Security

Anthropic blocks bioweapons research with Claude

2 min read

TL;DR Too Long; Didn’t read

According to its own statements, Anthropic has blocked five attempts to use Claude for the research of biological weapons. One user circumvented a location ban to research the transmissibility of avian influenza to mammals. The company blocked the accounts but cannot definitively prove malicious intent.

A hand with an Anthropic logo sticker places a glass bell over a glowing red virus model, with a crossed-out test tube in front. Image generated with GPT Image 2

Key takeaways

  • Five case studies in the fourth threat report revolve around potential connections to biological weapons.
  • One case concerns research on avian influenza transmission to mammals via a circumvented location ban.
  • Anthropic blocked the affected accounts but acknowledges uncertainty about the actual intent.
  • The report covers the period from December 2025 to August 2026.
  • In addition to bioweapons cases, the report also documents state-sponsored cyber and influence operations.
  • US lawmakers simultaneously point to growing security risks posed by AI systems.

Anthropic has disclosed five cases in which users attempted to use the chatbot Claude for research potentially related to biological weapons. The company suspended the affected accounts but could not definitively prove malicious intent in every case. The underlying threat report covers abuse attempts between December 2025 and August 2026.

Report cites avian influenza case as an example of abuse

The threat report describes five case studies with potential links to biological weapons. Cyberattacks and influence operations make up a significantly larger portion of the same document. In one of the five cases, a person outside the USA accessed Claude by circumventing a location restriction. They were researching the adaptation of highly pathogenic avian influenza (H5N1) to mammals – a topic with dual-use potential. The same information could help detect naturally occurring virus variants early or be misused for harmful purposes. Anthropic therefore categorizes the request as clearly “dual use” and does not attribute any proven intent to cause harm to those involved. Nevertheless, the requests were sufficient to permanently suspend the affected accounts. The company identified the cases using the same automated classifiers that Anthropic already employs for blocking risky model actions. This is additionally supplemented by manual reviews of particularly conspicuous conversation logs. The disclosure aims to improve its own protective mechanisms and share insights with authorities and the industry.

Numbers on abuse cases are hardly verifiable independently

This is already the fourth threat report that Anthropic has published since last year. In addition to the five bioweapons case studies, the current document documents state-sponsored cyber operations from Russia, China, and France. It also includes commercial influence campaigns across several continents, such as against elections in Malaysia. Overall, the company has thwarted dozens of abuse attempts since December 2025. This number cannot be independently verified, as Anthropic does not disclose the affected accounts or the complete raw data. “Sophisticated attacks no longer require sophisticated attackers,” the company says of the disclosure, pointing to falling technical barriers for lone actors. The security incident at Claude Opus is being investigated separately by the organization METR. Anthropic reported it two days earlier, and it does not appear in the current report. The disclosure also comes at a time of increasing political pressure. A report from the intelligence committee in the U.S. House of Representatives warned in the same week about AI systems as a security policy blind spot, as regulation is not keeping pace with the speed of technology.

It will be crucial whether Anthropic’s transparency strategy becomes the industry standard or whether competitors like OpenAI and Google keep comparable cases under wraps. For companies using Claude in their daily work, the report initially changes nothing – the described suspensions only affected individual, specifically identified accounts. It remains to be seen how Anthropic will respond to the growing political pressure in the next threat report.

Frequently asked questions

What does 'dual use' mean in an AI inquiry about pathogens?

The term describes information that can serve both prevention and misuse – for example, knowledge about viruses that researchers use for early detection, but which could also be suitable for harmful purposes.

How did Anthropic identify the affected users?

The report does not provide technical details on this. Anthropic generally refers to automated detection systems and the manual review of suspicious conversation patterns.

Are the identified users facing criminal consequences?

The report does not comment on this. Anthropic states that it limits itself to blocking the affected accounts and sharing information with authorities.

Do OpenAI or Google also publish comparable abuse reports?

Both companies occasionally report on blocked abuse attempts, but so far less frequently and with fewer case studies than Anthropic in its series of threat reports.

Where can the full report be read?

Anthropic publishes the document freely accessible on its own website as part of its threat intelligence series.

Sources (2)
  1. Anthropic – Threat Intelligence Report, September 2026
  2. ABC News – Anthropic says it blocked potential AI bioweapon misuse

Your AI update for the work week

Once a week, the most important AI news – plus one practical tip to try right away. No spam, unsubscribe anytime.

← Back to the blog