Anthropic Reports State-Backed Actors Attempted to Use Claude for Bioweapon Research

Five cases of potential misuse involving viruses and toxins detailed in threat intelligence report

edit
By LineZotpaper
Published
Read Time3 min
AI company Anthropic has revealed that state-sponsored actors attempted to use its Claude AI assistant to conduct research potentially related to biological weapons, including efforts to engineer deadlier viruses and evade detection. The findings, detailed in a threat intelligence report covering November 2025 to September 2026, describe five particularly concerning cases where accounts used anonymization techniques and U.S. proxies to bypass regional blocks.

Anthropic has published a threat intelligence report detailing activity between November 2025 and September 2026, highlighting five instances where its Claude AI was asked to perform work that could potentially be used in biological weapons. The cases involved requests related to three viruses and two toxins, with all threat actors using varying degrees of anonymization and attempting to evade Anthropic's regional blocking.

The company noted the difficulty of distinguishing between legitimate biological research—such as vaccine development or virus spread prediction—and nefarious inquiries. "Out of an abundance of caution," Anthropic said it launched recent models with stronger safeguards.

In one case, a request for assistance in developing a grant application involved improving the chikungunya virus, aiming to increase its mutation and virulence. Although the application appeared to be for civilian researchers, Anthropic discovered the actual investigation was meant to proceed at a military facility. The request was routed through a third-party LLM platform associated with both military and civilian institutions in countries that are geo-blocked by Anthropic. The platform used U.S. infrastructure to evade detection, gray-market resellers, and catered to customers seeking to skirt content restrictions. Anthropic banned the accounts and shared information with authorities, though the same individuals repeatedly attempted to access Claude via zero-data-retention services.

Another case involved a non-U.S. researcher investigating how avian flu adapts to mammals and causes diseases outside the respiratory tract. Given avian flu's high fatality rate and low population immunity, the research could discover mechanisms to increase transmissibility. The researcher used a random username, a private email service, and accessed Claude through a VPS, prompting Anthropic to decline the inquiry.

A third case similarly involved a grant application about orthopoxviruses, the family that includes smallpox and Mpox. The application discussed containment facilities and live experimentation, focusing on understanding genetics for immunity evasion. While initially not alarming, Anthropic traced the account to a reselling service with a randomly generated email, routed through U.S. infrastructure, and linked to a previously banned account.

The report does not specify which states were behind the attempts, but Anthropic is known to block access to Claude from China, Russia, Iran, North Korea, and other countries.

§

Analysis

Why This Matters

  • The incidents show state-sponsored actors actively seeking to exploit AI for bioweapon research, raising national security concerns.
  • Anthropic's detection challenges highlight the difficulty of balancing legitimate biological research with preventing misuse.
  • The use of proxies and gray-market services indicates sophisticated efforts to circumvent AI safety measures.

Background

Anthropic, a leading AI safety company, has regularly published reports on misuse of its Claude AI assistant. The company has implemented regional blocks and safety safeguards to prevent malicious use, but threat actors continue to develop evasion techniques. This report covers activity from November 2025 to September 2026, focusing on five particularly concerning cases among tens of case studies.

Key Perspectives

[Anthropic]: Sees these cases as serious misuse attempts requiring model safeguards and sharing threat information with authorities. The company emphasizes the difficulty of distinguishing benign from malicious research. [State-sponsored actors (unnamed)]: Used anonymization techniques, U.S. proxies, and third-party platforms to evade detection and content restrictions, indicating a persistent effort to access AI capabilities for bioweapon-related research. [Critics/Skeptics]: Might question whether AI companies can effectively police such use, or argue that stronger safeguards could hinder legitimate research. The report itself notes the challenge of distinguishing nefarious from defensive research.

What to Watch

  • Future reports from Anthropic and other AI companies on similar threat patterns.
  • Government responses to shared threat intelligence, including potential policy or legal actions.
  • Effectiveness of AI safeguards against increasingly sophisticated evasion techniques.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.