covers seven categories: cyber operations, influence campaigns, surveillance, fraud, conventional weapons, biological misuse and attempts to copy model capabilities through illicit distillation.
The company described suspected state-sponsored groups, commercial spyware vendors, financially motivated criminals and politically motivated individuals using Claude. The larger pattern is that AI is moving from answering isolated questions to organizing workflows, processing intelligence and coordinating complex tasks.
That backdrop makes the biology cases more significant. Even when a model does not provide a breakthrough scientific insight, it can accelerate literature reviews, experimental planning, analysis, grant writing and documentation. Those individual efficiencies can add up across a sophisticated research program.
The disclosure also arrives during heightened scrutiny of Anthropic’s safety posture. Earlier in the week, researcher Jacob Coxon said he was leaving the company while warning that competition among frontier AI developers was moving faster than safeguards. His departure and Anthropic’s misuse report concern different types of risk, but together they intensify questions about whether voluntary company controls are keeping pace with increasingly capable systems. Readers can find more context in NextWatch AI’s report on Coxon’s resignation and warning.
A timeline of the disclosure
| Date | Development |
|---|---|
| December 2025 to August 2026 | Period covered by Anthropic’s new threat intelligence report. |
| May 2026 | Anthropic detected and investigated several biology-related cases, including the chikungunya and avian-influenza activity. |
| May 2026 | The company banned accounts, worked with partners to disrupt relay infrastructure and shared information with authorities and other AI providers. |
| Within days and weeks | The operator connected to the chikungunya platform allegedly restored access through new identities and alternative services. |
| September 10, 2026 | Anthropic publicly released its report describing five biological-misuse case studies. |
What to watch next
The largest unanswered question is whether governments or independent investigators will corroborate Anthropic’s assessment. Because the report omits countries, institutions and most technical identifiers, outsiders cannot fully evaluate the cases from the published evidence alone.
Other developments to watch include:
- Cross-company coordination: Whether major AI providers share indicators for reseller networks, account farms and recurring evasion methods without compromising legitimate users’ privacy.
- Trusted scientific access: How Anthropic and its competitors verify researchers while allowing beneficial work on vaccines, therapeutics and disease surveillance.
- Government oversight: Whether policymakers establish common standards for model evaluations, incident reporting and access to high-risk biological capabilities.
- Persistent evasion: Whether the actors identified by Anthropic continue moving among providers after accounts and relay services are disrupted.
- Independent evidence: Whether authorities disclose that any of the described projects crossed from ambiguous dual-use research into prohibited weapons activity.
The immediate takeaway is narrower than the most alarming interpretation, but still serious. Anthropic did not report that Claude built a biological weapon. It reported that sensitive research programs with concerning state and military associations were already seeking AI assistance, that some users tried to evade safeguards and that conventional content filters did not catch every dual-use request.
That makes the September 10 disclosure less a story about a completed weapon than a warning about access control. As frontier models become more capable scientists, deciding who can use them, under what conditions and with what oversight is rapidly becoming as important as deciding which individual questions they should answer.
Make YouTube smarter with NextWatch AI
Use AI search, smarter discovery, playback tools and speed testing directly in your browser.
Add NextWatch AI to Chrome ↗
