Artificial intelligence company Anthropic stopped multiple attempts by scientists and researchers to use its Claude AI models for biological weapons research. The details came out in a 154-page threat intelligence report published by the company.
The report showed that between late 2025 and mid-2026, several individuals and groups tried to trick Claude into helping with dangerous biological experiments. These experiments included making deadly viruses easier to spread and designing harmful animal toxins.
Anthropic took immediate action by banning the user accounts, shutting down access networks, and sharing the findings with government officials and other AI companies. This disclosure marks the first time an AI company has publicly shared evidence of people trying to use AI models to build biological weapons.
It shows that as AI models become smarter, the effort to keep them safe is getting much harder.
Why AI Safety in Biology Is Such a Tricky Problem
Preventing AI from helping people make dangerous biological weapons is not simple. The main reason is that the science used to create a cure or a vaccine is almost identical to the science used to create a biological weapon.
Build Funnels, Email Lists & Sell Online With One Free Tool
Create funnels, send emails, and sell online using Systeme.io without paying for multiple tools.
Create Free AccountFree forever • No credit card • Beginner-friendly
Scientists call this the dual-use problem. If a researcher asks an AI model how to stop a virus from infecting human cells, that same technical information could theoretically be flipped around to make the virus infect people faster.
Anthropic acknowledged that distinguishing between good research and bad intent is one of the hardest challenges in the tech world. In many cases, the users asking Claude for help were actual working scientists. Some were affiliated with foreign universities or military research centers.
Because it was impossible to know for sure if these scientists wanted to heal people or harm people, Anthropic chose to play it safe. The company stepped in and blocked the research requests before any real harm could happen.
To learn more about how tech companies handle security risks and policy changes across the internet, explore our technology and AI guides.
The 5 Biological Misuse Cases Explained Simply
In its report, Anthropic detailed five specific cases where users tried to use Claude for risky biological work. None of the users came right out and asked how to build a bomb or a bio-weapon. Instead, they used complex scientific language to disguise their goals.
Case 1: Modifying the Chikungunya Virus
In May 2026, a researcher tried to use Claude to write a grant proposal for research on the chikungunya virus. Chikungunya is a virus spread by mosquitoes that causes high fever and severe joint pain in humans.
The proposal involved gain-of-function research. This type of research forces a virus to mutate rapidly inside live animals so scientists can see if it becomes more contagious or severe.
Anthropic discovered that the user was trying to make the virus progressively more harmful. Anthropic’s biological safety system flagged and blocked the prompt right away. When Claude refused to help, the user tried routing the request through a third-party service that automatically switched to a competitor’s AI model when Claude said no.
Case 2: Adapting Avian Flu for Mammals
Another troubling incident involved avian influenza, commonly known as bird flu. A researcher spent weeks planning experiments to see how bird flu could adapt to infect mammals more easily.
If bird flu adapts to spread easily among mammals, it creates a serious risk of a human pandemic. Anthropic’s safety filters picked up on the risky nature of the prompts. The system restricted the user to older, weaker versions of Claude that could not assist with complex lab instructions.
Case 3: Drafting Proposals for Smallpox-Related Viruses
In another case, a user connected to a state-backed research institute used Claude Opus to draft a scientific research proposal about orthopoxviruses. This is the family of viruses that includes smallpox, one of the deadliest diseases in human history.
The user wanted the AI to write a plan on how orthopoxviruses evade human immune systems. By using an automated setup, the user managed to get a complete draft in about an hour before the system detected the policy violation and killed the session.
Cases 4 and 5: Redesigning Venoms and Toxins
The final two cases involved animal toxins and venoms. In one instance, a researcher used Claude to build a searchable atlas of venom peptides to optimize how toxins behave. In another, a researcher under a national scientific program tried to computationally redesign natural toxins while hiding the true names of the chemicals.
Anthropic stepped in, banned the accounts, and shut down their access points.
How Users Bypassed Regional Blocks and AI Restrictions
Anthropic does not allow its AI models to be accessed in certain countries, including Russia, China, and Iran. However, bad actors used several clever tricks to bypass these geographic limits and safety filters.
- Reseller Relays: Bad actors bought access to Claude through third-party platforms. These platforms buy access to AI models legally and then resell access to users around the world without proper identity checks.
- Obfuscation: Users hid the true names of viruses and toxins by using chemical codes, technical jargon, or vague terms to trick the safety filters into thinking the research was safe.
- Fallback Systems: Some platforms set up automatic fallback systems. If Claude refused a prompt because of safety rules, the system automatically sent the prompt to a different AI model with weaker rules.
- Private Networks: Researchers used private server networks and fake accounts to hide their true locations and institutions.
This game of cat and mouse shows why stopping AI misuse requires looking beyond the chatbot itself. It requires securing the entire digital supply chain.
As nations invest heavily in artificial intelligence infrastructure, stopping these leaks is a top national security goal. For instance, read about how South Korea launched a massive budget to power its AI revolution and protect its digital systems.
Beyond Bioweapons: Cyber Spying, Drone Swarms, and Surveillance
Biological research was not the only type of misuse uncovered in Anthropic’s investigation. The report revealed that users were also attempting to use Claude for cyber warfare, military equipment, and foreign influence operations.
Russian Cyberattacks and Drone Swarms
Anthropic discovered that Russian freelancers used Claude Code, an AI coding tool, to design software systems for autonomous military drone swarms. These software tools were created to help military drones coordinate during battle.
