Anthropic identifies five cases in which Claude was used for dangerous biological research
Anthropic has disclosed five cases in which researchers used its Claude AI models in research that could have supported the development of biological weapons. The company closed the accounts involved and strengthened its safeguards, while stressing that some of the same research may be entirely legitimate.
The cases occurred in regions where Anthropic does not permit access, and the users attempted to circumvent geographical restrictions. The research involved, among other things, altering virus properties and toxins. Anthropic did not disclose the names of the researchers, institutions or countries involved.
AI assisted real laboratory research
The most concerning aspect is not that someone asked a chatbot for theoretical information about biological weapons. Anthropic found links to operating laboratories and state-backed research programmes.
In one case, a researcher was studying the adaptation of avian influenza to mammals. Anthropic found indications in the user's conversations that the research group may have had access to the relevant virus isolates. Claude assisted with data analysis, study design and structuring ideas, among other tasks.
Anthropic assessed the AI's actual contribution in this case as remaining limited. More capable models blocked more dangerous content, forcing the user to turn to the less capable Claude Sonnet 4 and Haiku 4.5 models.
In another case, a state-backed programme used Claude for toxin-related research. Another user employed the model to computationally redesign various toxins and specifically asked Claude to conceal the exact nature of the proteins being studied in reports.
Dual-use research is the major challenge
For Anthropic, identifying such cases is not straightforward. The same information that can make a pathogen more dangerous can also help develop a vaccine or treatment. A toxin can likewise be both a dangerous substance and a starting point for a medicine.
As a result, simply blocking keywords is not enough. A highly qualified researcher does not need to tell Claude that they want to create a biological weapon. They can divide the work into dozens of seemingly routine scientific tasks.
Anthropic concluded in its report that granting access to the most capable biological AI tools requires more thorough vetting of users and research institutions than before. The company also considers it necessary to retain sufficient activity history in order to identify broader suspicious patterns rather than isolated queries.
Current models change the risk assessment
Anthropic also acknowledges a significant change in the capabilities of its models in the report. In the company's assessment, the 2025 Claude Opus 4 and Sonnet 4.5 models fell clearly short of the threshold at which they could have provided significant assistance to an experienced researcher engaged in dangerous biological research.
Anthropic can no longer make the same confident claim about newer models.
As a result, the company applies stricter restrictions on biological content to its most capable models. Anthropic stresses, however, that the five identified cases do not prove that an AI-created biological threat is imminent. Instead, they show that state-backed and dual-use research programmes are already attempting to gain access to the most capable US AI models.