Anthropic says it blocked five bids to use Claude on biological weapons work
A threat report covering late 2025 to August 2026 describes gain-of-function queries on chikungunya, work on toxins, and accounts that routed around regional blocks. Newer models can now finish complex lab tasks that older ones could not.

San Francisco3 min read
Last updated
Anthropic said on 10 September that it had identified and shut down accounts that used its Claude models in ways that could support biological weapons work. The finding sits in the company's third threat-intelligence report since March 2025 and covers activity from late 2025 through August 2026.
The firm listed five case studies it treats as biological misuse. Over a 30-day window it also flagged about 35 distinct research efforts that raised concern. Jacob Klein, head of threat intelligence, told The New York Times that the company does not know whether the work was meant to be weaponised. Andrew Weber of the Council on Strategic Risks, who reviewed the report before release, said access to such models should be limited to trusted researchers.
What the five cases involved
Three of the cases concerned viruses. Two concerned toxins and venoms. In one episode, in May, a user asked Claude to help write a grant application for work on the chikungunya virus. The proposed research was gain-of-function: genetic changes aimed at transmissibility and immune evasion, including tests that would make the virus more harmful in live animals. Anthropic said it could tell the work was intended for a military research institute. The accounts were banned.
The users tried to hide. They routed traffic through U.S. proxies, evaded regional blocks and described the work in language meant to look like ordinary science. Anthropic already refuses service in China, Russia, Iran and North Korea. The report does not name a state sponsor.
The same document records misuse in six other categories: cyber operations, political influence work, surveillance, scams and fraud, conventional weapons development, and distillation, the practice of training a smaller model on the outputs of a larger one. None of the biological cases involved Claude Fable or the Mythos-class models, except one distillation attempt. The company said recent models, including Claude Fable 5, now ship with tighter blocks on dual-use biology questions.
Why this year is different
Evaluations of older Claude versions last year found they could not give meaningful help on dangerous biological work. Newer models can complete complex scientific tasks. That is the shift the report is written to mark. The same information that can design a vaccine can, in another prompt, design a pathogen. Anthropic's own phrasing is that biological misuse is one of the most serious risks of frontier models and that, without safeguards, the consequences could be catastrophic.
The report arrives in the same week as a separate warning from Jacob Coxon, a former Anthropic researcher, who wrote that people building the systems believe there is a real chance advanced AI could kill everyone by the end of the decade. That claim is not in the threat report. It is part of the climate in which the report is being read.
Regulators have not issued a new rule in response. The United States still has no statute that forces model makers to publish misuse case studies. Anthropic is doing so on its own timetable. Critics will note that the company both sells the models and grades the risk. Supporters will note that no other major lab has put five biological case studies on the record this week.
What was actually stopped
What Anthropic stopped is account access and further answers. It did not seize laboratories, arrest anyone or confirm that a weapon was in production. The users may have been scientists doing sloppy grant writing. They may have been doing what the prompts describe. The company says it chose caution and cut them off.
That choice will now be copied or ignored by rivals. OpenAI, Google DeepMind and others run their own classifiers. None of them published a matching set of biological case studies on 10 September. The next test is whether the same pattern appears in their logs, and whether they say so.
Continue reading
- Tech
Enflame shares jump 179% on Shanghai debut as China lists another AI chipmaker
Almanaque Digital DeskShanghai
- News
CDC to spend up to $50 million tracking people who were children on 9/11
Almanaque Digital DeskAtlanta
- News
France withdraws backing for Infantino after the failed World Cup stake sale
Almanaque Digital Desk