
Anthropic says it has stopped multiple attempts by scientists this year to use Claude in ways that could support bioweapons research, underscoring growing worries that advanced AI systems may be misused in biology as well as cybersecurity. In a report on malicious activity, the company said some users “circumvented controls” and tried to “obfuscate” the purpose of their work to avoid its safeguards.
Anthropic says it blocked attempts to push Claude toward dangerous biological research
The startup said it found five examples of possible misuse, including cases involving users in countries that it prohibits from accessing its models, such as Russia, China and Iran. Anthropic said one researcher from an “unsupported region” spent weeks planning experiments involving avian influenza with Claude, but the company’s safety systems limited the work to its weakest models.
Anthropic stressed that it could not know whether the people in the examples intended to cause harm. The same information that could help create biological weapons can also be relevant to legitimate work, including vaccine development. Even so, the company said it banned the accounts involved and chose to share the incidents to push broader discussion across the AI industry and with governments.
Why AI and biology are becoming a bigger safety concern
The report lands as concern over AI safety continues to intensify. Earlier this week, Jacob Coxon resigned from Anthropic, saying employees “earnestly believe it [AI] could kill us all by the end of the decade.” That warning came amid a wider escalation in debate over what highly capable models might be able to do once they are applied to sensitive scientific domains.
Experts increasingly worry that AI could assist terrorist groups, state actors or lone attackers in designing biological weapons, creating viruses or weaponizing existing pathogens. At the same time, there are practical limits: even if a model can help with theory or planning, actually producing a bioweapon still requires know-how, equipment and other resources.
Not just biology: Anthropic also flagged cyber and abuse cases
Anthropic’s report did not focus only on biological risks. The company said it also identified misuse tied to cybercrime and surveillance, including “a network of fake dating apps designed to defraud users to surveillance systems built to identify and monitor dissidents.” The examples were presented as part of a broader effort to show how people are trying to bend frontier models toward harmful goals.
Cybersecurity has remained one of the largest concerns for safety advocates, in part because AI can lower the skill level needed for certain kinds of abuse. Anthropic said attackers have been finding ways to work around guardrails rather than simply asking directly for dangerous instructions, which makes detection and prevention harder.
China-linked model cloning attempts add to the pressure
The company also used the report to expand on claims that seven China-based labs, including Moonshot and DeepSeek, tried to replicate its technology through distillation. Anthropic said it had observed “increasingly sophisticated methods to circumvent our defenses and harvest the capabilities of US frontier models.”
Distillation is a process in which one model is used to train or imitate another, and the technique can be legitimate. Anthropic’s concern is that adversaries may use it to copy the capabilities of powerful proprietary systems while avoiding the safeguards those systems were designed to enforce.
What Anthropic is signaling to regulators and competitors
By publishing the cases, Anthropic is signaling that model safety is no longer just a theoretical issue for labs to handle privately. The company is effectively asking for a policy response as AI systems become more capable and more useful across scientific work that has dual-use implications.
That message may resonate with governments that are already considering how to regulate frontier AI. It may also put pressure on rival companies to explain how they are screening for harmful biology requests, how they detect evasive behavior and how they respond when users try to disguise their intentions.
What the Claude cases show about the limits of safeguards
The examples Anthropic described suggest that users are testing not only what Claude can say, but how far they can push it before safety systems intervene. The company said some actors tried to get around those controls by masking the true purpose of their research, a reminder that safeguards are often being evaluated by people actively looking for loopholes.
- Anthropic said it identified five examples of attempted misuse tied to biological research.
- Some cases involved users in countries barred from accessing its models.
- One case involved planning experiments related to avian influenza.
- The company said it restricted such work to weaker models and banned the accounts involved.
- Anthropic also highlighted cyber and surveillance abuses alongside the biology cases.
The company’s report reflects a broader shift in the AI debate: the question is no longer only whether models can generate harmful information, but whether people can creatively route around the barriers intended to stop them. As frontier systems spread into more fields, that challenge is likely to grow.
Source: Original report
Was this helpful?
Explore more: AI Automation Services More AI & Automation Tech News
Last Modified: September 11, 2026 at 10:31 pm
2 views

