Anthropic flags five Claude AI uses linked to biological weapons research

Anthropic flags five Claude AI uses linked to biological weapons research

Anthropic, the company behind Claude AI, says it identified five cases in which users employed its artificial intelligence models in ways that could support biological weapons development.

The company disclosed this in its latest threat intelligence report published on Thursday, saying the cases were among a range of malicious or potentially harmful activities detected and disrupted on its platform between December 2025 and August 2026.

Anthropic particularly flagged five Claude AI use cases that involved research into areas including chikungunya virus, highly pathogenic avian influenza, orthopoxviruses, venom peptides and toxins.

The company said it had banned the accounts involved and incorporated information from its investigations into its safeguards, enforcement and threat intelligence systems.

However, Anthropic stressed that it was not asserting that the scientists involved intended to cause harm.

“We do not assert that they intended harm, and identifying them or their labs could expose them to harm,” the company said, adding that it would withhold the names of the research institutions, countries and specific biological agents or techniques involved.

Anthropic said the cases demonstrated the difficulty of distinguishing between legitimate scientific research and activities that could be used for harmful purposes.

Biological misuse is one of the most serious risks of frontier AI models,” the company said, warning that AI could potentially be used to make existing pathogens more dangerous or create new ones.

“The same information that can be used to develop a biological weapon could also be used to develop, for example, a vaccine or a cure for a disease,” the AI giant added.

In the first case, Anthropic said its biological safety classifier blocked a request to help prepare a grant application involving gain-of-function research on chikungunya virus.

The company said its subsequent investigation found that a reseller platform was being used to provide access to Claude to researchers in regions where Anthropic does not offer its services.

The platform also allegedly routed requests rejected by Claude to other AI models with more permissive safeguards.

Anthropic said it banned the associated accounts, worked with partners to take down the relay networks and shared its findings with AI companies and government authorities.

In a second case, the company said a researcher outside the US used Claude over several weeks while planning research involving highly pathogenic avian influenza and its adaptation to mammals.

According to Anthropic, the researcher used Claude for study planning, data analysis, interpretation and prioritisation of experiments, as well as editorial assistance.

The company said its safeguards restricted the researcher to weaker Claude models and that the AI’s contribution was primarily limited to clerical assistance, study ideation and design.

Anthropic said the case nevertheless provided evidence of active research programmes involving pathogens with enhanced pandemic potential.

A third case involved a grant application for orthopoxvirus research at a state-associated infectious disease laboratory. Anthropic said a reseller relay serving more than a dozen customers used Claude to draft the application.

The company said the application involved research into how orthopoxviruses interact with the immune system and was produced using Claude Opus 5 in about an hour.

The fourth and fifth cases involved research into venoms and toxins.

Anthropic said one researcher used Claude to develop an atlas of venom toxin peptides and a generative system for optimising toxin characteristics, with the stated goal of developing therapeutic molecules.

In another case, a researcher used Claude in projects involving the computational redesign of toxins under a national public research programme. Anthropic said the researcher deliberately obscured the identities of some toxins and viral proteins in progress reports.

The company said both accounts were banned in May 2026 for violating its Supported Regions Policy.

Anthropic said the cases highlighted the challenge of regulating AI-assisted biological research because many applications are “dual use”, meaning they can have both beneficial and harmful applications.

Anthropic, however, cautioned against interpreting its findings as evidence that Claude was currently enabling imminent biological threats.

“We take these cases as evidence not of the imminence of biological threats currently uplifted by Claude, but rather as evidence that significant dual-use research efforts are associated with state actors of concern,” the company said.

The report is part of a wider disclosure by Anthropic on the misuse of its AI systems.

The company said its investigations over the past eight months also uncovered cyber operations, surveillance, influence operations, scams and fraud, conventional weapons development and attempts to illicitly distil its models.

The report comes shortly after concerns raised publicly by former Anthropic researcher Jacob Coxon about the risks posed by increasingly capable AI systems.

Online previously reported that Coxon resigned from Anthropic and said “people building AI earnestly believe that it could kill us all by the end of the decade.”

Anthropic’s latest report also said it had identified a Russia-linked cyber espionage operation in which Claude was used to automate parts of attacks against organisations in Ukraine and Europe.