Anthropic has published a threat intelligence report detailing activity between November 2025 and September 2026, highlighting five instances where its Claude AI was asked to perform work that could potentially be used in biological weapons. The cases involved requests related to three viruses and two toxins, with all threat actors using varying degrees of anonymization and attempting to evade Anthropic's regional blocking.
The company noted the difficulty of distinguishing between legitimate biological research—such as vaccine development or virus spread prediction—and nefarious inquiries. "Out of an abundance of caution," Anthropic said it launched recent models with stronger safeguards.
In one case, a request for assistance in developing a grant application involved improving the chikungunya virus, aiming to increase its mutation and virulence. Although the application appeared to be for civilian researchers, Anthropic discovered the actual investigation was meant to proceed at a military facility. The request was routed through a third-party LLM platform associated with both military and civilian institutions in countries that are geo-blocked by Anthropic. The platform used U.S. infrastructure to evade detection, gray-market resellers, and catered to customers seeking to skirt content restrictions. Anthropic banned the accounts and shared information with authorities, though the same individuals repeatedly attempted to access Claude via zero-data-retention services.
Another case involved a non-U.S. researcher investigating how avian flu adapts to mammals and causes diseases outside the respiratory tract. Given avian flu's high fatality rate and low population immunity, the research could discover mechanisms to increase transmissibility. The researcher used a random username, a private email service, and accessed Claude through a VPS, prompting Anthropic to decline the inquiry.
A third case similarly involved a grant application about orthopoxviruses, the family that includes smallpox and Mpox. The application discussed containment facilities and live experimentation, focusing on understanding genetics for immunity evasion. While initially not alarming, Anthropic traced the account to a reselling service with a randomly generated email, routed through U.S. infrastructure, and linked to a previously banned account.
The report does not specify which states were behind the attempts, but Anthropic is known to block access to Claude from China, Russia, Iran, North Korea, and other countries.