Anthropic Flags Five Cases of Claude Use in Potential Bioweapon Development
A September threat intelligence report from Anthropic revealed instances where researchers leveraged Claude to advance biological research with possible weapons applications, prompting the company to strengthen safeguards around dual-use biology queries.

Anthropic developed Claude to assist with demanding scientific work, yet the company has acknowledged that certain researchers have directed that same capability toward applications carrying bioweapon risks. On September 10, Anthropic released a threat intelligence report documenting five separate biological-research scenarios tied to its AI systems. According to the company, this activity bore hallmarks of potential biological weapons advancement, with certain users circumventing geographic access restrictions or obscuring their research objectives.
The company took action by refusing some queries and deactivating user accounts, though it acknowledged being unable to confirm whether the scientists harbored malicious intent.
Organizations deploying cutting-edge AI for research purposes face a critical insight from these cases: problematic conduct may remain concealed when examining individual requests in isolation. Broader patterns—including account history, geographic location, and the full scope of research activities—can prove equally significant in identifying risk.
Five cases show the dual-use problem
Anthropic identified cases spanning chikungunya, avian influenza, orthopoxviruses, venom peptides, and toxins. One researcher invested considerable time designing avian influenza experiments, while a second leveraged Opus 5 to compose a grant proposal centered on orthopoxvirus immune-evasion strategies.
The Guardian reported that in multiple instances, researchers evaded protective measures designed for users in regions where the service lacks official support and took deliberate steps to hide their research focus. Anthropic terminated these accounts but declined to disclose the researchers' identities, affiliations, or geographic locations, citing lingering uncertainty regarding their true motivations.
These biological cases formed part of a broader investigation into misuse spanning December 2025 through August 2026. The Associated Press noted that Anthropic characterized these examples as among the most striking and previously unseen threat behaviors it had encountered, distinguishing them from routine policy violations.
The chikungunya case moved beyond a grant request
The most transparent instance centered on a government-backed initiative pursuing gain-of-function modifications to chikungunya. Anthropic indicated the research targeted a military research facility and aimed to engineer mutations rendering the mosquito-borne pathogen more virulent, though equivalent research could equally support vaccine or therapeutic development.
According to Anthropic, an intermediary service channeled connections via American servers to circumvent geographic blocks and depended on informal resellers and fabricated user profiles. When Anthropic declined certain sensitive requests, the platform redirected biology-related queries toward less restrictive models. Claude subsequently furnished writing assistance on research documents, which Anthropic interpreted as evidence the initiative had expanded past the initial grant stage.
Despite these concerning indicators, Anthropic refrained from definitively labeling the endeavor a weapons initiative.
What we don't know is if the research was meant to be weaponized
Jacob Klein, Anthropic's head of threat intelligence, told The New York Times
AI safeguards may need more than prompt blocking
Anthropic noted that earlier generations of Claude fell substantially short of providing meaningful assistance to advanced users pursuing hazardous biological work. With current-generation models, the company stated it can no longer offer that same guarantee, leading to the implementation of stricter controls targeting dual-use biology inquiries.
The chikungunya scenario demonstrates the inadequacy of model refusals alone. Anthropic blocked pertinent exchanges, yet the intermediary subsequently directed sensitive queries to less cautious models. When organizations leverage multiple AI vendors, a protective measure on a single platform risks being circumvented if a system automatically resubmits the request to alternative services.
The report underscores the challenge inherent in evaluating biological research through isolated prompts. Anthropic emphasized that biology represents an inherent dual-use field—identical information can advance vaccines or medicines while simultaneously enabling pathogen enhancement. The company cautioned that sophisticated operators can weaponize this ambiguity to mask the genuine scope of their objectives.
In high-stakes research contexts, institutions may require examination of the complete activity surrounding a query, rather than the query alone. Persistent model refusals, efforts to sidestep geographic limitations, unexpected intermediary connections, or attempts to mask account provenance should all warrant heightened scrutiny.


