SAN FRANCISCO, United States — Anthropic says it blocked and disrupted five cases in which users attempted to use its Claude artificial intelligence models for research that could potentially support biological-weapons development.
The cases were among misuse incidents identified between December 2025 and August 2026, according to Anthropic’s latest threat intelligence report. The company said it banned associated accounts, investigated the activity and used its findings to strengthen safeguards around biological research.
Anthropic did not identify the countries, research institutions or specific biological agents involved. It also said it was not asserting that the scientists involved intended to cause harm, emphasizing that biological research can have both legitimate and dangerous applications.
Anthropic identifies five biological-risk cases
The company described five cases involving different forms of advanced biological research.
One involved researchers working under a state-sponsored grant who sought assistance with gain-of-function research involving chikungunya virus. Anthropic said its biological safety classifier blocked the relevant request in May and that a subsequent investigation raised additional concerns about the research environment and attempts to circumvent regional restrictions.
Another case involved a researcher using Claude while planning experiments related to the adaptation of highly pathogenic avian influenza to mammals.
Anthropic also identified a case in which its Opus 5 model was used through a reseller platform to prepare a research grant application involving orthopoxvirus immune evasion. Two other cases involved the design or optimization of biological molecules and computational work involving toxins.
The company said the cases demonstrated how difficult it can be to distinguish legitimate scientific research from activity that could create serious biological risks.
Researchers attempted to bypass safeguards
Anthropic said some users attempted to circumvent restrictions imposed on its services.
In one case, a reseller platform routed traffic through U.S. infrastructure to bypass regional restrictions. The platform also used a system that could redirect requests rejected by Claude to other AI models with less restrictive safeguards, according to Anthropic.
The company said it banned accounts associated with the activity and worked with partners to disrupt the relay networks involved. It also said some operators subsequently attempted to regain access using new identities and other routes.
Anthropic said the incidents demonstrated that sophisticated users are actively testing AI safety controls and adapting their methods when restrictions interfere with their work.
Company says biological research presents a dual-use problem
Anthropic stressed that the underlying research cannot always be classified simply as malicious.
Scientific work involving pathogens, genetic changes or biological molecules can contribute to vaccines, treatments and other medical advances. The same knowledge can also potentially be used to increase the harmful properties of biological agents.
That dual-use nature makes automated detection particularly difficult, the company said. Researchers may also present sensitive work in terms that obscure its potential risks.
Anthropic said some actors appeared to use this ambiguity to maintain what it described as plausible deniability while seeking assistance from AI systems.
New models face stronger restrictions
Anthropic said its assessment of biological risk has changed as its models have become more capable.
Earlier evaluations of models such as Claude Opus 4 and Claude Sonnet 4.5 found that they were well below the company’s threshold for meaningfully assisting sophisticated users with dangerous biological research.
The company said it could no longer make the same assumption about newer models. As a result, Anthropic has introduced stronger safeguards on newer systems, including restrictions covering a wider range of dual-use biological research queries.
The company has also conducted controlled biological-risk evaluations and says its current approach combines model testing, automated safeguards, monitoring and investigations of suspected misuse.
Anthropic says no biological attack was established
Anthropic’s disclosure does not establish that a biological weapon was created or deployed as a result of the reported activity.
The company described the five cases as examples of activity that could support biological-weapons development. It said the purpose of the research could not always be established and that it was withholding identifying information partly because the people involved are working scientists.
The findings nevertheless point to a growing challenge for AI companies as increasingly capable models become useful for complex scientific work.
Anthropic said it plans to continue improving its safeguards and sharing relevant intelligence with authorities and other industry partners.
8. Reporting Credit: Anthropic — September 2026 Threat Intelligence Report on detected and disrupted misuse of Claude, including five biological-risk case studies, account enforcement, safeguard improvements and information shared with authorities and industry partners.














