Anthropic Blocks Researchers from Using Claude AI for Sensitive Bioresearch Projects

Anthropic said the five biological-misuse incidents occurred between December 2025 and August 2026, as part of a broader threat-intelligence report on misuse involving cyberattacks, influence operations, surveillance and weapons development.
Anthropic’s head of threat intelligence, Jacob Klein, said suspected misuse rarely involves an explicit declaration of malicious intent: “You are not seeing someone in a comic book kind of way say, ‘Hey, I want to build a biological weapon to kill everybody.’ It’s an incredibly nuanced situation.”
Anthropic described chikungunya as a mosquito-borne virus that can cause severe pain and fever lasting weeks or months and has no licensed treatment, details that contributed to the company’s concern about the proposed research.
The company said it disrupted every operation discussed in the wider report and is incorporating lessons from the investigations into new detection and prevention measures.
Anthropic said it detected and stopped five cases where researchers used Claude for biological work that could support weapons development, Fox News reported. The cases occurred between December 2025 and August 2026. They included drafting a grant proposal and planning gain-of-function research involving chikungunya and avian influenza. Some researchers tried to bypass regional restrictions and safety systems. Anthropic banned their accounts, strengthened monitoring, and shared findings with authorities and other AI companies.
The company withheld details about which countries, institutions, and specific agents were involved. AOL noted that Anthropic said the cases underscore how hard it is to tell legitimate biomedical research from dangerous misuse. The same AI capabilities can support vaccines and harmful pathogens. Jacob Klein, Anthropic's head of threat intelligence, emphasized that suspected misuse rarely involves explicit declarations of harm.
One case involved a chikungunya research proposal affiliated with a military institute. Anthropic blocked assistance because the work focused on increased transmissibility and immune evasion. Chikungunya is a mosquito-borne virus that causes severe pain and fever lasting weeks or months, with no licensed treatment. Fox News reported that researchers outside the United States used frontier AI models to plan experiments involving highly pathogenic bird flu and other biological agents with potential weapons applications.
Anthropic's investigations identified work on orthopoxvirus immune-response genes and toxin design as well. Some users reportedly attempted to bypass regional restrictions and safety systems in their requests. The company said it disrupted every operation discussed in its broader threat-intelligence report covering cyberattacks, influence operations, surveillance, and weapons development.
Jacob Klein said suspected misuse rarely involves an explicit declaration of malicious intent. "You are not seeing someone in a comic book kind of way say, 'Hey, I want to build a biological weapon to kill everybody,' " he explained. "It's an incredibly nuanced situation." Intent is rarely explicit, and scientific requests can appear legitimate. Safeguards must assess the combination of biological objectives, institutional affiliations, requested capabilities, and attempts to bypass controls.
The same methods that help researchers develop vaccines can also increase a pathogen's transmissibility and immune evasion. This dual-use nature makes it extremely difficult for AI safety systems to distinguish between beneficial and harmful research. AOL reported that Anthropic has incorporated lessons from the investigations into new detection and prevention measures.
AI can accelerate biological work by helping users analyze pathogen properties, explore immune evasion, and design toxins. The immediate risk is not necessarily autonomous weapon creation. Instead, it is the amplification of capabilities among actors who already possess laboratory expertise, materials, and institutional access. This could shorten the path from scientific concept to actionable experiment. AOL noted that the incidents reveal limits of regional blocking alone.
Regional restrictions fail when users alter their location, use intermediaries, or move to other services. Effective governance requires identity verification, behavioral monitoring, cross-provider intelligence sharing, rapid account enforcement, and cooperation with authorities. Anthropic said it strengthened monitoring and shared findings with other AI companies and law enforcement to address the threat.
Publishers
18
Articles
17
Reach
35