Anthropic Says It Stopped 5 Cases of Claude Being Used in Bioweapons-Adjacent Research
Set Trending Topics as a preferred source on Google.
AI company Anthropic recently published its most detailed report yet on how its models are being misused. Among the findings are five cases in which scientists used Claude for biological research that could potentially contribute to the development of biological weapons. The threat intelligence report runs to roughly 150 pages and covers activity over a period of about eight months.
What stands out is how Anthropic handles the uncertainty. The company concedes that in none of the cases could it determine whether the research served a legitimate or a harmful purpose. Basic biological research that leads to vaccines often relies on the same methods that make it possible to engineer dangerous pathogens. Faced with that ambiguity, Anthropic said it erred on the side of caution, because the consequences of missing malicious activity could be severe, the New York Times reports.
Chikungunya, Avian Flu and Orthopoxviruses
The documented cases include a grant application concerning chikungunya virus, complete with modifications intended to increase transmissibility and evade immune responses. The application was linked to a military research institute. Other cases involved weeks of study planning and data analysis around highly pathogenic avian influenza, as well as work on orthopoxviruses, toxins and venom-related compounds.
Claude’s safeguards blocked the sensitive requests and denied access to more capable model versions. In at least one case, those involved then routed their prompts to a competitor’s model with weaker protections. Anthropic banned the accounts in question and shared its findings with authorities and other AI providers.
The report deliberately withholds the names of institutions, countries and individuals. The reasoning: Anthropic does not assert that the people involved intended harm, and identifying them could expose them to risk. Jacob Klein, who leads threat intelligence at Anthropic, describes the cases as far subtler than the popular cliché. Nobody types into the chat window that they want to build a biological weapon.
The report also exposes a structural problem. Over a 30-day review period, Anthropic identified 35 research efforts originating from state-linked institutions, the majority of which involved legitimate civilian science. A classifier cannot simultaneously enable benefit and prevent harm, as the report puts it.
Andrew Weber, a senior fellow at the Council on Strategic Risks who reviewed the report before publication, told the New York Times that the findings were “chilling examples of state-sponsored biological weapons developers tapping into the rapidly advancing capabilities” of leading AI models.
New in the Report: Conventional Weapons
For the first time, Anthropic also documents attempts to use Claude for conventional weapons development. Six cases are described in total:
- China: In three cases, developers used Claude Code as a substitute for software engineers, working on guidance and control systems for weapons platforms.
- Russia: In two cases, freelance actors used the model to develop autonomous kamikaze drone swarms.
- Yemen: A cell in the north of the country worked with Claude on three weapons programs, among them a guided rocket (test-fired, apparently unsuccessfully), a multi-stage ballistic missile with a targeted range of more than 2,000 kilometers, and hypersonic glide vehicle variants. The report does not name those involved, though the context makes clear it is referring to the Iran-backed Houthi militia.
Surveillance, Propaganda and Cyber Operations
The bulk of the report covers misuse patterns that are already familiar. Among them are state-linked actors from China and Iran surveilling dissidents and diaspora communities. In Mali, a single consultant built a system called Lakana 360, designed to monitor around 25 million SIM cards across all three of the country’s mobile operators while circumventing court order requirements. Iranian actors distributed a malicious Firefox extension that harvested social media identities. In China, a religious affairs unit automated the work of analysts, while a separate operation scored social media posts for political sensitivity and flagged individuals for “control.”
On influence operations, Anthropic describes Russian state media using Claude to generate online propaganda designed to look like independent reporting, including fabricated claims about an election in Moldova. Add to that a French digital agency running roughly 70 fake news sites in 20 languages, and an election manipulation platform targeting Malaysia with some 1,000 fake accounts on X.
In the cyber category, the report lists a Russian espionage campaign attributed to Midnight Blizzard that targeted Ukrainian and European government bodies, along with criminal groups going after the AI supply chain itself, for instance by stealing API keys. Anthropic has previously reported on AI-assisted extortion attempts and autonomous attacks on companies.
Anthropic sums up the central finding itself: sophisticated attacks no longer require sophisticated attackers. AI has lowered the effort and the skill threshold far enough that individuals can now run operations that once took entire teams. What still separates one group of actors from another, the company says, is intent.