In another case, a Russian-linked cyber espionage team used Claude to automate parts of cyberattacks against organizations across Europe and Ukraine. The AI helped the hackers write malicious code and process stolen data faster than human hackers could on their own.
These developments show how defense tech and AI are merging rapidly. To see how private companies are building tools for national security, read about how Palantir’s CEO launched a defense tech startup.
Missile Technology and Guided Rockets
In Yemen, users submitted queries asking Claude to help write code for guided rockets using mobile phone technology. Anthropic identified the safety breach and banned the associated accounts before any software could be deployed.
Mass Surveillance and Online Manipulation
The report also highlighted attempts to use Claude for mass surveillance and social media manipulation. In one instance, a company built a network of fake dating apps to scam users and track political dissidents.
In another case, foreign actors set up hundreds of automated social media profiles to make propaganda look like real opinions from everyday people.
This mirrors a broader trend across tech platforms. For example, check out how Instagram cracked down on fake human accounts and AI influencers to keep social media safe.
Internal Drama and Growing Warnings From AI Experts
The disclosure of these threat reports comes at a time of internal tension within the AI industry. Just two days before Anthropic published the findings, a senior AI safety researcher named Jacob Coxon resigned from the company.
In a statement that went viral across the tech world, Coxon warned that AI systems are advancing faster than safety controls. He stated that many researchers inside top AI companies genuinely fear that uncontrollable AI systems could pose existential risks to humanity before the end of the decade.
Build Funnels, Email Lists & Sell Online With One Free Tool
Create funnels, send emails, and sell online using Systeme.io without paying for multiple tools.
Create Free AccountFree forever • No credit card • Beginner-friendly
Coxon’s resignation caught the attention of US lawmakers. Senator Bernie Sanders announced plans to introduce legislation called the Ban Artificial Superintelligence Act. The bill proposes a temporary pause on the development of advanced AI models until strong safety regulations are written into law.
At the same time, massive investments continue to pour into AI hardware, leading to public debate over resource usage. If you want to understand how communities are responding to this growth, read about why investors are worried about the backlash against AI data centers.
How Anthropic Is Upgrading Its Safety Classifiers
In response to these threat discoveries, Anthropic updated how its models handle biological and military questions. The company made major changes to ensure its newest models remain protected against abuse.
- Stricter Biological Classifiers: Anthropic built automated filters that automatically detect dual-use biology questions. If a prompt touches on enhancing pathogen transmissibility or evading immune systems, the AI triggers a hard refusal.
- Model Downgrading: If an unvetted account asks complex questions about sensitive science, the system automatically routes the user to a weaker model tier that lacks the capability to generate advanced molecular instructions.
- Proactive Account Sweeps: The safety team runs regular automated sweeps to spot suspicious network traffic, identifying third-party resellers and VPN relays that bypass regional bans.
- Partner Collaboration: Anthropic shares intelligence reports with other AI developers, cybersecurity agencies, and government departments so the entire industry can block malicious users together.
- Restricted Access for Powerful Models: Anthropic’s most advanced models, like Claude Mythos and Claude Fable, are kept behind strict wall systems and are not available to the general public.
In addition to safety updates, AI developers are also building transparency features into their everyday products. To learn more about how watermark removals work in consumer software, check out our piece on how Google lets users remove Gemini AI watermarks.
If you are interested in automated tech workflows for online creation, take a look at our guide to YouTube automation strategies.
Frequently Asked Questions (FAQs)
Did anyone successfully build a biological weapon using Claude?
No. Anthropic confirmed that none of the users succeeded in building a working biological weapon. The safety systems caught the requests early, blocked the prompts, or restricted the users to weaker models that could not provide usable instructions.
Why cannot AI companies just block all virus research?
Blocking all virus research would stop scientists from using AI to develop vaccines, cancer treatments, and life-saving medicines. Because beneficial science and dangerous weapons use similar technical principles, filtering out bad actors without stopping good science is a delicate balancing act.
Which AI models were involved in these attempts?
The report noted that older models like Claude Opus 4 and Claude Sonnet 4.5 were targeted because they had less strict filters at the time. Newer models, including Claude Mythos and Claude Fable, have much stronger built-in safeguards and are restricted to vetted organizations.
How did users get around geographical bans?
Bad actors used private networks, proxy servers, and third-party reseller relays. These resellers buy API access legally and let overseas users submit prompts without verifying their identity or location.
What is Anthropic doing with the data from these incidents?
Anthropic banned the offending accounts, closed down reseller backdoors, updated its safety classifiers, and shared its technical findings with government security officials and rival AI companies.
How can I get in touch or learn more about this topic?
You can read more about our mission on our About Page or send us your questions directly through our Contact Page.
Looking Ahead in the Age of Frontier AI
The findings in Anthropic’s latest threat report serve as a wake-up call for the entire tech world. As artificial intelligence models become more capable, the line between helpful scientific tools and dangerous threats grows thinner every day.
While Anthropic successfully stopped these five bioweapon attempts and disrupted cyberattacks from state actors, the threats are constantly evolving. Stopping future misuse will require clear government policies, global cooperation, and continuous safety updates from AI companies.
Keeping up with breaking news in technology, security, and global events is essential in this fast-moving digital world. Connect with our community and share your thoughts on social media:
- Follow our visual updates on Instagram
- Join the discussion on Facebook
- Get real-time alerts on X (formerly Twitter)

