Anthropic Says Claude Used in Possible Bioweapon Research

Anthropic Says Claude Used in Possible Bioweapon Research

Anthropic says Claude was used in biological research that could potentially support bioweapons development. Image generated via ChatGPT

Anthropic says researchers used Claude for biological work that could support weapons development, exposing new challenges for AI safeguards.

Écrit par
Kezia Jungco
Kezia Jungco
Sep 11, 2026

Claude was built to help with complex research. Anthropic says some scientists pushed that capability into territory with possible bioweapon implications.

In a Sept. 10 threat intelligence report, Anthropic detailed five biological-research cases involving its AI models. The company said the activity could support biological weapons development and that some users bypassed regional controls or concealed the purpose of their work.

Anthropic blocked some requests and banned accounts, but said it could not determine whether the scientists intended harm.

For organizations using frontier AI in research, the cases show that risky activity may not be obvious from a single prompt. Account behavior, location, and the wider research context can matter just as much.

Five cases show the dual-use problem

Anthropic said the cases included work on chikungunya, avian influenza, orthopoxviruses, venom peptides, and toxins. One researcher spent weeks planning avian influenza experiments, while another used Opus 5 to draft an orthopoxvirus immune-evasion grant application.

The Guardian reported that researchers in several cases circumvented safeguards for users in unsupported regions and took steps to obscure their work. Anthropic banned the accounts but withheld the scientists’ names, institutions, and countries because it remained uncertain about their intent.

The biological cases were part of wider abuses Anthropic investigated between December 2025 and August 2026. The Associated Press reported that Anthropic described the examples as some of the most notable and novel threat activity it had identified, rather than typical misuse.

Must-read security coverage

The chikungunya case moved beyond a grant request

The clearest example involved a state-sponsored grant for gain-of-function research on chikungunya. Anthropic said the work was intended for a military research institute and sought mutations that could make the mosquito-borne virus more harmful, although similar research could also contribute to vaccines or treatments.

Anthropic also said an intermediary platform tunneled traffic through US infrastructure to bypass regional blocks and relied on gray-market resellers and synthetic accounts. After blocking sensitive requests, the platform routed some biology prompts to more permissive models. Claude later provided editorial help on research outputs, which Anthropic said showed the effort had progressed beyond the grant proposal.

Advertisement

Even with those warning signs, Anthropic stopped short of calling it a weapons program.

“What we don’t know is if the research was meant to be weaponized,” Jacob Klein, Anthropic’s head of threat intelligence, told The New York Times.

AI safeguards may need more than prompt blocking

Anthropic said older Claude models were well below the threshold for meaningfully assisting sophisticated users with dangerous biological research. With newer models, the company said it can no longer make that same assurance, prompting stronger safeguards around dual-use biology queries.

The chikungunya case shows why a model refusal may not be enough. Anthropic blocked relevant exchanges, yet the intermediary later routed sensitive requests to more permissive models. For organizations using multiple AI providers, a safety control on one model can be undermined if an application automatically retries the request elsewhere.

The report also highlights the difficulty of judging biological research one prompt at a time. Anthropic said biology is inherently dual use because the same knowledge can contribute to vaccines or treatments while potentially making pathogens more dangerous. It warned that sophisticated actors can exploit that ambiguity to conceal the broader purpose of their work.

For sensitive research environments, organizations may need to look at the activity surrounding a prompt, not just the prompt itself. Repeated refusals, attempts to bypass geographic restrictions, unusual third-party routing, or efforts to conceal an account’s origin could all merit closer review.

For more on the company’s latest moves, read why Anthropic walked away from a reported $6 billion Decart AI deal after due diligence.

Kezia Jungco

Kezia Jungco is a technology writer and researcher specializing in artificial intelligence, data analytics, CRM software, cloud infrastructure, cybersecurity, and emerging business technologies. With more than five years of experience evaluating software platforms and technology solutions, she helps business leaders understand the tools and trends shaping the future of work. Kezia has extensive hands-on experience testing and analyzing generative AI platforms, chatbots, natural language processing (NLP) tools, CRM systems, and business software. Her work focuses on translating complex technologies into practical insights that help organizations make informed decisions about technology adoption, operational efficiency, and digital transformation. As a staff writer for TechnologyAdvice, Kezia covers AI innovation, business applications of machine learning, data-driven technologies, cloud computing, cybersecurity, and sales technology. Her background in journalism, research, and education enables her to combine rigorous analysis with clear, accessible reporting for both enterprise and consumer audiences. Kezia holds a bachelor's degree in Development Communication with a major in Development Journalism from the University of the Philippines Los Baños. She has also completed professional training in artificial intelligence, data privacy, and information security. Her work has been featured in TechnologyAdvice, TechRepublic, eWeek, Datamation, and Selling Signals, where she helps readers navigate a rapidly evolving technology landscape with practical, research-driven guidance.