Anthropic reported that during the current year it prevented several attempts to use its Claude chatbot and other models for projects that could potentially aid the development of biological weapons. The company published an eight-month review on Thursday that details observed instances of improper use.
The report covers more than just biological issues: it identifies surveillance activity by actors the company links to the Chinese and Iranian governments, notes examples of Russian state media producing propaganda — including disinformation tied to the Moldovan election — and documents attempts to use the models to assist in designing conventional weapons such as firearms, rockets, weaponized drones and bombs.
Biotech-related cases raise the greatest concern
According to the New York Times account of the report, the cases connected to biological research are the most worrying. Anthropic did not disclose the names of researchers or institutions, their countries, or the specific pathogens involved, partly because in many instances it could not determine whether the intent was lawful or malicious. The company reported that certain researchers circumvented regional access restrictions and tried to conceal the true purpose of their work to evade safety filters.
In one May case, a researcher sought Claude’s help drafting a grant application to fund gain-of-function research on the chikungunya virus. The researcher aimed to generate mutations that would increase the pathogen’s virulence during repeated infections in living animals. Anthropic noted that while this type of work can be legitimate — for example, in pursuit of vaccine development — it also carries the risk of producing enhanced pathogens.
The company said it was particularly alarmed that the proposed experiments were to be carried out at a military research institute.
Model capabilities and tighter safeguards
Anthropic emphasized that whereas earlier versions of its models were not judged capable of materially contributing to dangerous biological research based on last year’s evaluations, its current models can perform complex scientific tasks. That capability growth prompted the company to implement stricter safety measures, especially to limit queries related to dual-use biological research.
Expert comments
Andrew Weber, a staff member at the Council on Strategic Risks and a former deputy assistant secretary of defense in the Obama administration, called the report’s examples “stunning” demonstrations of how state-supported biological weapons developers might try to exploit advanced AI models. Weber argued that access to AI tools capable of supporting such research should be restricted and made available only to trusted researchers.
Susan Monarez, a microbiologist and former biothreat security official in the Obama administration, warned that advanced AI could enable bad actors to hide malicious work behind the guise of legitimate research, producing pathogens whose consequences are unpredictable and uncontrollable once released.
Conclusion
Anthropic’s eight-month review highlights a range of misuse attempts — from disinformation and surveillance to weapon design and risky biological research — and stresses that improvements in model capabilities raise new security concerns. The company withheld identifying details about people, institutions and pathogens, citing uncertainty about intent and safety considerations.
Tags: artificial intelligence, biological weapon, biotechnology, chatbot, security risk, disinformation



