AI safety debates have run on red-team experiments and hypotheticals for years. Anthropic has now put names and dates to the problem, disclosing that it detected and disrupted real-world use of its Claude AI in biological research programs with potential weapons applications. According to CNN, the company considers biological misuse one of the most serious risks facing AI models.
The threat intelligence report details five cases where users were conducting biological research that could support weapons development, drawn from activity between December 2025 and August 2026. However, the company has not demonstrated that any of these programs were definitely intended to produce a weapon. It banned the accounts anyway.
The main problem is that this research can have both good and harmful uses. The same knowledge that helps scientists develop vaccines or track diseases can also be used to make pathogens more dangerous. That makes it difficult for simple AI safety filters to tell the difference between legitimate research and malicious work.
One of these cases came from a military research institute
The most detailed case involved a scientist who used Claude to prepare a grant proposal for gain-of-function experiments on the chikungunya virus, which is spread by mosquitoes. The proposed research focused on mutations that could make the virus spread more easily, cause more severe disease, or better evade the immune system. The work appeared to be connected to a military research institute.
The user accessed Claude from a country where the service is unavailable by using a reseller that routed traffic through U.S. infrastructure. When Claude refused some requests, the reseller simply sent them to other AI models with weaker safeguards.
That points to a problem no single company can fix on its own. Anthropic banned the accounts and worked with partners to disable some of the relay infrastructure, but the operator re-established access within days using new accounts. A refusal from one model means very little as long as another provider will answer.
In another case, a researcher used Claude for several weeks to study genetic changes in highly pathogenic avian influenza. The work included planning experiments and analyzing how the virus adapts to mammals and spreads through the air. Anthropic believes the researcher likely had access to real virus samples, although the project still appeared to be in its early stages.
Safeguards kept that researcher off the strongest models. The work ran on older, weaker versions of Claude, which limited the scientific uplift to basic data analysis and brainstorming. There is no evidence that Claude independently designed a virus that researchers then built.
The other cases involved more than viruses. Anthropic identified a reseller network drafting a proposal on orthopoxvirus immune evasion, a state-backed researcher studying venom peptides that can cause paralysis, and another researcher trying to redesign toxins while hiding their identities in progress reports.
Anthropic, which held back Claude Mythos Preview from public release earlier this year, believes its newest models have crossed a capability threshold. Older systems were not sophisticated enough to meaningfully assist dangerous research, and the company says it cannot guarantee the same about its current ones. Stricter safeguards now sit around its most advanced models, including automated classifiers and constant monitoring.
Anthropic is trying to draw a line between legitimate scientific research and work that could create serious biological risks. Its new verification program may give trusted researchers more access, but these cases show how difficult that line is to enforce. As AI models become more capable, the challenge will be keeping them useful for medicine and research without giving dangerous actors the same advantages.
Published: Sep 22, 2026 11:15 am