Santo Domingo 28°C
Technology

Anthropic Blocks Five Claude Research Efforts Linked to Biological Weapons

Anthropic says it disrupted five cases in which researchers used its Claude AI models for work that could support biological weapons development, including projects involving pathogens, toxins and research with potential pandemic implications.

| 5 min read

Anthropic has disclosed five cases in which its Claude artificial intelligence models were used in research that could potentially support the development of biological weapons, prompting the company to block accounts and strengthen restrictions on advanced biological queries.

The cases were identified between December 2025 and August 2026 as part of Anthropic’s latest threat-intelligence review. The company said the examples demonstrate a growing challenge for AI developers: the same advanced capabilities that can accelerate legitimate scientific research can also assist work involving dangerous biological agents.

Anthropic did not publicly identify the governments or institutions connected to the research. However, it said at least four of the five cases had links to state-supported programs or research environments, while stressing that some of the work could have had legitimate scientific purposes because of the dual-use nature of advanced biological research.

Five Cases Raised Biological Security Concerns

One of the cases involved a reseller platform that circumvented regional restrictions and provided Claude access to researchers working on a state-sponsored grant involving chikungunya virus. Anthropic said the proposed work involved gain-of-function research focused on properties including transmissibility and immune evasion.

The company said its biological safety systems blocked the high-risk requests and restricted the researchers to weaker Claude models. Anthropic’s assessment is that Claude’s contribution in this case was largely limited to areas such as data analysis, study ideation and experimental planning rather than expert-level biological research.

A second case involved a researcher who spent weeks using Claude to plan experiments related to the adaptation of avian influenza to mammals. Anthropic said its classifiers limited this activity to its least capable models, reducing the level of assistance the system could provide.

The remaining cases involved research into novel venoms and toxins. In one instance, a researcher used Claude for projects involving the computational redesign of toxins while presenting the work within a therapeutic research context. Anthropic said the program was also connected to state-supported research.

Another researcher used Claude across several projects involving the computational redesign of toxins and proteins associated with diseases considered high priority because of their epidemic and pandemic potential. Anthropic said both accounts were ultimately banned for violating its regional access policies.

Why Advanced AI Creates a New Dual-Use Problem

The disclosures highlight the difficulty of distinguishing legitimate scientific research from activity that could create security risks. Biological research routinely involves technologies and knowledge that can have beneficial applications in medicine while also being potentially useful for harmful purposes.

Anthropic said some of the toxin-related research largely bypassed its biological safety classifier because the compounds being studied could plausibly have therapeutic as well as harmful applications. The company argues that intent cannot always be reliably inferred from a technical research request, making simple automated blocking insufficient as the sole safeguard.

This concern has become more significant as frontier AI models have improved at sophisticated scientific tasks. Anthropic said its newer models can outperform experts on some complex biological problems and provide operational assistance on others, increasing both their potential value to legitimate researchers and the consequences of misuse.

Anthropic Is Tightening Access to Biology Capabilities

Anthropic has responded by separating general access to Claude from access to its most capable biology models. The company says Claude Fable 5 was initially launched with very restrictive biology safeguards because of concerns that its capabilities could be misused in biological weapons development.

In August, Anthropic said an update to Fable 5 reduced biology-related false positives and unnecessary model fallbacks by about 85%. However, the company continues to restrict professional biology and drug-development queries involving areas such as virology, toxicology and molecular design on Fable models.

Anthropic has instead been developing a trusted-access model for advanced life-sciences research. Its Mythos 5.1 model, introduced in September, is currently available only to vetted organizations and life-sciences researchers participating in controlled access programs. Anthropic says the system is intended for researchers whose identities, institutions and intended uses can be verified.

The company has also expanded its broader AI-for-science initiative, offering verified academic and nonprofit researchers access to Claude through subscriptions and research credits while keeping the most sensitive biology capabilities behind additional verification.

The Debate Is Moving Beyond Chatbot Safety

The latest incidents come as AI developers face growing pressure to demonstrate that safeguards work outside laboratory evaluations. Anthropic’s report said its systems successfully blocked many harmful requests, but not all attempts, and that users sometimes tried to evade protections by concealing their objectives, distributing work across multiple sessions or obtaining access through intermediaries.

The company has also reported other forms of misuse involving Claude, including cyber operations, surveillance, influence campaigns, conventional weapons development and attempts to extract or reproduce AI models. Those cases have strengthened Anthropic’s argument that increasingly capable AI systems require safeguards that extend beyond simply refusing individual prompts.

Anthropic CEO Dario Amodei has also called for the AI industry to slow the pace of development enough for safety systems and oversight mechanisms to catch up with rapidly increasing model capabilities. His latest proposals include independent evaluations inside AI companies, greater coordination among developers and broader international cooperation on advanced AI risks.

What the Cases Do — and Do Not — Prove

Anthropic’s disclosure does not establish that Claude successfully enabled the creation of a biological weapon. The company explicitly says its case studies illustrate potential pathways for misuse and that evaluations of AI capability cannot by themselves demonstrate that a model will be used to develop a biological weapon in the real world.

Instead, the cases provide evidence that researchers working on sophisticated biological projects are attempting to use frontier AI systems, including in areas where the same scientific capabilities could have legitimate medical applications. That distinction is important because the central policy challenge is not simply whether AI can answer a dangerous question, but how much additional capability it provides to someone who already has access to laboratories, biological materials and specialized expertise.

Anthropic’s response is increasingly based on controlled access rather than universal availability of the most powerful biological capabilities. The company says this approach would allow advanced AI to support legitimate scientific discovery while reducing the possibility that the same tools become broadly accessible to actors seeking to develop dangerous biological agents.

Share this article
Facebook X LinkedIn WhatsApp Email