Anthropic has disclosed five cases in which users attempted to use the chatbot Claude for research potentially related to biological weapons. The company suspended the affected accounts but could not definitively prove malicious intent in every case. The underlying threat report covers abuse attempts between December 2025 and August 2026.
Report cites avian influenza case as an example of abuse
The threat report describes five case studies with potential links to biological weapons. Cyberattacks and influence operations make up a significantly larger portion of the same document. In one of the five cases, a person outside the USA accessed Claude by circumventing a location restriction. They were researching the adaptation of highly pathogenic avian influenza (H5N1) to mammals – a topic with dual-use potential. The same information could help detect naturally occurring virus variants early or be misused for harmful purposes. Anthropic therefore categorizes the request as clearly “dual use” and does not attribute any proven intent to cause harm to those involved. Nevertheless, the requests were sufficient to permanently suspend the affected accounts. The company identified the cases using the same automated classifiers that Anthropic already employs for blocking risky model actions. This is additionally supplemented by manual reviews of particularly conspicuous conversation logs. The disclosure aims to improve its own protective mechanisms and share insights with authorities and the industry.
Numbers on abuse cases are hardly verifiable independently
This is already the fourth threat report that Anthropic has published since last year. In addition to the five bioweapons case studies, the current document documents state-sponsored cyber operations from Russia, China, and France. It also includes commercial influence campaigns across several continents, such as against elections in Malaysia. Overall, the company has thwarted dozens of abuse attempts since December 2025. This number cannot be independently verified, as Anthropic does not disclose the affected accounts or the complete raw data. “Sophisticated attacks no longer require sophisticated attackers,” the company says of the disclosure, pointing to falling technical barriers for lone actors. The security incident at Claude Opus is being investigated separately by the organization METR. Anthropic reported it two days earlier, and it does not appear in the current report. The disclosure also comes at a time of increasing political pressure. A report from the intelligence committee in the U.S. House of Representatives warned in the same week about AI systems as a security policy blind spot, as regulation is not keeping pace with the speed of technology.
It will be crucial whether Anthropic’s transparency strategy becomes the industry standard or whether competitors like OpenAI and Google keep comparable cases under wraps. For companies using Claude in their daily work, the report initially changes nothing – the described suspensions only affected individual, specifically identified accounts. It remains to be seen how Anthropic will respond to the growing political pressure in the next threat report.


